NAME
App::FuguBench::Keys - the embedded release keys of fugubench
SYNOPSIS
use App::FuguBench::Keys;
for my $pair (App::FuguBench::Keys->keys) {
my ($name, $body) = @$pair;
}
DESCRIPTION
App::FuguBench::Keys holds the release public keys of the organization. The program embeds them in this module, so a release carries the keys that verify the next release. The keys are those of deps/KEYS.txt of the org pack, and t/fugubench/keys.t holds this module to that file.
The deps verb never reads this list. It verifies with the keys of the consumer, because a consumer decides what it trusts.
keys
keys returns the [name, body] pair of each release key. A name is the name of the key line, and a body is the 56 base64 characters of a signify public key: the second line of a .pub file. A public key carries no secret, so the list is source.
THE TRUST ORDER
The list order is the line order of deps/KEYS.txt, which is the trust order. The current key comes first.
A rotation is a release of the program. The old key stays in the list for one release after the new key enters it, so an operator one release behind can still update.
RETURN VALUES
keys returns a list of array references, one for each release key.
SEE ALSO
App::FuguBench, App::FuguBench::Deps, Fugu::Signify
AUTHORS
Dick Olsson <hi@senzilla.io>