constellation/hack/oci-pin/sum.go
miampf f16ccf5679
rewrote packages
keyservice
joinservice
upgrade-agent
measurement-reader
debugd
disk-mapper

rewrote joinservice main

rewrote some unit tests

rewrote upgrade-agent + some grpc functions

rewrote measurement-reader

rewrote debugd

removed unused import

removed forgotten zap reference in measurements reader

rewrote disk-mapper + tests

rewrote packages

verify
disk-mapper
malicious join
bootstrapper
attestationconfigapi
versionapi
internal/cloud/azure
disk-mapper tests
image/upload/internal/cmd

rewrote verify (WIP with loglevel increase)

rewrote forgotten zap references in disk-mapper

rewrote malicious join

rewrote bootstrapper

rewrote parts of internal/

rewrote attestationconfigapi (WIP)

rewrote versionapi cli

rewrote internal/cloud/azure

rewrote disk-mapper tests (untested by me rn)

rewrote image/upload/internal/cmd

removed forgotten zap references in verify/cmd

rewrote packages

hack/oci-pin
hack/qemu-metadata-api
debugd/internal/debugd/deploy
hack/bazel-deps-mirror
cli/internal/cmd
cli-k8s-compatibility

rewrote hack/qemu-metadata-api/server

rewrote debugd/internal/debugd/deploy

rewrote hack/bazel-deps-mirror

rewrote rest of hack/qemu-metadata-api

rewrote forgotten zap references in joinservice server

rewrote cli/internal/cmd

rewrote cli-k8s-compatibility

rewrote packages

internal/staticupload
e2d/internal/upgrade
internal/constellation/helm
internal/attestation/aws/snp
internal/attestation/azure/trustedlaunch
joinservice/internal/certcache/amkds

some missed unit tests

rewrote e2e/internal/upgrade

rewrote internal/constellation/helm

internal/attestation/aws/snp

internal/attestation/azure/trustedlaunch

joinservice/internal/certcache/amkds

search and replace test logging over all left *_test.go
2024-02-08 13:14:14 +01:00

139 lines
3.3 KiB
Go

/*
Copyright (c) Edgeless Systems GmbH
SPDX-License-Identifier: AGPL-3.0-only
*/
package main
import (
"fmt"
"io"
"log/slog"
"os"
"path/filepath"
"strings"
"github.com/edgelesssys/constellation/v2/hack/oci-pin/internal/extract"
"github.com/edgelesssys/constellation/v2/hack/oci-pin/internal/sums"
"github.com/spf13/cobra"
)
func newSumCmd() *cobra.Command {
cmd := &cobra.Command{
Use: "sum",
Short: "Generate sha256sum file that pins an OCI image.",
RunE: runSum,
}
cmd.Flags().String("oci-path", "", "Path to the OCI image to pin.")
cmd.Flags().String("output", "-", "Output file. If not set, the output is written to stdout.")
cmd.Flags().String("image-name", "", "Short name (suffix) of the OCI image to pin.")
cmd.Flags().String("repoimage-tag-file", "", "Tag file of the OCI image to pin.")
must(cmd.MarkFlagRequired("repoimage-tag-file"))
must(cmd.MarkFlagRequired("oci-path"))
return cmd
}
func runSum(cmd *cobra.Command, _ []string) error {
flags, err := parseSumFlags(cmd)
if err != nil {
return err
}
log := slog.New(slog.NewTextHandler(os.Stdout, &slog.HandlerOptions{Level: flags.logLevel}))
log.Debug(fmt.Sprintf("Parsed flags: %+v", flags))
registry, prefix, name, tag, err := splitRepoTag(flags.imageRepoTag)
if err != nil {
return fmt.Errorf("splitting repo tag: %w", err)
}
log.Debug(fmt.Sprintf("Generating sum file for OCI image %s.", name))
ociIndexPath := filepath.Join(flags.ociPath, "index.json")
index, err := os.Open(ociIndexPath)
if err != nil {
return fmt.Errorf("opening OCI index at %q: %w", ociIndexPath, err)
}
defer index.Close()
var out io.Writer
if flags.output == "-" {
out = cmd.OutOrStdout()
} else {
f, err := os.Create(flags.output)
if err != nil {
return fmt.Errorf("creating output file %q: %w", flags.output, err)
}
defer f.Close()
out = f
}
digest, err := extract.Digest(index)
if err != nil {
return fmt.Errorf("extracting OCI image digest: %w", err)
}
log.Debug(fmt.Sprintf("OCI image digest: %s", digest))
refs := []sums.PinnedImageReference{
{
Registry: registry,
Prefix: prefix,
Name: name,
Tag: tag,
Digest: digest,
},
}
if err := sums.Create(refs, out); err != nil {
return fmt.Errorf("creating sum file: %w", err)
}
log.Debug(fmt.Sprintf("Sum file created at %q 🤖", flags.output))
return nil
}
type sumFlags struct {
ociPath string
output string
imageRepoTag string
logLevel slog.Level
}
func parseSumFlags(cmd *cobra.Command) (sumFlags, error) {
ociPath, err := cmd.Flags().GetString("oci-path")
if err != nil {
return sumFlags{}, err
}
output, err := cmd.Flags().GetString("output")
if err != nil {
return sumFlags{}, err
}
imageTagFile, err := cmd.Flags().GetString("repoimage-tag-file")
if err != nil {
return sumFlags{}, err
}
tag, err := os.ReadFile(imageTagFile)
if err != nil {
return sumFlags{}, fmt.Errorf("reading image repotag file %q: %w", imageTagFile, err)
}
imageRepoTag := strings.TrimSpace(string(tag))
verbose, err := cmd.Flags().GetBool("verbose")
if err != nil {
return sumFlags{}, err
}
logLevel := slog.LevelInfo
if verbose {
logLevel = slog.LevelDebug
}
return sumFlags{
ociPath: ociPath,
output: output,
imageRepoTag: imageRepoTag,
logLevel: logLevel,
}, nil
}