types

package
v0.28.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 28, 2026 License: Apache-2.0 Imports: 2 Imported by: 0

Documentation

Overview

Package types is a little bit of a hacky way to generate the cargo-ship-config jsonschema

Index

Constants

This section is empty.

Variables

View Source
var CommonRegistries = []string{
	"docker.io",
	"ghcr.io",
	"quay.io",
	"gcr.io",
	"registry.k8s.io",
	"public.ecr.aws",
}

CommonRegistries are suggested, non-exhaustive registry names used in generated schemas -- editors with YAML/JSON schema support (e.g. the redhat.vscode-yaml extension) offer them as autocomplete, for RegistryOverrideMap's registry_override keys here and for ZarfClusterRegistrieName's registry name field in the cluster API.

Functions

This section is empty.

Types

type AgeOptions

type AgeOptions struct {
	// IdentityFiles are paths to identity files, each holding either the age private keys that
	// decrypt registry credentials or an SSH private key. Equivalent to repeating
	// --age-identity-file.
	IdentityFiles []string `` /* 155-byte string literal not displayed */
	// Recipients are the public keys registry credentials are encrypted to, each either an age
	// recipient or an SSH public key. Equivalent to repeating --age-recipient.
	Recipients []string `` /* 282-byte string literal not displayed */
	// RecipientsFiles are paths to files holding public keys, one per line, with # comments
	// allowed, mixing age recipients and SSH public keys freely. An authorized_keys file works as
	// it is. Equivalent to repeating --age-recipients-file.
	RecipientsFiles []string `` /* 155-byte string literal not displayed */
}

AgeOptions holds the values for the `.age` section of the config file, the age alternative to the Ansible Vault password given by --vault-password-file.

It sits at the root rather than under `.distro` because both halves of the workflow read it: the `cargoship vault` commands that write ciphertext into a cluster configuration, and the install commands that read it back at apply time.

Each is a list because age is built around encrypting to more than one key: a configuration is normally encrypted to every operator who has to apply it plus whatever CI holds, and an operator may hold more than one identity. Recipients here are equivalent to repeating --age-recipient, which is what makes a shared recipient set something a team can commit alongside the config rather than something every command line has to restate.

type ApplyOptions

type ApplyOptions struct{}

ApplyOptions holds the values for the `.distro.apply` section of the config file

type DistroConfig

type DistroConfig struct {
	// CachePath is the folder where cargoship caches what it fetches: oras artifacts, and the release assets the example generation targets read
	CachePath string `json:"zarf_cache,omitempty" mapstructure:"zarf_cache"`
	// DistroOpts are various options used by the command
	DistroOpts DistroOptions `json:"distro,omitempty" mapstructure:"distro"`
	// LogFormat how the logs are displayed well running
	LogFormat string `json:"log_format,omitempty" mapstructure:"log_format" jsonschema:"enum=console,enum=json,enum=dev,default=console"`
	// LogLevel the level of logs that will be displayed
	LogLevel string `json:"log_level,omitempty" mapstructure:"log_level" jsonschema:"enum=warn,enum=info,enum=debug,enum=trace,default=info"`
	// NoColor whether to disable terminal color codes in logging and stdout prints
	NoColor bool `json:"no_color,omitempty" mapstructure:"no_color"`
	// LogFile enables always writing a full-verbosity debug log to a file, regardless of LogLevel
	LogFile bool `json:"log_file,omitempty" mapstructure:"log_file"`
	// Architecture the CPU architecture to use for OCI operations
	Architecture string `json:"architecture,omitempty" mapstructure:"architecture"`
	// TempDirectory the directory where we store stuff before deleting them
	TempDirectory string `json:"tmp_dir,omitempty" mapstructure:"tmp_dir" jsonschema:"default=/tmp"`
	// Timeout the longest we will run long ran tasks before failing
	Timeout string `json:"timeout,omitempty" mapstructure:"timeout" jsonschema:"default=20m"`
	// AgeOpts are the age keys used to encrypt and decrypt registry credentials
	AgeOpts AgeOptions `json:"age,omitempty" mapstructure:"age"`
}

