File: quickstart.go

package info (click to toggle)
golang-github-notaryproject-notation 1.3.2-1
  • links: PTS, VCS
  • area: main
  • in suites: forky, sid
  • size: 2,284 kB
  • sloc: sh: 346; makefile: 79; python: 60
file content (101 lines) | stat: -rw-r--r-- 3,748 bytes parent folder | download
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
// Copyright The Notary Project Authors.
// Licensed under the Apache License, Version 2.0 (the "License");
// you may not use this file except in compliance with the License.
// You may obtain a copy of the License at
//
// http://www.apache.org/licenses/LICENSE-2.0
//
// Unless required by applicable law or agreed to in writing, software
// distributed under the License is distributed on an "AS IS" BASIS,
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
// See the License for the specific language governing permissions and
// limitations under the License.

package scenario_test

import (
	"fmt"

	. "github.com/notaryproject/notation/test/e2e/internal/notation"
	"github.com/notaryproject/notation/test/e2e/internal/utils"
	"github.com/notaryproject/notation/test/e2e/internal/utils/validator"
	. "github.com/onsi/ginkgo/v2"
)

// quickstart doc: https://notaryproject.dev/docs/quickstart/
var _ = Describe("notation quickstart E2E test", Ordered, func() {
	var vhost *utils.VirtualHost
	var artifact *Artifact
	var artifact2 *Artifact
	var notation *utils.ExecOpts
	BeforeAll(func() {
		var err error
		// setup host
		vhost, err = utils.NewVirtualHost(NotationBinPath, CreateNotationDirOption())
		if err != nil {
			panic(err)
		}
		vhost.SetOption(AuthOption("", ""))
		notation = vhost.Executor

		// add an image to the OCI-compatible registry
		artifact = GenerateArtifact("", "")
		artifact2 = GenerateArtifact("", "")
	})

	It("list the signatures associated with the container image", func() {
		notation.Exec("ls", artifact.ReferenceWithTag()).
			MatchKeyWords("has no associated signature")
	})

	It("generate a test key and self-signed certificate", func() {
		notation.Exec("cert", "generate-test", "--default", "wabbit-networks.io").
			MatchKeyWords(
				"Successfully added wabbit-networks.io.crt",
				"wabbit-networks.io: added to the key list",
				"wabbit-networks.io: mark as default signing key")

		notation.Exec("key", "ls").
			MatchKeyWords(
				"notation/localkeys/wabbit-networks.io.key",
				"notation/localkeys/wabbit-networks.io.crt",
			)

		notation.Exec("cert", "ls").
			MatchKeyWords(
				"ca",
				"wabbit-networks.io",
				"wabbit-networks.io.crt",
			)
	})

	It("sign the container image with jws format (by default)", func() {
		notation.Exec("sign", artifact.ReferenceWithDigest()).
			MatchContent(fmt.Sprintf("Successfully signed %s\n", artifact.ReferenceWithDigest()))

		notation.Exec("ls", artifact.ReferenceWithDigest()).
			MatchKeyWords(fmt.Sprintf("%s\n└── application/vnd.cncf.notary.signature\n    └── sha256:", artifact.ReferenceWithDigest()))
	})
	It("sign the container image with cose format", func() {
		notation.Exec("sign", "--signature-format", "cose", artifact2.ReferenceWithDigest()).
			MatchContent(fmt.Sprintf("Successfully signed %s\n", artifact2.ReferenceWithDigest()))

		notation.Exec("ls", artifact2.ReferenceWithDigest()).
			MatchKeyWords(fmt.Sprintf("%s\n└── application/vnd.cncf.notary.signature\n    └── sha256:", artifact2.ReferenceWithDigest()))
	})

	It("Create a trust policy", func() {
		vhost.SetOption(AddTrustPolicyOption("quickstart_trustpolicy.json"))
		validator.CheckFileExist(vhost.AbsolutePath(NotationDirName, TrustPolicyName))
	})

	It("Verify the container image with jws format", func() {
		notation.Exec("verify", artifact.ReferenceWithDigest()).
			MatchKeyWords(fmt.Sprintf("Successfully verified signature for %s\n", artifact.ReferenceWithDigest()))
	})

	It("Verify the container image with cose format", func() {
		notation.Exec("verify", artifact2.ReferenceWithDigest()).
			MatchContent(fmt.Sprintf("Successfully verified signature for %s\n", artifact2.ReferenceWithDigest()))
	})
})