Skip to content

cub attestation create

cub attestation create

Record an attestation about revisions in a space

Synopsis

Record an attestation about one revision of each unit in a space.

The units are those --where selects, every unit in the space by default. The revision of each is named by --revision in the form the other unit commands take: a number, HeadRevisionNum, LastReleasedRevisionNum, Tag:, ChangeSet: or ChangeOrder:, optionally prefixed with Before:. With --change-order and no --revision, it is the revision the change order's end tag marks; otherwise it is the head. A unit with no such revision is reported as skipped rather than covered at some other revision, and when no unit has one, nothing is recorded.

To approve the units of one or more spaces, cub variant approve is shorter.

Examples:

  # Record that a security review of the head revisions passed
  cub attestation create --space payments-prod --type SecurityReview --note "reviewed network policy"

  # Record a change record from another system against what change order checkout-v42 brought
  cub attestation create --space payments-prod --type ChangeRecord \
    --change-order payments-base/checkout-v42 --claim servicenow.com/change=CHG0012345

  # Reject the revisions tagged v1.2.0
  cub attestation create --space payments-prod --revision Tag:v1.2.0 --reject --note "breaks the ingress"
cub attestation create [flags]

Options

      --change-order string           the change order the attestation is made in the context of
      --claim stringArray             a key=value pair to record with the attestation, such as servicenow.com/change=CHG0012345; repeatable
      --dry-run                       report what would be covered, and record nothing
      --evidence stringArray          the ID of another attestation this one relied on; repeatable
      --expires-in duration           how long the attestation satisfies requirements for, such as 72h; by default it does not expire
  -h, --help                          help for create
      --include-hidden string[="*"]   Also select hidden entities, to list or to act on: those hidden for the given HiddenReasons, comma-separated, as in --include-hidden=BackingUnit, or for any reason when given no value or "*". ConfigHub/YAML Units, which hold the configuration of other entities, are hidden with the reason BackingUnit. A --where naming entities by Slug or ID selects them whether hidden or not
      --note string                   the reason for the claim, in your own words
  -o, --output string                 Output format. One of: json, yaml, name, wide, mutations, jq=<expr>, yq=<expr>, custom-columns=<spec>
      --permission strings            permission in format Action:UserIDOrUsername (e.g., Manage:user@example.com, can be repeated)
      --quiet                         No default output.
      --reject                        record a Fail result: a rejection, for an approval
      --revision string               the revision of each unit to attest to; defaults to the change order's, or the head
      --type string                   what is being claimed, such as Approval or SecurityReview (default "Approval")
      --verbose                       Detailed output, additive with default output
      --where string                  Filter expression using SQL-inspired syntax. Supports conjunctions with AND. String operators: =, !=, <, >, <=, >=, LIKE, NOT LIKE, ILIKE, ~~, !~~, ~, ~*, !~, !~*. Pattern matching with LIKE/ILIKE uses % and _ wildcards. Regex operators (~, ~*, !~, !~*) support POSIX regular expressions. A related entity is referenced by prefix, as in "UpstreamUnit.Slug = 'base'"; when the reference names a list, a * segment matches any element, as in "FromLink.*.Slug = 'upgrade-app'". Examples: "Slug LIKE 'app-%'", "DisplayName ILIKE '%backend%'", "Slug ~ '^[a-z]+-[0-9]+$'"

Options inherited from parent commands

      --context string   The context to use for this command
      --debug            Debug output
      --space string     space to operate in, by slug or UUID. Omitted, a list or bulk operation spans the organization and a single entity is named as <space>/<slug>

SEE ALSO