mirror of
https://github.com/hashicorp/packer.git
synced 2026-09-18 22:11:39 -04:00
* feat(provenance): add SLSA provenance and attestation signing libraries Add internal/provenance for deriving in-toto subjects from Packer artifacts, building SLSA Provenance v1 predicates, wrapping in-toto statements, and best-effort git/CI source detection. Add internal/attestation for DSSE envelope handling and a pluggable Signer/Verifier backend supporting key (local PEM), kms (aws/gcp/ azure/hashivault), and keyless (Sigstore Fulcio) modes, plus Sigstore bundle handling and DSSE/policy verification. Add the supporting module dependencies in go.mod/go.sum. * feat(provenance): add provenance post-processor Add the opt-in "provenance" post-processor that runs after a build, derives subjects from the artifact, emits DSSE-wrapped SLSA provenance (and optional SBOM) attestations, signs them via the configured signing backend, and writes sidecar files (including *.sigstore.json bundles in keyless mode). Register it in the core post-processor set. The provenance enable flag is a tri-state so an unset value stays enabled through HCL2 decoding instead of being silently disabled. * feat(provenance): add verify-attestation command Add "packer verify-attestation" to verify signed DSSE attestations against key, KMS, and keyless policy inputs, including optional Sigstore bundle checks for Rekor and timestamp evidence. Register the command in the CLI. * docs(provenance): add reference CI workflows and changelog Add reference GitHub Actions workflows under examples/ci for SLSA L2 keyless signing and L3-compatible delegated signing * fix: lint and tests * Added docs for Provenance PostProcessor
151 lines
3.4 KiB
Go
151 lines
3.4 KiB
Go
// Copyright IBM Corp. 2024, 2025
|
|
// SPDX-License-Identifier: BUSL-1.1
|
|
|
|
package main
|
|
|
|
import (
|
|
"github.com/hashicorp/packer/command"
|
|
"github.com/mitchellh/cli"
|
|
)
|
|
|
|
// Commands is the mapping of all the available Packer commands.
|
|
var Commands map[string]cli.CommandFactory
|
|
|
|
// CommandMeta is the Meta to use for the commands. This must be written
|
|
// before the CLI is started.
|
|
var CommandMeta *command.Meta
|
|
|
|
const ErrorPrefix = "e:"
|
|
const OutputPrefix = "o:"
|
|
|
|
func init() {
|
|
Commands = map[string]cli.CommandFactory{
|
|
"build": func() (cli.Command, error) {
|
|
return &command.BuildCommand{Meta: *CommandMeta}, nil
|
|
},
|
|
"console": func() (cli.Command, error) {
|
|
return &command.ConsoleCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"execute": func() (cli.Command, error) {
|
|
return &command.ExecuteCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"fix": func() (cli.Command, error) {
|
|
return &command.FixCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"fmt": func() (cli.Command, error) {
|
|
return &command.FormatCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"hcl2_upgrade": func() (cli.Command, error) {
|
|
return &command.HCL2UpgradeCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"init": func() (cli.Command, error) {
|
|
return &command.InitCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"inspect": func() (cli.Command, error) {
|
|
return &command.InspectCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"plugins": func() (cli.Command, error) {
|
|
return &command.PluginsCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"plugins installed": func() (cli.Command, error) {
|
|
return &command.PluginsInstalledCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"plugins install": func() (cli.Command, error) {
|
|
return &command.PluginsInstallCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"plugins remove": func() (cli.Command, error) {
|
|
return &command.PluginsRemoveCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"plugins required": func() (cli.Command, error) {
|
|
return &command.PluginsRequiredCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"validate": func() (cli.Command, error) {
|
|
return &command.ValidateCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
|
|
"version": func() (cli.Command, error) {
|
|
return &command.VersionCommand{
|
|
Meta: *CommandMeta,
|
|
CheckFunc: commandVersionCheck,
|
|
}, nil
|
|
},
|
|
|
|
"sbom-generate": func() (cli.Command, error) {
|
|
return &command.SBOMGenerateCommand{Meta: *CommandMeta}, nil
|
|
},
|
|
|
|
"verify-attestation": func() (cli.Command, error) {
|
|
return &command.VerifyAttestationCommand{Meta: *CommandMeta}, nil
|
|
},
|
|
|
|
// plugin is essentially an alias to the plugins command
|
|
//
|
|
// It is not meant to be documented or used outside of simple
|
|
// typos, as it's easy to write plugin instead of plugins, so
|
|
// we opted not to error, but silently alias the two writings.
|
|
"plugin": func() (cli.Command, error) {
|
|
return &command.PluginsCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
"plugin installed": func() (cli.Command, error) {
|
|
return &command.PluginsInstalledCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
"plugin install": func() (cli.Command, error) {
|
|
return &command.PluginsInstallCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
"plugin remove": func() (cli.Command, error) {
|
|
return &command.PluginsRemoveCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
"plugin required": func() (cli.Command, error) {
|
|
return &command.PluginsRequiredCommand{
|
|
Meta: *CommandMeta,
|
|
}, nil
|
|
},
|
|
}
|
|
}
|