autonomy registry

Seed and govern OCI registries for edge / air-gapped deployments

Synopsis

Registry orchestration for edge and disconnected sites.

ADK does not implement registry transport; it governs it. "registry seed"
delegates image replication to skopeo (preserving multi-arch manifest lists),
re-seeds the lock/policy sidecars, verifies the destination with the existing
4-step bundle pipeline (fail-closed), and emits a digest-pinned seed manifest
the operator can carry as an audit artifact.

Options inherited from parent commands

      --require-signed-manifest   Refuse to start if the SHA256SUMS release manifest or its cosign signature is missing/invalid (Tier 2 binary-integrity check; default: build-time compile-in via -ldflags -X, build-hardened artifacts=true, all others=false)

Subcommands