tap: attesto 0.5.0 + attesto-local-vault 2.0.1
Mirrored from attesto-v1 ops/get-host/homebrew/ (commit f21339ce); hashes from the KMS-signed channel manifests on get.attesto.eu. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,178 @@
|
||||
# Attesto Local Vault — container-wrapper formula.
|
||||
#
|
||||
# The Local Vault ships ONLY as a container image, pinned by digest. This
|
||||
# formula does not install a native vault; it installs a small POSIX-sh
|
||||
# wrapper that runs every CLI subcommand inside that image via Docker.
|
||||
#
|
||||
# PROVENANCE OF THE sha256 VALUE: the url below is the signed installer copy
|
||||
# from the versioned channel, and its hash is copied verbatim from the SIGNED
|
||||
# manifest https://get.attesto.eu/local-vault/2.0.1/SHA256SUMS after
|
||||
# verifying its cosign signature:
|
||||
#
|
||||
# curl -fsSLO https://get.attesto.eu/cosign.pub
|
||||
# curl -fsSLO https://get.attesto.eu/local-vault/2.0.1/SHA256SUMS
|
||||
# curl -fsSLO https://get.attesto.eu/local-vault/2.0.1/SHA256SUMS.sig
|
||||
# cosign verify-blob --key cosign.pub --insecure-ignore-tlog \
|
||||
# --signature SHA256SUMS.sig SHA256SUMS
|
||||
#
|
||||
# (--insecure-ignore-tlog: KMS release key, no Rekor entry — the project's
|
||||
# documented verification flow.)
|
||||
#
|
||||
# SYNC CONTRACT: the wrapper heredoc below must stay behaviorally identical
|
||||
# (same docker argv) to the wrapper embedded in the channel installer
|
||||
# (ops/get-host/local-vault/install.sh in the main repo, served as
|
||||
# https://get.attesto.eu/local-vault/install.sh). The check
|
||||
# tests/wrapper_sync_check.sh in the tap source tree runs both against a
|
||||
# stub docker and diffs the argv; it extracts the heredoc textually, so keep
|
||||
# the <<~'WRAPPER' markers and the 6-space body indentation.
|
||||
class AttestoLocalVault < Formula
|
||||
desc "Container wrapper for the Attesto Local Vault (digest-pinned image)"
|
||||
homepage "https://attesto.eu"
|
||||
url "https://get.attesto.eu/local-vault/2.0.1/install.sh"
|
||||
sha256 "35770b22886f04a7021d6b854d21f1208092fa02eca5d9c8762218ced4861ae5"
|
||||
license "Apache-2.0"
|
||||
|
||||
def install
|
||||
# The staged download is the signed channel installer. It is kept for
|
||||
# reference/out-of-band verification only — never executed; the wrapper
|
||||
# written below is the Homebrew-native equivalent of the wrapper that
|
||||
# installer would write.
|
||||
pkgshare.install "install.sh"
|
||||
|
||||
(bin/"attesto-local-vault").write wrapper_script
|
||||
chmod 0755, bin/"attesto-local-vault"
|
||||
end
|
||||
|
||||
def caveats
|
||||
<<~EOS
|
||||
attesto-local-vault is a container wrapper: it needs a working Docker
|
||||
engine at runtime (Docker Desktop on macOS, Docker Engine on Linux).
|
||||
Homebrew does not and cannot install Docker for you.
|
||||
|
||||
Honesty note for macOS: the Local Vault and its Linux-only provider
|
||||
sandbox run inside Docker Desktop's Linux VM. Attesto's isolation
|
||||
claims apply within that VM — a native macOS process would not carry
|
||||
them, which is exactly why this install is a container wrapper and
|
||||
never claims native isolation.
|
||||
|
||||
The first run pulls the digest-pinned image and prepares the state and
|
||||
config directories under
|
||||
${XDG_DATA_HOME:-~/.local/share}/attesto-local-vault
|
||||
(override the root with ATTESTO_LOCAL_VAULT_HOME). The state directory
|
||||
holds the vault's keys, spool, and provenance capsules — deleting it
|
||||
destroys evidence that may exist nowhere else.
|
||||
|
||||
Get started (mint a single-use enrollment token in the console):
|
||||
attesto-local-vault init --base-url https://verify.attesto.eu --enrollment-token lvet_...
|
||||
attesto-local-vault doctor
|
||||
EOS
|
||||
end
|
||||
|
||||
test do
|
||||
# The wrapper must at least parse.
|
||||
system "sh", "-n", bin/"attesto-local-vault"
|
||||
|
||||
# Run it against a stub docker and inspect the argv it produces: the
|
||||
# digest-pinned image, the state/config mounts, and our arguments must
|
||||
# all be there.
|
||||
(testpath/"stub").mkpath
|
||||
(testpath/"stub/docker").write <<~STUB
|
||||
#!/bin/sh
|
||||
printf '%s\\n' "$@" >> "#{testpath}/docker-argv.log"
|
||||
exit 0
|
||||
STUB
|
||||
chmod 0755, testpath/"stub/docker"
|
||||
ENV.prepend_path "PATH", testpath/"stub"
|
||||
ENV["ATTESTO_LOCAL_VAULT_HOME"] = (testpath/"vault-home").to_s
|
||||
|
||||
system bin/"attesto-local-vault", "--help"
