MAQPNADocs

maqpna verify bundle

Verify an air-gap bundle's checksums, signature and images

Operate-o json | yaml

Synopsis#

maqpna verify bundle DIR [--require-signature] [--key cosign.pub | --certificate-identity[-regexp] ...] [--trusted-root F]

Description#

From the help of maqpna verify:

Exit status 3 when any check fails. Defaults trust the MAQPNA release workflows: images and the chart signed by the MAQPNA release.yml at the tag, binaries by the MAQPNA maqpna-signed-release.yml.

Flags#

FlagTypeDescriptionDefault
--certificate-identitystringkeyless SHA256SUMS.cosign.bundle: exact signer identitynone
--certificate-identity-regexpstringkeyless: signer identity regexp (default: the MAQPNA release workflows)none
--certificate-oidc-issuerstringkeyless: OIDC issuer (default https://token.actions.githubusercontent.com)none
--keystringcosign public key for SHA256SUMS.sig (default DIR/cosign.pub)none
--no-image-checkswitchdo not require all 11 MAQPNA images in images.txtnone
--require-signatureswitchfail when the signature is missing or cannot be verifiednone
--trusted-rootstringkeyless: Sigstore trusted_root.json for offline verificationnone

The global flags (--context, -o, --no-color, ...) work with every command.

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna verify bundle --help.cast

This command downloads signatures, images or charts from the network, so the recording shows its help.