UNCLASSIFIED - NO CUI

Skip to content
Snippets Groups Projects
Commit cddf46a2 authored by Noah Birrer's avatar Noah Birrer Committed by Ryan Garcia
Browse files

feat: enable `require-image-signature` policy as `audit`

parent c2468a44
No related branches found
No related tags found
1 merge request!3286feat: enable `require-image-signature` policy as `audit`
...@@ -160,7 +160,7 @@ policies: ...@@ -160,7 +160,7 @@ policies:
# Kyverno Beta feature - https://kyverno.io/docs/writing-policies/verify-images/ # Kyverno Beta feature - https://kyverno.io/docs/writing-policies/verify-images/
require-image-signature: require-image-signature:
enabled: false enabled: true
validationFailureAction: audit validationFailureAction: audit
require-istio-on-namespaces: require-istio-on-namespaces:
......
...@@ -411,6 +411,8 @@ kyvernoPolicies: ...@@ -411,6 +411,8 @@ kyvernoPolicies:
- 'kyverno-policies-bbtest/test: required' - 'kyverno-policies-bbtest/test: required'
- kyverno-policies-bbtest/required - kyverno-policies-bbtest/required
require-image-signature: require-image-signature:
enabled: true
validationFailureAction: enforce
parameters: parameters:
require: require:
- imageReferences: - imageReferences:
...@@ -424,6 +426,8 @@ kyvernoPolicies: ...@@ -424,6 +426,8 @@ kyvernoPolicies:
MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE8nXRh950IZbRj8Ra/N9sbqOPZrfM MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE8nXRh950IZbRj8Ra/N9sbqOPZrfM
5/KAQN0/KjHcorm/J5yctVd7iEcnessRQjU917hmKO6JWVGHpDguIyakZA== 5/KAQN0/KjHcorm/J5yctVd7iEcnessRQjU917hmKO6JWVGHpDguIyakZA==
-----END PUBLIC KEY----- -----END PUBLIC KEY-----
mutateDigest: false
verifyDigest: false
- imageReferences: - imageReferences:
- "registry1.dso.mil/ironbank/*" - "registry1.dso.mil/ironbank/*"
attestors: attestors:
......
0% Loading or .
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment