MAQPNADocs

maqpna airgap

Build, verify and mirror offline (air-gap) install bundles

Operate-o json | yaml

Synopsis#

maqpna airgap bundle [--repo DIR] [--tag T] [--registry R] [--out DIR] [--key REF | --keyless] [--pull]
maqpna airgap verify DIR [--require-signature] [--key cosign.pub | --certificate-identity[-regexp] I --certificate-oidc-issuer U] [--trusted-root F]
maqpna airgap push   DIR --registry REG [--dry-run]

Description#

bundle runs hack/airgap-bundle.sh from a MAQPNA source checkout (--repo, default the current directory). verify exits 3 when a checksum, the signature (with --require-signature) or one of the 11 images fails. push copies every image of images.txt to REG with skopeo, crane or docker; then install with the bundle's hack/airgap-install.sh (SKIP_PUSH=1) or maqpna install.

Subcommands#

Examples#

maqpna airgap bundle --tag v1.4.0 --out bundle/
maqpna airgap verify bundle/ --require-signature --key cosign.pub
maqpna airgap push bundle/ --registry registry.internal:5000

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.
  • Exits 3 when the check fails or a result does not match (see exit codes below), so scripts and CI can act on it.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch)

Terminal demo#

maqpna airgap --help.cast

This command downloads signatures, images or charts from the network, so the recording shows its help.