imagepreparation

package
v0.50.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0 Imports: 21 Imported by: 0

Documentation

Overview

Package imagepreparation prepares neutral caches, never installed stacks.

Index

Constants

View Source
const ManifestName = "neutral-image.json"

Variables

View Source
var ErrAdmissionMismatch = errors.New("neutral image admission mismatch")
View Source
var ErrNotNeutral = errors.New("image roots contain state that cannot be cloned")

Functions

func CleanTarget

func CleanTarget(target string) error

CleanTarget refuses every existing entry, including foreign custody nested beneath arbitrary directories. Preparation never scrubs an initialized host.

func FileDigest

func FileDigest(name string) (string, error)

func SafePath

func SafePath(name string) error

SafePath checks every existing ancestor, not just the final directory.

Types

type ContainerCache

type ContainerCache interface {
	Run(context.Context, ...string) ([]byte, error)
}

type Image

type Image struct {
	Component string `json:"component"`
	Ref       string `json:"ref"`
	Digest    string `json:"digest"`
}

type LocalDocker

type LocalDocker struct{ Config string }

LocalDocker always addresses the local Unix socket with an empty config. Contexts, DOCKER_HOST and user registry credentials cannot redirect a bake.

func (LocalDocker) Run

func (docker LocalDocker) Run(ctx context.Context, args ...string) ([]byte, error)

type Manifest

type Manifest struct {
	SchemaVersion string            `json:"schemaVersion"`
	Profile       Profile           `json:"profile"`
	Platform      Platform          `json:"platform"`
	Release       Release           `json:"release"`
	Binaries      map[string]string `json:"binaries"`
	ProviderFiles map[string]string `json:"providerFiles"`
}

func Prepare

func Prepare(ctx context.Context, options Options, id string) (Manifest, error)

Prepare downloads the current exact attested release into the neutral cache, verifies the actual packaged tools, and only pulls immutable container images.

func ReadManifest

func ReadManifest(name string) (Manifest, error)

func Verify

func Verify(ctx context.Context, options Options, manifestPath string) (Manifest, error)

Verify re-observes the clone, release bytes and cache. An unsigned manifest's asserted digests or its writer's previous host evidence authorize nothing.

func VerifyCache added in v0.50.1

func VerifyCache(ctx context.Context, options Options, manifestPath string) (Manifest, error)

VerifyCache re-observes the host, attested release, packaged tools and exact neutral container cache. It does not admit deployment contents: init must separately require an empty target or an already-applied canonical intent.

type Options

type Options struct {
	CacheRoot  string
	Target     string
	Executable string
	Version    string
	Installer  releaseindex.Installer
	Docker     ContainerCache
	// Host observation is injectable only for package tests. The CLI always
	// supplies ObserveHost and LocalDocker; manifests never supply these facts.
	ObserveHost func() (Platform, error)
}

type Platform

type Platform struct {
	OS           string `json:"os"`
	Arch         string `json:"arch"`
	Distribution string `json:"distribution"`
	Version      string `json:"version"`
}

func ObserveHost

func ObserveHost() (Platform, error)

type Profile

type Profile struct {
	ID              string   `json:"id"`
	Kit             string   `json:"kit"`
	Module          string   `json:"module"`
	DefaultOS       string   `json:"defaultOS"`
	CompatibleOS    []string `json:"compatibleOS"`
	Architectures   []string `json:"architectures"`
	Runtime         string   `json:"runtime"`
	ManagedTarget   string   `json:"managedTarget"`
	CacheScope      string   `json:"cacheScope"`
	NetworkRequired bool     `json:"networkRequired"`
	Images          []Image  `json:"images"`
}

func Plan

func Plan(id string) (Profile, error)

type Release

type Release struct {
	Kit           string `json:"kit"`
	Version       string `json:"version"`
	ArchiveSHA256 string `json:"archiveSha256"`
	IndexSHA256   string `json:"indexSha256"`
}

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL