-
Notifications
You must be signed in to change notification settings - Fork 11
feat(xpkg): add --annotation flag to xpkg build and xpkg push #11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
base: main
Are you sure you want to change the base?
Changes from all commits
4386cea
7ec8790
a119d6e
73f8bf9
29c10b2
f40a61f
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,61 @@ | ||
| /* | ||
| Copyright 2026 The Crossplane Authors. | ||
|
|
||
| Licensed under the Apache License, Version 2.0 (the "License"); | ||
| you may not use this file except in compliance with the License. | ||
| You may obtain a copy of the License at | ||
|
|
||
| http://www.apache.org/licenses/LICENSE-2.0 | ||
|
|
||
| Unless required by applicable law or agreed to in writing, software | ||
| distributed under the License is distributed on an "AS IS" BASIS, | ||
| WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| See the License for the specific language governing permissions and | ||
| limitations under the License. | ||
| */ | ||
|
|
||
| package xpkg | ||
|
|
||
| import ( | ||
| "strings" | ||
|
|
||
| v1 "github.com/google/go-containerregistry/pkg/v1" | ||
| "github.com/google/go-containerregistry/pkg/v1/mutate" | ||
|
|
||
| "github.com/crossplane/crossplane-runtime/v2/pkg/errors" | ||
| ) | ||
|
|
||
| // parseAnnotations parses a slice of "key=value" strings into a map. Returns | ||
| // an error if any entry is not in key=value format. | ||
| func parseAnnotations(kvs []string) (map[string]string, error) { | ||
| anns := make(map[string]string, len(kvs)) | ||
| for _, kv := range kvs { | ||
| k, v, ok := strings.Cut(kv, "=") | ||
| if !ok { | ||
| return nil, errors.Errorf("invalid annotation %q: must be in key=value format", kv) | ||
| } | ||
| if k == "" { | ||
| return nil, errors.Errorf("invalid annotation %q: key must not be empty", kv) | ||
| } | ||
| anns[k] = v | ||
| } | ||
| return anns, nil | ||
| } | ||
|
|
||
| // annotateImage applies annotations to an OCI image manifest. It is a no-op | ||
| // when annotations is empty or nil. | ||
| func annotateImage(img v1.Image, annotations map[string]string) v1.Image { | ||
| if len(annotations) == 0 { | ||
| return img | ||
| } | ||
| return mutate.Annotations(img, annotations).(v1.Image) //nolint:forcetypeassert // mutate.Annotations always returns v1.Image when given v1.Image input | ||
| } | ||
|
|
||
| // annotateIndex applies annotations to an OCI image index manifest. It is a | ||
| // no-op when annotations is empty or nil. | ||
| func annotateIndex(idx v1.ImageIndex, annotations map[string]string) v1.ImageIndex { | ||
| if len(annotations) == 0 { | ||
| return idx | ||
| } | ||
| return mutate.Annotations(idx, annotations).(v1.ImageIndex) //nolint:forcetypeassert // mutate.Annotations always returns v1.ImageIndex when given v1.ImageIndex input | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,86 @@ | ||
| /* | ||
| Copyright 2026 The Crossplane Authors. | ||
|
|
||
| Licensed under the Apache License, Version 2.0 (the "License"); | ||
| you may not use this file except in compliance with the License. | ||
| You may obtain a copy of the License at | ||
|
|
||
| http://www.apache.org/licenses/LICENSE-2.0 | ||
|
|
||
| Unless required by applicable law or agreed to in writing, software | ||
| distributed under the License is distributed on an "AS IS" BASIS, | ||
| WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. | ||
| See the License for the specific language governing permissions and | ||
| limitations under the License. | ||
| */ | ||
|
|
||
| package xpkg | ||
|
|
||
| import ( | ||
| "testing" | ||
|
|
||
| "github.com/google/go-cmp/cmp" | ||
| "github.com/google/go-cmp/cmp/cmpopts" | ||
| ) | ||
|
|
||
| func TestParseAnnotations(t *testing.T) { | ||
| type args struct { | ||
| kvs []string | ||
| } | ||
| type want struct { | ||
| anns map[string]string | ||
| err error | ||
| } | ||
|
|
||
| cases := map[string]struct { | ||
| reason string | ||
| args args | ||
| want want | ||
| }{ | ||
| "EmptySlice": { | ||
| reason: "Empty input should return an empty map with no error.", | ||
| args: args{kvs: []string{}}, | ||
| want: want{anns: map[string]string{}}, | ||
| }, | ||
| "SingleEntry": { | ||
| reason: "A single valid key=value entry should be parsed correctly.", | ||
| args: args{kvs: []string{"org.example/key=value"}}, | ||
| want: want{anns: map[string]string{"org.example/key": "value"}}, | ||
| }, | ||
| "MultipleEntries": { | ||
| reason: "Multiple valid key=value entries should all be parsed.", | ||
| args: args{kvs: []string{ | ||
| "org.opencontainers.image.source=https://github.com/example/pkg", | ||
| "org.opencontainers.image.version=v1.0.0", | ||
| }}, | ||
| want: want{anns: map[string]string{ | ||
| "org.opencontainers.image.source": "https://github.com/example/pkg", | ||
