{ "$schema": "https://json-schema.org/draft/2020-12/schema", "title": "Recipe", "type": "object", "properties": { "$schema": { "type": [ "string", "null" ] }, "allowed_devices": { "description": "List of serial numbers of allowed devices. If not present or empty, all devices are allowed.", "type": [ "array", "null" ], "items": { "type": "string" } }, "id": { "description": "The ID of the recipe. It must be unique and determines the execution order.", "type": "integer", "format": "uint32", "minimum": 0 }, "steps": { "description": "The steps of the recipe, executed in order.", "type": "array", "items": { "$ref": "#/$defs/RecipeStep" } } }, "additionalProperties": false, "required": [ "id", "steps" ], "$defs": { "RecipeStep": { "oneOf": [ { "description": "Installs an SWU package.", "type": "object", "properties": { "name": { "description": "The name of the step (used for logging).", "type": "string" }, "path": { "description": "The path to the SWU package, relative to the root of the removable media.", "type": "string" }, "sha256": { "description": "The SHA-256 of the SWU package, used for integrity verification.\nThis is mandatory for signed deployments, but optional for unsigned deployments.\n\nFor unsigned deployments, deployment will fail if a sha is specified but does not match the actual sha of the SWU package.\nIf no sha is specified, no check will be performed.\n\nFor signed deployments, all SWU steps must have a sha specified, and the sha must match the actual sha of the SWU package.\nThis is to prevent tampering with the SWU packages, as the signature only covers the recipe file itself, but not the SWU packages on the media device.", "type": [ "string", "null" ] }, "type": { "type": "string", "const": "SWU" } }, "additionalProperties": false, "required": [ "type", "name", "path" ] }, { "description": "Executes a task by forwarding the payload to the task runner.", "type": "object", "properties": { "name": { "description": "The name of the step (used for logging).", "type": "string" }, "path": { "description": "The path to the task runner payload. This can be any file that the task runner can handle, for example:\n\n* A tar archive containing a task-description.json and payloads\n* A task-description.json file that directly describes the task to be executed, including any necessary payloads\n\nIf the path ends with .json, it will be treated as a task-description.json file. Otherwise, it will be treated as a tar archive.", "type": "string" }, "sha256": { "description": "The SHA-256 of the task runner payload, used for integrity verification.\nThis is mandatory for signed deployments, but optional for unsigned deployments.\n\nFor unsigned deployments, deployment will fail if a sha is specified but does not match the actual sha of the task runner payload.\nIf no sha is specified, no check will be performed.\n\nFor signed deployments, all task steps must have a sha specified, and the sha must match the actual sha of the task runner payload.\nThis is to prevent tampering with the task runner payloads, as the signature only covers the recipe file itself, but not the task runner payloads on the media device.", "type": [ "string", "null" ] }, "type": { "type": "string", "const": "TASK" } }, "additionalProperties": false, "required": [ "type", "name", "path" ] } ] } } }