artifact

package
v0.20.0-rc3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 30, 2026 License: AGPL-3.0 Imports: 16 Imported by: 0

Documentation

Overview

Package artifact defines the content-addressed forms of what a policy evaluation depends on: the policy bundle, the input data and the policy data. Agents upload these as they have them; the API converts them to the canonical forms here and hashes the result, so equal content always has one digest. Stored digests must stay reproducible, so the forms are permanent. Golden tests pin them.

Index

Constants

View Source
const (
	// MediaTypePolicyBundle is a policy bundle. Uploads may be a tar or a gzipped tar; the
	// stored form is always the canonical tar CanonicalBundle writes.
	MediaTypePolicyBundle = "application/vnd.ccf.policy-bundle.v1+tar"
	// MediaTypeJSON is JSON. Uploads may be formatted in any way; the stored form is always
	// the canonical JSON CanonicalJSON writes.
	MediaTypeJSON = "application/json"
)
View Source
const (
	PropPolicyBundleDigest = "_policy_bundle_digest"
	PropPolicyInputDigest  = "_policy_input_digest"
	PropPolicyDataDigest   = "_policy_data_digest"
)

Evidence props the API writes to record which artifacts produced a piece of evidence. They are covered by the evidence signature. Clients may not set them themselves.

Variables

View Source
var ErrInvalid = errors.New("invalid artifact content")

ErrInvalid wraps every reason content cannot be made canonical.

Functions

func Canonical

func Canonical(mediaType string, content []byte, maxBytes int64) ([]byte, error)

Canonical converts uploaded content of mediaType to its canonical form. maxBytes bounds the canonical size, which also bounds how far a compressed bundle may expand.

func CanonicalBundle

func CanonicalBundle(archive []byte, maxBytes int64) ([]byte, error)

CanonicalBundle rewrites a policy bundle archive, a tar or a gzipped tar, as an uncompressed tar with every variable removed: regular files only, sorted by slash-separated path, mode 0644, owner 0/0, zero modification time. Directory entries are dropped. Links, devices, absolute or escaping paths and duplicate paths are rejected, and the files may total at most maxBytes, however well they compress.

func CanonicalJSON

func CanonicalJSON(v any) ([]byte, error)

CanonicalJSON encodes v so that equal JSON values always give equal bytes: object keys sorted, no insignificant whitespace, no HTML escaping, and numbers kept exactly as they were written rather than rounded through float64. The playback endpoint decodes input the same way, so a policy replayed from these bytes sees the values the agent evaluated.

func Digest

func Digest(b []byte) string

Digest returns the content address of b: "sha256:" and 64 lowercase hex characters.

func IsReservedProp

func IsReservedProp(name string) bool

IsReservedProp reports whether name is one of the props only the API may write.

func ValidDigest

func ValidDigest(s string) bool

ValidDigest reports whether s is a well-formed digest.

Types

type Bundle

type Bundle struct {
	// Modules maps each Rego file's path in the bundle to its source.
	Modules map[string]string
	// Data is the bundle's merged data documents (data.json / data.yaml files).
	Data map[string]any
}

Bundle is a policy bundle read back from its canonical tar.

func ReadBundleTar

func ReadBundleTar(b []byte) (*Bundle, error)

ReadBundleTar parses a bundle tar with OPA's bundle reader, so modules and data documents are interpreted exactly as when the agent loads the bundle directory.

type Info

type Info struct {
	Digest    string `json:"digest"`
	MediaType string `json:"mediaType"`
	SizeBytes int64  `json:"sizeBytes"`
}

Info describes a stored artifact without its content.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL