1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2024-12-14 11:57:48 +00:00
kyverno/samples/RestrictImageRegistries.md

31 lines
724 B
Markdown
Raw Normal View History

2019-10-23 21:06:03 +00:00
# Disallow unknown image registries
2019-10-23 22:36:37 +00:00
Images from unknown registries may not be scanned and secured. Requiring the use of trusted registries helps reduce threat exposure.
You can customize this policy to allow image registries that you trust.
2019-10-23 21:06:03 +00:00
## Policy YAML
2019-11-12 02:21:16 +00:00
[restrict_image_registries.yaml](more/restrict_image_registries.yaml)
2019-10-23 21:06:03 +00:00
````yaml
2019-11-13 21:56:20 +00:00
apiVersion : kyverno.io/v1
2019-10-23 21:06:03 +00:00
kind: ClusterPolicy
metadata:
2019-11-11 02:13:01 +00:00
name: restrict-image-registries
2019-10-23 21:06:03 +00:00
spec:
validationFailureAction: audit
2019-10-23 21:06:03 +00:00
rules:
2019-11-11 02:13:01 +00:00
- name: validate-registries
2019-10-23 21:06:03 +00:00
match:
resources:
kinds:
- Pod
validate:
message: "Unknown image registry"
2019-10-23 21:06:03 +00:00
pattern:
spec:
containers:
- image: "k8s.gcr.io/* | gcr.io/*"
````