Documentation
¶
Index ¶
- func GenerateKeyPair(ctx context.Context, outputDir string, password string) (privateKeyPath, publicKeyPath string, err error)
- func GetRekorEntryFromOutput(output string) string
- func RunCosignWithRetry(ctx context.Context, label string, args, env []string, timeout time.Duration) (string, error)
- func RunCosignWithRetryConfirm(ctx context.Context, label string, args, env []string, timeout time.Duration, ...) (string, error)
- func ValidateOIDCToken(token string) error
- type CertificateInfo
- type Config
- type ConfirmProbe
- type KeyBasedSigner
- type KeylessSigner
- type PolicyChecker
- type SignResult
- type Signer
- type SignerConfig
- type Verifier
- type VerifyResult
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func GenerateKeyPair ¶
func GenerateKeyPair(ctx context.Context, outputDir string, password string) (privateKeyPath, publicKeyPath string, err error)
GenerateKeyPair generates a new cosign key pair
func GetRekorEntryFromOutput ¶
GetRekorEntryFromOutput parses cosign output to extract Rekor entry information
func RunCosignWithRetry ¶
func RunCosignWithRetry(ctx context.Context, label string, args, env []string, timeout time.Duration) (string, error)
RunCosignWithRetry runs `cosign <args>` with no conflict confirmation: a conflict is retried and then reported. See RunCosignWithRetryConfirm.
func RunCosignWithRetryConfirm ¶
func RunCosignWithRetryConfirm(ctx context.Context, label string, args, env []string, timeout time.Duration, confirm *ConfirmProbe) (string, error)
RunCosignWithRetryConfirm runs `cosign <args>` and returns its stdout, retrying Rekor entry conflicts. label names the operation in the retry warning ("sbom attest"); the returned error is prefixed from args[0], so it reads "cosign attest failed". The second return value reports whether the run ended by confirming an existing artifact rather than by producing a new one, in which case stdout is empty because no fresh cosign output exists.
Every attempt is a fresh process with its own full timeout budget. Under keyless signing each invocation mints a new ephemeral certificate, so the body cosign replays differs and the conflict clears.
Two failure classes are retried. A Rekor 409 conflict says the transparency log already holds an identical entry, and "already attested" is the desired end state of an idempotent re-run — a redeploy of an unchanged digest regenerates a byte-identical predicate and lands there every time. It is not proof on its own, because cosign uploads to Rekor before it pushes to the registry, so each conflict is checked with confirm: a confirmed conflict returns success, an unconfirmed one is retried and then reported. A transient give-up against the log-entries endpoint attached nothing, so it is simply retried. A nil confirm disables confirmation, which is the correct setting wherever the caller cannot name the identity to verify against.
func ValidateOIDCToken ¶
ValidateOIDCToken performs basic format validation on the OIDC token. This checks JWT structure (3 dot-separated segments) only — it does NOT verify the signature, issuer, audience, or expiry. Full validation is performed by Fulcio when the token is exchanged for a signing certificate.
Types ¶
type CertificateInfo ¶
CertificateInfo contains information about the signing certificate
type Config ¶
type Config struct {
Enabled bool
Required bool
Keyless bool
PrivateKey string
PublicKey string
// Password is the cosign private key passphrase.
// json:"-" prevents accidental serialization if this struct is ever marshaled
// as part of a larger config object (e.g., debug logging, cache key hashing).
// It is always populated programmatically from CLI flags or env vars, never loaded from JSON.
Password string `json:"-" yaml:"-"`
Timeout string
// OIDCToken is the OIDC identity token for keyless signing/attestation.
// Set at runtime from CI environment (ACTIONS_ID_TOKEN_REQUEST_*).
// Used by SBOM attacher and provenance attacher for cosign attestations.
OIDCToken string `json:"-" yaml:"-"`
// Verification settings
OIDCIssuer string
IdentityRegexp string
// VerifyEnv is appended to the environment of the cosign verify process.
VerifyEnv []string
}
Config contains configuration for image signing operations
func (*Config) AttestationConfirmProbe ¶
func (c *Config) AttestationConfirmProbe(predicateType string) *ConfirmProbe
AttestationConfirmProbe builds the read-only check that decides whether a Rekor conflict on `cosign attest --type predicateType` is an idempotent no-op. Nil when the config names no verification identity.
func (*Config) CreateSigner ¶
CreateSigner creates a signer based on the configuration. The oidcToken parameter takes precedence; falls back to c.OIDCToken if empty.
func (*Config) CreateVerifier ¶
CreateVerifier creates a verifier based on the configuration
func (*Config) SignatureConfirmProbe ¶
func (c *Config) SignatureConfirmProbe() *ConfirmProbe
SignatureConfirmProbe is AttestationConfirmProbe's twin for `cosign sign`.
type ConfirmProbe ¶
ConfirmProbe is the read-only cosign invocation that decides whether a Rekor conflict is an idempotent no-op. Args is a cosign argv WITHOUT the image reference; the retry loop appends the same image reference the conflicting attempt used. What names the artifact in the log line.
