cub attestation create
cub attestation create
Record an attestation about revisions in a space
Synopsis
Record an attestation about one revision of each unit in a space.
The units are those --where selects, every unit in the space by default. The revision
of each is named by --revision in the form the other unit commands take: a number,
HeadRevisionNum, LastReleasedRevisionNum, Tag:
To approve the units of one or more spaces, cub variant approve is shorter.
Examples:
# Record that a security review of the head revisions passed
cub attestation create --space payments-prod --type SecurityReview --note "reviewed network policy"
# Record a change record from another system against what change order checkout-v42 brought
cub attestation create --space payments-prod --type ChangeRecord \
--change-order payments-base/checkout-v42 --claim servicenow.com/change=CHG0012345
# Reject the revisions tagged v1.2.0
cub attestation create --space payments-prod --revision Tag:v1.2.0 --reject --note "breaks the ingress"
cub attestation create [flags]
Options
--change-order string the change order the attestation is made in the context of
--claim stringArray a key=value pair to record with the attestation, such as servicenow.com/change=CHG0012345; repeatable
--dry-run report what would be covered, and record nothing
--evidence stringArray the ID of another attestation this one relied on; repeatable
--expires-in duration how long the attestation satisfies requirements for, such as 72h; by default it does not expire
-h, --help help for create
--include-hidden string[="*"] Also select hidden entities, to list or to act on: those hidden for the given HiddenReasons, comma-separated, as in --include-hidden=BackingUnit, or for any reason when given no value or "*". ConfigHub/YAML Units, which hold the configuration of other entities, are hidden with the reason BackingUnit. A --where naming entities by Slug or ID selects them whether hidden or not
--note string the reason for the claim, in your own words
-o, --output string Output format. One of: json, yaml, name, wide, mutations, jq=<expr>, yq=<expr>, custom-columns=<spec>
--permission strings permission in format Action:UserIDOrUsername (e.g., Manage:user@example.com, can be repeated)
--quiet No default output.
--reject record a Fail result: a rejection, for an approval
--revision string the revision of each unit to attest to; defaults to the change order's, or the head
--type string what is being claimed, such as Approval or SecurityReview (default "Approval")
--verbose Detailed output, additive with default output
--where string Filter expression using SQL-inspired syntax. Supports conjunctions with AND. String operators: =, !=, <, >, <=, >=, LIKE, NOT LIKE, ILIKE, ~~, !~~, ~, ~*, !~, !~*. Pattern matching with LIKE/ILIKE uses % and _ wildcards. Regex operators (~, ~*, !~, !~*) support POSIX regular expressions. A related entity is referenced by prefix, as in "UpstreamUnit.Slug = 'base'"; when the reference names a list, a * segment matches any element, as in "FromLink.*.Slug = 'upgrade-app'". Examples: "Slug LIKE 'app-%'", "DisplayName ILIKE '%backend%'", "Slug ~ '^[a-z]+-[0-9]+$'"
Options inherited from parent commands
--context string The context to use for this command
--debug Debug output
--space string space to operate in, by slug or UUID. Omitted, a list or bulk operation spans the organization and a single entity is named as <space>/<slug>
SEE ALSO
- cub attestation - Attestation commands