PageSourceSearch

https://ratify.dev/assets/js/61d4a294.76a61107.js

js ratify.dev collected 2026-09-24 19:29:05 UTC 5,728 bytes, 1 lines download raw bytes

1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[3722],{10857(e,t,i){i.r(t),i.d(t,{assets:()=>l,contentTitle:()=>o,default:()=>u,frontMatter:()=>r,metadata:()=>n,toc:()=>c});const n=JSON.parse('{"id":"quick-start","title":"Getting Started","description":"Note You can follow this interactive tutorial to get started with Ratify within 5 minutes in an online playground.","source":"@site/versioned_docs/version-1.0/quick-start.mdx","sourceDirName":".","slug":"/quick-start","permalink":"/docs/1.0/quick-start","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/versioned_docs/version-1.0/quick-start.mdx","tags":[],"version":"1.0","sidebarPosition":2,"frontMatter":{"title":"Getting Started","sidebar_position":2},"sidebar":"tutorialSidebar","previous":{"title":"What is Ratify","permalink":"/docs/1.0/what-is-ratify"},"next":{"title":"Overview","permalink":"/docs/1.0/ratify-configuration"}}');var s=i(74848),a=i(28453);const r={title:"Getting Started",sidebar_position:2},o=void 0,l={},c=[{value:"Step 1: Install Gatekeeper, Ratify, and Constraints",id:"step-1-install-gatekeeper-ratify-and-constraints",level:3},{value:"Step 2: See Ratify in action",id:"step-2-see-ratify-in-action",level:3},{value:"Step 4: Uninstall",id:"step-4-uninstall",level:3},{value:"Notes",id:"notes",level:3}];function d(e){const t={a:"a",blockquote:"blockquote",code:"code",h3:"h3",li:"li",p:"p",pre:"pre",strong:"strong",ul:"ul",...(0,a.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsxs)(t.blockquote,{children:["\n",(0,s.jsxs)(t.p,{children:[(0,s.jsx)(t.strong,{children:"Note"})," You can follow this ",(0,s.jsx)(t.a,{href:"https://killercoda.com/notaryproject/scenario/notation/ratify",children:"interactive tutorial"})," to get started with Ratify within 5 minutes in an online playground."]}),"\n"]}),"\n",(0,s.jsx)(t.p,{children:"Try out ratify in Kubernetes through Gatekeeper as the admission controller."}),"\n",(0,s.jsx)(t.p,{children:"Prerequisites:"}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsx)(t.li,{children:"Kubernetes v1.20 or higher"}),"\n",(0,s.jsx)(t.li,{children:"OPA Gatekeeper v3.10 or higher"}),"\n",(0,s.jsxs)(t.li,{children:[(0,s.jsx)(t.a,{href:"https://helmfile.readthedocs.io/en/latest/#installation",children:"helmfile"})," v0.14 or higher. For production use and if you would like to avoid automatic installation of resources using helmfile, please refer to ",(0,s.jsx)(t.a,{href:"/docs/1.0/quickstarts/quickstart-manual",children:"ratify-quickstart-manual.md"})," for manual install steps."]}),"\n"]}),"\n",(0,s.jsx)(t.h3,{id:"step-1-install-gatekeeper-ratify-and-constraints",children:"Step 1: Install Gatekeeper, Ratify, and Constraints"}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{className:"language-bash",children:"helmfile sync -f git::https://github.com/notaryproject/[email protected]\n"})}),"\n",(0,s.jsx)(t.h3,{id:"step-2-see-ratify-in-action",children:"Step 2: See Ratify in action"}),"\n",(0,s.jsx)(t.p,{children:"Once the installation is completed, you can test the deployment of an image that is signed using Notation solution."}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsxs)(t.li,{children:["This will successfully create the pod ",(0,s.jsx)(t.code,{children:"demo"})]}),"\n"]}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{className:"language-bash",children:"kubectl run demo --image=ghcr.io/deislabs/ratify/notary-image:signed -n default\nkubectl get pods demo -n default\n"})}),"\n",(0,s.jsxs)(t.p,{children:["Optionally you can see the output of the pod logs via: ",(0,s.jsx)(t.code,{children:"kubectl logs demo"})]}),"\n",(0,s.jsxs)(t.ul,{children:["\n",(0,s.jsx)(t.li,{children:"Now deploy an unsigned image"}),"\n"]}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{className:"language-bash",children:"kubectl run demo1 --image=ghcr.io/deislabs/ratify/notary-image:unsigned -n default\n"})}),"\n",(0,s.jsx)(t.p,{children:"You will see a deny message from Gatekeeper denying the request to create it as the image doesn't have any signatures."}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{className:"language-bash",children:'Error from server (Forbidden): admission webhook "validation.gatekeeper.sh" denied the request: [ratify-constraint] Subject failed verification: wabbitnetworks.azurecr.io/test/net-monitor:unsigned\n'})}),"\n",(0,s.jsx)(t.p,{children:"You just validated the container images in your k8s cluster!"}),"\n",(0,s.jsx)(t.h3,{id:"step-4-uninstall",children:"Step 4: Uninstall"}),"\n",(0,s.jsx)(t.pre,{children:(0,s.jsx)(t.code,{className:"language-bash",children:"helmfile destroy --skip-charts -f git::https://github.com/notaryproject/[email protected]\n"})}),"\n",(0,s.jsx)(t.h3,{id:"notes",children:"Notes"}),"\n",(0,s.jsxs)(t.p,{children:["If the image reference provided resolves to an OCI Index or a Docker Manifest List, validation will occur ONLY at the index or manifest list level. Ratify currently does NOT support image validation based on automatic platform selection. For more information, ",(0,s.jsx)(t.a,{href:"https://github.com/ratify-project/ratify/issues/101",children:"see this issue"}),"."]})]})}function u(e={}){const{wrapper:t}={...(0,a.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(d,{...e})}):d(e)}},28453(e,t,i){i.d(t,{R:()=>r,x:()=>o});var n=i(96540);const s={},a=n.createContext(s);function r(e){const t=n.useContext(a);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function o(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:r(e.components),n.createElement(a.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.