diff --git a/chart/templates/kyverno-policies/values.yaml b/chart/templates/kyverno-policies/values.yaml index 1c18f0624aa731143974be7de100df2abe5ea694..30bbc918e62ac0cc9871d6b3c8da31ee1cb4d239 100644 --- a/chart/templates/kyverno-policies/values.yaml +++ b/chart/templates/kyverno-policies/values.yaml @@ -160,7 +160,7 @@ policies: # Kyverno Beta feature - https://kyverno.io/docs/writing-policies/verify-images/ require-image-signature: - enabled: false + enabled: true validationFailureAction: audit require-istio-on-namespaces: diff --git a/tests/test-values.yaml b/tests/test-values.yaml index 1355c4c43e81c6599ebe81117791745f52504454..79a46a386198382d533b814ace0044406d4790ed 100644 --- a/tests/test-values.yaml +++ b/tests/test-values.yaml @@ -411,6 +411,8 @@ kyvernoPolicies: - 'kyverno-policies-bbtest/test: required' - kyverno-policies-bbtest/required require-image-signature: + enabled: true + validationFailureAction: enforce parameters: require: - imageReferences: @@ -424,6 +426,8 @@ kyvernoPolicies: MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE8nXRh950IZbRj8Ra/N9sbqOPZrfM 5/KAQN0/KjHcorm/J5yctVd7iEcnessRQjU917hmKO6JWVGHpDguIyakZA== -----END PUBLIC KEY----- + mutateDigest: false + verifyDigest: false - imageReferences: - "registry1.dso.mil/ironbank/*" attestors: