MAQPNADocs

maqpna verify chart

Verify the Helm chart's signature

Operate-o json | yaml

Synopsis#

maqpna verify chart  REF|--version V [--registry R]

Description#

From the help of maqpna verify:

Exit status 3 when any check fails. Defaults trust the MAQPNA release workflows: images and the chart signed by the MAQPNA release.yml at the tag, binaries by the MAQPNA maqpna-signed-release.yml.

Flags#

FlagTypeDescriptionDefault
--identitystringexact signer identity (e.g. <release-repo>/.github/workflows/release.yml@refs/tags/v0.1.0)none
--identity-regexpstringsigner identity regexp (default: the MAQPNA release.yml at a v* tag)none
--issuerstringOIDC issuer (default https://token.actions.githubusercontent.com)none
--registrystringregistry prefix for --version<release-registry>
--sbomswitchalso verify the SPDX SBOM attestationnone
--versionstringchart: verify REGISTRY/charts/maqpna:VERSIONnone

The global flags (--context, -o, --no-color, ...) work with every command.

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna verify chart --help.cast

This command downloads signatures, images or charts from the network, so the recording shows its help.