Skip to main content

Module native

Module native 

Source
Expand description

Native-tarball packaging (R407-T2, W154).

Emits a .tar.gz containing a static musl Rust binary plus a workload-spec manifest. Kamaji consumes the tarball at deploy time and directly fork+exec+cgroup+pidfd-supervises the binary — no systemd Portable Service, no per-workload .service unit. The tarball doubles as the deploy artifact and the manifest-of-record describing how to launch the workload.

§Layout inside the tarball

bin/<basename>          ← the static musl binary, 0o755
manifest.toml           ← [`NativeTarballManifest`] serialized

Pure filesystem work; the runner-side dispatch (catalog lookup, validation that the catalog entry actually declares produces = ["native-tarball"]) lives in crate::runner::PipelineRunner::execute_step_package_native_tarball.

Structs§

CosignSigner
Default production signer — shells out to cosign sign-blob --yes. Set cosign_bin to "cosign" (PATH lookup) or an absolute path; a missing binary surfaces as a NotFound IO error so the runner reports a clean step-failure message at the call site.
LoggingSigner
Test / local-dev fake — writes deterministic placeholder bytes so a pipeline’s sign-native-tarball step succeeds without a real cosign install. NOT suitable for releases; release CI must wire CosignSigner explicitly.
NativeTarballManifest
The manifest.toml written into every native-tarball.
SignedBlob
On-disk paths emitted by a successful SigstoreSigner::sign_blob call.

Traits§

SigstoreSigner
Sign a single blob (a native tarball, conventionally) with the same Sigstore keyless OIDC trust model that signs the OCI images today. The signer writes the resulting .sig / .crt / .bundle files next to the blob and reports their paths back so the caller can publish them.

Functions§

native_tarball_output_path
Path the packaging step writes (and the signing step reads) under <camp_root>/.yah/cache/native/<safe-stem>.tar.gz. Single source of truth for the on-disk convention so signing never drifts from packaging.
pack_native_tarball
Write <binary> and manifest.toml into a .tar.gz at output_path.
tarball_stem
Filesystem-safe tarball stem for a catalog image + triple pair. The runner uses this for the on-disk filename so packaging and signing both resolve the same path without re-deriving it (R407-T2 / R407-T5).