Public/Test-KadenPublicationKeyReadiness.ps1

function Test-KadenPublicationKeyReadiness {
    <#
    .SYNOPSIS
        Decide whether a production publication has a package-specific Gallery key in secret custody.
    .DESCRIPTION
        PackageRegistered, KeyScope, and HeldInSecretStore are facts supplied by the caller.
        KeyScope is TemporaryBroad or PackageSpecific. This command does not take a Gallery
        API key and does not call the Gallery. A ready result records those facts.
        -RecordPath writes that record only when the release is ready. A failed check names
        a KDN-RELEASE requirement and does not write the file. An unrecognized KeyScope is
        not copied into the result.
    .EXAMPLE
        Test-KadenPublicationKeyReadiness -PackageRegistered $true -KeyScope PackageSpecific -HeldInSecretStore $true -RecordPath .\key-readiness.json
    #>

    [CmdletBinding()]
    param(
        [Parameter(Mandatory = $true)]
        [bool]$PackageRegistered,

        [Parameter(Mandatory = $true)]
        [string]$KeyScope,

        [Parameter(Mandatory = $true)]
        [bool]$HeldInSecretStore,

        [string]$RecordPath
    )

    $recordedScope = $null
    $failed = $null
    if ($KeyScope -eq 'PackageSpecific' -or $KeyScope -eq 'TemporaryBroad') {
        $recordedScope = $KeyScope
    }
    else {
        $failed = 'KDN-RELEASE-KEY-SCOPE: Publication key scope is not recognized.'
    }

    if (-not $failed -and -not $PackageRegistered) {
        $failed = 'KDN-RELEASE-PACKAGE-UNREGISTERED: Gallery package identity is not registered.'
    }
    if (-not $failed -and $recordedScope -eq 'TemporaryBroad') {
        $failed = 'KDN-RELEASE-KEY-BROAD: A package-specific key is required.'
    }
    if (-not $failed -and -not $HeldInSecretStore) {
        $failed = 'KDN-RELEASE-KEY-ABSENT: The publication key is not in the release secret store.'
    }

    $ready = -not $failed
    $result = [pscustomobject]@{
        Ready              = [bool]$ready
        PackageRegistered  = [bool]$PackageRegistered
        KeyScope           = $recordedScope
        HeldInSecretStore  = [bool]$HeldInSecretStore
        FailedRequirement  = $failed
    }

    if ($ready -and -not [string]::IsNullOrWhiteSpace($RecordPath)) {
        Write-KadenJsonAtomic -LiteralPath $RecordPath -Object $result
    }

    return $result
}