Documentation
¶
Overview ¶
Package federationbinding is the public producer contract for StackKits' provider-free external Federation link handshake. An external fabric authority builds the opaque, unsigned binding for one compiler-derived FederationLinkRequirement; the local Owner signs and adopts it with `stackkit federation binding adopt`. The package never creates a fabric, a key, an interface or an endpoint, and it accepts no provider, credential or lifecycle field.
Index ¶
Constants ¶
const ( RequirementAPIVersion = "stackkit.federation-link-requirement/v1" BindingAPIVersion = "stackkit.external-federation-link-binding/v1" Capability = "inter-site-link" MaxValidity = 24 * time.Hour SchemeBinding = "federation-link-binding" SchemeFabric = "federation-link-fabric" SchemeCustody = "federation-link-custody-attestation" )
Variables ¶
This section is empty.
Functions ¶
func ComputeHash ¶
ComputeHash is the canonical hash of the binding body without bindingHash.
func OpaqueReference ¶
OpaqueReference hashes evidence into an opaque reference of one scheme.
Types ¶
type Input ¶
type Input struct {
BindingEvidence []byte
FabricEvidence []byte
CustodyEvidence []byte
StackKitsVersion string
CandidateDigest string
IssuedAt time.Time
ValidUntil time.Time
}
Input is everything the fabric authority adds to the requirement. The three evidence values are hashed into opaque references and never emitted.