1
0
Fork 0
mirror of https://github.com/kyverno/kyverno.git synced 2024-12-14 11:57:48 +00:00

fix: transfer image verify iamges to kyverno (#11340)

Signed-off-by: Vishal Choudhary <vishal.choudhary@nirmata.com>
Co-authored-by: Charles-Edouard Brétéché <charles.edouard@nirmata.com>
Co-authored-by: Jim Bugwadia <jim@nirmata.com>
This commit is contained in:
Vishal Choudhary 2024-10-07 21:26:12 +05:30 committed by GitHub
parent 373f942ea9
commit 00fd6d47f8
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
36 changed files with 43 additions and 43 deletions

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -18,7 +18,7 @@ spec:
verifyImages:
- failureAction: Enforce
imageReferences:
- "ghcr.io/chipzoller/zulu*"
- "ghcr.io/kyverno/zulu*"
attestations:
- type: https://slsa.dev/provenance/v0.2
attestors:

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -18,7 +18,7 @@ spec:
verifyImages:
- failureAction: Enforce
imageReferences:
- "ghcr.io/chipzoller/zulu*"
- "ghcr.io/kyverno/zulu*"
attestations:
- type: https://slsa.dev/provenance/v0.2
attestors:

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -2,10 +2,10 @@ apiVersion: v1
kind: Pod
metadata:
annotations:
kyverno.io/verify-images: '{"ghcr.io/chipzoller/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
kyverno.io/verify-images: '{"ghcr.io/kyverno/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
name: zulu
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
- image: ghcr.io/kyverno/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
name: zulu

View file

@ -32,6 +32,6 @@ spec:
value: true
predicateType: https://slsa.dev/provenance/v0.2
imageReferences:
- ghcr.io/chipzoller/zulu*
- ghcr.io/kyverno/zulu*
failureAction: Enforce
webhookTimeoutSeconds: 30

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -2,10 +2,10 @@ apiVersion: v1
kind: Pod
metadata:
annotations:
kyverno.io/verify-images: '{"ghcr.io/chipzoller/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
kyverno.io/verify-images: '{"ghcr.io/kyverno/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
name: zulu
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
- image: ghcr.io/kyverno/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
name: zulu

View file

@ -32,6 +32,6 @@ spec:
value: true
predicateType: cosign.sigstore.dev/attestation/vuln/v1
imageReferences:
- ghcr.io/chipzoller/zulu*
- ghcr.io/kyverno/zulu*
failureAction: Enforce
webhookTimeoutSeconds: 30

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -32,6 +32,6 @@ spec:
value: true
predicateType: cosign.sigstore.dev/attestation/vuln/v1
imageReferences:
- ghcr.io/chipzoller/zulu*
- ghcr.io/kyverno/zulu*
failureAction: Enforce
webhookTimeoutSeconds: 30

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -2,10 +2,10 @@ apiVersion: v1
kind: Pod
metadata:
annotations:
kyverno.io/verify-images: '{"ghcr.io/chipzoller/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
kyverno.io/verify-images: '{"ghcr.io/kyverno/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
name: zulu
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
- image: ghcr.io/kyverno/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
name: zulu

View file

@ -23,5 +23,5 @@ spec:
value: true
predicateType: https://slsa.dev/provenance/v0.2
imageReferences:
- ghcr.io/chipzoller/zulu*
- ghcr.io/kyverno/zulu*
failureAction: Enforce

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -2,10 +2,10 @@ apiVersion: v1
kind: Pod
metadata:
annotations:
kyverno.io/verify-images: '{"ghcr.io/chipzoller/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
kyverno.io/verify-images: '{"ghcr.io/kyverno/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
name: zulu
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
- image: ghcr.io/kyverno/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
name: zulu

View file

@ -40,6 +40,6 @@ spec:
value: true
predicateType: https://slsa.dev/provenance/v0.2
imageReferences:
- ghcr.io/chipzoller/zulu*
- ghcr.io/kyverno/zulu*
failureAction: Enforce
webhookTimeoutSeconds: 30

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -40,6 +40,6 @@ spec:
value: true
predicateType: https://slsa.dev/provenance/v0.2
imageReferences:
- ghcr.io/chipzoller/zulu*
- ghcr.io/kyverno/zulu*
failureAction: Enforce
webhookTimeoutSeconds: 30

