Skip to main content

SignConfig

Struct SignConfig 

Source
pub struct SignConfig {
Show 14 fields pub id: Option<String>, pub artifacts: Option<String>, pub cmd: Option<String>, pub args: Option<Vec<String>>, pub signature: Option<String>, pub stdin: Option<String>, pub stdin_file: Option<String>, pub ids: Option<Vec<String>>, pub env: Option<Vec<String>>, pub certificate: Option<String>, pub output: Option<StringOrBool>, pub authenticode: Option<AuthenticodeConfig>, pub verify: Option<SignVerifyConfig>, pub if_condition: Option<String>,
}

Fields§

§id: Option<String>

Unique identifier for this sign config.

§artifacts: Option<String>

Artifact types to sign: “all”, “archive”, “binary”, “checksum”, “package”, “sbom” (default: “none”).

§cmd: Option<String>

Signing command to invoke (default: “cosign” or “gpg”).

§args: Option<Vec<String>>

Arguments passed to the signing command (supports templates with ${artifact} and ${signature}).

§signature: Option<String>

Signature output filename template (supports templates).

§stdin: Option<String>

Content written to the signing command’s stdin.

§stdin_file: Option<String>

Path to a file whose content is written to the signing command’s stdin.

§ids: Option<Vec<String>>

Build IDs filter: only sign artifacts from builds whose id is in this list.

§env: Option<Vec<String>>

Environment variables passed to the signing command.

§certificate: Option<String>

Certificate file to embed in the signature (Cosign bundle signing).

§output: Option<StringOrBool>

Capture and log stdout/stderr of the signing command. Accepts bool or template string (e.g., “{{ IsSnapshot }}”).

§authenticode: Option<AuthenticodeConfig>

Authenticode (Windows PE/MSI) signing backend. When set, this sign config signs Windows artifacts in place via osslsigncode (Linux/cross) or signtool (Windows) instead of producing a detached cosign/gpg signature. The signing command, argv, timestamp URL, and artifact selector are all derived; supply only the cert (a secret).

§verify: Option<SignVerifyConfig>

Post-sign verification knobs. Verification is ON by default wherever its inputs are derivable (keyed cosign, keyless cosign on GitHub Actions, gpg); set verify: { enabled: false } to disable, or supply the keyless certificate identity / issuer when they cannot be derived from the environment.

§if_condition: Option<String>

Template-conditional: skip this sign config if rendered result is “false” or empty.

Implementations§

Source§

impl SignConfig

Source

pub const DEFAULT_ID: &'static str = "default"

Default id when a sign config has none ("default"). Used to label log lines and uniqueness-error messages.

Source

pub const DEFAULT_ARTIFACTS: &'static str = "none"

Default artifacts filter for top-level signs:[]. Mirrors the canonical artifacts = "none" — by default nothing is signed unless the user opts in.

Source

pub const DEFAULT_ARTIFACTS_BINARY: &'static str = "binary"

Default artifacts filter for binary_signs:[]. The binary-only driver always restricts the artifact-kind filter to binaries even when the user leaves artifacts: unset. Anodize-specific helper (anodizer-specific — distinct config type for binary signing) but kept on SignConfig because anodize unifies signs[] and binary_signs[] into one struct.

Source

pub const DEFAULT_SIGNATURE_TEMPLATE: &'static str = "{{ .Artifact }}.sig"

Default signature template for top-level signs:[]. Mirrors the canonical signature = "${artifact}.sig". Anodize uses Tera-style {{ .Artifact }} placeholders that the arg-resolver rewrites to the same path at execution time.

Source

pub const DEFAULT_BINARY_SIGNATURE_TEMPLATE: &'static str = "{{ .Artifact }}.sig"

Default signature template for binary_signs:[].

