diff --git a/chart/templates/kyverno-policies/values.yaml b/chart/templates/kyverno-policies/values.yaml index b667324a8f313d375b2196e651b9945a80e8f355..c76e0bc912aba94528144dcf004efbcec1931248 100644 --- a/chart/templates/kyverno-policies/values.yaml +++ b/chart/templates/kyverno-policies/values.yaml @@ -160,7 +160,7 @@ policies: # Kyverno Beta feature - https://kyverno.io/docs/writing-policies/verify-images/ require-image-signature: - enabled: false + enabled: true validationFailureAction: audit require-istio-on-namespaces: diff --git a/tests/test-values.yaml b/tests/test-values.yaml index 77d5674eaecec08924a203418c39906b8d0245cb..1472bc4e0a96731c4007a45cd77d9fbe04e9bb8c 100644 --- a/tests/test-values.yaml +++ b/tests/test-values.yaml @@ -411,6 +411,8 @@ kyvernoPolicies: - 'kyverno-policies-bbtest/test: required' - kyverno-policies-bbtest/required require-image-signature: + enabled: true + validationFailureAction: enforce parameters: require: - imageReferences: @@ -424,6 +426,8 @@ kyvernoPolicies: MFkwEwYHKoZIzj0CAQYIKoZIzj0DAQcDQgAE8nXRh950IZbRj8Ra/N9sbqOPZrfM 5/KAQN0/KjHcorm/J5yctVd7iEcnessRQjU917hmKO6JWVGHpDguIyakZA== -----END PUBLIC KEY----- + mutateDigest: false + verifyDigest: false - imageReferences: - "registry1.dso.mil/ironbank/*" attestors: