- I think it would be better if one for commands only, one for the spec handling core logic so people won't be confused by the core logic inside the commands folder (cleaner I guess) - Regen docs
85 lines
5.9 KiB
Go
85 lines
5.9 KiB
Go
package ops
|
|
|
|
import (
|
|
"github.com/versenilvis/iris/spec"
|
|
)
|
|
|
|
func init() {
|
|
spec.Register(&spec.Spec{
|
|
Name: "cosign",
|
|
Description: "Provides utilities for attaching artifacts to other artifacts in a registry",
|
|
Subcommands: []spec.Subcommand{
|
|
{Name: "attach", Description: "Provides utilities for attaching artifacts to other artifacts in a registry"},
|
|
{Name: "attestation", Description: "Attach attestation to the supplied container image"},
|
|
{Name: "sbom", Description: "Attach sbom to the supplied container image"},
|
|
{Name: "signature", Description: "Attach signatures to the supplied container image"},
|
|
{Name: "attest", Description: "Attest the supplied container image"},
|
|
{Name: "clean", Description: "Remove all signatures from an image"},
|
|
{Name: "completion", Description: "Generate completion script"},
|
|
{Name: "copy", Description: "Copy the supplied container image and signatures"},
|
|
{Name: "verify", Description: "Verify a signature on the base image specified in the Dockerfile"},
|
|
{Name: "generate", Description: "Generates (unsigned) signature payloads from the supplied container image"},
|
|
{Name: "generate-key-pair", Description: "Generates a key-pair"},
|
|
{Name: "import-key-pair", Description: "Imports a PEM-encoded RSA or EC private key"},
|
|
{Name: "load", Description: "Load a signed image on disk to a remote registry"},
|
|
{Name: "login", Description: "Log in to a registry"},
|
|
{Name: "piv-tool", Description: "This cosign was not built with piv-tool support!"},
|
|
{Name: "pkcs11-tool", Description: "This cosign was not built with pkcs11-tool support!"},
|
|
{Name: "policy", Description: "Subcommand to manage a keyless policy"},
|
|
{Name: "init", Description: "Generate a new keyless policy"},
|
|
{Name: "sign", Description: "Sign a keyless policy"},
|
|
{Name: "public-key", Description: "Gets a public key from the key-pair"},
|
|
{Name: "sign-blob", Description: "Sign the supplied blob, outputting the base64-encoded signature to stdout"},
|
|
{Name: "upload", Description: "Provides utilities for uploading artifacts to a registry"},
|
|
{Name: "blob", Description: "Upload one or more blobs to the supplied container image address"},
|
|
{Name: "wasm", Description: "Upload a wasm module to the supplied container image reference"},
|
|
{Name: "verify-attestation", Description: "Verify an attestation on the supplied container image"},
|
|
{Name: "verify-blob", Description: "Verify a signature on the supplied blob"},
|
|
{Name: "version", Description: "Prints the version"},
|
|
{Name: "help", Description: "Help about any command"},
|
|
},
|
|
Options: []spec.Option{
|
|
{Name: "--output-file", Description: "Log output to a file"},
|
|
{Name: "--timeout", Description: "Timeout for commands"},
|
|
{Name: "--verbose", Description: "Log debug output"},
|
|
{Name: "--allow-insecure-registry", Description: "Path to the attestation envelope"},
|
|
{Name: "--k8s-keychain", Description: "Help for attestation"},
|
|
{Name: "--type", Description: "Type of sbom (spdx|cyclonedx|syft)"},
|
|
{Name: "--help", Description: "Help for sbom"},
|
|
{Name: "--signature", Description: "The signature, path to the signature, or {-} for stdin"},
|
|
{Name: "--force", Description: "Skip warnings and confirmations"},
|
|
{Name: "--fulcio-url", Description: "[EXPERIMENTAL] address of sigstore PKI server"},
|
|
{Name: "--identity-token", Description: "[EXPERIMENTAL] identity token to use for certificate from fulcio"},
|
|
{Name: "--insecure-skip-verify", Description: "Path to the private key file, KMS URI or Kubernetes Secret"},
|
|
{Name: "--no-upload", Description: "Do not upload the generated attestation"},
|
|
{Name: "--oidc-client-id", Description: "[EXPERIMENTAL] OIDC client ID for application"},
|
|
{Name: "--oidc-client-secret", Description: "[EXPERIMENTAL] OIDC client secret for application"},
|
|
{Name: "--oidc-issuer", Description: "[EXPERIMENTAL] OIDC provider to be used to issue ID token"},
|
|
{Name: "--predicate", Description: "Path to the predicate file"},
|
|
{Name: "--recursive", Description: "If a multi-arch image is specified, additionally sign each discrete image"},
|
|
{Name: "--rekor-url", Description: "[EXPERIMENTAL] address of rekor STL server"},
|
|
{Name: "--replace", Description: "Whether to use a hardware security key"},
|
|
{Name: "--slot", Description: "Specify a predicate type (slsaprovenance|link|spdx|vuln|custom) or an URI"},
|
|
{Name: "--attachment", Description: "Related image attachment to sign (sbom), default none"},
|
|
{Name: "--attachment-tag-prefix", Description: "Only verify the base image (the last FROM image in the Dockerfile)"},
|
|
{Name: "--cert", Description: "Path to the public certificate"},
|
|
{Name: "--cert-email", Description: "The email expected in a valid Fulcio certificate"},
|
|
{Name: "--cert-oidc-issuer", Description: "Whether to check the claims found"},
|
|
{Name: "--local-image", Description: "Output format for the signing image information (json|text)"},
|
|
{Name: "--signature-digest-algorithm", Description: "Whether to use a hardware security key"},
|
|
{Name: "--kms", Description: "Create key pair in KMS service to use for signing"},
|
|
{Name: "--key", Description: "Import key pair to use for signing"},
|
|
{Name: "--mirror", Description: "GCS bucket to a SigStore TUF repository or HTTP(S) base URL"},
|
|
{Name: "--root", Description: "Path to trusted initial root. defaults to embedded root"},
|
|
{Name: "--dir", Description: "Path to directory where the signed image is stored on disk"},
|
|
{Name: "--password", Description: "Password"},
|
|
{Name: "--password-stdin", Description: "Take the password from stdin"},
|
|
{Name: "--username", Description: "Username"},
|
|
{Name: "--issuer", Description: "Trusted issuer to use for identity tokens, e.g. https://accounts.google.com"},
|
|
{Name: "--namespace", Description: "Registry namespace that the root policy belongs to"},
|
|
{Name: "--out", Description: "Output policy locally"},
|
|
{Name: "--threshold", Description: "Threshold for root policy signers"},
|
|
},
|
|
})
|
|
}
|