Expand description
OCI bundle layout and assembly.
The media types and in-tar paths of a stow artifact bundle, the manifest wire types the CLI reads after signature verification, and the assembler that builds the bundle tar the trusted publish stage pushes and the edge streams byte-for-byte.
Structs§
- Artifact
Blob Config - Embedded JSON config describing one artifact bundle’s identity.
- Artifact
Bundle File - One file inside an artifact bundle tar.
- Artifact
Bundle Manifest - Manifest at
manifest.jsoninside a bundle tar, describing the artifact the bundle carries and the signatures covering it. - Bundle
Artifact Config - Config blob of the
<tag>.bundleartifact: which signed artifact the bundle was assembled from. - Bundle
Layer - One layer payload handed to
assemble_bundle. - Bundle
Parts - Everything a bundle tar is assembled from.
- Bundle
Signature Material - One cosign signature as read off the signature image: the payload blob plus the annotations carried on its layer.
- Sigstore
Signature - One Sigstore (cosign) signature over a bundle’s OCI config.
Enums§
- Bundle
Assembly Error - Assembly failed: the parts do not describe one consistent artifact.
Constants§
- OCI_
IMAGE_ MANIFEST_ MEDIA_ TYPE - Media type of an OCI image manifest, which every stow artifact is pushed as.
- SIGSTORE_
BUNDLE_ ANNOTATION - Layer annotation carrying the Rekor bundle JSON, when uploaded.
- SIGSTORE_
CERT_ ANNOTATION - Layer annotation carrying the PEM Fulcio certificate of the signer.
- SIGSTORE_
OCI_ MEDIA_ TYPE - Media type cosign gives the simple-signing payload layer of a signature image.
- SIGSTORE_
SIGNATURE_ ANNOTATION - Layer annotation carrying the base64 signature over the payload.
- STOW_
ARTIFACT_ CONFIG_ MEDIA_ TYPE - Media type of the signed artifact’s OCI config blob.
- STOW_
BUNDLE_ CONFIG_ MEDIA_ TYPE - Media type of the
<tag>.bundleartifact’s OCI config blob. - STOW_
BUNDLE_ FILES_ DIR - Directory inside a bundle tar holding the artifact’s layer payloads.
- STOW_
BUNDLE_ MANIFEST_ PATH - Path of the per-artifact manifest inside a bundle tar.
- STOW_
BUNDLE_ MEDIA_ TYPE - Media type of the single-artifact bundle tar layer.
- STOW_
DYLIB_ MEDIA_ TYPE - Media type of a dylib file inside a bundle.
- STOW_
NATIVE_ ARCHIVE_ MEDIA_ TYPE - A tar of the build script’s
OUT_DIRtree, carried as its own layer. - STOW_
OCI_ CONFIG_ PATH - Path of the OCI config JSON inside a bundle tar — the document the cosign signature covers.
- STOW_
OCI_ MANIFEST_ PATH - Path of the OCI manifest JSON inside a bundle tar.
- STOW_
PROC_ MACRO_ MEDIA_ TYPE - Media type of a proc-macro dynamic library inside a bundle.
- STOW_
RLIB_ MEDIA_ TYPE - Media type of an
.rlibfile inside a bundle. - STOW_
RMETA_ MEDIA_ TYPE - Media type of an
.rmetafile inside a bundle. - STOW_
SIGSTORE_ PAYLOAD_ DIR - Directory inside a bundle tar holding Sigstore signature material.
- STOW_
ZSTD_ MEDIA_ TYPE_ SUFFIX - Media type suffix marking a zstd-compressed blob.
Functions§
- assemble_
bundle - Assemble the bundle tar for one signed artifact.
- bundle_
file_ path - In-tar path of a layer payload.
- sigstore_
payload_ path - In-tar path of the
index-th sigstore payload. - sigstore_
signature_ tag - The tag cosign stores an artifact’s signature image under: the manifest
digest with
:replaced by-, plus.sig.