autonomy oci¶
Manage OCI artifact attachments (lock, policy bundle)
Options inherited from parent commands¶
--require-signed-manifest Refuse to start if the SHA256SUMS release manifest or its cosign signature is missing/invalid (Tier 2 binary-integrity check; default: build-time compile-in via -ldflags -X, build-hardened artifacts=true, all others=false)
Subcommands¶
autonomy oci attach-lock— Attach an autonomy.lock.json to an OCI imageautonomy oci attach-policy— Attach a policy bundle tarball to an OCI imageautonomy oci probe— Probe the registry for OCI Referrers API supportautonomy oci pull-lock— Retrieve the autonomy.lock.json attached to an OCI imageautonomy oci pull-policy— Retrieve the policy bundle attached to an OCI imageautonomy oci push-test-artifact— Push a minimal test OCI artifact (for demo and development only)