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -39,6 +39,6 @@ spec:
value: true
predicateType: https://slsa.dev/provenance/v0.2
imageReferences:
- ghcr.io/chipzoller/zulu*
- ghcr.io/kyverno/zulu*
failureAction: Enforce
webhookTimeoutSeconds: 30

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -18,7 +18,7 @@ spec:
verifyImages:
- failureAction: Enforce
imageReferences:
- "ghcr.io/chipzoller/zulu:*"
- "ghcr.io/kyverno/zulu:*"
attestors:
- count: 1
entries:

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14
- image: ghcr.io/kyverno/zulu:v0.0.14
name: zulu

View file

@ -2,10 +2,10 @@ apiVersion: v1
kind: Pod
metadata:
annotations:
kyverno.io/verify-images: '{"ghcr.io/chipzoller/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
kyverno.io/verify-images: '{"ghcr.io/kyverno/zulu@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db":"pass"}'
name: zulu
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
- image: ghcr.io/kyverno/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
name: zulu

View file

@ -21,7 +21,7 @@ spec:
url: https://rekor.sigstore.dev
subject: https://github.com/chipzoller/zulu/.github/workflows/slsa-generic-keyless.yaml@refs/tags/v*
imageReferences:
- ghcr.io/chipzoller/zulu:*
- ghcr.io/kyverno/zulu:*
mutateDigest: true
required: true
verifyDigest: true

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu
- image: ghcr.io/kyverno/zulu
name: zulu

View file

@ -2,10 +2,10 @@ apiVersion: v1
kind: Pod
metadata:
annotations:
kyverno.io/verify-images: '{"ghcr.io/chipzoller/zulu:latest":"pass"}'
kyverno.io/verify-images: '{"ghcr.io/kyverno/zulu:latest":"pass"}'
name: zulu
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu
- image: ghcr.io/kyverno/zulu
name: zulu

View file

@ -21,7 +21,7 @@ spec:
url: https://rekor.sigstore.dev
subject: https://github.com/chipzoller/zulu/.github/workflows/slsa-generic-keyless.yaml@refs/tags/v*
imageReferences:
- ghcr.io/chipzoller/zulu*
- ghcr.io/kyverno/zulu*
mutateDigest: false
required: false
verifyDigest: false

View file

@ -5,5 +5,5 @@ metadata:
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu
- image: ghcr.io/kyverno/zulu
name: zulu

View file

@ -2,10 +2,10 @@ apiVersion: v1
kind: Pod
metadata:
annotations:
kyverno.io/verify-images: '{"ghcr.io/chipzoller/zulu:latest":"pass"}'
kyverno.io/verify-images: '{"ghcr.io/kyverno/zulu:latest":"pass"}'
name: zulu
namespace: default
spec:
containers:
- image: ghcr.io/chipzoller/zulu
- image: ghcr.io/kyverno/zulu
name: zulu

View file

@ -21,7 +21,7 @@ spec:
url: https://rekor.sigstore.dev
subject: https://github.com/chipzoller/zulu/.github/workflows/slsa-generic-keyless.yaml@refs/tags/v*
imageReferences:
- ghcr.io/chipzoller/zulu*
- ghcr.io/kyverno/zulu*
mutateDigest: false
required: true
verifyDigest: false

View file

@ -7,7 +7,7 @@ metadata:
namespace: exclude-refs
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
- image: ghcr.io/kyverno/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
name: test
resources: {}
- image: ghcr.io/kyverno/kyverno:latest

View file

@ -55,7 +55,7 @@ spec:
imageReferences:
- "ghcr.io/*"
skipImageReferences:
- "ghcr.io/chipzoller*"
- "ghcr.io/kyverno*"
failureAction: Enforce
attestors:
- count: 1

View file

@ -7,7 +7,7 @@ metadata:
namespace: exclude-refs
spec:
containers:
- image: ghcr.io/chipzoller/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
- image: ghcr.io/kyverno/zulu:v0.0.14@sha256:476b21f1a75dc90fac3579ee757f4607bb5546f476195cf645c54badf558c0db
name: test
resources: {}
dnsPolicy: ClusterFirst