maqpna verify chart
Verify the Helm chart's signature
Synopsis#
maqpna verify chart REF|--version V [--registry R]Description#
From the help of maqpna verify:
Exit status 3 when any check fails. Defaults trust the MAQPNA release workflows: images and the chart signed by the MAQPNA release.yml at the tag, binaries by the MAQPNA maqpna-signed-release.yml.
Flags#
| Flag | Type | Description | Default |
|---|---|---|---|
--identity | string | exact signer identity (e.g. <release-repo>/.github/workflows/release.yml@refs/tags/v0.1.0) | none |
--identity-regexp | string | signer identity regexp (default: the MAQPNA release.yml at a v* tag) | none |
--issuer | string | OIDC issuer (default https://token.actions.githubusercontent.com) | none |
--registry | string | registry prefix for --version | <release-registry> |
--sbom | switch | also verify the SPDX SBOM attestation | none |
--version | string | chart: verify REGISTRY/charts/maqpna:VERSION | none |
The global flags (--context, -o, --no-color, ...) work with every command.
What happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Related commands#
Terminal demo#
This command downloads signatures, images or charts from the network, so the recording shows its help.