PageSourceSearch

https://helm.sh/assets/js/386df5eb.8c8010c9.js

js helm.sh collected 2026-09-24 07:26:17 UTC 24,224 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkhelm_www=self.webpackChunkhelm_www||[]).push([["203"],{4525(e,i,n){n.r(i),n.d(i,{metadata:()=>t,default:()=>d,frontMatter:()=>a,contentTitle:()=>l,toc:()=>c,assets:()=>o});var t=JSON.parse('{"id":"hips/hip-0006","title":"OCI Support","description":"\x3c!--","source":"@site/community/hips/hip-0006.md","sourceDirName":"hips","slug":"/hips/hip-0006","permalink":"/community/hips/hip-0006","draft":false,"unlisted":false,"editUrl":"https://github.com/helm/community/edit/main/hips/hip-0006.md","tags":[],"version":"current","frontMatter":{"title":"OCI Support","sidebar_label":"0006: OCI Support"},"sidebar":"communitySidebar","previous":{"title":"0005: Helm Org Maintainers and Deprecated Projects","permalink":"/community/hips/hip-0005"},"next":{"title":"0007: Document and Track maintainer groups","permalink":"/community/hips/hip-0007"}}'),s=n(74848),r=n(28453);let a={title:"OCI Support",sidebar_label:"0006: OCI Support"},l,o={},c=[{value:"Abstract",id:"abstract",level:2},{value:"Motivation",id:"motivation",level:2},{value:"Rationale",id:"rationale",level:2},{value:"Specification",id:"specification",level:2},{value:"1. Implement <code>Getter</code> and introduce <code>Pusher</code>",id:"1-implement-getter-and-introduce-pusher",level:3},{value:"2. Support for provenance files",id:"2-support-for-provenance-files",level:3},{value:"3. Chart versions == OCI reference tags",id:"3-chart-versions--oci-reference-tags",level:3},{value:"4. Chart names == OCI reference basenames",id:"4-chart-names--oci-reference-basenames",level:3},{value:"5. Cache is removed",id:"5-cache-is-removed",level:3},{value:"6. <code>helm chart</code> is removed, integrated into rest of CLI",id:"6-helm-chart-is-removed-integrated-into-rest-of-cli",level:3},{value:"7. Experimental until clear messaging from OCI",id:"7-experimental-until-clear-messaging-from-oci",level:3},{value:"Backwards compatibility",id:"backwards-compatibility",level:2},{value:"Security implications",id:"security-implications",level:2},{value:"How to teach this",id:"how-to-teach-this",level:2},{value:"Reference implementation",id:"reference-implementation",level:2},{value:"Rejected ideas",id:"rejected-ideas",level:2},{value:"Will I be able to use custom tags such as &quot;latest&quot;?",id:"will-i-be-able-to-use-custom-tags-such-as-latest",level:3},{value:"Will I be able to pull a chart using the <code>:&lt;tag&gt;</code> syntax?",id:"will-i-be-able-to-pull-a-chart-using-the-tag-syntax",level:3},{value:"Open issues",id:"open-issues",level:2},{value:"What is the correct media type to use for the chart content layer?",id:"what-is-the-correct-media-type-to-use-for-the-chart-content-layer",level:3},{value:"What is the correct media type to use for the provenance file layer?",id:"what-is-the-correct-media-type-to-use-for-the-provenance-file-layer",level:3},{value:"References",id:"references",level:2}];function h(e){let i={a:"a",code:"code",h2:"h2",h3:"h3",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,r.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:["\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n",(0,s.jsxs)(i.table,{children:[(0,s.jsx)(i.thead,{children:(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.th,{children:(0,s.jsx)(i.strong,{children:"HIP"})}),(0,s.jsx)(i.th,{children:(0,s.jsx)(i.strong,{children:"Title"})}),(0,s.jsx)(i.th,{children:(0,s.jsx)(i.strong,{children:"Author(s)"})}),(0,s.jsx)(i.th,{children:(0,s.jsx)(i.strong,{children:"Created"})}),(0,s.jsx)(i.th,{children:(0,s.jsx)(i.strong,{children:"Type"})}),(0,s.jsx)(i.th,{children:(0,s.jsx)(i.strong,{children:"Status"})})]})}),(0,s.jsx)(i.tbody,{children:(0,s.jsxs)(i.tr,{children:[(0,s.jsx)(i.td,{children:"0006"}),(0,s.jsx)(i.td,{children:"OCI Support"}),(0,s.jsx)(i.td,{children:"Josh Dolitsky"}),(0,s.jsx)(i.td,{children:"2020-07-21"}),(0,s.jsx)(i.td,{children:"feature"}),(0,s.jsx)(i.td,{children:"accepted"})]})})]}),"\n",(0,s.jsx)(i.h2,{id:"abstract",children:"Abstract"}),"\n",(0,s.jsxs)(i.p,{children:["This feature proposal outlines a concrete plan for finalizing Helm's ",(0,s.jsx)(i.a,{href:"https://opencontainers.org/",children:"OCI"})," integration, which has been available as an experimental feature since Helm 3.0.0."]}),"\n",(0,s.jsx)(i.h2,{id:"motivation",children:"Motivation"}),"\n",(0,s.jsxs)(i.p,{children:["Until now, all OCI integration has been kept separate from the existing Helm user experience, and nested under the ",(0,s.jsx)(i.co
1de,{children:"helm chart"})," and ",(0,s.jsx)(i.code,{children:"helm registry"})," subcommands. These subcommands were designed to mimic the user experience of the Docker CLI. For example, ",(0,s.jsx)(i.code,{children:"helm chart list"})," is the equivalent of ",(0,s.jsx)(i.code,{children:"docker images"}),"."]}),"\n",(0,s.jsx)(i.p,{children:'While this experimental feature set has succeeded in providing a "Docker-like" user experience, it is too far removed from existing Helm features and should be partially redesigned.'}),"\n",(0,s.jsx)(i.p,{children:"In addition, there has not yet been a clear response to the following questions concerning Helm's OCI support:"}),"\n",(0,s.jsxs)(i.ul,{children:["\n",(0,s.jsx)(i.li,{children:"What is the relationship between a chart version and registry tag?"}),"\n",(0,s.jsxs)(i.li,{children:["Will this work with ",(0,s.jsx)(i.code,{children:"helm install"})," / ",(0,s.jsx)(i.code,{children:"helm upgrade"})," / ",(0,s.jsx)(i.code,{children:"helm dependency"}),"?"]}),"\n",(0,s.jsxs)(i.li,{children:["How will provenance files (",(0,s.jsx)(i.code,{children:".prov"}),") be supported?"]}),"\n",(0,s.jsx)(i.li,{children:"When will the experimental flag be removed?"}),"\n"]}),"\n",(0,s.jsx)(i.h2,{id:"rationale",children:"Rationale"}),"\n",(0,s.jsx)(i.p,{children:"The true value of leveraging OCI specs has very little to do with the command-line experience (i.e. Docker). OCI registries provide a common API for all types of packages, and address several security and scalability concerns. Additionally, many companies and organizations have invested in the infrastructure surrounding their container registry. Storing Helm charts in a registry reduces the number of moving parts."}),"\n",(0,s.jsx)(i.p,{children:"By making Helm's OCI support more closely aligned with the way that Helm currently works, users will have a more stable experience and still benefit from the advantages of OCI."}),"\n",(0,s.jsx)(i.h2,{id:"specification",children:"Specification"}),"\n",(0,s.jsx)(i.p,{children:"The specification for this HIP is broken into six (6) major sections:"}),"\n",(0,s.jsxs)(i.ol,{children:["\n",(0,s.jsxs)(i.li,{children:["Implement ",(0,s.jsx)(i.code,{children:"Getter"})," and introduce ",(0,s.jsx)(i.code,{children:"Pusher"})]}),"\n",(0,s.jsx)(i.li,{children:"Support for provenance files"}),"\n",(0,s.jsx)(i.li,{children:"Chart versions == OCI reference tags"}),"\n",(0,s.jsx)(i.li,{children:"Chart names == OCI reference basenames"}),"\n",(0,s.jsx)(i.li,{children:"Cache is removed"}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.code,{children:"helm chart"})," is removed, integrated into rest of CLI"]}),"\n",(0,s.jsx)(i.li,{children:"Experimental until clear messaging from OCI"}),"\n"]}),"\n",(0,s.jsxs)(i.h3,{id:"1-implement-getter-and-introduce-pusher",children:["1. Implement ",(0,s.jsx)(i.code,{children:"Getter"})," and introduce ",(0,s.jsx)(i.code,{children:"Pusher"})]}),"\n",(0,s.jsxs)(i.p,{children:["As of yet, the code related to registry support has been written standalone (see ",(0,s.jsx)(i.a,{href:"https://github.com/helm/helm/tree/master/internal/experimental/registry",children:"internal/experimental/registry"}),")."]}),"\n",(0,s.jsxs)(i.p,{children:["The act of downloading a chart from an OCI registry should mimic what is already possible using downloader plugins. Using the protocol prefix ",(0,s.jsx)(i.code,{children:"oci://"})," in any place where chart repos are referenced should work just by implementing a ",(0,s.jsx)(i.code,{children:"Getter"})," for OCI."]}),"\n",(0,s.jsxs)(i.p,{children:["Currently there is no Helm-specific way to upload chart packages. Using the same model of ",(0,s.jsx)(i.code,{children:"Getter"}),", a new interface called ",(0,s.jsx)(i.code,{children:"Pusher"})," should be introduced, with a single built-in implementation (OCI).\nThis opens the door for plugins to implement their own upload mechanism, and for Helm to add a new top-level upload command ",(0,s.jsx)(i.code,{children:"helm push"}),". For example, plugins may include a new ",(0,s.jsx)(i.code,{children:"uploaders"}
1)," section in ",(0,s.jsx)(i.code,{children:"plugin.yaml"}),", similar to the existing ",(0,s.jsx)(i.code,{children:"downloaders"})," section (see ",(0,s.jsx)(i.a,{href:"https://helm.sh/docs/topics/plugins/#downloader-plugins",children:'"Downloader Plugins"'}),")."]}),"\n",(0,s.jsxs)(i.p,{children:["This will also include a new, top-level subcommand, ",(0,s.jsx)(i.code,{children:"helm push"}),", which will leverage this new functionality. This command will take, as its first argument, the path to a chart archive (",(0,s.jsx)(i.code,{children:".tgz"}),"), and as the second argument a URL pointing to a remote OCI registry."]}),"\n",(0,s.jsxs)(i.p,{children:["Here is an example of what the ",(0,s.jsx)(i.code,{children:"helm push"})," UX will look like:"]}),"\n",(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{children:"$ helm create mychart\nCreating mychart\n\n$ helm package mychart/\nSuccessfully packaged chart and saved it to: /home/user/mychart-0.1.0.tgz\n\n$ helm push mychart-0.1.0.tgz oci://example.com/some/root/namespace\nThe push refers to repository [oci://example.com/some/root/namespace/mychart]\nref:     oci://example.com/some/root/namespace/mychart:0.1.0\ndigest:  1b251d38cfe948dfc0a5745b7af5ca574ecb61e52aed10b19039db39af6e1617\nsize:    2.4 KiB\nname:    mychart\nversion: 0.1.0\n0.1.0: pushed to remote (1 layer, 2.4 KiB total)\n"})}),"\n",(0,s.jsx)(i.h3,{id:"2-support-for-provenance-files",children:"2. Support for provenance files"}),"\n",(0,s.jsxs)(i.p,{children:["Helm currently has the ability to verify package signatures, assuming the presence of a file suffixed with ",(0,s.jsx)(i.code,{children:".prov"})," sitting next to a chart ",(0,s.jsx)(i.code,{children:".tgz"})," in a repository."]