Repository navigation
Examples: Add repository uploader #2241
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
lukpueh
merged 10 commits into
theupdateframework:develop
from
jku:repository-lib-uploader
Feb 8, 2023
Merged
Changes from all commits
Commits
Show all changes
10 commits
Select commit
Hold shift + click to select a range
9ec8459
examples: Add skeleton API endpoints
jku efcb3cf
examples: Add further scaffolding for upload API
jku 69b30ec
examples: Add uploader tool example
jku 92e03d2
examples: Implement the upload API
jku 0998c20
examples: Explain uploader tool in READMEs
jku d36c0cf
examples: Rename client example directory
jku 46930e5
examples: Improve repository README
jku 26495a5
examples: Improve uploader docs/messages
jku b6465dd
examples: Add missing link in repository README
jku 5a944f9
examples: More tweaks to uploader README
jku File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -1,5 +1,6 @@ | ||
| # Usage examples | ||
|
|
||
| * [repository](repository) | ||
| * [client](client_example) | ||
| * [repository built with low-level Metadata API](manual_repo) | ||
| * [client](client) | ||
| * [uploader tool](uploader) | ||
| * [Low-level Metadata API examples](manual_repo) |
File renamed without changes.
File renamed without changes.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,44 @@ | ||
| # TUF Uploader Tool Example | ||
|
|
||
| :warning: This example uses the repository module which is not considered | ||
| part of the python-tuf stable API quite yet. | ||
|
|
||
| This is an example maintainer tool: It makes it possible to add delegations to | ||
| a remote repository, and then to upload delegated metadata to the repository. | ||
|
jku marked this conversation as resolved.
|
||
|
|
||
| Features: | ||
| - Initialization (much like the [client example](../client/)) | ||
| - Claim delegation: this uses "unsafe repository API" in the sense that the | ||
| uploader sends repository unsigned data. This operation can be | ||
| compared to claiming a project name on PyPI.org | ||
| - Add targetfile: Here uploader uses signing keys that were added to the | ||
| delegation in the previous step to create a new version of the delegated | ||
| metadata. The repository will verify signatures on this metadata. | ||
|
|
||
| The used TUF repository can be set with `--url` (default repository is | ||
| "http://127.0.0.1:8001" which is also the default for the repository example). | ||
| In practice the uploader tool is only useful with the repository example. | ||
|
|
||
| ### Usage with the repository example | ||
|
|
||
| In one terminal, run the [repository example](../repository/) and leave it running: | ||
| ```console | ||
| examples/repository/repo | ||
| ``` | ||
|
|
||
| In another terminal, run uploader: | ||
|
|
||
| ```console | ||
| # Initialize with Trust-On-First-Use | ||
| ./uploader tofu | ||
|
|
||
| # Then claim a delegation for yourself (this also creates a new signing key): | ||
| ./uploader add-delegation myrole | ||
|
|
||
| # Then add a new downloadable target file to your delegated role (to keep the | ||
| # example simple, the target file content is always the targetpath): | ||
| ./uploader add-target myrole myrole/mytargetfile | ||
| ``` | ||
|
|
||
| At this point "myrole/mytargetfile" is downloadable from the repository | ||
|
jku marked this conversation as resolved.
|
||
| with the [client example](../client/). | ||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.