maqpna verify
Verify signatures, SBOM attestations and checksums of MAQPNA releases
Synopsis#
maqpna verify release VERSION [--registry R] [--sbom] [--binaries DIR] [--no-images] [--no-chart]
maqpna verify image REF [--identity I | --identity-regexp RE] [--issuer URL] [--sbom]
maqpna verify chart REF|--version V [--registry R]
maqpna verify binary FILE [--bundle FILE.sigstore.json] [--checksums checksums.txt]
maqpna verify bundle DIR [--require-signature] [--key cosign.pub | --certificate-identity[-regexp] ...] [--trusted-root F]Description#
Exit status 3 when any check fails. Defaults trust the MAQPNA release workflows: images and the chart signed by the MAQPNA release.yml at the tag, binaries by the MAQPNA maqpna-signed-release.yml.
Subcommands#
maqpna verify releaseVerify every image, the chart and the binaries of a release
maqpna verify imageVerify an image's signature and, optionally, its SBOM attestation
maqpna verify chartVerify the Helm chart's signature
maqpna verify binaryVerify a binary against its Sigstore bundle and checksums
maqpna verify bundleVerify an air-gap bundle's checksums, signature and images
Examples#
maqpna verify release v1.4.0
maqpna verify binary ./maqpna --checksums checksums.txt
maqpna verify image ghcr.io/maqpna/gateway:v1.4.0 --sbomWhat happens when you run it#
- Prints a table by default;
-o jsonor-o yamlprint the data, and--jq EXPRfilters the JSON.
Exit codes#
| Code | Meaning |
|---|---|
0 | success |
1 | error (the message says what failed, with a hint when there is one) |
2 | usage error: unknown flag, missing argument or bad value; the synopsis is printed |
3 | a check failed, a change is blocked, or a result did not match (tamper, policy mismatch) (not used by this command) |
Related commands#
Terminal demo#
This command downloads signatures, images or charts from the network, so the recording shows its help.