|
||||
|
||||
log = (testpath/"docker-argv.log").read
|
||||
assert_match "git.attesto.eu/attesto/local-vault@sha256:" \
|
||||
"5799e7f0669c9b42a55a338f4233cfa5afb5aa6a2627c2c50f7545a41bff1551", log
|
||||
assert_match "--help", log
|
||||
assert_match "/var/lib/attesto", log
|
||||
assert_match "/etc/attesto/local-vault", log
|
||||
end
|
||||
|
||||
private
|
||||
|
||||
# Kept in sync with the wrapper written by install.sh — see the SYNC
|
||||
# CONTRACT comment at the top of this file. The single-quoted chown script
|
||||
# inside the bootstrap block must stay byte-identical to install.sh's
|
||||
# (including its 4-space continuation line): it is a single docker argv
|
||||
# element and the sync check compares argv exactly.
|
||||
def wrapper_script
|
||||
<<~'WRAPPER'
|
||||
#!/usr/bin/env sh
|
||||
# attesto-local-vault — container wrapper installed by Homebrew
|
||||
# (attesto/attesto tap). Every argument is passed to the CLI inside the
|
||||
# image; stdin/stdout and the exit code pass through.
|
||||
# ATTESTO_LOCAL_VAULT_IMAGE overrides the image for one invocation; all
|
||||
# other ATTESTO_LOCAL_VAULT_* environment variables are forwarded into
|
||||
# the container. Kept behaviorally identical (same docker argv) to the
|
||||
# wrapper written by https://get.attesto.eu/local-vault/install.sh.
|
||||
set -eu
|
||||
|
||||
IMAGE="${ATTESTO_LOCAL_VAULT_IMAGE:-git.attesto.eu/attesto/local-vault@sha256:5799e7f0669c9b42a55a338f4233cfa5afb5aa6a2627c2c50f7545a41bff1551}"
|
||||
ROOT_DIR="${ATTESTO_LOCAL_VAULT_HOME:-${XDG_DATA_HOME:-$HOME/.local/share}/attesto-local-vault}"
|
||||
STATE_DIR="$ROOT_DIR/data" # mounted at /var/lib/attesto
|
||||
CONFIG_DIR="$ROOT_DIR/config" # mounted at /etc/attesto/local-vault
|
||||
|
||||
if ! command -v docker >/dev/null 2>&1; then
|
||||
echo "attesto-local-vault: docker is required but was not found on PATH." >&2
|
||||
echo "Install Docker Desktop (macOS) or Docker Engine (Linux) and retry." >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
# First run: create the state+config dirs and hand them to the image's
|
||||
# unprivileged user, exactly as the channel installer does at install
|
||||
# time. On Docker Desktop (macOS) the chown is a harmless no-op. The
|
||||
# quoted -c script must stay byte-identical to install.sh's.
|
||||
if [ ! -d "$STATE_DIR" ] || [ ! -d "$CONFIG_DIR" ]; then
|
||||
mkdir -p "$STATE_DIR" "$CONFIG_DIR"
|
||||
docker run --rm --user root --entrypoint /bin/sh \
|
||||
-v "$STATE_DIR:/var/lib/attesto" \
|
||||
-v "$CONFIG_DIR:/etc/attesto/local-vault" \
|
||||
"$IMAGE" -c 'chown attesto:attesto-provider /var/lib/attesto /etc/attesto/local-vault \
|
||||
&& install -d -o attesto -g attesto-provider -m 2770 /var/lib/attesto/provider-work /var/lib/attesto/run'
|
||||
fi
|
||||
|
||||
tty_flags=""
|
||||
if [ -t 0 ] && [ -t 1 ]; then tty_flags="-t"; fi
|
||||
|
||||
# Forward ATTESTO_LOCAL_VAULT_* env vars (after the wrapper defaults, so an
|
||||
# explicit host value wins). The wrapper's own image knob stays on the host,
|
||||
# and the container config dir is always the mounted path.
|
||||
env_flags=""
|
||||
for name in $(env | sed -n 's/^\(ATTESTO_LOCAL_VAULT_[A-Za-z0-9_]*\)=.*/\1/p'); do
|
||||
case "$name" in
|
||||
ATTESTO_LOCAL_VAULT_IMAGE|ATTESTO_LOCAL_VAULT_CONFIG_DIR) continue ;;
|
||||
esac
|
||||
env_flags="$env_flags -e $name"
|
||||
done
|
||||
|
||||
run() {
|
||||
# shellcheck disable=SC2086 # tty_flags/env_flags are token-safe
|
||||
exec docker run --rm -i $tty_flags \
|
||||
-v "$STATE_DIR:/var/lib/attesto" \
|
||||
-v "$CONFIG_DIR:/etc/attesto/local-vault" \
|
||||
-e ATTESTO_LOCAL_VAULT_CONFIG_DIR=/etc/attesto/local-vault \
|
||||
-e ATTESTO_LOCAL_VAULT_SPOOL_DB=/var/lib/attesto/spool.sqlite3 \
|
||||
-e ATTESTO_LOCAL_VAULT_FINALIZED_QUEUE_DB=/var/lib/attesto/finalized-evidence.sqlite3 \
|
||||
-e ATTESTO_LOCAL_VAULT_CAPSULE_STORE_DB=/var/lib/attesto/provenance-capsules.sqlite3 \
|
||||
-e ATTESTO_LOCAL_VAULT_WITNESS_DB=/var/lib/attesto/witness.sqlite3 \
|
||||
$env_flags \
|
||||
"$@"
|
||||
}
|
||||
|
||||
# Mount the caller's working directory so file arguments (attestation
|
||||
# files, JSON payloads) resolve transparently. Skipped for / and for
|
||||
# paths a -v flag cannot express.
|
||||
case "$PWD" in
|
||||
/|*:*) run "$IMAGE" "$@" ;;
|
||||
*) run -v "$PWD:/workdir" -w /workdir "$IMAGE" "$@" ;;
|
||||
esac
|
||||
WRAPPER
|
||||
end
|
||||
end
|
||||
Reference in New Issue
Block a user