Intentional divergence from the binary-sign default: the upstream stores binaries under per-target subdirectories (dist/linux_amd64/binname), so its template appends _{{ .Os }}_{{ .Arch }} to the bare binary name without collision. Anodize uses a flat dist/ layout where stage-build already names binaries with the platform suffix (myapp_linux_amd64, myapp_darwin_arm64, etc.). Appending Os/Arch again would produce myapp_linux_amd64_linux_amd64 with no .sig extension — a double-suffix bug.

The correct default for anodize’s layout is {{ .Artifact }}.sig — identical to DEFAULT_SIGNATURE_TEMPLATE. Binary names are already unique per target, so no collision risk exists. Users who want an explicit per-target suffix can set signature: in binary_signs:.

Source

pub const DEFAULT_ARGS: &[&'static str]

Default args for top-level signs:[] (["--output", "$signature", "--detach-sig", "$artifact"]). Anodize substitutes $signature / $artifact for {{ .Signature }} / {{ .Artifact }} Tera placeholders that the arg-resolver rewrites; the wire-level invocation is unchanged.

Source

pub fn resolved_id(&self) -> &str

Resolve the sign-config id, falling back to "default".

Source

pub fn resolved_artifacts<'a>(&'a self, fallback: &'a str) -> &'a str

Resolve the artifacts filter, falling back to the supplied fallback (Self::DEFAULT_ARTIFACTS for signs[], Self::DEFAULT_ARTIFACTS_BINARY for binary_signs[]).

Source

pub fn resolved_signature_template<'a>(&'a self, default: &'a str) -> &'a str

Resolve the signature template, falling back to the supplied default (Self::DEFAULT_SIGNATURE_TEMPLATE for signs[], Self::DEFAULT_BINARY_SIGNATURE_TEMPLATE for binary_signs[]).

Source

pub fn resolved_args(&self) -> Vec<String>

Resolve args, materializing the Self::DEFAULT_ARGS const into a Vec<String> when the user left args: unset. Returns a clone of the user-supplied list otherwise.

Source

pub fn verify_enabled(&self) -> bool

Whether post-sign verification is enabled (default: true; an absent verify: block means “verify with derived inputs”).

Source

pub fn is_gpg(&self) -> bool

true when this sign config will invoke gpg.

The top-level signs: driver defaults to gpg when cmd: is unset (see stage-sign::helpers::default_sign_cmd which falls back to git config gpg.program then to literal "gpg"). We treat any cmd whose basename starts with gpg (e.g., gpg, gpg2, /usr/local/bin/gpg) as a gpg invocation. A cmd of "cosign", "notation", etc. returns false.

Entries with artifacts: "none" (the default for top-level signs:) are treated as not-configured — the loop never fires.

Trait Implementations§

Source§

impl Clone for SignConfig

Source§

fn clone(&self) -> SignConfig

Returns a duplicate of the value. Read more
1.0.0 (const: unstable) · Source§

fn clone_from(&mut self, source: &Self)

Performs copy-assignment from source. Read more
Source§

impl Debug for SignConfig

Source§

fn fmt(&self, f: &mut Formatter<'_>) -> Result

Formats the value using the given formatter. Read more
Source§

impl Default for SignConfig

Source§

fn default() -> SignConfig

Returns the “default value” for a type. Read more
Source§

impl<'de> Deserialize<'de> for SignConfig

Source§

fn deserialize<__D>(__deserializer: __D) -> Result<Self, __D::Error>
where __D: Deserializer<'de>,

Deserialize this value from the given Serde deserializer. Read more
Source§

impl JsonSchema for SignConfig

Source§

fn schema_name() -> Cow<'static, str>

The name of the generated JSON Schema. Read more
Source§

fn schema_id() -> Cow<'static, str>

Returns a string that uniquely identifies the schema produced by this type. Read more
Source§

fn json_schema(generator: &mut SchemaGenerator) -> Schema

Generates a JSON Schema for this type. Read more
Source§

fn inline_schema() -> bool

Whether JSON Schemas generated for this type should be included directly in parent schemas, rather than being re-used where possible using the $ref keyword. Read more
Source§

impl Serialize for SignConfig

Source§

fn serialize<__S>(&self, __serializer: __S) -> Result<__S::Ok, __S::Error>
where __S: Serializer,