It must be a verify form, not a download form. `cosign download signature` and `cosign download attestation` answer "is anything of this shape stored under the legacy signature tag", which accepts a signature made under a rotated key or an attestation of the same predicate family produced by an unrelated workflow. They also return nothing at all under cosign v3, which defaults to the new bundle format and stores nothing in the legacy tag: on a current cosign the download probe never confirms, so every conflict runs the loop to exhaustion and the operation fails. `cosign verify` and `cosign verify-attestation` read both formats and check the identity, so a confirmation means the artifact the caller wanted is present AND ours.
The probe's exit code is the whole signal. Its stdout is not inspected: cosign prints the verification banner to stderr, so requiring non-empty stdout is another way to never confirm.
type KeyBasedSigner ¶
type KeyBasedSigner struct {
PrivateKey string // Path to private key file or key content
Password string // Optional password for encrypted keys
Timeout time.Duration
// contains filtered or unexported fields
}
KeyBasedSigner implements key-based signing using private keys
func NewKeyBasedSigner ¶
func NewKeyBasedSigner(privateKey, password string, timeout time.Duration) *KeyBasedSigner
NewKeyBasedSigner creates a new key-based signer
func (*KeyBasedSigner) Sign ¶
func (s *KeyBasedSigner) Sign(ctx context.Context, imageRef string) (*SignResult, error)
Sign signs a container image using a private key
type KeylessSigner ¶
type KeylessSigner struct {
OIDCToken string
Timeout time.Duration
// IdentityRegexp and OIDCIssuer name the certificate identity this signer
// produces. Both are needed to confirm a Rekor conflict against the image;
// with either missing the signer keeps the plain retry-then-report path
// rather than accepting a signature it cannot attribute. Config.CreateSigner
// populates them.
IdentityRegexp string
OIDCIssuer string
// contains filtered or unexported fields
}
KeylessSigner implements keyless signing using OIDC tokens
func NewKeylessSigner ¶
func NewKeylessSigner(oidcToken string, timeout time.Duration) *KeylessSigner
NewKeylessSigner creates a new keyless signer
func (*KeylessSigner) Sign ¶
func (s *KeylessSigner) Sign(ctx context.Context, imageRef string) (*SignResult, error)
Sign signs a container image using keyless OIDC signing
type PolicyChecker ¶
type PolicyChecker interface {
Check(result *VerifyResult) error
}
PolicyChecker is an interface for custom verification policies
type SignResult ¶
type SignResult struct {
ImageDigest string
Signature string
Bundle string
RekorEntry string // URL to Rekor transparency log entry
SignedAt string
// Confirmed reports that the signature was not produced by this run: the
// transparency log already held an identical entry and a verification probe
// confirmed the signature is on the image. Nothing fresh was emitted, so
// RekorEntry is empty even though the operation succeeded.
Confirmed bool
}
SignResult contains the result of a signing operation
type Signer ¶
type Signer interface {
// Sign signs a container image and returns the result
Sign(ctx context.Context, imageRef string) (*SignResult, error)
}
Signer is the interface for signing container images
type SignerConfig ¶
type SignerConfig struct {
// Required indicates whether signing is required (fail-closed) or optional (fail-open)
Required bool
// Timeout for signing operation
Timeout string
}
SignerConfig contains common configuration for signers
type Verifier ¶
type Verifier struct {
// For keyless verification
OIDCIssuer string
IdentityRegexp string
// For key-based verification
PublicKey string // Path to public key file
// ExtraEnv is appended to cosign's environment. A caller that verifies an
// image before the deploy has written registry credentials to the shared
// docker config needs it: without DOCKER_CONFIG pointing at credentials of
// its own, cosign pulls anonymously and a private registry answers DENIED,
// which is not a statement about the signature.
ExtraEnv []string
Timeout time.Duration
}
Verifier handles signature verification for container images
func NewKeyBasedVerifier ¶
NewKeyBasedVerifier creates a verifier for key-based signatures
func NewKeylessVerifier ¶
NewKeylessVerifier creates a verifier for keyless signatures
func (*Verifier) VerifyWithPolicy ¶
func (v *Verifier) VerifyWithPolicy(ctx context.Context, imageRef string, policy PolicyChecker) (*VerifyResult, error)
VerifyWithPolicy verifies a signature and applies additional policy checks
type VerifyResult ¶
type VerifyResult struct {
Verified bool
ImageDigest string
CertificateInfo *CertificateInfo
VerifiedAt string
}
VerifyResult contains the result of a signature verification
func VerifyImage ¶
VerifyImage is a convenience function to verify an image with the given configuration