Documentation
¶
Index ¶
- Constants
- Variables
- type CheckAccessRequest
- func (x *CheckAccessRequest) ClearPattern()
- func (x *CheckAccessRequest) ClearRequester()
- func (x *CheckAccessRequest) GetPattern() string
- func (x *CheckAccessRequest) GetRequester() *Requester
- func (x *CheckAccessRequest) HasPattern() bool
- func (x *CheckAccessRequest) HasRequester() bool
- func (*CheckAccessRequest) ProtoMessage()
- func (x *CheckAccessRequest) ProtoReflect() protoreflect.Message
- func (x *CheckAccessRequest) Reset()
- func (x *CheckAccessRequest) SetPattern(v string)
- func (x *CheckAccessRequest) SetRequester(v *Requester)
- func (x *CheckAccessRequest) String() string
- type CheckAccessRequest_builder
- type CheckAccessResponse
- func (x *CheckAccessResponse) ClearDecision()
- func (x *CheckAccessResponse) GetDecision() Decision
- func (x *CheckAccessResponse) HasDecision() bool
- func (*CheckAccessResponse) ProtoMessage()
- func (x *CheckAccessResponse) ProtoReflect() protoreflect.Message
- func (x *CheckAccessResponse) Reset()
- func (x *CheckAccessResponse) SetDecision(v Decision)
- func (x *CheckAccessResponse) String() string
- type CheckAccessResponse_builder
- type DarwinSigningInfo
- func (x *DarwinSigningInfo) ClearCdHash()
- func (x *DarwinSigningInfo) ClearCommonName()
- func (x *DarwinSigningInfo) ClearIdentifier()
- func (x *DarwinSigningInfo) ClearOrganization()
- func (x *DarwinSigningInfo) ClearStatus()
- func (x *DarwinSigningInfo) ClearTeamId()
- func (x *DarwinSigningInfo) GetCdHash() string
- func (x *DarwinSigningInfo) GetCommonName() string
- func (x *DarwinSigningInfo) GetIdentifier() string
- func (x *DarwinSigningInfo) GetOrganization() string
- func (x *DarwinSigningInfo) GetStatus() uint32
- func (x *DarwinSigningInfo) GetTeamId() string
- func (x *DarwinSigningInfo) HasCdHash() bool
- func (x *DarwinSigningInfo) HasCommonName() bool
- func (x *DarwinSigningInfo) HasIdentifier() bool
- func (x *DarwinSigningInfo) HasOrganization() bool
- func (x *DarwinSigningInfo) HasStatus() bool
- func (x *DarwinSigningInfo) HasTeamId() bool
- func (*DarwinSigningInfo) ProtoMessage()
- func (x *DarwinSigningInfo) ProtoReflect() protoreflect.Message
- func (x *DarwinSigningInfo) Reset()
- func (x *DarwinSigningInfo) SetCdHash(v string)
- func (x *DarwinSigningInfo) SetCommonName(v string)
- func (x *DarwinSigningInfo) SetIdentifier(v string)
- func (x *DarwinSigningInfo) SetOrganization(v string)
- func (x *DarwinSigningInfo) SetStatus(v uint32)
- func (x *DarwinSigningInfo) SetTeamId(v string)
- func (x *DarwinSigningInfo) String() string
- type DarwinSigningInfo_builder
- type Decision
- type LinuxSigningInfo
- func (x *LinuxSigningInfo) GetSigners() []*LinuxSigningInfo_Signer
- func (*LinuxSigningInfo) ProtoMessage()
- func (x *LinuxSigningInfo) ProtoReflect() protoreflect.Message
- func (x *LinuxSigningInfo) Reset()
- func (x *LinuxSigningInfo) SetSigners(v []*LinuxSigningInfo_Signer)
- func (x *LinuxSigningInfo) String() string
- type LinuxSigningInfo_Signer
- func (x *LinuxSigningInfo_Signer) ClearBuildTrigger()
- func (x *LinuxSigningInfo_Signer) ClearCertIdentity()
- func (x *LinuxSigningInfo_Signer) ClearCertIssuer()
- func (x *LinuxSigningInfo_Signer) ClearIntegratedTime()
- func (x *LinuxSigningInfo_Signer) ClearRekorLogIndex()
- func (x *LinuxSigningInfo_Signer) ClearRunInvocationUri()
- func (x *LinuxSigningInfo_Signer) ClearRunnerEnvironment()
- func (x *LinuxSigningInfo_Signer) ClearSourceCommit()
- func (x *LinuxSigningInfo_Signer) ClearSourceRef()
- func (x *LinuxSigningInfo_Signer) ClearSourceRepo()
- func (x *LinuxSigningInfo_Signer) GetBuildTrigger() string
- func (x *LinuxSigningInfo_Signer) GetCertIdentity() string
- func (x *LinuxSigningInfo_Signer) GetCertIssuer() string
- func (x *LinuxSigningInfo_Signer) GetIntegratedTime() *timestamppb.Timestamp
- func (x *LinuxSigningInfo_Signer) GetRekorLogIndex() int64
- func (x *LinuxSigningInfo_Signer) GetRunInvocationUri() string
- func (x *LinuxSigningInfo_Signer) GetRunnerEnvironment() string
- func (x *LinuxSigningInfo_Signer) GetSourceCommit() string
- func (x *LinuxSigningInfo_Signer) GetSourceRef() string
- func (x *LinuxSigningInfo_Signer) GetSourceRepo() string
- func (x *LinuxSigningInfo_Signer) HasBuildTrigger() bool
- func (x *LinuxSigningInfo_Signer) HasCertIdentity() bool
- func (x *LinuxSigningInfo_Signer) HasCertIssuer() bool
- func (x *LinuxSigningInfo_Signer) HasIntegratedTime() bool
- func (x *LinuxSigningInfo_Signer) HasRekorLogIndex() bool
- func (x *LinuxSigningInfo_Signer) HasRunInvocationUri() bool
- func (x *LinuxSigningInfo_Signer) HasRunnerEnvironment() bool
- func (x *LinuxSigningInfo_Signer) HasSourceCommit() bool
- func (x *LinuxSigningInfo_Signer) HasSourceRef() bool
- func (x *LinuxSigningInfo_Signer) HasSourceRepo() bool
- func (*LinuxSigningInfo_Signer) ProtoMessage()
- func (x *LinuxSigningInfo_Signer) ProtoReflect() protoreflect.Message
- func (x *LinuxSigningInfo_Signer) Reset()
- func (x *LinuxSigningInfo_Signer) SetBuildTrigger(v string)
- func (x *LinuxSigningInfo_Signer) SetCertIdentity(v string)
- func (x *LinuxSigningInfo_Signer) SetCertIssuer(v string)
- func (x *LinuxSigningInfo_Signer) SetIntegratedTime(v *timestamppb.Timestamp)
- func (x *LinuxSigningInfo_Signer) SetRekorLogIndex(v int64)
- func (x *LinuxSigningInfo_Signer) SetRunInvocationUri(v string)
- func (x *LinuxSigningInfo_Signer) SetRunnerEnvironment(v string)
- func (x *LinuxSigningInfo_Signer) SetSourceCommit(v string)
- func (x *LinuxSigningInfo_Signer) SetSourceRef(v string)
- func (x *LinuxSigningInfo_Signer) SetSourceRepo(v string)
- func (x *LinuxSigningInfo_Signer) String() string
- type LinuxSigningInfo_Signer_builder
- type LinuxSigningInfo_builder
- type Requester
- func (x *Requester) ClearAbsoluteBinaryPath()
- func (x *Requester) ClearDarwin()
- func (x *Requester) ClearLinux()
- func (x *Requester) ClearName()
- func (x *Requester) ClearPid()
- func (x *Requester) ClearSignedByDocker()
- func (x *Requester) ClearSigningInfo()
- func (x *Requester) ClearWindows()
- func (x *Requester) GetAbsoluteBinaryPath() string
- func (x *Requester) GetDarwin() *DarwinSigningInfo
- func (x *Requester) GetLinux() *LinuxSigningInfo
- func (x *Requester) GetName() string
- func (x *Requester) GetPid() int32
- func (x *Requester) GetSignedByDocker() bool
- func (x *Requester) GetWindows() *WindowsSigningInfo
- func (x *Requester) HasAbsoluteBinaryPath() bool
- func (x *Requester) HasDarwin() bool
- func (x *Requester) HasLinux() bool
- func (x *Requester) HasName() bool
- func (x *Requester) HasPid() bool
- func (x *Requester) HasSignedByDocker() bool
- func (x *Requester) HasSigningInfo() bool
- func (x *Requester) HasWindows() bool
- func (*Requester) ProtoMessage()
- func (x *Requester) ProtoReflect() protoreflect.Message
- func (x *Requester) Reset()
- func (x *Requester) SetAbsoluteBinaryPath(v string)
- func (x *Requester) SetDarwin(v *DarwinSigningInfo)
- func (x *Requester) SetLinux(v *LinuxSigningInfo)
- func (x *Requester) SetName(v string)
- func (x *Requester) SetPid(v int32)
- func (x *Requester) SetSignedByDocker(v bool)
- func (x *Requester) SetWindows(v *WindowsSigningInfo)
- func (x *Requester) String() string
- func (x *Requester) WhichSigningInfo() case_Requester_SigningInfo
- type Requester_builder
- type WindowsSigningInfo
- func (x *WindowsSigningInfo) ClearCompanyName()
- func (x *WindowsSigningInfo) ClearFileVersion()
- func (x *WindowsSigningInfo) ClearIntegrity()
- func (x *WindowsSigningInfo) ClearIsEv()
- func (x *WindowsSigningInfo) ClearIssuer()
- func (x *WindowsSigningInfo) ClearProductName()
- func (x *WindowsSigningInfo) ClearSubjectCommonName()
- func (x *WindowsSigningInfo) ClearSubjectOrg()
- func (x *WindowsSigningInfo) ClearThumbprintSha256()
- func (x *WindowsSigningInfo) ClearTrustedChain()
- func (x *WindowsSigningInfo) GetCompanyName() string
- func (x *WindowsSigningInfo) GetFileVersion() string
- func (x *WindowsSigningInfo) GetIntegrity() WindowsSigningInfo_IntegrityLevel
- func (x *WindowsSigningInfo) GetIsEv() bool
- func (x *WindowsSigningInfo) GetIssuer() string
- func (x *WindowsSigningInfo) GetProductName() string
- func (x *WindowsSigningInfo) GetSubjectCommonName() string
- func (x *WindowsSigningInfo) GetSubjectOrg() string
- func (x *WindowsSigningInfo) GetThumbprintSha256() string
- func (x *WindowsSigningInfo) GetTrustedChain() bool
- func (x *WindowsSigningInfo) HasCompanyName() bool
- func (x *WindowsSigningInfo) HasFileVersion() bool
- func (x *WindowsSigningInfo) HasIntegrity() bool
- func (x *WindowsSigningInfo) HasIsEv() bool
- func (x *WindowsSigningInfo) HasIssuer() bool
- func (x *WindowsSigningInfo) HasProductName() bool
- func (x *WindowsSigningInfo) HasSubjectCommonName() bool
- func (x *WindowsSigningInfo) HasSubjectOrg() bool
- func (x *WindowsSigningInfo) HasThumbprintSha256() bool
- func (x *WindowsSigningInfo) HasTrustedChain() bool
- func (*WindowsSigningInfo) ProtoMessage()
- func (x *WindowsSigningInfo) ProtoReflect() protoreflect.Message
- func (x *WindowsSigningInfo) Reset()
- func (x *WindowsSigningInfo) SetCompanyName(v string)
- func (x *WindowsSigningInfo) SetFileVersion(v string)
- func (x *WindowsSigningInfo) SetIntegrity(v WindowsSigningInfo_IntegrityLevel)
- func (x *WindowsSigningInfo) SetIsEv(v bool)
- func (x *WindowsSigningInfo) SetIssuer(v string)
- func (x *WindowsSigningInfo) SetProductName(v string)
- func (x *WindowsSigningInfo) SetSubjectCommonName(v string)
- func (x *WindowsSigningInfo) SetSubjectOrg(v string)
- func (x *WindowsSigningInfo) SetThumbprintSha256(v string)
- func (x *WindowsSigningInfo) SetTrustedChain(v bool)
- func (x *WindowsSigningInfo) String() string
- type WindowsSigningInfo_IntegrityLevel
- func (WindowsSigningInfo_IntegrityLevel) Descriptor() protoreflect.EnumDescriptor
- func (x WindowsSigningInfo_IntegrityLevel) Enum() *WindowsSigningInfo_IntegrityLevel
- func (x WindowsSigningInfo_IntegrityLevel) Number() protoreflect.EnumNumber
- func (x WindowsSigningInfo_IntegrityLevel) String() string
- func (WindowsSigningInfo_IntegrityLevel) Type() protoreflect.EnumType
- type WindowsSigningInfo_builder
Constants ¶
const Requester_Darwin_case case_Requester_SigningInfo = 5
const Requester_Linux_case case_Requester_SigningInfo = 7
const Requester_SigningInfo_not_set_case case_Requester_SigningInfo = 0
const Requester_Windows_case case_Requester_SigningInfo = 6
Variables ¶
var ( Decision_name = map[int32]string{ 0: "DECISION_DENY", 1: "DECISION_ALLOW", } Decision_value = map[string]int32{ "DECISION_DENY": 0, "DECISION_ALLOW": 1, } )
Enum value maps for Decision.
var ( WindowsSigningInfo_IntegrityLevel_name = map[int32]string{ 0: "INTEGRITY_LEVEL_UNSPECIFIED", 4096: "INTEGRITY_LEVEL_LOW", 8192: "INTEGRITY_LEVEL_MEDIUM", 12288: "INTEGRITY_LEVEL_HIGH", 16384: "INTEGRITY_LEVEL_SYSTEM", } WindowsSigningInfo_IntegrityLevel_value = map[string]int32{ "INTEGRITY_LEVEL_UNSPECIFIED": 0, "INTEGRITY_LEVEL_LOW": 4096, "INTEGRITY_LEVEL_MEDIUM": 8192, "INTEGRITY_LEVEL_HIGH": 12288, "INTEGRITY_LEVEL_SYSTEM": 16384, } )
Enum value maps for WindowsSigningInfo_IntegrityLevel.
var File_accesscontrol_v1_api_proto protoreflect.FileDescriptor
Functions ¶
This section is empty.
Types ¶
type CheckAccessRequest ¶
type CheckAccessRequest struct {
XXX_raceDetectHookData protoimpl.RaceDetectHookData
XXX_presence [1]uint32
// contains filtered or unexported fields
}
func (*CheckAccessRequest) ClearPattern ¶
func (x *CheckAccessRequest) ClearPattern()
func (*CheckAccessRequest) ClearRequester ¶
func (x *CheckAccessRequest) ClearRequester()
func (*CheckAccessRequest) GetPattern ¶
func (x *CheckAccessRequest) GetPattern() string
func (*CheckAccessRequest) GetRequester ¶
func (x *CheckAccessRequest) GetRequester() *Requester
func (*CheckAccessRequest) HasPattern ¶
func (x *CheckAccessRequest) HasPattern() bool
func (*CheckAccessRequest) HasRequester ¶
func (x *CheckAccessRequest) HasRequester() bool
func (*CheckAccessRequest) ProtoMessage ¶
func (*CheckAccessRequest) ProtoMessage()
func (*CheckAccessRequest) ProtoReflect ¶
func (x *CheckAccessRequest) ProtoReflect() protoreflect.Message
func (*CheckAccessRequest) Reset ¶
func (x *CheckAccessRequest) Reset()
func (*CheckAccessRequest) SetPattern ¶
func (x *CheckAccessRequest) SetPattern(v string)
func (*CheckAccessRequest) SetRequester ¶
func (x *CheckAccessRequest) SetRequester(v *Requester)
func (*CheckAccessRequest) String ¶
func (x *CheckAccessRequest) String() string
type CheckAccessRequest_builder ¶
type CheckAccessRequest_builder struct {
// What the caller is trying to resolve — mirrors the resolver pattern.
Pattern *string
// Identity/context of the process making the request.
Requester *Requester
// contains filtered or unexported fields
}
func (CheckAccessRequest_builder) Build ¶
func (b0 CheckAccessRequest_builder) Build() *CheckAccessRequest
type CheckAccessResponse ¶
type CheckAccessResponse struct {
XXX_raceDetectHookData protoimpl.RaceDetectHookData
XXX_presence [1]uint32
// contains filtered or unexported fields
}
func (*CheckAccessResponse) ClearDecision ¶
func (x *CheckAccessResponse) ClearDecision()
func (*CheckAccessResponse) GetDecision ¶
func (x *CheckAccessResponse) GetDecision() Decision
func (*CheckAccessResponse) HasDecision ¶
func (x *CheckAccessResponse) HasDecision() bool
func (*CheckAccessResponse) ProtoMessage ¶
func (*CheckAccessResponse) ProtoMessage()
func (*CheckAccessResponse) ProtoReflect ¶
func (x *CheckAccessResponse) ProtoReflect() protoreflect.Message
func (*CheckAccessResponse) Reset ¶
func (x *CheckAccessResponse) Reset()
func (*CheckAccessResponse) SetDecision ¶
func (x *CheckAccessResponse) SetDecision(v Decision)
func (*CheckAccessResponse) String ¶
func (x *CheckAccessResponse) String() string
type CheckAccessResponse_builder ¶
type CheckAccessResponse_builder struct {
Decision *Decision
// contains filtered or unexported fields
}
func (CheckAccessResponse_builder) Build ¶
func (b0 CheckAccessResponse_builder) Build() *CheckAccessResponse
type DarwinSigningInfo ¶
type DarwinSigningInfo struct {
XXX_raceDetectHookData protoimpl.RaceDetectHookData
XXX_presence [1]uint32
// contains filtered or unexported fields
}
DarwinSigningInfo carries macOS code-signing context (Security.framework SecCode* APIs) for the requesting process.