}),"\n",(0,s.jsxs)(i.p,{children:["Support for this method of signature validation should be carried over into OCI storage. As the format of the OCI manifest is custom to Helm, Helm can also choose to modify the resulting manifest on upload when a chart is being signed (e.g. ",(0,s.jsx)(i.code,{children:"helm push --sign"}),")."]}),"\n",(0,s.jsxs)(i.p,{children:["As far as the low-level details, the ",(0,s.jsx)(i.code,{children:".prov"})," file will simply be stored as another layer on the manifest. If running ",(0,s.jsx)(i.code,{children:"helm pull --verify oci://..."}),", the layer containing the provenance file will be retrieved from the registry.\nThe order and total number of layers on the manifest is not significant. The list of layers will be inspected, and the first one found matching the media type of the provenance file will be used. If multiple layers containing the provenance file media type are found, an error will occur. The same applies to the chart layer."]}),"\n",(0,s.jsx)(i.p,{children:"Here is an example of what a manifest will look like with a provenance file attached:"}),"\n",(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{className:"language-json",children:'{\n  "schemaVersion": 2,\n  "config": {\n    "mediaType": "application/vnd.cncf.helm.config.v1+json",\n    "digest": "sha256:8ec7c0f2f6860037c19b54c3cfbab48d9b4b21b485a93d87b64690fdb68c2111",\n    "size": 117\n  },\n  "layers": [\n    {\n      "mediaType": "application/vnd.cncf.helm.chart.content.v1.tar+gzip",\n      "digest": "sha256:1b251d38cfe948dfc0a5745b7af5ca574ecb61e52aed10b19039db39af6e1617",\n      "size": 2487\n    },\n    {\n      "mediaType": "application/vnd.cncf.helm.chart.provenance.v1.prov",\n      "digest": "sha256:3e207b409db364b595ba862cdc12be96dcdad8e36c59a03b7b3b61c946a5741a",\n      "size": 643\n    }\n  ]\n}\n\n'})}),"\n",(0,s.jsx)(i.h3,{id:"3-chart-versions--oci-reference-tags",children:"3. Chart versions == OCI reference tags"}),"\n",(0,s.jsx)(i.p,{children:"To keep things simple, the version of a chart will be 1-to-1 with the tag used on registry references. Arbitrary tags will not be supported."}),"\n",(0,s.jsxs)(i.p,{children:["This also means that tags are no longer necessary to be provided on the command-line in the form ",(0,s.jsx)(i.code,{children:"<ref>:<tag>"}),". Instead, users can provide ",(0,s.jsx)(i.code,{children:"--version <version>"}),"."]}),"\n",(0,s.jsx)(i.h3,{id:"4-chart-names--oci-reference-basenames",children:"4. Chart names == OCI reference basenames"}),"\n",(0,s.jsx)(i.p,{children:"Again, to keep things simple, the base
1name (the last segment of the URL path) on a registry reference should be equivalent to the chart name."}),"\n",(0,s.jsxs)(i.p,{children:["For example, given a chart with the name ",(0,s.jsx)(i.code,{children:"pepper"})," and the version ",(0,s.jsx)(i.code,{children:"1.2.3"}),", users may run a command such as the following:"]}),"\n",(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{children:"$ helm push pepper-1.2.3.tgz oci://r.myreg.io/mycharts\n"})}),"\n",(0,s.jsx)(i.p,{children:"which would result in the following reference:"}),"\n",(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{children:"oci://r.myreg.io/mycharts/pepper:1.2.3\n"})}),"\n",(0,s.jsx)(i.p,{children:'By placing such restrictions on registry URLs and tags, Helm users are less likely to do "strange things" with charts in registries.'}),"\n",(0,s.jsx)(i.h3,{id:"5-cache-is-removed",children:"5. Cache is removed"}),"\n",(0,s.jsx)(i.p,{children:'Since chart packages are small in size (<1mb), the cache is hard to justify. The cache was introduced only to provide a "Docker-like" experience. While this is neat, it does not provide the user with much value.'}),"\n",(0,s.jsx)(i.p,{children:"By removing the cache, much of the existing OCI features can be cut down dramatically in size. This will make OCI features much more seamless with the existing Helm user experience."}),"\n",(0,s.jsxs)(i.h3,{id:"6-helm-chart-is-removed-integrated-into-rest-of-cli",children:["6. ",(0,s.jsx)(i.code,{children:"helm chart"})," is removed, integrated into rest of CLI"]}),"\n",(0,s.jsxs)(i.p,{children:["Wherever possible, the subcommands provided by the new ",(0,s.jsx)(i.code,{children:"helm chart"})," command should be integrated into existing Helm CLI commands."]}),"\n",(0,s.jsxs)(i.p,{children:[(0,s.jsx)(i.code,{children:"helm chart pull"})," should be baked into ",(0,s.jsx)(i.code,{children:"helm pull"}),", ",(0,s.jsx)(i.code,{children:"helm chart push"})," should be ",(0,s.jsx)(i.code,{children:"helm push"})," (new)."]}),"\n",(0,s.jsxs)(i.p,{children:["Commands that work with the cache will be removed: ",(0,s.jsx)(i.code,{children:"helm chart save"}),", ",(0,s.jsx)(i.code,{children:"helm chart remove"})," and ",(0,s.jsx)(i.code,{children:"helm chart export"}),"."]}),"\n",(0,s.jsxs)(i.p,{children:[(0,s.jsx)(i.code,{children:"helm registry"})," will be kept as is. This manages auth against OCI registries."]}),"\n",(0,s.jsx)(i.h3,{id:"7-experimental-until-clear-messaging-from-oci",children:"7. Experimental until clear messaging from OCI"}),"\n",(0,s.jsx)(i.p,{children:"Considering that the rest of the items above are implemented and resolved, the OCI feature set will not be made generally available until there is clear messaging from the Open Container Initiative (OCI) regarding the way that Helm is using registries."}),"\n",(0,s.jsx)(i.p,{children:"The technical details of how Helm is using the OCI distribution spec must be further validated. It is currently unclear whether or not this is the correct way to publish an arbitrary artifact. Only after more clarity will these features be taken out of experimental mode and made generally available."}),"\n",(0,s.jsx)(i.h2,{id:"backwards-compatibility",children:"Backwards compatibility"}),"\n",(0,s.jsx)(i.p,{children:"Since the existing feature set is currently experimental, there will be no promise of backwards compatibility with prior OCI support (sorry!)"}),"\n",(0,s.jsx)(i.h2,{id:"security-implications",children:"Security implications"}),"\n",(0,s.jsxs)(i.p,{children:["Registry authentication introduces a new attack vector. Upon running ",(0,s.jsx)(i.code,{children:"helm registry login"}),", these credentials can possibly be stored in an unencrypted JSON file.\nHowever, if your system supports Docker's credential helpers (such as ",(0,s.jsx)(i.code,{children:"osxkeychain"}),"), then no crendetials are stored in this file. Credentials are stored elsewhere, such as in the system's secure keychain."]}),"\n",(0,s.jsx)(i.p,{children:"Here is an example of a registry config file using a credential helper:"}
1),"\n",(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{children:'{\n	"auths": {\n		"example.com": {}\n	},\n	"credsStore": "osxkeychain"\n}\n'})}),"\n",(0,s.jsx)(i.p,{children:"Here is an example of a registry config file without a credential helper:"}),"\n",(0,s.jsx)(i.pre,{children:(0,s.jsx)(i.code,{children:'{\n	"auths": {\n		"example.com": {\n			"auth": "<password>",\n			"email": "<username>"\n		}\n	}\n}\n'})}),"\n",(0,s.jsxs)(i.p,{children:["So, while a new attack vector has been introduced, it should not be considered any less safe than using ",(0,s.jsx)(i.code,{children:"docker login"}),".\nIn fact, he underlying code is leveraging docker/cli, and existing logins created with ",(0,s.jsx)(i.code,{children:"docker login"})," are leveraged if not found in Helm's config."]}),"\n",(0,s.jsx)(i.p,{children:"Note: this is already implemented in the current OCI feature set."}),"\n",(0,s.jsx)(i.h2,{id:"how-to-teach-this",children:"How to teach this"}),"\n",(0,s.jsx)(i.p,{children:"Following the implementation of all facets of this HIP, extensive documentation should be added to the Helm website on how to leverage OCI."}),"\n",(0,s.jsxs)(i.p,{children:["Additionally, sites containing community charts, such as ",(0,s.jsx)(i.a,{href:"https://artifacthub.io/",children:"Artifact Hub"}),", should enable providers to distribute charts over OCI, and display friendly copy-paste instructions for how to download an OCI-based chart."]}),"\n",(0,s.jsxs)(i.p,{children:["Helm and charts maintainers should be educated on how to make a transition from classic chart repositories to registries.\nIn short the workflow for uploading a chart goes from ",(0,s.jsx)(i.code,{children:"helm package"})," (+ custom upload) to ",(0,s.jsx)(i.code,{children:"helm package && helm registry login && helm push"}),"."]}),"\n",(0,s.jsx)(i.h2,{id:"reference-implementation",children:"Reference implementation"}),"\n",(0,s.jsx)(i.p,{children:"The features are currently under development."}),"\n",(0,s.jsx)(i.p,{children:"Here are the following outstanding tasks:"}),"\n",(0,s.jsxs)(i.ul,{children:["\n",(0,s.jsx)(i.li,{children:"We need to implement helm push, which does not exist"}),"\n",(0,s.jsxs)(i.li,{children:["Helm needs to implement OCI Getter support so that helm dependency and helm pull can support OCI registries (see ",(0,s.jsx)(i.a,{href:"https://github.com/helm/helm/pull/8843",children:"https://github.com/helm/helm/pull/8843"}),")"]}),"\n",(0,s.jsx)(i.li,{children:"Support for provenance files must be added"}),"\n",(0,s.jsxs)(i.li,{children:[(0,s.jsx)(i.code,{children:"helm chart save"}),", ",(0,s.jsx)(i.code,{children:"helm chart export"}),", ",(0,s.jsx)(i.code,{children:"helm chart list"}),", ",(0,s.jsx)(i.code,{children:"helm chart remove"}),", ",(0,s.jsx)(i.code,{children:"helm chart pull"}),", and ",(0,s.jsx)(i.code,{children:"helm chart push"})," need to be removed"]}),"\n",(0,s.jsxs)(i.li,{children:["The Helm documentation for OCI support needs to be updated (",(0,s.jsx)(i.a,{href:"https://helm.sh/docs/topics/registries/",children:"https://helm.sh/docs/topics/registries/"}),"))"]}),"\n"]}),"\n",(0,s.jsx)(i.h2,{id:"rejected-ideas",children:"Rejected ideas"}),"\n",(0,s.jsx)(i.h3,{id:"will-i-be-able-to-use-custom-tags-such-as-latest",children:'Will I be able to use custom tags such as "latest"?'}),"\n",(0,s.jsxs)(i.p,{children:["The implications of this are not yet fully understood. For now, it will be strictly enforced that the tag on the reference will match the version found in ",(0,s.jsx)(i.code,{children:"Chart.yaml"}),". This functionality may be added at a later time."]}),"\n",(0,s.jsxs)(i.h3,{id:"will-i-be-able-to-pull-a-chart-using-the-tag-syntax",children:["Will I be able to pull a chart using the ",(0,s.jsx)(i.code,{children:":<tag>"})," syntax?"]