| "org.opencontainers.image.version": "v1.0.0", | ||
| }}, | ||
| }, | ||
| "ValueContainsEquals": { | ||
| reason: "Values that contain '=' characters should be preserved intact.", | ||
| args: args{kvs: []string{"key=val=ue"}}, | ||
| want: want{anns: map[string]string{"key": "val=ue"}}, | ||
| }, | ||
| "MissingEquals": { | ||
| reason: "An entry without '=' should return an error.", | ||
| args: args{kvs: []string{"invalid-no-equals"}}, | ||
| want: want{err: cmpopts.AnyError}, | ||
| }, | ||
| } | ||
|
|
||
| for name, tc := range cases { | ||
| t.Run(name, func(t *testing.T) { | ||
| got, err := parseAnnotations(tc.args.kvs) | ||
|
|
||
| if diff := cmp.Diff(tc.want.err, err, cmpopts.EquateErrors()); diff != "" { | ||
| t.Errorf("\n%s\nparseAnnotations(...): -want error, +got error:\n%s", tc.reason, diff) | ||
| } | ||
|
|
||
| if diff := cmp.Diff(tc.want.anns, got); diff != "" { | ||
| t.Errorf("\n%s\nparseAnnotations(...): -want, +got:\n%s", tc.reason, diff) | ||
| } | ||
| }) | ||
| } | ||
| } |
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -65,8 +65,9 @@ type pushCmd struct { | |
| Package string `arg:"" help:"Where to push the package. Must be a fully qualified OCI tag, including the registry, repository, and tag." placeholder:"REGISTRY/REPOSITORY:TAG"` | ||
|
|
||
| // Flags. Keep sorted alphabetically. | ||
| OCIAnnotation []string `help:"An OCI manifest annotation to add to the package in key=value format. Repeatable." name:"oci-annotation" placeholder:"KEY=VALUE" short:"a"` | ||
| InsecureSkipTLSVerify bool `help:"[INSECURE] Skip verifying TLS certificates."` | ||
| PackageFiles []string `help:"A comma-separated list of xpkg files to push." placeholder:"PATH" predictor:"xpkg_file" short:"f" type:"existingfile"` | ||
| PackageFiles []string `help:"A comma-separated list of xpkg files to push." placeholder:"PATH" predictor:"xpkg_file" short:"f" type:"existingfile"` | ||
|
|
||
| // Internal state. These aren't part of the user-exposed CLI structure. | ||
| fs afero.Fs | ||
|
|
@@ -126,7 +127,12 @@ func (c *pushCmd) Run(logger logging.Logger) error { | |
| remote.WithTransport(t), | ||
| } | ||
|
|
||
| return pushImages(logger, images, c.Package, options...) | ||
| anns, err := parseAnnotations(c.OCIAnnotation) | ||
| if err != nil { | ||
| return errors.Wrap(err, errParseAnnotations) | ||
| } | ||
|
|
||
| return pushImages(logger, images, c.Package, anns, options...) | ||
| } | ||
|
|
||
| // packageImage describes a package image that will be pushed. | ||
|
|
@@ -140,7 +146,7 @@ type packageImage struct { | |
| } | ||
|
|
||
| // pushImages pushes package images to the given URL using the provided options. | ||
| func pushImages(logger logging.Logger, images []packageImage, url string, options ...remote.Option) error { | ||
| func pushImages(logger logging.Logger, images []packageImage, url string, annotations map[string]string, options ...remote.Option) error { | ||
| if len(options) == 0 { | ||
| options = []remote.Option{ | ||
| remote.WithAuthFromKeychain(authn.DefaultKeychain), | ||
|
|
@@ -161,6 +167,8 @@ func pushImages(logger logging.Logger, images []packageImage, url string, option | |
| return errors.Wrapf(err, errAnnotateLayers) | ||
| } | ||
|
|
||
| img = annotateImage(img, annotations) | ||
|
|
||
| if err := remote.Write(tag, img, options...); err != nil { | ||
| return errors.Wrapf(err, errFmtPushPackage, pi.Path) | ||
| } | ||
|
|
@@ -183,6 +191,8 @@ func pushImages(logger logging.Logger, images []packageImage, url string, option | |
| return errors.Wrapf(err, errAnnotateLayers) | ||
| } | ||
|
|
||
| img = annotateImage(img, annotations) | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Should we apply the same annotations to the index (built below with
Author
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Added |
||
|
|
||
| d, err := img.Digest() | ||
| if err != nil { | ||
| return errors.Wrapf(err, errFmtGetDigest, pi.Path) | ||
|
|
@@ -230,7 +240,8 @@ func pushImages(logger logging.Logger, images []packageImage, url string, option | |
| return err | ||
| } | ||
|
|
||
| if err := remote.WriteIndex(tag, mutate.AppendManifests(empty.Index, adds...), options...); err != nil { | ||
| idx := annotateIndex(mutate.AppendManifests(empty.Index, adds...), annotations) | ||
| if err := remote.WriteIndex(tag, idx, options...); err != nil { | ||
| return errors.Wrapf(err, errFmtWriteIndex, len(adds)) | ||
| } | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
As far as I can tell, the image annotations actually get persisted anywhere by
crossplane xpkg build(they're not represented anywhere in the tarball written bytarball.Write). Assuming that's true, we should remove the flag here and keep it onpushonly; otherwise, a user could reasonably expect that they don't need to provide annotations topushif they've already provided them tobuild, which isn't true.