DistroConfig holds the values for the `.`, or root, section of the config file

type DistroCreateOptions

type DistroCreateOptions struct {
	// RegistryOverride maps a source registry to the registry cargoship uses instead
	// when pulling images, for example {"docker.io": "mirror.example.com"}
	RegistryOverride RegistryOverrideMap `json:"registry_override,omitempty" mapstructure:"-"` // mapstructure:"-": viper always splits a map key on "." when merging its settings tree, so a domain key like "docker.io" gets silently corrupted into a nested map; read directly from the config file instead (see initViper in cmd/viper.go)
}

DistroCreateOptions holds the values for the `.distro.create` section of the config file

type DistroDeployOptions

type DistroDeployOptions struct {
	// Retries how many times we will try to push a package
	Retries int `json:"retries,omitempty" mapstructure:"retries"`
}

DistroDeployOptions holds the values for the `.distro.deploy` section of the config file

type DistroOptions

type DistroOptions struct {
	// CreateOpts are options used by the create subcommand
	CreateOpts DistroCreateOptions `json:"create,omitempty" mapstructure:"create"`
	// PublishOpts are options used by the publish subcommand
	PublishOpts DistroPublishOptions `json:"publish,omitempty" mapstructure:"publish"`
	// DeployOpts are options used by the deploy subcommand
	DeployOpts DistroDeployOptions `json:"deploy,omitempty" mapstructure:"deploy"`
	// ApplyOpts are options used by the apply subcommand
	ApplyOpts ApplyOptions `json:"apply,omitempty" mapstructure:"apply"`
	// ResetOptions are options used by the reset subcommand
	ResetOpts ResetOptions `json:"reset,omitempty" mapstructure:"reset"`
	// OCIConcurrency is how many concurrent oci artifacts that will be pushed at a time
	OCIConcurrency int `json:"oci_concurrency,omitempty" mapstructure:"oci_concurrency"`
	// Concurrency how many nodes we will try to interact with at a time, 0 means that all nodes will be done at once
	Concurrency int `json:"concurrency,omitempty" mapstructure:"concurrency" jsonschema:"minimum=0"`
	// FAPolicyd whether we will update hosts with fapolicyd
	FAPolicyd bool `json:"fapolicyd,omitempty" mapstructure:"fapolicyd" jsonschema:"default=true"`
	// FirewallUpdate whether we will update the host firewall
	FirewallUpdate bool `json:"firewall,omitempty" mapstructure:"firewall" jsonschema:"default=true"`
	// HostUpdate whether we will update the etc host file
	HostUpdate bool `json:"hosts,omitempty" mapstructure:"hosts" jsonschema:"default=true"`
	// AllowUnmanagedNodes whether an apply continues when the cluster holds a node that no host
	// in the config accounts for
	AllowUnmanagedNodes bool `json:"allow_unmanaged_nodes,omitempty" mapstructure:"allow_unmanaged_nodes"`
	// LabelNodes whether we will check and add the node-role.kubernetes.io/<profile> label on nodes
	LabelNodes bool `json:"label_nodes,omitempty" mapstructure:"label_nodes" jsonschema:"default=true"`
	// UpdateKubeConfig whether we will update a kubeconfig file with the admin creds for the cluster
	UpdateKubeConfig bool `json:"update_kubeconfig,omitempty" mapstructure:"update_kubeconfig" jsonschema:"default=true"`
	// KubeConfig path of the kubeconfig file the admin creds are merged into, the standard
	// location -- KUBECONFIG, else ~/.kube/config -- when empty
	KubeConfig string `json:"kubeconfig,omitempty" mapstructure:"kubeconfig"`
	// WorkerConcurrency number of worker nodes that will be upgraded at once, as a fixed count
	// ("5") or a percentage of the batch ("25%")
	WorkerConcurrency string `` /* 177-byte string literal not displayed */
	// Retry number of retries we will try
	Retry int `json:"retry,omitempty" mapstructure:"retry" jsonschema:"minimum=0"`
	// Type of distro we are interacting with
	Type string `json:"type,omitempty" mapstructure:"type" jsonschema:"enum=rke2,enum=k3s"`
	// Output the folder that we will create the distro tar balls in
	Output string `json:"output,omitempty" mapstructure:"output"`
	// Verify the Cargoship package signature
	Verify string `json:"verify,omitempty" mapstructure:"-" jsonschema:"enum=never,enum=if-possible,enum=always"` // mapstructure:"-": common_verify.go needs v.IsSet to distinguish "unset" from "set to zero value" (never read from the resolved struct)
	// PublicKey path to public key file for validating signed packages
	PublicKey string `json:"public_key,omitempty" mapstructure:"public_key"`
	// CertificateIdentity required identity claim in the signing certificate
	CertificateIdentity string `json:"certificate_identity,omitempty" mapstructure:"certificate_identity"`
	// CertificateIdentityRegexp equired identity claim in the signing certificate, allows usage of regex
	CertificateIdentityRegexp string `json:"certificate_identity_regexp,omitempty" mapstructure:"certificate_identity_regexp"`
	// CertificateOIDCIssuer required OIDC issuer claim in the signing certificate
	CertificateOIDCIssuer string `json:"certificate_oidc_issuer,omitempty" mapstructure:"certificate_oidc_issuer"`
	// CertificateOIDCIssuerRegexp required OIDC issuer claim in the signing certificate, allows usage of regex
	CertificateOIDCIssuerRegexp string `json:"certificate_oidc_issuer_regexp,omitempty" mapstructure:"certificate_oidc_issuer_regexp"`
	// TrustedRoot path to a Sigstore TrustedRoot JSON
	TrustedRoot string `json:"trusted_root,omitempty" mapstructure:"trusted_root"`
	// InsecureIgnoreTLog
	InsecureIgnoreTLog string `json:"insecure_ignore_tlog,omitempty" mapstructure:"-"` // mapstructure:"-": same v.IsSet reasoning as Verify above, plus this is really a bool (read via v.GetBool) despite the string type
	// UseSignedTimestamps verify RFC3161 signed timestamps in the bundle. Auto-enabled when the bundle contains TSA timestamp data.
	UseSignedTimestamps string `json:"use_signed_timestamps,omitempty" mapstructure:"-"` // mapstructure:"-": really a bool (read via v.GetBool in common_verify.go) despite the string type
}