}),"\n",(0,s.jsxs)(i.p,{children:["It's unclear if users will be able to pull charts with a specific version using the ",(0,s.jsx)(i.code,{children:":<tag>"})," syntax (vs. ",(0,s.jsx)(i.code,{children:"--version <version>"}),"). This seems relatively harmless to allow both, but this may have implications on dependencies and other areas."]}),"\n",(0,s.jsx)(i.h2,{id:"open-issues",children:"Open issues"}),"\n",(0,s.jsx)(i.p,{children:"The issues below are still unresolved."}),"\n",(0,s.jsx)(i.h3,{id:"what-is-the-correct-media-type-to-use-for-the-chart-content-layer",children:"What is the correct media type to use for the chart content layer?"}),"\n",(0,s.jsxs)(i.p,{children:["The media type for the chart content layer is currently ",(0,s.jsx)(i.co
1de,{children:"application/tar+gzip"}),", however it has been pointed out that ",(0,s.jsx)(i.a,{href:"https://www.iana.org/assignments/media-types/media-types.xhtml",children:"this is not an official type in the IANA database"}),"."]}),"\n",(0,s.jsxs)(i.p,{children:["Due to this, a unique media type will be used: ",(0,s.jsx)(i.code,{children:"application/vnd.cncf.helm.chart.content.v1.tar+gzip"}),"."]}),"\n",(0,s.jsx)(i.p,{children:"The only real issue with this is that the chart package is not technically a unique type. As in, a registry vendor could treat it as a typical gzipped tarball."}),"\n",(0,s.jsx)(i.h3,{id:"what-is-the-correct-media-type-to-use-for-the-provenance-file-layer",children:"What is the correct media type to use for the provenance file layer?"}),"\n",(0,s.jsx)(i.p,{children:"Again, there doesn't appear to be an IANA media type for this type of file. Additionally, this file format appears unique to Helm."}),"\n",(0,s.jsxs)(i.p,{children:["In this case, it seems the only option is to use a custom media type such as ",(0,s.jsx)(i.code,{children:"application/vnd.cncf.helm.chart.provenance.v1.prov"}),"."]}),"\n",(0,s.jsx)(i.h2,{id:"references",children:"References"}),"\n",(0,s.jsx)(i.p,{children:"The following links are used as references in this HIP:"}),"\n",(0,s.jsxs)(i.ul,{children:["\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.a,{href:"https://opencontainers.org/",children:"Open Container Initiative"})}),"\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.a,{href:"https://github.com/opencontainers/distribution-spec",children:"OCI Distribution Specification"})}),"\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.a,{href:"https://www.iana.org/assignments/media-types/media-types.xhtml",children:"List of IANA media types"})}),"\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.a,{href:"https://helm.sh/docs/topics/registries/",children:"Helm Documentation - Registries"})}),"\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.a,{href:"https://artifacthub.io/",children:"Artifact Hub"})}),"\n",(0,s.jsx)(i.li,{children:(0,s.jsx)(i.a,{href:"https://github.com/helm/helm/tree/master/internal/experimental/registry",children:"Existing standalone code for OCI support"})}),"\n"]})]})}function d(e={}){let{wrapper:i}={...(0,r.R)(),...e.components};return i?(0,s.jsx)(i,{...e,children:(0,s.jsx)(h,{...e})}):h(e)}},28453(e,i,n){n.d(i,{R:()=>a,x:()=>l});var t=n(96540);let s={},r=t.createContext(s);function a(e){let i=t.useContext(r);return t.useMemo(function(){return"function"==typeof e?e(i):{...i,...e}},[i,e])}function l(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:a(e.components),t.createElement(r.Provider,{value:i},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.