Binaries
CLI and server binaries for Linux, macOS and Windows, signed by the release-of-record workflow, with a .sigstore.json bundle next to each file and a signed checksums.txt.
Trust centre
MAQPNA is a security boundary for untrusted agent code, so you should not have to take our word for anything. Every release is signed, every image carries an SBOM, and nothing calls home.
Release signing
Releases are signed in GitHub Actions with Sigstore cosign keyless signing. The certificate binds each signature to the workflow identity that built and signed it. There is no long-lived signing key to steal.
CLI and server binaries for Linux, macOS and Windows, signed by the release-of-record workflow, with a .sigstore.json bundle next to each file and a signed checksums.txt.
11 multi-arch images (linux/amd64, linux/arm64), distroless, running as UID 65532, cosign-signed with SPDX SBOM attestations.
The chart is published as a signed OCI artifact. Air-gap bundles include a SHA256SUMS file, signed with cosign when built with a signing key.
Verify a download
The install scripts always check the SHA-256 and verify the cosign signature when cosign is installed (--cosign requires it). To check by hand, use cosign 2.x or later.
maqpna verify checks signatures, SBOM attestations and checksums of MAQPNA releases from the CLI. Per-file commands for every platform are on the download page.
V=v0.1.0
R=https://github.com/AzmxAI/maqpna-releases/releases/download/$V
curl -fsSLO $R/maqpna_linux_amd64 -fsSLO $R/maqpna_linux_amd64.sigstore.json -fsSLO $R/checksums.txt
grep ' maqpna_linux_amd64$' checksums.txt | sha256sum --check
cosign verify-blob maqpna_linux_amd64 --bundle maqpna_linux_amd64.sigstore.json \
--certificate-identity-regexp '^https://github\.com/AzmxAI/azmx-ai/\.github/workflows/maqpna-signed-release\.yml@refs/.+$' \
--certificate-oidc-issuer https://token.actions.githubusercontent.comSBOMs and provenance
Every archive ships with an SPDX 2.3 SBOM next to it, and every image carries its SBOM as a signed attestation.
gh attestation verify.cosign verify-attestation --type spdxjson.CGO_ENABLED=0) built from the tagged source.No phone-home
No telemetry, usage analytics, update checks or licence validation. An unexpected outbound network call is treated as a vulnerability.
allowedEgressHosts and allowedEgressCIDRs.Secure defaults
No matching rule, or no policy, means the call is denied. Sandboxes start with default-deny egress.
If the revocation list is unavailable, calls are denied. In the sovereign profile, so are calls when the audit ledger is unavailable.
Non-root, read-only root filesystem and no Kubernetes service-account token in the agent's pod.
The generated identity key and the sample attestation verifier are for development and say so; the attestation service will not start without verifier keys.
Security testing
The CI pipeline runs on every pull request and on main.
govulncheck and staticcheck on the Go code.Vulnerability disclosure
Do not open a public issue. Email [email protected] with the affected component and version, your configuration (trust tier, runtime, Kubernetes version), reproduction steps and the impact you observed.
Vulnerabilities in upstream projects (gVisor, Kata Containers, Firecracker, Confidential Containers, agent-sandbox, Kubernetes) go to those projects; tell us too if our defaults make them worse. Findings that need cluster-admin, and the documented development-only modes, are out of scope.
Install the CLI with checksum and signature verification, or read the release before you run it.
curl -fsSL https://maqpna.com/install.sh | shbrew install azmxai/maqpna/maqpnairm https://maqpna.com/install.ps1 | iexNo Kubernetes, GPU or API key needed to try it. Every download is checked against its SHA-256 and cosign signature.