Documentation
¶
Index ¶
- Constants
- func Canonical(manifest Manifest) ([]byte, error)
- func Digest(manifest Manifest) (string, error)
- func Signature(secret, timestamp, nonce string, body []byte) string
- func Verify(signed SignedManifest, trusted TrustedPublisher) error
- func VerifySignature(secret, timestamp, nonce, signature string, body []byte, now time.Time) error
- type Broker
- type BrokerImplementation
- type Compatibility
- type ConfigureRequest
- type Connection
- type Credential
- type HTTPClient
- type HTTPHandler
- type IssueRequest
- type Manifest
- type Material
- type PrepareRequest
- type Publisher
- type RenderRequest
- type RenderedEnvironment
- type RenderedFile
- type RenderedMaterial
- type Renderer
- type RendererArtifact
- type SignedManifest
- type Subject
- type TrustedPublisher
- type Verification
- type VerifyRequest
Constants ¶
View Source
const ( ManifestProtocol = "misconfig.provider-adapter/v1" BrokerProtocol = "misconfig.credential-broker/v1" RendererProtocol = "misconfig.credential-renderer/v1" )
Variables ¶
This section is empty.
Functions ¶
func Verify ¶
func Verify(signed SignedManifest, trusted TrustedPublisher) error
Types ¶
type BrokerImplementation ¶
type BrokerImplementation interface {
Prepare(context.Context, PrepareRequest) (Connection, error)
Verify(context.Context, VerifyRequest) (Verification, error)
Issue(context.Context, IssueRequest) (Material, error)
}
type Compatibility ¶
type ConfigureRequest ¶
type ConfigureRequest struct {
Protocol string `json:"protocol"`
Release string `json:"release"`
ManifestDigest string `json:"manifest_digest"`
Provider string `json:"provider"`
CredentialKind string `json:"credential_kind"`
SessionID string `json:"session_id"`
AccountRef string `json:"account_ref"`
Environments []string `json:"environments"`
ResourcePrefixes []string `json:"resource_prefixes,omitempty"`
ActivePath string `json:"active_path"`
RuntimeExecutable string `json:"runtime_executable"`
RendererExecutable string `json:"renderer_executable"`
RuntimeDirectory string `json:"runtime_directory"`
LeaseCommand []string `json:"lease_command"`
}
ConfigureRequest contains only immutable session and adapter coordinates. It never contains provider credential material. A renderer uses it to emit the provider-native environment and configuration files that cause the native client to call LeaseCommand when it needs short-lived material.
type Connection ¶
type Connection struct {
Configuration json.RawMessage `json:"configuration"`
Onboarding json.RawMessage `json:"onboarding"`
}
type Credential ¶
type HTTPClient ¶
type HTTPClient struct {
Endpoint string
ManifestDigest string
Release string
HTTP *http.Client
Now func() time.Time
Nonce func() (string, error)
}
func (HTTPClient) Issue ¶
func (c HTTPClient) Issue(ctx context.Context, request IssueRequest) (Material, error)
func (HTTPClient) Prepare ¶
func (c HTTPClient) Prepare(ctx context.Context, request PrepareRequest) (Connection, error)
func (HTTPClient) Verify ¶
func (c HTTPClient) Verify(ctx context.Context, request VerifyRequest) (Verification, error)
type HTTPHandler ¶
type HTTPHandler struct {
Implementation BrokerImplementation
ManifestDigest string
Release string
Now func() time.Time
// contains filtered or unexported fields
}
type IssueRequest ¶
type IssueRequest struct {
RequestID string `json:"request_id"`
ConnectionID string `json:"connection_id"`
Provider string `json:"provider"`
Release string `json:"release"`
AccountRef string `json:"account_ref"`
Configuration json.RawMessage `json:"configuration"`
Subject Subject `json:"subject"`
Now time.Time `json:"now"`
}
type Manifest ¶
type Manifest struct {
Protocol string `json:"protocol"`
Publisher Publisher `json:"publisher"`
Compatibility Compatibility `json:"compatibility"`
Release string `json:"release"`
Provider string `json:"provider"`
ConfigurationSchema any `json:"configuration_schema"`
Credential Credential `json:"credential"`
Renderer Renderer `json:"renderer"`
Broker Broker `json:"broker"`
}
type PrepareRequest ¶
type PrepareRequest struct {
RequestID string `json:"request_id"`
TenantID string `json:"tenant_id"`
ConnectionID string `json:"connection_id"`
Provider string `json:"provider"`
Release string `json:"release"`
AccountRef string `json:"account_ref"`
Name string `json:"name"`
Input json.RawMessage `json:"input"`
Now time.Time `json:"now"`
}
type RenderRequest ¶
type RenderRequest struct {
Protocol string `json:"protocol"`
Release string `json:"release"`
ManifestDigest string `json:"manifest_digest"`
SessionID string `json:"session_id"`
ActivePath string `json:"active_path"`
RuntimePath string `json:"runtime_path"`
Material json.RawMessage `json:"material"`
}
type RenderedEnvironment ¶
type RenderedEnvironment struct {
Remove []string `json:"remove"`
Set map[string]string `json:"set"`
Files []RenderedFile `json:"files,omitempty"`
}
type RenderedFile ¶
type RenderedMaterial ¶
type RenderedMaterial struct {
Stdout string `json:"stdout"`
}
RenderedMaterial is an envelope so the runtime can validate and bound the renderer result before writing provider-native credential output to stdout.
type Renderer ¶
type Renderer struct {
Protocol string `json:"protocol"`
Executable string `json:"executable"`
Artifacts []RendererArtifact `json:"artifacts"`
SensitiveEnvironment []string `json:"sensitive_environment,omitempty"`
}
type RendererArtifact ¶ added in v0.2.0
type SignedManifest ¶
type SignedManifest struct {
Manifest Manifest `json:"manifest"`
Digest string `json:"digest"`
Signature string `json:"signature"`
}
func Sign ¶
func Sign(manifest Manifest, privateKey ed25519.PrivateKey) (SignedManifest, error)
type TrustedPublisher ¶
type Verification ¶
type VerifyRequest ¶
type VerifyRequest struct {
RequestID string `json:"request_id"`
TenantID string `json:"tenant_id"`
ConnectionID string `json:"connection_id"`
Provider string `json:"provider"`
Release string `json:"release"`
AccountRef string `json:"account_ref"`
Configuration json.RawMessage `json:"configuration"`
Now time.Time `json:"now"`
}
Click to show internal directories.
Click to hide internal directories.