Skip to content

kindgi build

Bundle + build + sign a pack image. Emits deploy-envelope.json for kindgi deploy. --local builds the image with this machine's Docker instead: no build service, no signing; with --push, it pushes the image, signs it, and writes the envelope.

Terminal window
kindgi build [--local [--push [<repository>]] [--platform <os/arch>]] [--target <t>] [--endpoint <url>] [--env <name>] [--out <dir>] [--artifact-version <v>] [--published-at <iso>] [--tenant <id>] [--signing-key <path>] [--registry-push-creds <ref>] [--skip-integrity-gate] [--skip-image-pull] [--skip-sign] [--path <dir>]

Flags:

  • --artifact-version <value>: The artifact version, in the image and its signature. Default: today's date as YYYYMMDD.1 (UTC).
  • --endpoint <value>: The build server. Default: the env block's build. Not used with --local.
  • --env <value>: The environment block in kindgi.config.ts to build for. Default: staging.
  • --local: Build with this machine's Docker instead of a build server: no signing and no envelope unless --push. TypeScript packs only.
  • --out <value>: Where the build output and deploy-envelope.json go. Default: .kindgi/build under the pack root.
  • --path <value>: The pack root. Default: the current directory.
  • --platform <value>: With --local: the image's platform. Default: linux/amd64 when pushing, else this machine's.
  • --published-at <value>: The publish time (ISO 8601), in the image and its signature. Default: the Unix epoch, so builds are reproducible.
  • --push <value>: With --local: push the image, sign it and write the envelope. Default repository: the env block's registry + /&lt;packId&gt;.
  • --registry-push-creds <value>: A reference to the registry push credentials for the build server to use, passed through as is.
  • --signer-key-id <value>: The key id the signature names. Default: the env block's signerKeyId, else the key file's name.
  • --signing-key <value>: The Ed25519 private key (PEM) to sign with. Default: the env block's signingKey.
  • --skip-image-pull: Check the image's index by hash only, without pulling the image. Build-server builds only.
  • --skip-integrity-gate: Sign without checking the image's index against the local one. Prints a warning. Build-server builds only.
  • --skip-sign: Write an unsigned envelope (for CI that signs elsewhere); kindgi deploy refuses it.
  • --target <value>: The build target, set in the image build and sent to the build server. Default: the env block's buildTarget, else the env name.
  • --tenant <value>: The tenant the signature names. Default: the env block's tenantId, else KINDGI_TENANT_ID.

Every command also takes the global flags.