mirror of
				https://github.com/linuxkit/linuxkit.git
				synced 2025-10-31 10:41:44 +00:00 
			
		
		
		
	Prior to notary 0.6.0, notary expected a terminal and only accepted username/password interactively. With notary 0.6.0 this can now be passed as en environment variable 'NOTARY_AUTH' in the form of a base64 encoded 'username:password'. This commit removes the ugly 'expect' hack in favour of the much cleaner use of an environment variable. Signed-off-by: Rolf Neugebauer <rolf.neugebauer@docker.com>
		
			
				
	
	
		
			78 lines
		
	
	
		
			2.6 KiB
		
	
	
	
		
			Bash
		
	
	
		
			Executable File
		
	
	
	
	
			
		
		
	
	
			78 lines
		
	
	
		
			2.6 KiB
		
	
	
	
		
			Bash
		
	
	
		
			Executable File
		
	
	
	
	
| #! /bin/sh
 | |
| 
 | |
| set -e
 | |
| 
 | |
| # This script pushes a multiarch manifest for packages and signs it.
 | |
| #
 | |
| # The TARGET must be of the form <org>/<image>:<tag> and this is what
 | |
| # the manifest is pushed to. It assumes that there is are images of
 | |
| # the form <org>/<image>:<tag>-<arch> already on hub.
 | |
| #
 | |
| # If TRUST is not set, the manifest will not be signed.
 | |
| #
 | |
| # For signing, DOCKER_CONTENT_TRUST_REPOSITORY_PASSPHRASE must be set.
 | |
| 
 | |
| # This should all be replaced with 'docker manifest' once it lands.
 | |
| 
 | |
| TARGET=$1
 | |
| TRUST=$2
 | |
| 
 | |
| REPO=$(echo "$TARGET" | cut -d':' -f1)
 | |
| TAG=$(echo "$TARGET" | cut -d':' -f2)
 | |
| 
 | |
| # Work out credentials. On macOS they are needed for manifest-tool and
 | |
| # we need them for notary on all platforms.
 | |
| case $(uname -s) in
 | |
|     Darwin)
 | |
|         # Prior to 2018-03-27 D4M used a .bin suffix on the keychain utility binary name. Support the old name for a while
 | |
|         if [ -f /Applications/Docker.app/Contents/Resources/bin/docker-credential-osxkeychain.bin ]; then
 | |
|             CRED=$(echo "https://index.docker.io/v1/" | /Applications/Docker.app/Contents/Resources/bin/docker-credential-osxkeychain.bin get)
 | |
|         else
 | |
|             CRED=$(echo "https://index.docker.io/v1/" | /Applications/Docker.app/Contents/Resources/bin/docker-credential-osxkeychain get)
 | |
|         fi
 | |
|         USER=$(echo "$CRED" | jq -r '.Username')
 | |
|         PASS=$(echo "$CRED" | jq -r '.Secret')
 | |
|         MT_ARGS="--username $USER --password $PASS"
 | |
|         ;;
 | |
|     Linux)
 | |
|         CRED=$(cat ~/.docker/config.json | jq -r '.auths."https://index.docker.io/v1/".auth' | base64 -d -)
 | |
|         USER=$(echo $CRED | cut -d ':' -f 1)
 | |
|         PASS=$(echo $CRED | cut -d ':' -f 2-)
 | |
|         # manifest-tool can use docker credentials directly
 | |
|         MT_ARGS=
 | |
|         ;;
 | |
|     *)
 | |
|         echo "Unsupported platform"
 | |
|         exit 1
 | |
|         ;;
 | |
| esac
 | |
| 
 | |
| # Push manifest list
 | |
| OUT=$(manifest-tool $MT_ARGS push from-args \
 | |
|                     --ignore-missing \
 | |
|                     --platforms linux/amd64,linux/arm64,linux/s390x \
 | |
|                     --template "$TARGET"-ARCH \
 | |
|                     --target "$TARGET")
 | |
| 
 | |
| echo "$OUT"
 | |
| if [ -z "$TRUST" ]; then
 | |
|     echo "Not signing $TARGET"
 | |
|     exit 0
 | |
| fi
 | |
| 
 | |
| # Extract sha256 and length from the manifest-tool output
 | |
| SHA256=$(echo "$OUT" | cut -d' ' -f2 | cut -d':' -f2)
 | |
| LEN=$(echo "$OUT" | cut -d' ' -f3)
 | |
| 
 | |
| # notary 0.6.0 accepts authentication as base64-encoded "username:password"
 | |
| export NOTARY_AUTH=$(echo "$USER:$PASS" | base64)
 | |
| export NOTARY_DELEGATION_PASSPHRASE="$DOCKER_CONTENT_TRUST_REPOSITORY_PASSPHRASE"
 | |
| 
 | |
| notary -s https://notary.docker.io -d $HOME/.docker/trust addhash \
 | |
|        -p docker.io/$REPO $TAG $LEN --sha256 $SHA256 \
 | |
|        -r targets/releases
 | |
| 
 | |
| echo
 | |
| echo "New signed multi-arch image: $REPO:$TAG"
 | |
| echo
 |