38 lines
1.4 KiB
YAML
38 lines
1.4 KiB
YAML
name: 'HSM Signing'
|
|
description: 'Signs APKs and makes detached signatures of files, with a key held in an HSM'
|
|
author: 'lobo'
|
|
inputs:
|
|
files:
|
|
description: 'Files to make detached signatures of (a glob in one directory, or dir/** for all files under dir). Signatures are written beside them as FILE.sig'
|
|
required: false
|
|
apk:
|
|
description: 'An unsigned, zipaligned APK to sign (signature schemes v2 and v3). Signed before files, so files can include apk_output'
|
|
required: false
|
|
apk_output:
|
|
description: 'Where to write the signed APK. Required with apk'
|
|
required: false
|
|
pin:
|
|
description: 'User pin for HSM on build server'
|
|
required: true
|
|
key_id:
|
|
description: 'CKA_ID of the key, in hex'
|
|
required: true
|
|
default: '03'
|
|
slot_index:
|
|
description: 'PKCS#11 slot, by position in the slot list'
|
|
required: true
|
|
default: '0'
|
|
key_alias:
|
|
description: 'APK only: the key alias, when the token holds more than one key with a certificate'
|
|
required: false
|
|
default: ''
|
|
public_key:
|
|
description: 'URL to PEM format public key. Specify only if uploading detached signatures to sigstore'
|
|
required: false
|
|
uhub_control:
|
|
description: 'If HSM is attached to software controlled power hub, setting this to "true" will power cycle the HSM before signing and power it off afterwards. The runner needs UHUB_PORT set (see README)'
|
|
required: true
|
|
default: "false"
|
|
runs:
|
|
using: 'docker'
|
|
image: 'Dockerfile'
|