ImageTrustPolicy
kguardian.dev / v1alpha1
apiVersion: kguardian.dev/v1alpha1
kind: ImageTrustPolicy
metadata:
name: example
apiVersion
string
kind
string
metadata
object
spec object required
attestations []object
Attestations that must also be attached, verified, and
signed by one of the authorities.
maxItems:
16
builderIdRegExp
string
maxLength:
1024
predicateType
string required
maxLength:
512
sourceRepoRegExp
string
maxLength:
1024authorities []object required
An image is trusted when a signature from any one of
these verified. Exactly one of keyless and key each.
minItems:
1maxItems:
32key object
A public key (PEM) or the sha256 (hex) of its DER
SubjectPublicKeyInfo. The supplychain component must
hold the same key to verify such signatures
(supplychain.signatureDiscovery.publicKeys).
fingerprint
string
pattern:
^[0-9a-fA-F]{64}$
publicKey
string
maxLength:
16384keyless object
Fulcio certificate identity. issuer (or
issuerRegExp) and subject (or subjectRegExp) are
both required; regular expressions must match the
whole value.
issuer
string
maxLength:
1024
issuerRegExp
string
maxLength:
1024
subject
string
maxLength:
1024
subjectRegExp
string
maxLength:
1024
name
string
maxLength:
128
images
[]string
Glob patterns over the image repository
(docker.io/library/nginx, ghcr.io/org/app). "*" matches
within one path segment, "**" across segments. Empty
matches every image.
maxItems:
64status object
Written by the kguardian evaluator.
conditions []object
BrokerRead (True once running containers were read; False with NeverRead, BrokerUnavailable or BrokerUnauthorized).
lastTransitionTime
string required
format:
date-time
message
string required
maxLength:
32768
observedGeneration
integer
format:
int64minimum:
0
reason
string required
minLength:
1maxLength:
1024
status
string required
enum:
True, False, Unknown
type
string required
maxLength:
316
error
string
evaluation object
containers
integer
format:
int64findings []object
container
string
digest
string
namespace
string
reason
string
repository
string
verdict
string
workload
string
lastChanged
string
format:
date-time
lastEvaluated
string
format:
date-time
state
string
enum:
evaluated, never-read, broker-unavailable, broker-unauthorized
truncated
boolean
trusted
integer
format:
int64
unknown
integer
format:
int64
wouldDeny
integer
format:
int64
message
string
Why containers are Unknown because the broker could not be read, with the last successful read.
observedGeneration
integer
format:
int64No matches. Try .spec.attestations for an exact path