Documentation
¶
Overview ¶
Package releasecontract defines the public, provider-neutral identity of a SecondBox release.
Index ¶
- Constants
- func ArtifactManifestLocation(version string) string
- func BinaryLocation(version, name, platform string) string
- func CompareVersions(left, right string) (int, error)
- func Digest(data []byte) string
- func GVisorMaterializationLocation(version string) string
- func GVisorQualificationEvidenceLocation(version string, pod bool) string
- func GVisorQualificationSuite(pod bool) string
- func InstallBootstrapLocation(version string) string
- func InstallerQualificationEvidenceLocation(version string) string
- func ParseTag(tag string) (string, error)
- func QualificationEvidenceLocation(version string) string
- func SourceFreeSuiteLocation(version string) string
- type ArtifactManifest
- type BinaryArtifact
- type BundledServiceImages
- type GVisorArtifact
- type GVisorLaunchArtifact
- type GVisorMaterialization
- type GVisorMaterializationKey
- type GVisorQualificationDeviceEvidence
- type GVisorQualificationEvidence
- type GVisorQualificationHostEvidence
- type Identity
- type InstallerQualificationEvidence
- type MicroVMArtifact
- type OCIArtifact
- type OpenAPIArtifact
- type PlatformMatrix
- type ProtocolWindow
- type QualificationDeviceEvidence
- type QualificationEvidence
- type QualificationFilesystemEvidence
- type QualificationHostEvidence
- type Reference
- type SDKArtifact
- type SignedComponent
- type StandardBundleArtifact
- type StandardProfileIdentity
Constants ¶
const ( ArtifactManifestSchema = "secondbox.release/artifact-manifest/v6" // LegacyArtifactManifestSchema is accepted for recorded releases that // predate the gVisor artifact section; a newer updater still // authenticates them. LegacyArtifactManifestSchema = "secondbox.release/artifact-manifest/v5" QualificationEvidenceSchema = "secondbox.release/qualification-evidence/v2" LegacyQualificationEvidenceSchema = "secondbox.release/qualification-evidence/v1" InstallerQualificationEvidenceSchema = "secondbox.release/installer-qualification-evidence/v2" LegacyInstallerQualificationEvidenceSchema = "secondbox.release/installer-qualification-evidence/v1" TypeScriptPackage = "@secondstack-ai/secondbox" GoModule = "github.com/SecondStack-AI/SecondBox" ControlPlaneImage = "ghcr.io/secondstack-ai/secondbox/control-plane" RunnerImage = "ghcr.io/secondstack-ai/secondbox/runner" MicroVMImage = "ghcr.io/secondstack-ai/secondbox/microvm-artifacts" InstallerToolsImage = "ghcr.io/secondstack-ai/secondbox/installer-tools" GVisorRunnerImage = "ghcr.io/secondstack-ai/secondbox/runner-gvisor" GVisorImage = "ghcr.io/secondstack-ai/secondbox/gvisor-artifacts" )
const GVisorMaterializationSchema = "secondbox.runner/backend-materialization/v1"
GVisorMaterializationSchema is the runner's backend materialization schema.
Variables ¶
This section is empty.
Functions ¶
func BinaryLocation ¶
func CompareVersions ¶ added in v0.6.0
CompareVersions orders two canonical release versions according to SemVer precedence. It rejects build metadata because release tags do not admit it.
func GVisorMaterializationLocation ¶ added in v0.9.0
GVisorMaterializationLocation is the canonical release file carrying the gVisor backend materialization.
func GVisorQualificationEvidenceLocation ¶ added in v0.9.0
GVisorQualificationEvidenceLocation is the canonical release file carrying the gVisor host (or pod) scenario evidence.
func GVisorQualificationSuite ¶ added in v0.9.0
GVisorQualificationSuite names the evidence suite of a gVisor run.
func InstallBootstrapLocation ¶ added in v0.4.0
func InstallerQualificationEvidenceLocation ¶ added in v0.4.0
func QualificationEvidenceLocation ¶ added in v0.2.0
func SourceFreeSuiteLocation ¶
Types ¶
type ArtifactManifest ¶
type ArtifactManifest struct {
SchemaVersion string `json:"schemaVersion"`
Candidate bool `json:"candidate,omitempty"`
Identity
OpenAPI OpenAPIArtifact `json:"openapi"`
RunnerProtocol ProtocolWindow `json:"runnerProtocol"`
GuestProtocol ProtocolWindow `json:"guestProtocol"`
Platforms PlatformMatrix `json:"platforms"`
GoSDK SDKArtifact `json:"goSdk"`
TypeScriptSDK SDKArtifact `json:"typeScriptSdk"`
ControlPlane OCIArtifact `json:"controlPlane"`
Runner OCIArtifact `json:"runner"`
InstallerTools OCIArtifact `json:"installerTools"`
BundledServices BundledServiceImages `json:"bundledServices"`
InstallBootstrap Reference `json:"installBootstrap"`
MicroVM MicroVMArtifact `json:"microvm"`
GVisor *GVisorArtifact `json:"gvisor,omitempty"`
Binaries []BinaryArtifact `json:"binaries"`
SBOMs []Reference `json:"sboms"`
ArtifactAttestations []Reference `json:"artifactAttestations,omitempty"`
SourceFreeSuite Reference `json:"sourceFreeSuite,omitempty"`
QualificationEvidence Reference `json:"qualificationEvidence"`
InstallerQualificationEvidence Reference `json:"installerQualificationEvidence"`
StandardBundles []StandardBundleArtifact `json:"standardBundles"`
}
ArtifactManifest contains immutable release artifact identity.
