Expand description
Native-tarball packaging (R407-T2, W154).
Emits a .tar.gz containing a static musl Rust binary plus a workload-spec
manifest. Kamaji consumes the tarball at deploy time and directly
fork+exec+cgroup+pidfd-supervises the binary — no systemd Portable Service,
no per-workload .service unit. The tarball doubles as the deploy artifact
and the manifest-of-record describing how to launch the workload.
§Layout inside the tarball
bin/<basename> ← the static musl binary, 0o755
manifest.toml ← [`NativeTarballManifest`] serializedPure filesystem work; the runner-side dispatch (catalog lookup, validation
that the catalog entry actually declares produces = ["native-tarball"])
lives in crate::runner::PipelineRunner::execute_step_package_native_tarball.
Structs§
- Cosign
Signer - Default production signer — shells out to
cosign sign-blob --yes. Setcosign_binto"cosign"(PATH lookup) or an absolute path; a missing binary surfaces as aNotFoundIO error so the runner reports a clean step-failure message at the call site. - Logging
Signer - Test / local-dev fake — writes deterministic placeholder bytes so a
pipeline’s
sign-native-tarballstep succeeds without a real cosign install. NOT suitable for releases; release CI must wireCosignSignerexplicitly. - Native
Tarball Manifest - The
manifest.tomlwritten into every native-tarball. - Signed
Blob - On-disk paths emitted by a successful
SigstoreSigner::sign_blobcall.
Traits§
- Sigstore
Signer - Sign a single blob (a native tarball, conventionally) with the same
Sigstore keyless OIDC trust model that signs the OCI images today. The
signer writes the resulting
.sig/.crt/.bundlefiles next to the blob and reports their paths back so the caller can publish them.
Functions§
- native_
tarball_ output_ path - Path the packaging step writes (and the signing step reads) under
<camp_root>/.yah/cache/native/<safe-stem>.tar.gz. Single source of truth for the on-disk convention so signing never drifts from packaging. - pack_
native_ tarball - Write
<binary>andmanifest.tomlinto a.tar.gzatoutput_path. - tarball_
stem - Filesystem-safe tarball stem for a catalog image + triple pair. The runner uses this for the on-disk filename so packaging and signing both resolve the same path without re-deriving it (R407-T2 / R407-T5).