Synopsis
The request should be reviewed in the Kosli UI. The artifact fingerprint can be provided directly with the
--fingerprint flag, or
calculated based on --artifact-type flag.
Artifact type can be one of: “file” for files, “dir” for directories, “oci” for container
images in registries or “docker” for local docker images.
Note: --artifact-type=docker reads the image’s repo digest via the local Docker daemon.
The image must have been pushed to or pulled from a registry for a repo digest to exist;
a freshly built image (just docker build) will not have one. If the image is already in
a registry, prefer --artifact-type=oci, which fetches the digest directly from the
registry without needing a local Docker daemon.
For --artifact-type=oci (and for --artifact-type=docker when --registry-username
is set), registry credentials are resolved as follows:
- If
--registry-username(and optionally--registry-password) is set, it is used directly. - Otherwise, credentials are discovered automatically from:
- the Docker config file (
~/.docker/config.json, populated bydocker login) - the Podman/containers auth file (
~/.config/containers/auth.json, or$REGISTRY_AUTH_FILE) - any Docker credential helper configured in that config (e.g.
docker-credential-ecr-loginfor AWS ECR,docker-credential-gcloudfor GCR/Artifact Registry, an ACR helper for Azure, or a local keychain helper), invoked as an external binary on$PATH - if none of the above yield credentials, the registry is accessed anonymously, which works
for public images
--registry-provideris deprecated and no longer used.
- the Docker config file (
Flags
Flags inherited from parent commands
Examples Use Cases
These examples all assume that the flags--api-token, --org, --host, (and --flow, --trail when required), are set/provided.