func DecodeArtifactManifest ¶
func DecodeArtifactManifest(data []byte) (ArtifactManifest, error)
func (ArtifactManifest) InstallerQualificationSubjectDigest ¶ added in v0.4.0
func (manifest ArtifactManifest) InstallerQualificationSubjectDigest() (string, error)
InstallerQualificationSubjectDigest identifies all public release contract fields except the installer-evidence reference itself. Omitting that one reference avoids a digest cycle while still binding qualification to the exact binaries, images, protocols, bundles, and other immutable release objects that the final manifest publishes.
func (ArtifactManifest) Validate ¶
func (manifest ArtifactManifest) Validate() error
type BinaryArtifact ¶
type BundledServiceImages ¶ added in v0.4.0
type BundledServiceImages struct {
Postgres string `json:"postgres"`
}
type GVisorArtifact ¶ added in v0.9.0
type GVisorArtifact struct {
Identity Identity `json:"identity"`
RunnerReference string `json:"runnerReference"`
ImageReference string `json:"imageReference"`
Materialization Reference `json:"materialization"`
MaterializationDigest string `json:"materializationDigest"`
FlatRootDigest string `json:"flatRootDigest"`
RunscRelease string `json:"runscRelease"`
QualificationEvidence Reference `json:"qualificationEvidence"`
PodQualificationEvidence Reference `json:"podQualificationEvidence"`
}
GVisorArtifact names the gVisor backend distribution: the runner image and the artifact transport carrying the prepared flat root, the launch artifacts, and the backend materialization whose canonical digest runners and platform operators pin. The materialization is also a release file.
func (GVisorArtifact) VerifyGVisorMaterialization ¶ added in v0.9.0
func (artifact GVisorArtifact) VerifyGVisorMaterialization(data []byte) error
VerifyGVisorMaterialization checks that a published materialization agrees with the identities the artifact manifest records for it.
type GVisorLaunchArtifact ¶ added in v0.9.0
type GVisorMaterialization ¶ added in v0.9.0
type GVisorMaterialization struct {
SchemaVersion string `json:"schemaVersion"`
Key GVisorMaterializationKey `json:"key"`
SourceOCIManifestDigest string `json:"sourceOciManifestDigest,omitempty"`
FlatRootDigest string `json:"flatRootDigest,omitempty"`
LaunchArtifacts []GVisorLaunchArtifact `json:"launchArtifacts"`
AgentProtocolGeneration uint32 `json:"agentProtocolGeneration"`
AgentFeatures []string `json:"agentFeatures"`
BackendBuildID string `json:"backendBuildId"`
HelperBuildID string `json:"helperBuildId,omitempty"`
}
GVisorMaterialization mirrors the runner's backend materialization document field for field, so its canonical digest here equals the runner's.
func DecodeGVisorMaterialization ¶ added in v0.9.0
func DecodeGVisorMaterialization(data []byte) (GVisorMaterialization, error)
DecodeGVisorMaterialization strictly decodes a published materialization.
func (GVisorMaterialization) Digest ¶ added in v0.9.0
func (materialization GVisorMaterialization) Digest() (string, error)
Digest is the canonical digest runners pin: sha256 over the compact JSON encoding of the validated typed document.
func (GVisorMaterialization) Validate ¶ added in v0.9.0
func (materialization GVisorMaterialization) Validate() error
Validate applies the runner's materialization invariants for the gVisor backend, so a release cannot publish a document a runner would refuse.
type GVisorMaterializationKey ¶ added in v0.9.0
type GVisorQualificationDeviceEvidence ¶ added in v0.9.0
type GVisorQualificationEvidence ¶ added in v0.9.0
type GVisorQualificationEvidence struct {
SchemaVersion string `json:"schemaVersion"`
SourceCommit string `json:"sourceCommit"`
RepositoryDirty bool `json:"repositoryDirty"`
Suite string `json:"suite"`
Backend string `json:"backend"`
PassCount int64 `json:"passCount"`
WallClockSeconds int64 `json:"wallClockSeconds"`
Host GVisorQualificationHostEvidence `json:"host"`
QualifiedAt string `json:"qualifiedAt"`
}
GVisorQualificationEvidence is the scenario evidence of a gVisor host or pod run: the same schema as the Firecracker evidence, on a host without KVM and naming its backend.
