Documentation
¶
Overview ¶
Package release implements the pure taskman-release/0 release-control model. It performs no I/O and grants no publication or execution authority.
Index ¶
- Constants
- Variables
- func AttestationDigest(a Attestation) wire.Digest
- func Authorized(role, operation, provenance string, configured map[string][]string) bool
- func CandidateDigest(c *Candidate) wire.Digest
- func DefinitionDigest(r *Record) wire.Digest
- func Encode(r *Record) []byte
- func PromotionDigest(p *Promotion) wire.Digest
- func ValidateGraph(records []*Record) error
- type Actor
- type Attestation
- type Candidate
- type Envelope
- type Gate
- type Observation
- type PredecessorBinding
- type Promotion
- type Readiness
- type Record
- type TicketBinding
Constants ¶
View Source
const ( OpCreate = "RELEASE_CREATE" OpUpdate = "RELEASE_UPDATE" OpCandidate = "RELEASE_CANDIDATE" OpExternalAttest = "RELEASE_EXTERNAL_ATTEST" OpManualAttest = "RELEASE_MANUAL_ATTEST" OpPromote = "RELEASE_PROMOTE" )
View Source
const ( Blocked = "BLOCKED" Unknown = "UNKNOWN" ReadyAttested = "READY_ATTESTED" Manual = "MANUAL_ATTESTATION" External = "EXTERNAL_ATTESTATION" )
View Source
const AttestationProfile = "taskman-release-attestation/0"
View Source
const MutationProfile = "taskman-release-mutation/0"
View Source
const Profile = "taskman-release/0"
Variables ¶
View Source
var DefaultRoleMatrix = map[string][]string{ "OWNER": Operations, "OPERATOR": {OpCandidate, OpCreate, OpExternalAttest, OpUpdate}, }
View Source
var Operations = []string{OpCandidate, OpCreate, OpExternalAttest, OpManualAttest, OpPromote, OpUpdate}
Functions ¶
func AttestationDigest ¶
func AttestationDigest(a Attestation) wire.Digest
func Authorized ¶
Authorized applies the policy-removable maximum role matrix. A configured role row may remove operations but can never add beyond the maximum.
func CandidateDigest ¶
func DefinitionDigest ¶
func PromotionDigest ¶
func ValidateGraph ¶
ValidateGraph checks the complete queue-scoped release DAG. It performs no I/O and does not treat graph validity as evidence that a release is ready.
Types ¶
type Attestation ¶
type Envelope ¶
type Envelope struct {
RequestID string
Actor Actor
QueueID wire.QueueID
ReleaseID string
ExpectedRevision *wire.Count
Operation string
Payload wire.Value
IssuedAt wire.Timestamp
Raw []byte
}
func DecodeEnvelope ¶
type Observation ¶
type PredecessorBinding ¶
type Record ¶
type Record struct {
QueueID wire.QueueID
ReleaseID string
Revision wire.Count
PreviousSha256 *wire.Digest
Version string
Title string
PredecessorIDs []string
TicketIDs []wire.TicketID
AcceptanceCriteria []string
RequiredGates []string
Candidate *Candidate
Attestations []Attestation
Promotion *Promotion
}
Click to show internal directories.
Click to hide internal directories.