Skip to search

ImageTrustPolicy

kguardian.dev / v1alpha1

apiVersion: kguardian.dev/v1alpha1 kind: ImageTrustPolicy metadata: name: example
View raw schema
apiVersion string
kind string
metadata object
spec object required
attestations []object
Attestations that must also be attached, verified, and signed by one of the authorities.
maxItems: 16
builderIdRegExp string
maxLength: 1024
predicateType string required
maxLength: 512
sourceRepoRegExp string
maxLength: 1024
authorities []object required
An image is trusted when a signature from any one of these verified. Exactly one of keyless and key each.
minItems: 1
maxItems: 32
key object
A public key (PEM) or the sha256 (hex) of its DER SubjectPublicKeyInfo. The supplychain component must hold the same key to verify such signatures (supplychain.signatureDiscovery.publicKeys).
fingerprint string
pattern: ^[0-9a-fA-F]{64}$
publicKey string
maxLength: 16384
keyless object
Fulcio certificate identity. issuer (or issuerRegExp) and subject (or subjectRegExp) are both required; regular expressions must match the whole value.
issuer string
maxLength: 1024
issuerRegExp string
maxLength: 1024
subject string
maxLength: 1024
subjectRegExp string
maxLength: 1024
name string
maxLength: 128
images []string
Glob patterns over the image repository (docker.io/library/nginx, ghcr.io/org/app). "*" matches within one path segment, "**" across segments. Empty matches every image.
maxItems: 64
status object
Written by the kguardian evaluator.
conditions []object
BrokerRead (True once running containers were read; False with NeverRead, BrokerUnavailable or BrokerUnauthorized).
lastTransitionTime string required
format: date-time
message string required
maxLength: 32768
observedGeneration integer
format: int64
minimum: 0
reason string required
minLength: 1
maxLength: 1024
status string required
enum: True, False, Unknown
type string required
maxLength: 316
error string
evaluation object
containers integer
format: int64
findings []object
container string
digest string
namespace string
reason string
repository string
verdict string
workload string
lastChanged string
format: date-time
lastEvaluated string
format: date-time
state string
enum: evaluated, never-read, broker-unavailable, broker-unauthorized
truncated boolean
trusted integer
format: int64
unknown integer
format: int64
wouldDeny integer
format: int64
message string
Why containers are Unknown because the broker could not be read, with the last successful read.
observedGeneration integer
format: int64

No matches. Try .spec.attestations for an exact path