func DecodeGVisorQualificationEvidence ¶ added in v0.9.0
func DecodeGVisorQualificationEvidence(data []byte, pod bool) (GVisorQualificationEvidence, error)
func (GVisorQualificationEvidence) Validate ¶ added in v0.9.0
func (evidence GVisorQualificationEvidence) Validate(pod bool) error
func (GVisorQualificationEvidence) ValidateForRelease ¶ added in v0.9.0
func (evidence GVisorQualificationEvidence) ValidateForRelease(sourceCommit string, pod bool) error
type GVisorQualificationHostEvidence ¶ added in v0.9.0
type GVisorQualificationHostEvidence struct {
Platform string `json:"platform"`
KVM GVisorQualificationDeviceEvidence `json:"kvm"`
TUN GVisorQualificationDeviceEvidence `json:"tun"`
WorkspaceFilesystem QualificationFilesystemEvidence `json:"workspaceFilesystem"`
}
type Identity ¶
type Identity struct {
Version string `json:"version"`
Tag string `json:"tag"`
SourceCommit string `json:"sourceCommit"`
}
Identity is repeated on every independently inspectable release object.
type InstallerQualificationEvidence ¶ added in v0.4.0
type InstallerQualificationEvidence struct {
SchemaVersion string `json:"schemaVersion"`
SourceCommit string `json:"sourceCommit"`
RepositoryDirty bool `json:"repositoryDirty"`
Suite string `json:"suite"`
PassCount int64 `json:"passCount"`
WallClockSeconds int64 `json:"wallClockSeconds"`
Host QualificationHostEvidence `json:"host"`
ReleaseManifestDigest string `json:"releaseManifestDigest"`
FilesystemIdentity string `json:"filesystemIdentity"`
RebootPassed bool `json:"rebootPassed"`
QualifiedAt string `json:"qualifiedAt"`
}
func DecodeInstallerQualificationEvidence ¶ added in v0.4.0
func DecodeInstallerQualificationEvidence(data []byte) (InstallerQualificationEvidence, error)
func (InstallerQualificationEvidence) Validate ¶ added in v0.4.0
func (evidence InstallerQualificationEvidence) Validate() error
func (InstallerQualificationEvidence) ValidateForRelease ¶ added in v0.4.0
func (evidence InstallerQualificationEvidence) ValidateForRelease(sourceCommit, qualificationSubjectDigest string) error
type MicroVMArtifact ¶
type MicroVMArtifact struct {
Identity Identity `json:"identity"`
ImageReference string `json:"imageReference"`
SignedManifestDigest string `json:"signedManifestDigest"`
SigningKeyFingerprint string `json:"signingKeyFingerprint"`
RuntimeBundle SignedComponent `json:"runtimeBundle"`
ToolchainBundle SignedComponent `json:"toolchainBundle"`
}
type OCIArtifact ¶
type OpenAPIArtifact ¶
type PlatformMatrix ¶
type ProtocolWindow ¶
type QualificationDeviceEvidence ¶ added in v0.2.0
type QualificationEvidence ¶ added in v0.2.0
type QualificationEvidence struct {
SchemaVersion string `json:"schemaVersion"`
SourceCommit string `json:"sourceCommit"`
RepositoryDirty bool `json:"repositoryDirty"`
Suite string `json:"suite"`
PassCount int64 `json:"passCount"`
WallClockSeconds int64 `json:"wallClockSeconds"`
Host QualificationHostEvidence `json:"host"`
QualifiedAt string `json:"qualifiedAt"`
}
func DecodeQualificationEvidence ¶ added in v0.2.0
func DecodeQualificationEvidence(data []byte) (QualificationEvidence, error)
func (QualificationEvidence) Validate ¶ added in v0.2.0
func (evidence QualificationEvidence) Validate() error
func (QualificationEvidence) ValidateForRelease ¶ added in v0.2.0
func (evidence QualificationEvidence) ValidateForRelease(sourceCommit string) error
type QualificationFilesystemEvidence ¶ added in v0.2.0
type QualificationHostEvidence ¶ added in v0.2.0
type QualificationHostEvidence struct {
Platform string `json:"platform"`
KVM QualificationDeviceEvidence `json:"kvm"`
TUN QualificationDeviceEvidence `json:"tun"`
WorkspaceFilesystem QualificationFilesystemEvidence `json:"workspaceFilesystem"`
}
type SDKArtifact ¶
type SignedComponent ¶ added in v0.1.3
type SignedComponent struct {
ArtifactID string `json:"artifactId"`
ManifestDigest string `json:"manifestDigest"`
MandatoryGuestFeatures []string `json:"mandatoryGuestFeatures"`
}
SignedComponent is one independently selected component bound by the signed top-level microVM manifest.
type StandardBundleArtifact ¶
type StandardBundleArtifact struct {
Identity Identity `json:"identity"`
Name string `json:"name"`
Document Reference `json:"document"`
Profiles []StandardProfileIdentity `json:"profiles"`
}