Produce a single-layer (flattened) OCI image of the full merged state of `view`. Because a draft view sees its entire parent chain, the materialized content is the complete, self-contained rootfs — a deployable runtime. Provenance (view name and Merkle state) is recorded in the manifest annotations. Returns the manifest digest and file count.
(&self, opts: SealOptions)
| 328 | /// Provenance (view name and Merkle state) is recorded in the manifest |
| 329 | /// annotations. Returns the manifest digest and file count. |
| 330 | pub fn seal(&self, opts: SealOptions) -> Result<SealResult, RepositoryError> { |
| 331 | let work_dir = tempfile::tempdir()?; |
| 332 | let files = self.materialize_view_to(&opts.view, work_dir.path())?; |
| 333 | let layer = oci::layer_from_dir(work_dir.path())?; |
| 334 | |
| 335 | let view_info = self.get_view_info(&opts.view)?; |
| 336 | let mut annotations = BTreeMap::new(); |
| 337 | annotations.insert("org.atomic.view".to_string(), opts.view.clone()); |
| 338 | annotations.insert( |
| 339 | "org.atomic.view-merkle".to_string(), |
| 340 | view_info.state_base32(), |
| 341 | ); |
| 342 | |
| 343 | let config = OciImageConfig { |
| 344 | architecture: oci::host_arch(), |
| 345 | os: "linux".to_string(), |
| 346 | env: opts.env.clone(), |
| 347 | entrypoint: opts.entrypoint.clone(), |
| 348 | annotations, |
| 349 | }; |
| 350 | |
| 351 | let manifest_digest = oci::write_image_layout(&opts.out, &[layer], &config)?; |
| 352 | |
| 353 | Ok(SealResult { |
| 354 | manifest_digest, |
| 355 | files, |
| 356 | out: opts.out, |
| 357 | }) |
| 358 | } |
| 359 | } |
| 360 | |
| 361 | /// Clone a working tree from `src` to `dest`, one file at a time, reflinking |