NAME

App::FuguBench::Keys - the embedded release keys of fugubench

SYNOPSIS

use App::FuguBench::Keys;

for my $pair (App::FuguBench::Keys->keys) {
    my ($name, $body) = @$pair;
}

DESCRIPTION

App::FuguBench::Keys holds the release public keys of the organization. The program embeds them in this module, so a release carries the keys that verify the next release. The keys are those of deps/KEYS.txt of the org pack, and t/fugubench/keys.t holds this module to that file.

The deps verb never reads this list. It verifies with the keys of the consumer, because a consumer decides what it trusts.

keys

keys returns the [name, body] pair of each release key. A name is the name of the key line, and a body is the 56 base64 characters of a signify public key: the second line of a .pub file. A public key carries no secret, so the list is source.

THE TRUST ORDER

The list order is the line order of deps/KEYS.txt, which is the trust order. The current key comes first.

A rotation is a release of the program. The old key stays in the list for one release after the new key enters it, so an operator one release behind can still update.

RETURN VALUES

keys returns a list of array references, one for each release key.

SEE ALSO

App::FuguBench, App::FuguBench::Deps, Fugu::Signify

AUTHORS

Dick Olsson <hi@senzilla.io>