MAQPNADocs

maqpna verify release

Verify every image, the chart and the binaries of a release

Operate-o json | yaml

Synopsis#

maqpna verify release VERSION [--registry R] [--sbom] [--binaries DIR] [--no-images] [--no-chart]

Description#

From the help of maqpna verify:

Exit status 3 when any check fails. Defaults trust the MAQPNA release workflows: images and the chart signed by the MAQPNA release.yml at the tag, binaries by the MAQPNA maqpna-signed-release.yml.

Flags#

FlagTypeDescriptionDefault
--binariesstringdirectory of downloaded release binaries (+ .sigstore.json, checksums.txt) to verifynone
--no-chartswitchskip the Helm chartnone
--no-imagesswitchskip the imagesnone
--registrystringimage registry prefix<release-registry>
--sbomswitchalso verify the SBOM attestation of every imagenone

The global flags (--context, -o, --no-color, ...) work with every command.

Examples#

maqpna verify release v1.4.0

What happens when you run it#

  • Prints a table by default; -o json or -o yaml print the data, and --jq EXPR filters the JSON.

Exit codes#

CodeMeaning
0success
1error (the message says what failed, with a hint when there is one)
2usage error: unknown flag, missing argument or bad value; the synopsis is printed
3a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command)

Terminal demo#

maqpna verify release --help.cast

This command downloads signatures, images or charts from the network, so the recording shows its help.