action-hsm-sign/action.yml

38 lines
1.4 KiB
YAML

name: 'HSM Signing'
description: 'Signs APKs and makes detached signatures of files, with a key held in an HSM'
author: 'lobo'
inputs:
files:
description: 'Files to make detached signatures of (a glob in one directory, or dir/** for all files under dir). Signatures are written beside them as FILE.sig'
required: false
apk:
description: 'An unsigned, zipaligned APK to sign (signature schemes v2 and v3). Signed before files, so files can include apk_output'
required: false
apk_output:
description: 'Where to write the signed APK. Required with apk'
required: false
pin:
description: 'User pin for HSM on build server'
required: true
key_id:
description: 'CKA_ID of the key, in hex'
required: true
default: '03'
slot_index:
description: 'PKCS#11 slot, by position in the slot list'
required: true
default: '0'
key_alias:
description: 'APK only: the key alias, when the token holds more than one key with a certificate'
required: false
default: ''
public_key:
description: 'URL to PEM format public key. Specify only if uploading detached signatures to sigstore'
required: false
uhub_control:
description: 'If HSM is attached to software controlled power hub, setting this to "true" will power cycle the HSM before signing and power it off afterwards. The runner needs UHUB_PORT set (see README)'
required: true
default: "false"
runs:
using: 'docker'
image: 'Dockerfile'