func (*DarwinSigningInfo) ClearCdHash ¶
func (x *DarwinSigningInfo) ClearCdHash()
func (*DarwinSigningInfo) ClearCommonName ¶
func (x *DarwinSigningInfo) ClearCommonName()
func (*DarwinSigningInfo) ClearIdentifier ¶
func (x *DarwinSigningInfo) ClearIdentifier()
func (*DarwinSigningInfo) ClearOrganization ¶
func (x *DarwinSigningInfo) ClearOrganization()
func (*DarwinSigningInfo) ClearStatus ¶
func (x *DarwinSigningInfo) ClearStatus()
func (*DarwinSigningInfo) ClearTeamId ¶
func (x *DarwinSigningInfo) ClearTeamId()
func (*DarwinSigningInfo) GetCdHash ¶
func (x *DarwinSigningInfo) GetCdHash() string
func (*DarwinSigningInfo) GetCommonName ¶
func (x *DarwinSigningInfo) GetCommonName() string
func (*DarwinSigningInfo) GetIdentifier ¶
func (x *DarwinSigningInfo) GetIdentifier() string
func (*DarwinSigningInfo) GetOrganization ¶
func (x *DarwinSigningInfo) GetOrganization() string
func (*DarwinSigningInfo) GetStatus ¶
func (x *DarwinSigningInfo) GetStatus() uint32
func (*DarwinSigningInfo) GetTeamId ¶
func (x *DarwinSigningInfo) GetTeamId() string
func (*DarwinSigningInfo) HasCdHash ¶
func (x *DarwinSigningInfo) HasCdHash() bool
func (*DarwinSigningInfo) HasCommonName ¶
func (x *DarwinSigningInfo) HasCommonName() bool
func (*DarwinSigningInfo) HasIdentifier ¶
func (x *DarwinSigningInfo) HasIdentifier() bool
func (*DarwinSigningInfo) HasOrganization ¶
func (x *DarwinSigningInfo) HasOrganization() bool
func (*DarwinSigningInfo) HasStatus ¶
func (x *DarwinSigningInfo) HasStatus() bool
func (*DarwinSigningInfo) HasTeamId ¶
func (x *DarwinSigningInfo) HasTeamId() bool
func (*DarwinSigningInfo) ProtoMessage ¶
func (*DarwinSigningInfo) ProtoMessage()
func (*DarwinSigningInfo) ProtoReflect ¶
func (x *DarwinSigningInfo) ProtoReflect() protoreflect.Message
func (*DarwinSigningInfo) Reset ¶
func (x *DarwinSigningInfo) Reset()
func (*DarwinSigningInfo) SetCdHash ¶
func (x *DarwinSigningInfo) SetCdHash(v string)
func (*DarwinSigningInfo) SetCommonName ¶
func (x *DarwinSigningInfo) SetCommonName(v string)
func (*DarwinSigningInfo) SetIdentifier ¶
func (x *DarwinSigningInfo) SetIdentifier(v string)
func (*DarwinSigningInfo) SetOrganization ¶
func (x *DarwinSigningInfo) SetOrganization(v string)
func (*DarwinSigningInfo) SetStatus ¶
func (x *DarwinSigningInfo) SetStatus(v uint32)
func (*DarwinSigningInfo) SetTeamId ¶
func (x *DarwinSigningInfo) SetTeamId(v string)
func (*DarwinSigningInfo) String ¶
func (x *DarwinSigningInfo) String() string
type DarwinSigningInfo_builder ¶
type DarwinSigningInfo_builder struct {
// Apple-assigned Team Identifier (kSecCodeInfoTeamIdentifier). Apple
// guarantees uniqueness per developer account, so this is a reliable
// trust key.
TeamId *string
// Code-signing identifier (kSecCodeInfoIdentifier), typically the bundle
// ID, e.g. "com.docker.docker". Use to pin a specific application within
// a team.
Identifier *string
// Company name from the leaf certificate subject.O, e.g. "Docker Inc".
// Human-readable but NOT guaranteed unique or immutable — display/logging
// only, never a sole trust key.
Organization *string
// Leaf certificate subject.CN, e.g.
// "Developer ID Application: Docker Inc (9BNSXJN65R)". Contains the company
// name and team ID as embedded display text.
CommonName *string
// Code directory hash (kSecCodeInfoUnique), the exact identity of this
// specific binary build, hex-encoded. Use to pin an exact build.
CdHash *string
// Dynamic code-signing status word (kSecCodeInfoStatus) — the kernel's live
// view of the signature. Raw uint32 bitmask; values are fixed by Apple's
// <Security/SecCode.h> and preserved verbatim (unknown bits included).
// Known flags:
//
// 0x0000_0001 VALID — dynamically valid; cleared on runtime tamper.
// 0x0000_0100 HARD — kernel refuses to page in invalid pages.
// 0x0000_0200 KILL — process killed if it becomes invalid.
// 0x1000_0000 DEBUGGED — debugger attached; red flag for a secrets peer.
Status *uint32
// contains filtered or unexported fields
}
func (DarwinSigningInfo_builder) Build ¶
func (b0 DarwinSigningInfo_builder) Build() *DarwinSigningInfo
type Decision ¶
type Decision int32
func (Decision) Descriptor ¶
func (Decision) Descriptor() protoreflect.EnumDescriptor
func (Decision) Number ¶
func (x Decision) Number() protoreflect.EnumNumber
func (Decision) Type ¶
func (Decision) Type() protoreflect.EnumType
type LinuxSigningInfo ¶
type LinuxSigningInfo struct {
// contains filtered or unexported fields
}
LinuxSigningInfo carries sigstore (Fulcio/Rekor) signing context for the requesting process. A binary may be signed by more than one signer.
func (*LinuxSigningInfo) GetSigners ¶
func (x *LinuxSigningInfo) GetSigners() []*LinuxSigningInfo_Signer
func (*LinuxSigningInfo) ProtoMessage ¶
func (*LinuxSigningInfo) ProtoMessage()
func (*LinuxSigningInfo) ProtoReflect ¶
func (x *LinuxSigningInfo) ProtoReflect() protoreflect.Message
func (*LinuxSigningInfo) Reset ¶
func (x *LinuxSigningInfo) Reset()
func (*LinuxSigningInfo) SetSigners ¶
func (x *LinuxSigningInfo) SetSigners(v []*LinuxSigningInfo_Signer)
func (*LinuxSigningInfo) String ¶
func (x *LinuxSigningInfo) String() string
type LinuxSigningInfo_Signer ¶
type LinuxSigningInfo_Signer struct {
XXX_raceDetectHookData protoimpl.RaceDetectHookData
XXX_presence [1]uint32
// contains filtered or unexported fields
}
Signer is one verified sigstore signature over the binary: the Fulcio certificate identity plus its bound provenance and Rekor inclusion.
func (*LinuxSigningInfo_Signer) ClearBuildTrigger ¶
func (x *LinuxSigningInfo_Signer) ClearBuildTrigger()
func (*LinuxSigningInfo_Signer) ClearCertIdentity ¶
func (x *LinuxSigningInfo_Signer) ClearCertIdentity()
func (*LinuxSigningInfo_Signer) ClearCertIssuer ¶
func (x *LinuxSigningInfo_Signer) ClearCertIssuer()
func (*LinuxSigningInfo_Signer) ClearIntegratedTime ¶
func (x *LinuxSigningInfo_Signer) ClearIntegratedTime()
func (*LinuxSigningInfo_Signer) ClearRekorLogIndex ¶
func (x *LinuxSigningInfo_Signer) ClearRekorLogIndex()
func (*LinuxSigningInfo_Signer) ClearRunInvocationUri ¶
func (x *LinuxSigningInfo_Signer) ClearRunInvocationUri()
func (*LinuxSigningInfo_Signer) ClearRunnerEnvironment ¶
func (x *LinuxSigningInfo_Signer) ClearRunnerEnvironment()
func (*LinuxSigningInfo_Signer) ClearSourceCommit ¶
func (x *LinuxSigningInfo_Signer) ClearSourceCommit()
func (*LinuxSigningInfo_Signer) ClearSourceRef ¶
func (x *LinuxSigningInfo_Signer) ClearSourceRef()
func (*LinuxSigningInfo_Signer) ClearSourceRepo ¶
func (x *LinuxSigningInfo_Signer) ClearSourceRepo()
func (*LinuxSigningInfo_Signer) GetBuildTrigger ¶
func (x *LinuxSigningInfo_Signer) GetBuildTrigger() string
func (*LinuxSigningInfo_Signer) GetCertIdentity ¶
func (x *LinuxSigningInfo_Signer) GetCertIdentity() string
func (*LinuxSigningInfo_Signer) GetCertIssuer ¶
func (x *LinuxSigningInfo_Signer) GetCertIssuer() string
func (*LinuxSigningInfo_Signer) GetIntegratedTime ¶
func (x *LinuxSigningInfo_Signer) GetIntegratedTime() *timestamppb.Timestamp
func (*LinuxSigningInfo_Signer) GetRekorLogIndex ¶
func (x *LinuxSigningInfo_Signer) GetRekorLogIndex() int64
func (*LinuxSigningInfo_Signer) GetRunInvocationUri ¶
func (x *LinuxSigningInfo_Signer) GetRunInvocationUri() string
func (*LinuxSigningInfo_Signer) GetRunnerEnvironment ¶
func (x *LinuxSigningInfo_Signer) GetRunnerEnvironment() string
func (*LinuxSigningInfo_Signer) GetSourceCommit ¶
func (x *LinuxSigningInfo_Signer) GetSourceCommit() string
func (*LinuxSigningInfo_Signer) GetSourceRef ¶
func (x *LinuxSigningInfo_Signer) GetSourceRef() string
func (*LinuxSigningInfo_Signer) GetSourceRepo ¶
func (x *LinuxSigningInfo_Signer) GetSourceRepo() string
func (*LinuxSigningInfo_Signer) HasBuildTrigger ¶
func (x *LinuxSigningInfo_Signer) HasBuildTrigger() bool
func (*LinuxSigningInfo_Signer) HasCertIdentity ¶
func (x *LinuxSigningInfo_Signer) HasCertIdentity() bool
func (*LinuxSigningInfo_Signer) HasCertIssuer ¶
func (x *LinuxSigningInfo_Signer) HasCertIssuer() bool
func (*LinuxSigningInfo_Signer) HasIntegratedTime ¶
func (x *LinuxSigningInfo_Signer) HasIntegratedTime() bool
func (*LinuxSigningInfo_Signer) HasRekorLogIndex ¶
func (x *LinuxSigningInfo_Signer) HasRekorLogIndex() bool
func (*LinuxSigningInfo_Signer) HasRunInvocationUri ¶
func (x *LinuxSigningInfo_Signer) HasRunInvocationUri() bool
func (*LinuxSigningInfo_Signer) HasRunnerEnvironment ¶
func (x *LinuxSigningInfo_Signer) HasRunnerEnvironment() bool
func (*LinuxSigningInfo_Signer) HasSourceCommit ¶
func (x *LinuxSigningInfo_Signer) HasSourceCommit() bool
func (*LinuxSigningInfo_Signer) HasSourceRef ¶
func (x *LinuxSigningInfo_Signer) HasSourceRef() bool
func (*LinuxSigningInfo_Signer) HasSourceRepo ¶
func (x *LinuxSigningInfo_Signer) HasSourceRepo() bool
func (*LinuxSigningInfo_Signer) ProtoMessage ¶
func (*LinuxSigningInfo_Signer) ProtoMessage()
func (*LinuxSigningInfo_Signer) ProtoReflect ¶
func (x *LinuxSigningInfo_Signer) ProtoReflect() protoreflect.Message
func (*LinuxSigningInfo_Signer) Reset ¶
func (x *LinuxSigningInfo_Signer) Reset()
func (*LinuxSigningInfo_Signer) SetBuildTrigger ¶
func (x *LinuxSigningInfo_Signer) SetBuildTrigger(v string)
func (*LinuxSigningInfo_Signer) SetCertIdentity ¶
func (x *LinuxSigningInfo_Signer) SetCertIdentity(v string)
func (*LinuxSigningInfo_Signer) SetCertIssuer ¶
func (x *LinuxSigningInfo_Signer) SetCertIssuer(v string)
func (*LinuxSigningInfo_Signer) SetIntegratedTime ¶
func (x *LinuxSigningInfo_Signer) SetIntegratedTime(v *timestamppb.Timestamp)
func (*LinuxSigningInfo_Signer) SetRekorLogIndex ¶
func (x *LinuxSigningInfo_Signer) SetRekorLogIndex(v int64)
func (*LinuxSigningInfo_Signer) SetRunInvocationUri ¶
func (x *LinuxSigningInfo_Signer) SetRunInvocationUri(v string)
func (*LinuxSigningInfo_Signer) SetRunnerEnvironment ¶
func (x *LinuxSigningInfo_Signer) SetRunnerEnvironment(v string)
func (*LinuxSigningInfo_Signer) SetSourceCommit ¶
func (x *LinuxSigningInfo_Signer) SetSourceCommit(v string)
func (*LinuxSigningInfo_Signer) SetSourceRef ¶
func (x *LinuxSigningInfo_Signer) SetSourceRef(v string)
func (*LinuxSigningInfo_Signer) SetSourceRepo ¶
func (x *LinuxSigningInfo_Signer) SetSourceRepo(v string)
func (*LinuxSigningInfo_Signer) String ¶
func (x *LinuxSigningInfo_Signer) String() string
type LinuxSigningInfo_Signer_builder ¶
type LinuxSigningInfo_Signer_builder struct {
// OIDC issuer embedded in the Fulcio leaf certificate, e.g.
// "https://token.actions.githubusercontent.com".
CertIssuer *string
// Certificate SAN — the signer's workflow identity, e.g.
// ".../sign-release.yml@refs/tags/v0.7.1".
CertIdentity *string
// Source repository URI from the Fulcio GitHub extension, e.g.
// "https://github.com/docker/secrets-engine".
SourceRepo *string
// Git ref that was built, e.g. "refs/tags/v0.7.1". Ties the binary to a
// release tag.
SourceRef *string
// Source commit SHA the binary was built from (Fulcio source-repository
// digest extension).
SourceCommit *string
// "github-hosted" or "self-hosted" (Fulcio extension) — a self-hosted
// runner minting a release signature would be a red flag.
RunnerEnvironment *string
// Event that started the signing workflow, e.g. "release" (Fulcio
// extension).
BuildTrigger *string
// Points at the specific GitHub Actions run that produced the signature
// (Fulcio extension) — for audit/log correlation.
RunInvocationUri *string
// Entry's index in the Rekor transparency log.
RekorLogIndex *int64
// When the signature was recorded in Rekor.
IntegratedTime *timestamppb.Timestamp
// contains filtered or unexported fields
}
func (LinuxSigningInfo_Signer_builder) Build ¶
func (b0 LinuxSigningInfo_Signer_builder) Build() *LinuxSigningInfo_Signer
type LinuxSigningInfo_builder ¶
type LinuxSigningInfo_builder struct {
Signers []*LinuxSigningInfo_Signer
// contains filtered or unexported fields
}
func (LinuxSigningInfo_builder) Build ¶
func (b0 LinuxSigningInfo_builder) Build() *LinuxSigningInfo
type Requester ¶
type Requester struct {
XXX_raceDetectHookData protoimpl.RaceDetectHookData
XXX_presence [1]uint32
// contains filtered or unexported fields
}
Requester mirrors runtime procinfo.Details: the verified context of the peer process asking for secrets.
func (*Requester) ClearAbsoluteBinaryPath ¶
func (x *Requester) ClearAbsoluteBinaryPath()
func (*Requester) ClearDarwin ¶
func (x *Requester) ClearDarwin()
func (*Requester) ClearLinux ¶
func (x *Requester) ClearLinux()
func (*Requester) ClearSignedByDocker ¶
func (x *Requester) ClearSignedByDocker()
func (*Requester) ClearSigningInfo ¶
func (x *Requester) ClearSigningInfo()
func (*Requester) ClearWindows ¶
func (x *Requester) ClearWindows()
func (*Requester) GetAbsoluteBinaryPath ¶
func (*Requester) GetDarwin ¶
func (x *Requester) GetDarwin() *DarwinSigningInfo
func (*Requester) GetLinux ¶
func (x *Requester) GetLinux() *LinuxSigningInfo
func (*Requester) GetSignedByDocker ¶
func (*Requester) GetWindows ¶
func (x *Requester) GetWindows() *WindowsSigningInfo
func (*Requester) HasAbsoluteBinaryPath ¶
func (*Requester) HasSignedByDocker ¶
func (*Requester) HasSigningInfo ¶
func (*Requester) HasWindows ¶
func (*Requester) ProtoMessage ¶
func (*Requester) ProtoMessage()
func (*Requester) ProtoReflect ¶
func (x *Requester) ProtoReflect() protoreflect.Message
func (*Requester) SetAbsoluteBinaryPath ¶
func (*Requester) SetDarwin ¶
func (x *Requester) SetDarwin(v *DarwinSigningInfo)
func (*Requester) SetLinux ¶
func (x *Requester) SetLinux(v *LinuxSigningInfo)
func (*Requester) SetSignedByDocker ¶
func (*Requester) SetWindows ¶
func (x *Requester) SetWindows(v *WindowsSigningInfo)
func (*Requester) WhichSigningInfo ¶
func (x *Requester) WhichSigningInfo() case_Requester_SigningInfo
type Requester_builder ¶
type Requester_builder struct {
// OS process ID of the caller.
Pid *int32
// Process name.
Name *string
// Absolute path to the caller's binary on disk.
AbsoluteBinaryPath *string
// True if the binary's signature chains to Docker's signing identity.
SignedByDocker *bool
// Fields of oneof xxx_hidden_SigningInfo:
Darwin *DarwinSigningInfo
Windows *WindowsSigningInfo
Linux *LinuxSigningInfo
// contains filtered or unexported fields
}
func (Requester_builder) Build ¶
func (b0 Requester_builder) Build() *Requester
type WindowsSigningInfo ¶
type WindowsSigningInfo struct {
XXX_raceDetectHookData protoimpl.RaceDetectHookData
XXX_presence [1]uint32
// contains filtered or unexported fields
}
WindowsSigningInfo carries Windows Authenticode context for the requesting process. Fields fall into three trust tiers: signature-derived (verified by WinVerifyTrust), token-derived (OS-enforced runtime properties), and corroborating PE version metadata (unsigned, display only).
func (*WindowsSigningInfo) ClearCompanyName ¶
func (x *WindowsSigningInfo) ClearCompanyName()
func (*WindowsSigningInfo) ClearFileVersion ¶
func (x *WindowsSigningInfo) ClearFileVersion()
func (*WindowsSigningInfo) ClearIntegrity ¶
func (x *WindowsSigningInfo) ClearIntegrity()
func (*WindowsSigningInfo) ClearIsEv ¶
func (x *WindowsSigningInfo) ClearIsEv()
func (*WindowsSigningInfo) ClearIssuer ¶
func (x *WindowsSigningInfo) ClearIssuer()
func (*WindowsSigningInfo) ClearProductName ¶
func (x *WindowsSigningInfo) ClearProductName()
func (*WindowsSigningInfo) ClearSubjectCommonName ¶
func (x *WindowsSigningInfo) ClearSubjectCommonName()
func (*WindowsSigningInfo) ClearSubjectOrg ¶
func (x *WindowsSigningInfo) ClearSubjectOrg()
func (*WindowsSigningInfo) ClearThumbprintSha256 ¶
func (x *WindowsSigningInfo) ClearThumbprintSha256()
func (*WindowsSigningInfo) ClearTrustedChain ¶
func (x *WindowsSigningInfo) ClearTrustedChain()
func (*WindowsSigningInfo) GetCompanyName ¶
func (x *WindowsSigningInfo) GetCompanyName() string
func (*WindowsSigningInfo) GetFileVersion ¶
func (x *WindowsSigningInfo) GetFileVersion() string
func (*WindowsSigningInfo) GetIntegrity ¶
func (x *WindowsSigningInfo) GetIntegrity() WindowsSigningInfo_IntegrityLevel
func (*WindowsSigningInfo) GetIsEv ¶
func (x *WindowsSigningInfo) GetIsEv() bool
func (*WindowsSigningInfo) GetIssuer ¶
func (x *WindowsSigningInfo) GetIssuer() string
func (*WindowsSigningInfo) GetProductName ¶
func (x *WindowsSigningInfo) GetProductName() string
func (*WindowsSigningInfo) GetSubjectCommonName ¶
func (x *WindowsSigningInfo) GetSubjectCommonName() string
func (*WindowsSigningInfo) GetSubjectOrg ¶
func (x *WindowsSigningInfo) GetSubjectOrg() string
func (*WindowsSigningInfo) GetThumbprintSha256 ¶
func (x *WindowsSigningInfo) GetThumbprintSha256() string
func (*WindowsSigningInfo) GetTrustedChain ¶
func (x *WindowsSigningInfo) GetTrustedChain() bool
func (*WindowsSigningInfo) HasCompanyName ¶
func (x *WindowsSigningInfo) HasCompanyName() bool
func (*WindowsSigningInfo) HasFileVersion ¶
func (x *WindowsSigningInfo) HasFileVersion() bool
func (*WindowsSigningInfo) HasIntegrity ¶
func (x *WindowsSigningInfo) HasIntegrity() bool
func (*WindowsSigningInfo) HasIsEv ¶
func (x *WindowsSigningInfo) HasIsEv() bool
func (*WindowsSigningInfo) HasIssuer ¶
func (x *WindowsSigningInfo) HasIssuer() bool
func (*WindowsSigningInfo) HasProductName ¶
func (x *WindowsSigningInfo) HasProductName() bool
func (*WindowsSigningInfo) HasSubjectCommonName ¶
func (x *WindowsSigningInfo) HasSubjectCommonName() bool
func (*WindowsSigningInfo) HasSubjectOrg ¶
func (x *WindowsSigningInfo) HasSubjectOrg() bool
func (*WindowsSigningInfo) HasThumbprintSha256 ¶
func (x *WindowsSigningInfo) HasThumbprintSha256() bool
func (*WindowsSigningInfo) HasTrustedChain ¶
func (x *WindowsSigningInfo) HasTrustedChain() bool
func (*WindowsSigningInfo) ProtoMessage ¶
func (*WindowsSigningInfo) ProtoMessage()
func (*WindowsSigningInfo) ProtoReflect ¶
func (x *WindowsSigningInfo) ProtoReflect() protoreflect.Message
func (*WindowsSigningInfo) Reset ¶
func (x *WindowsSigningInfo) Reset()
func (*WindowsSigningInfo) SetCompanyName ¶
func (x *WindowsSigningInfo) SetCompanyName(v string)
func (*WindowsSigningInfo) SetFileVersion ¶
func (x *WindowsSigningInfo) SetFileVersion(v string)
func (*WindowsSigningInfo) SetIntegrity ¶
func (x *WindowsSigningInfo) SetIntegrity(v WindowsSigningInfo_IntegrityLevel)
func (*WindowsSigningInfo) SetIsEv ¶
func (x *WindowsSigningInfo) SetIsEv(v bool)
func (*WindowsSigningInfo) SetIssuer ¶
func (x *WindowsSigningInfo) SetIssuer(v string)
func (*WindowsSigningInfo) SetProductName ¶
func (x *WindowsSigningInfo) SetProductName(v string)
func (*WindowsSigningInfo) SetSubjectCommonName ¶
func (x *WindowsSigningInfo) SetSubjectCommonName(v string)
func (*WindowsSigningInfo) SetSubjectOrg ¶
func (x *WindowsSigningInfo) SetSubjectOrg(v string)
func (*WindowsSigningInfo) SetThumbprintSha256 ¶
func (x *WindowsSigningInfo) SetThumbprintSha256(v string)
func (*WindowsSigningInfo) SetTrustedChain ¶
func (x *WindowsSigningInfo) SetTrustedChain(v bool)
func (*WindowsSigningInfo) String ¶
func (x *WindowsSigningInfo) String() string
type WindowsSigningInfo_IntegrityLevel ¶
type WindowsSigningInfo_IntegrityLevel int32
IntegrityLevel is a Windows mandatory integrity level, ordered so higher values denote a more privileged context (mirrors winnt.h RIDs).
const ( // SECURITY_MANDATORY_UNTRUSTED_RID (0x0000). Also the value used when the // integrity level could not be determined. WindowsSigningInfo_INTEGRITY_LEVEL_UNSPECIFIED WindowsSigningInfo_IntegrityLevel = 0 // SECURITY_MANDATORY_LOW_RID (0x1000), e.g. AppContainer/sandboxed. WindowsSigningInfo_INTEGRITY_LEVEL_LOW WindowsSigningInfo_IntegrityLevel = 4096 // SECURITY_MANDATORY_MEDIUM_RID (0x2000), default for standard user procs. WindowsSigningInfo_INTEGRITY_LEVEL_MEDIUM WindowsSigningInfo_IntegrityLevel = 8192 // SECURITY_MANDATORY_HIGH_RID (0x3000), e.g. elevated (administrator). WindowsSigningInfo_INTEGRITY_LEVEL_HIGH WindowsSigningInfo_IntegrityLevel = 12288 // SECURITY_MANDATORY_SYSTEM_RID (0x4000), e.g. services running as SYSTEM. WindowsSigningInfo_INTEGRITY_LEVEL_SYSTEM WindowsSigningInfo_IntegrityLevel = 16384 )
func (WindowsSigningInfo_IntegrityLevel) Descriptor ¶
func (WindowsSigningInfo_IntegrityLevel) Descriptor() protoreflect.EnumDescriptor
func (WindowsSigningInfo_IntegrityLevel) Enum ¶
func (x WindowsSigningInfo_IntegrityLevel) Enum() *WindowsSigningInfo_IntegrityLevel
func (WindowsSigningInfo_IntegrityLevel) Number ¶
func (x WindowsSigningInfo_IntegrityLevel) Number() protoreflect.EnumNumber
func (WindowsSigningInfo_IntegrityLevel) String ¶
func (x WindowsSigningInfo_IntegrityLevel) String() string
func (WindowsSigningInfo_IntegrityLevel) Type ¶
func (WindowsSigningInfo_IntegrityLevel) Type() protoreflect.EnumType
type WindowsSigningInfo_builder ¶
type WindowsSigningInfo_builder struct {
// Whether WinVerifyTrust confirmed the Authenticode signature chains to a
// trusted root and is not revoked. The remaining signature fields are only
// meaningful when true.
TrustedChain *bool
// Signing certificate Subject Organization (O), e.g. "Docker Inc".
SubjectOrg *string
// Signing certificate Subject Common Name (CN).
SubjectCommonName *string
// Common Name of the issuing CA, e.g. the DigiCert / Sectigo code-signing
// intermediate.
Issuer *string
// Hex-encoded SHA-256 hash of the leaf signing certificate. Strongest
// identity pin, but brittle across cert rotation.
ThumbprintSha256 *string
// Whether the signature uses an Extended Validation code-signing certificate
// (hardware-backed key, stricter vetting), detected from the leaf
// certificate's CA/Browser Forum EV policy OID.
IsEv *bool
// Peer process's mandatory integrity level from its access token. Collected
// for logging/diagnostics only; trust is gated on the signature, not
// integrity (the engine itself runs at Medium as a per-user service).
Integrity *WindowsSigningInfo_IntegrityLevel
// --- Corroborating only (PE version resource; NOT trustworthy) ---
//
// From the PE VERSIONINFO resource: unsigned and attacker-controllable, so
// display/logging only — must never gate trust.
CompanyName *string
ProductName *string
FileVersion *string
// contains filtered or unexported fields
}
func (WindowsSigningInfo_builder) Build ¶
func (b0 WindowsSigningInfo_builder) Build() *WindowsSigningInfo