Documentation
¶
Overview ¶
Package artifact defines the content-addressed forms of what a policy evaluation depends on: the policy bundle, the input data and the policy data. Agents upload these as they have them; the API converts them to the canonical forms here and hashes the result, so equal content always has one digest. Stored digests must stay reproducible, so the forms are permanent. Golden tests pin them.
Index ¶
- Constants
- Variables
- func Canonical(mediaType string, content []byte, maxBytes int64) ([]byte, error)
- func CanonicalBundle(archive []byte, maxBytes int64) ([]byte, error)
- func CanonicalJSON(v any) ([]byte, error)
- func Digest(b []byte) string
- func IsReservedProp(name string) bool
- func ValidDigest(s string) bool
- type Bundle
- type Info
Constants ¶
const ( // MediaTypePolicyBundle is a policy bundle. Uploads may be a tar or a gzipped tar; the // stored form is always the canonical tar CanonicalBundle writes. MediaTypePolicyBundle = "application/vnd.ccf.policy-bundle.v1+tar" // MediaTypeJSON is JSON. Uploads may be formatted in any way; the stored form is always // the canonical JSON CanonicalJSON writes. MediaTypeJSON = "application/json" )
const ( PropPolicyBundleDigest = "_policy_bundle_digest" PropPolicyInputDigest = "_policy_input_digest" PropPolicyDataDigest = "_policy_data_digest" )
Evidence props the API writes to record which artifacts produced a piece of evidence. They are covered by the evidence signature. Clients may not set them themselves.
Variables ¶
var ErrInvalid = errors.New("invalid artifact content")
ErrInvalid wraps every reason content cannot be made canonical.
Functions ¶
func Canonical ¶
Canonical converts uploaded content of mediaType to its canonical form. maxBytes bounds the canonical size, which also bounds how far a compressed bundle may expand.
func CanonicalBundle ¶
CanonicalBundle rewrites a policy bundle archive, a tar or a gzipped tar, as an uncompressed tar with every variable removed: regular files only, sorted by slash-separated path, mode 0644, owner 0/0, zero modification time. Directory entries are dropped. Links, devices, absolute or escaping paths and duplicate paths are rejected, and the files may total at most maxBytes, however well they compress.
func CanonicalJSON ¶
CanonicalJSON encodes v so that equal JSON values always give equal bytes: object keys sorted, no insignificant whitespace, no HTML escaping, and numbers kept exactly as they were written rather than rounded through float64. The playback endpoint decodes input the same way, so a policy replayed from these bytes sees the values the agent evaluated.
func IsReservedProp ¶
IsReservedProp reports whether name is one of the props only the API may write.
func ValidDigest ¶
ValidDigest reports whether s is a well-formed digest.
Types ¶
type Bundle ¶
type Bundle struct {
// Modules maps each Rego file's path in the bundle to its source.
Modules map[string]string
// Data is the bundle's merged data documents (data.json / data.yaml files).
Data map[string]any
}
Bundle is a policy bundle read back from its canonical tar.
func ReadBundleTar ¶
ReadBundleTar parses a bundle tar with OPA's bundle reader, so modules and data documents are interpreted exactly as when the agent loads the bundle directory.