Serialize this value into the given Serde serializer. Read more

Auto Trait Implementations§

Blanket Implementations§

Source§

impl<T> Any for T
where T: 'static + ?Sized,

Source§

fn type_id(&self) -> TypeId

Gets the TypeId of self. Read more
Source§

impl<T> Borrow<T> for T
where T: ?Sized,

Source§

fn borrow(&self) -> &T

Immutably borrows from an owned value. Read more
Source§

impl<T> BorrowMut<T> for T
where T: ?Sized,

Source§

fn borrow_mut(&mut self) -> &mut T

Mutably borrows from an owned value. Read more
Source§

impl<T> CloneToUninit for T
where T: Clone,

Source§

unsafe fn clone_to_uninit(&self, dest: *mut u8)

🔬This is a nightly-only experimental API. (clone_to_uninit)
Performs copy-assignment from self to dest. Read more
Source§

impl<T> DeserializeOwned for T
where T: for<'de> Deserialize<'de>,

Source§

impl<T> DynClone for T
where T: Clone,

Source§

fn __clone_box(&self, _: Private) -> *mut ()

Source§

impl<T> From<T> for T

Source§

fn from(t: T) -> T

Returns the argument unchanged.

Source§

impl<T> Instrument for T

Source§

fn instrument(self, span: Span) -> Instrumented<Self>

Instruments this type with the provided Span, returning an Instrumented wrapper. Read more
Source§

fn in_current_span(self) -> Instrumented<Self>

Instruments this type with the current Span, returning an Instrumented wrapper. Read more
Source§

impl<T, U> Into<U> for T
where U: From<T>,

Source§

fn into(self) -> U

Calls U::from(self).

That is, this conversion is whatever the implementation of From<T> for U chooses to do.

Source§

impl<T> PolicyExt for T
where T: ?Sized,

Source§

fn and<P, B, E>(self, other: P) -> And<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow only if self and other return Action::Follow. Read more
Source§

fn or<P, B, E>(self, other: P) -> Or<T, P>
where T: Sized + Policy<B, E>, P: Policy<B, E>,

Create a new Policy that returns Action::Follow if either self or other returns Action::Follow. Read more
Source§

impl<T> Same for T

Source§

type Output = T

Should always be Self
Source§

impl<T> ToOwned for T
where T: Clone,

Source§

type Owned = T

The resulting type after obtaining ownership.
Source§

fn to_owned(&self) -> T

Creates owned data from borrowed data, usually by cloning. Read more
Source§

fn clone_into(&self, target: &mut T)

Uses borrowed data to replace owned data, usually by cloning. Read more
Source§

impl<T, U> TryFrom<U> for T
where U: Into<T>,

Source§

type Error = Infallible

The type returned in the event of a conversion error.
Source§

fn try_from(value: U) -> Result<T, <T as TryFrom<U>>::Error>

Performs the conversion.
Source§

impl<T, U> TryInto<U> for T
where U: TryFrom<T>,

Source§

type Error = <U as TryFrom<T>>::Error

The type returned in the event of a conversion error.
Source§

fn try_into(self) -> Result<U, <U as TryFrom<T>>::Error>

Performs the conversion.
Source§

impl<T> WithSubscriber for T

Source§

fn with_subscriber<S>(self, subscriber: S) -> WithDispatch<Self>
where S: Into<Dispatch>,

Attaches the provided Subscriber to this type, returning a WithDispatch wrapper. Read more
Source§

fn with_current_subscriber(self) -> WithDispatch<Self>

Attaches the current default Subscriber to this type, returning a WithDispatch wrapper. Read more