DistroOptions holds the values for the `.distro` section of the config file

type DistroPublishOptions

type DistroPublishOptions struct {
	// SigningKey is the path to the private key, a Cosign-supported key provider, used to sign, or re-sign, the package
	SigningKey string `` /* 197-byte string literal not displayed */
	// SigningKeyPassword the password for the private key used for signing
	SigningKeyPassword string `json:"signing_key_password,omitempty" mapstructure:"signing_key_password"`
}

DistroPublishOptions holds the values for the `.distro.publish` section of the config file

type RegistryOverrideMap

type RegistryOverrideMap map[string]string

RegistryOverrideMap maps a source registry to the registry cargoship uses instead. It's a named type (rather than a bare map[string]string) solely so it can implement JSONSchemaExtend below and suggest common registries in the generated schema; the config file is not restricted to those.

func (RegistryOverrideMap) JSONSchemaExtend

func (RegistryOverrideMap) JSONSchemaExtend(s *jsonschema.Schema)

JSONSchemaExtend adds CommonRegistries to the schema's properties, alongside the additionalProperties the reflector already set for the map[string]string element type, so the suggestions are additive and don't restrict which keys are allowed.

type ResetOptions

type ResetOptions struct{}

ResetOptions holds the values for the `.distro.reset` section of the config file

Directories

Path Synopsis
Package distrocfg defines the standard interface that all distro config settings
Package distrocfg defines the standard interface that all distro config settings
registry
Package registry is used to register a distro
Package registry is used to register a distro
os
Package os is for running commands on a remote host
Package os is for running commands on a remote host
linux
Package linux is implementing the interface github.com/colonel-byte/cargoship/types/os.Configurer for Linux based hosts
Package linux is implementing the interface github.com/colonel-byte/cargoship/types/os.Configurer for Linux based hosts
linux/enterpriselinux
Package enterpriselinux is implementing the interface github.com/colonel-byte/cargoship/types/os.Configurer for Enterprise Linux hosts
Package enterpriselinux is implementing the interface github.com/colonel-byte/cargoship/types/os.Configurer for Enterprise Linux hosts

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL