1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[2349],{16761(e,n,i){i.d(n,{A:()=>t});const t=i.p+"assets/images/alibabacloud-policy-governance-54f4bf4253311218d5cf12b6cff5c6d4.png"},28453(e,n,i){i.d(n,{R:()=>r,x:()=>c});var t=i(96540);const a={},s=t.createContext(a);function r(e){const n=t.useContext(s);return t.useMemo(function(){return"function"==typeof e?e(n):{...n,...e}},[n,e])}function c(e){let n;return n=e.disableParentContext?"function"==typeof e.components?e.components(a):e.components||a:r(e.components),t.createElement(s.Provider,{value:n},e.children)}},65645(e,n,i){i.r(n),i.d(n,{assets:()=>o,contentTitle:()=>c,default:()=>h,frontMatter:()=>r,metadata:()=>t,toc:()=>l});const t=JSON.parse('{"id":"quickstarts/ratify-on-alibabacloud","title":"Ratify on Alibaba Cloud","description":"This guide will explain how to get up and running with Ratify on Alibaba Cloud using Alibaba Cloud Container Service for Kubernetes (ACK) and Alibaba Cloud Container Registry (ACR). This will involve setting up necessary Alibaba Cloud resources, installing necessary components, and configuring them properly. Once everything is set up we will walk through a simple scenario of verifying the signature on a container image at deployment time.","source":"@site/docs/quickstarts/ratify-on-alibabacloud.md","sourceDirName":"quickstarts","slug":"/quickstarts/ratify-on-alibabacloud","permalink":"/docs/next/quickstarts/ratify-on-alibabacloud","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/docs/quickstarts/ratify-on-alibabacloud.md","tags":[],"version":"current","frontMatter":{},"sidebar":"tutorialSidebar","previous":{"title":"Ratify CLI","permalink":"/docs/next/quickstarts/ratify-cli"},"next":{"title":"Ratify on AWS","permalink":"/docs/next/quickstarts/ratify-on-aws"}}');var a=i(74848),s=i(28453);const r={},c="Ratify on Alibaba Cloud",o={},l=[{value:"Table of Contents",id:"table-of-contents",level:2},{value:"Prerequisites",id:"prerequisites",level:2},{value:"Prepare the container images in ACR:",id:"prepare-the-container-images-in-acr",level:2},{value:"Sign ACR images",id:"sign-acr-images",level:2},{value:"Sign with Notation and the keys managed in Alibaba Cloud KMS service",id:"sign-with-notation-and-the-keys-managed-in-alibaba-cloud-kms-service",level:3},{value:"Configuration instructions",id:"configuration-instructions",level:4},{value:"Managing KMS instances",id:"managing-kms-instances",level:4},{value:"Option 1: Using KMS created and managed keys",id:"option-1-using-kms-created-and-managed-keys",level:5},{value:"Option 2: Use self-signed and imported key material",id:"option-2-use-self-signed-and-imported-key-material",level:5},{value:"Artifact Signing with Notation CLI",id:"artifact-signing-with-notation-cli",level:4},{value:"Install Ratify & Gatekeeper",id:"install-ratify--gatekeeper",level:2},{value:"Prerequisites <a></a>",id:"prerequisites-",level:3},{value:"Install Ratify",id:"install-ratify",level:3},{value:"Deploy RatifyVerification policy instance",id:"deploy-ratifyverification-policy-instance",level:3},{value:"Configure Ratify",id:"configure-ratify",level:2},{value:"Configuring a verifier to validate artifact's Notation signature",id:"configuring-a-verifier-to-validate-artifacts-notation-signature",level:3},{value:"KeyManagementProvider Configuration",id:"keymanagementprovider-configuration",level:3},{value:"Pulling ACR private image signature manifest with RRSA",id:"pulling-acr-private-image-signature-manifest-with-rrsa",level:3},{value:"Deploying application in an ACK cluster with a specified image",id:"deploying-application-in-an-ack-cluster-with-a-specified-image",level:2}];function d(e){const n={a:"a",blockquote:"blockquote",code:"code",h1:"h1",h2:"h2",h3:"h3",h4:"h4",h5:"h5",header:"header",img:"img",li:"li",ol:"ol",p:"p",pre:"pre",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,s.R)(),...e.components};return(0,a.jsxs)(a.Fragment,{children:[(0,a.jsx)(n.header,{children:(0,a.jsx)(n.h1,{id:"ratify-on-alibaba-cloud",children:"Ratify on Alibaba Cloud"})}),"\n",(0,a.jsx)(n.p,{children:"This guide will explain how to get up and running with Ratify on Alibaba Cloud using Alibaba Cloud Container Service for Kubernetes (ACK) and Alibaba Cloud Container Registry (ACR). This will involve setting up necessary Alibaba Cloud resources, installing necessary components, and configuring them properly. Once everything is set up we will walk through a simple scenario of verifying the signature on a container image at deployment time."}),"\n",(0,a.jsx)(n.p,{children:"With ACK, you can quickly deploy Gatekeeper and Ratify through visual configuration. With ACR, you can store and distribute images with signatures together. You can use Alibaba Cloud Secrets Manager to keep your signing keys and certificates safe, and then use tools like Notation or Cosign to sign your container images with them."}
1),"\n",(0,a.jsx)(n.p,{children:"This article walks you through an end-to-end workflow of deploying only signed images on ACK with Ratify."}),"\n",(0,a.jsx)(n.h2,{id:"table-of-contents",children:"Table of Contents"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#prerequisites",children:"Prerequisites"})}),"\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#prepare-the-container-images-in-acr",children:"Prepare the container images in ACR"})}),"\n",(0,a.jsxs)(n.li,{children:[(0,a.jsx)(n.a,{href:"#sign-acr-images",children:"Sign ACR images"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsxs)(n.li,{children:[(0,a.jsx)(n.a,{href:"#sign-with-notation-and-the-keys-managed-in-alibaba-cloud-kms-service",children:"Sign with Notation and the keys managed in Alibaba Cloud KMS service"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#configuration-instructions",children:"Configuration instructions"})}),"\n",(0,a.jsxs)(n.li,{children:[(0,a.jsx)(n.a,{href:"#managing-kms-instances",children:"Managing KMS instances"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#option-1-using-kms-created-and-managed-keys",children:"Option 1: Using KMS created and managed keys"})}),"\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#option-2-use-self-signed-and-imported-key-material",children:"Option 2: Use self-signed and imported key material"})}),"\n"]}),"\n"]}),"\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#artifact-signing-with-notation-cli",children:"Artifact Signing with Notation CLI"})}),"\n"]}),"\n"]}),"\n"]}),"\n"]}),"\n",(0,a.jsxs)(n.li,{children:[(0,a.jsx)(n.a,{href:"#install-ratify-&-gatekeeper",children:"Install Ratify & Gatekeeper"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#second-prerequisites",children:"Prerequisites"})}),"\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#install-ratify",children:"Install Ratify"})}),"\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#deploy-ratifyVerification-policy-instance",children:"Deploy RatifyVerification policy instance"})}),"\n"]}),"\n"]}),"\n",(0,a.jsxs)(n.li,{children:[(0,a.jsx)(n.a,{href:"#configure-ratify",children:"Configure Ratify"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#configuring-a-verifier-to-validate-artifact's-notation-signature",children:"Configuring a verifier to validate artifact's Notation signature"})}),"\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#keymanagementprovider-configuration",children:"KeyManagementProvider Configuration"})}),"\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#pulling-acr-private-image-signature-manifest-with-rrsa",children:"Pulling ACR private image signature manifest with RRSA"})}),"\n"]}),"\n"]}),"\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"#deploying-application-in-an-ack-cluster-with-a-specified-image",children:"Deploying application in an ACK cluster with a specified image"})}),"\n"]}),"\n",(0,a.jsx)(n.h2,{id:"prerequisites",children:"Prerequisites"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsxs)(n.li,{children:["\n",(0,a.jsxs)(n.p,{children:["Already created ACK managed/dedicated cluster, version ",(0,a.jsx)(n.code,{children:"1.20"})," or later is required."]}),"\n"]}),"\n",(0,a.jsxs)(n.li,{children:["\n",(0,a.jsx)(n.p,{children:"Use Alibaba Cloud ACR to manage container images and signatures."}),"\n"]}),"\n",(0,a.jsxs)(n.li,{children:["\n",(0,a.jsx)(n.p,{children:"Use Alibaba Cloud KMS service to manage signing keys and certificates."}),"\n"]}),"\n",(0,a.jsxs)(n.li,{children:["\n",(0,a.jsxs)(n.p,{children:["Already install and use ",(0,a.jsx)(n.a,{href:"https://github.com/notaryproject/notation/releases",children:"Notation CLI"})," plug-in for image signing."]}),"\n"]}),"\n",(0,a.jsxs)(n.li,{children:["\n",(0,a.jsxs)(n.p,{children:["Already install ",(0,a.jsx)(n.a,{href:"https://github.com/AliyunContainerService/notation-alibabacloud-secret-manager/releases",children:"notation-alibabacloud-secret-manager"})," plug-in, which could sign the specified image with the keys managed in Alibaba Cloud Secrets Manager based on the plug-in specification of the Notation community."]}),"\n"]}),"\n"]}),"\n",(0,a.jsx)(n.h2,{id:"prepare-the-container-images-in-acr",children:"Prepare the container images in ACR:"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsx)(n.li,{children:(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/acr/user-guide/create-a-container-registry-enterprise-edition-instance",children:"Create an ACR Enterprise Edition instance"})}),"\n",(0,a.jsxs)(n.li,{children:["You can ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/acr/user-guide/build-images-on-container-registry-enterprise-edition-instances",children:"use an ACR EE instance to build an image"})]}),"\n",(0,a.jsxs)(n.li,{children:["The ACR EE instance supports the OCI v1.1.0 Image and Distribution specification, and
1you can use CLI tools such as ORAS to manage and distribute OCI artifacts such as image signatures and SBOMs, for details, please refer to ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/acr/use-cases/operating-with-oci-image-and-distribution-specification-v1-1-0",children:"Using OCI v1.1.0 Specification to Manage and Associate Container Images and Their Derivative Artifacts"})]}),"\n",(0,a.jsxs)(n.li,{children:["You have configured access control on the proprietary network or public network for connecting to the ACR EE instance, for details, please refer to ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/acr/user-guide/configure-network-access-control",children:"Configure network access control"}),"."]}),"\n",(0,a.jsxs)(n.li,{children:["You have obtained the password for logging to the ACR EE instance. You can reset it if you forget or lose your password, for details, please refer to ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/acr/user-guide/configure-access-credentials",children:"Configure access credentials for a Container Registry Enterprise Edition instance"}),"."]}),"\n"]}),"\n",(0,a.jsx)(n.h2,{id:"sign-acr-images",children:"Sign ACR images"}),"\n",(0,a.jsx)(n.h3,{id:"sign-with-notation-and-the-keys-managed-in-alibaba-cloud-kms-service",children:"Sign with Notation and the keys managed in Alibaba Cloud KMS service"}),"\n",(0,a.jsxs)(n.p,{children:["Alibaba Cloud Key Management Service (KMS) is a comprehensive on-cloud data encryption solution that includes KMS and Cloud Hardware Security Module. This solution helps solve concerns such as data security, key security, key management, and secret management. User can sign the specific image with the keys and certificates in ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/kms/key-management-service/support/overview-6",children:"Alibaba Cloud Secrets Manager"})," based on the plug-in specification of the Notation community."]}),"\n",(0,a.jsx)(n.h4,{id:"configuration-instructions",children:"Configuration instructions"}),"\n",(0,a.jsxs)(n.p,{children:["The notation-alibabacloud-secret-manager plugin uses the",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/kms/key-management-service/developer-reference/kms-instance-sdk",children:" KMS Instance SDK"})," and you need to meet the following prerequisites and customize the environment variables:"]}),"\n",(0,a.jsxs)(n.table,{children:[(0,a.jsx)(n.thead,{children:(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Env"})}),(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Description"})})]})}),(0,a.jsxs)(n.tbody,{children:[(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"ALIBABA_CLOUD_ACCESS_KEY_ID"}),(0,a.jsx)(n.td,{children:"Alibaba Cloud Account Access Key ID"})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"ALIBABA_CLOUD_ACCESS_KEY_SECRET"}),(0,a.jsx)(n.td,{children:"Alibaba Cloud Account Secret Access Key"})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"ALIBABA_CLOUD_KMS_INSTANCE_ENDPOINT"}),(0,a.jsx)(n.td,{children:"VPC Endpoint of the Dedicated KMS Instance, for example, kst-hzxxxxxxxxxx.cryptoservice.kms.aliyuncs.com"})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"ALIBABA_CLOUD_KMS_CLIENTKEY_FILEPATH"}),(0,a.jsx)(n.td,{children:"Local File Path of the ClientKey Credential for the Dedicated KMS Instance Application Access Point (AAP)"})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"ALIBABA_CLOUD_KMS_PASSWORD"}),(0,a.jsx)(n.td,{children:"Password for the Dedicated KMS Instance Application Access Point (AAP)"})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"ALIBABA_CLOUD_KMS_CA_FILEPATH"}),(0,a.jsx)(n.td,{children:"Local Path of the CA Certificate for the Dedicated KMS Instance"})]})]})]}),"\n",(0,a.jsxs)(n.blockquote,{children:["\n",(0,a.jsxs)(n.p,{children:["Note: The notation-alibabacloud-secret-manager plugin supports multiple credentials configuration methods. Please refer to ",(0,a.jsx)(n.a,{href:"https://aliyuncontainerservice.github.io/ack-ram-tool/#credentials",children:"credentials"})," for more configuration options."]}),"\n"]}),"\n",(0,a.jsx)(n.h4,{id:"managing-kms-instances",children:"Managing KMS instances"}),"\n",(0,a.jsxs)(n.p,{children:["User can enable and manage KMS instances from the console, please refer to the ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/kms/key-management-service/user-guide/manage-kms-instances#section-yal-idg-c4y",children:"Prerequisites"})," when enabling a KMS instance"]}),"\n",(0,a.jsx)(n.p,{children:"The plugin supports signing with two types of keys:"}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsx)(n.li,{children:"Keys are created and managed by
1KMS instances"}),"\n",(0,a.jsx)(n.li,{children:"Keys are self-signed and imported to KMS instances."}),"\n"]}),"\n",(0,a.jsx)(n.h5,{id:"option-1-using-kms-created-and-managed-keys",children:"Option 1: Using KMS created and managed keys"}),"\n",(0,a.jsx)(n.p,{children:"Users can create keys in the KMS service console by following these steps."}),"\n",(0,a.jsxs)(n.ol,{children:["\n",(0,a.jsxs)(n.li,{children:["\n",(0,a.jsx)(n.p,{children:"Log in to the Key Management Service Console, and after selecting the target region in the top menu bar, click Resources > Keys in the left navigation bar."}),"\n"]}),"\n",(0,a.jsxs)(n.li,{children:["\n",(0,a.jsx)(n.p,{children:"On the Keys page, click the Keys tab, and select the target Key Management instance for the Instance ID, and click Create Key."}),"\n"]}),"\n",(0,a.jsxs)(n.li,{children:["\n",(0,a.jsxs)(n.p,{children:["In the Create Key panel, complete the configuration settings, noting that you need to select ",(0,a.jsx)(n.strong,{children:"Asymmetric Key"})," for Key Type, ",(0,a.jsx)(n.strong,{children:"SIGN/VERIFY"})," for Key Usage, and select the ",(0,a.jsx)(n.strong,{children:"Key Specifications"})," supported by Plug-in Specification Compatibility (",(0,a.jsx)(n.code,{children:"RSA-2048"}),", ",(0,a.jsx)(n.code,{children:"RSA-3072"}),", ",(0,a.jsx)(n.code,{children:"EC-256"}),") above, and then click OK."]}),"\n"]}),"\n",(0,a.jsxs)(n.li,{children:["\n",(0,a.jsx)(n.p,{children:"Execute the following notation CLI signing command to sign the specified image in ACR repository"}),"\n"]}),"\n"]}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:"notation sign --id <keyId> --plugin alibabacloud.secretmanager.plugin $REGISTRY/$REPO:$TAG --plugin-config output_cert_dir=<dirPath>\n"})}),"\n",(0,a.jsx)(n.h5,{id:"option-2-use-self-signed-and-imported-key-material",children:"Option 2: Use self-signed and imported key material"}),"\n",(0,a.jsx)(n.p,{children:"Users can use self-signed keys and import key material into KMS instance management. As a quick start, this tutorial uses openssl to generate private keys and certificates"}),"\n",(0,a.jsxs)(n.ol,{children:["\n",(0,a.jsxs)(n.li,{children:["Create asymmetric keys in the KMS console, see ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/kms/key-management-service/user-guide/import-key-material-into-an-asymmetric-key#p-qcf-3d4-pel",children:"Step 1"}),"."]}),"\n",(0,a.jsxs)(n.li,{children:["Download a wrapping public key and an import token, see ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/kms/key-management-service/user-guide/import-key-material-into-an-asymmetric-key#p-f9p-n7u-88m",children:"Step 2"}),"."]}),"\n",(0,a.jsxs)(n.li,{children:["Encrypt the key material with the wrapping public key, see ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/kms/key-management-service/user-guide/import-key-material-into-an-asymmetric-key#p-jar-kxa-iun",children:"Step 3"}),"."]}),"\n",(0,a.jsxs)(n.li,{children:["Import the key material, see ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/kms/key-management-service/user-guide/import-key-material-into-an-asymmetric-key#p-j5c-vp9-9vd",children:"Step 4"}),"."]}),"\n"]}),"\n",(0,a.jsx)(n.h4,{id:"artifact-signing-with-notation-cli",children:"Artifact Signing with Notation CLI"}),"\n",(0,a.jsxs)(n.p,{children:["Now that we have completed all the configuration, let's start the artifact signing with Notation CLI. If you haven't downloaded the notation CLI tool, you can get it ",(0,a.jsx)(n.a,{href:"https://github.com/notaryproject/notation/releases",children:"here"}),"."]}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:"notation sign --id <keyId> --plugin alibabacloud.secretmanager.plugin <myRegistry>/<myRepo>@<digest> --plugin-config output_cert_dir=<dirPath>\n"})}),"\n",(0,a.jsxs)(n.table,{children:[(0,a.jsx)(n.thead,{children:(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Parameter"})}),(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Description"})})]})}),(0,a.jsxs)(n.tbody,{children:[(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"id"}),(0,a.jsx)(n.td,{children:"Specificed Alibaba Cloud KMS Instance ID"})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"plugin-config"}),(0,a.jsx)(n.td,{children:"Plugin customized parameters, support the following configurations: output_cert_dir\uff1aUser can use this parameter to issue the corresponding x509 certificate based on the specified KMS key during the signing process, and output it as a file to the directory specified in this parameter. ca_certs\uff1aWhen signing with the imported self-signed key material, if you also self issued an x509 certificate with the key, you can use the parameter to specify the filepath of the self-signed certificate."})]})]})]}),"\n",(0,a.jsx)(n.h2,{id:"install-ratify--gatekeeper",children:"Install Ratify & Gatekeeper"}),"\n",(0,a.jsxs)(n.h3,{id:"prerequisites-",children:["Prerequisites ",(0,a.jsx)("a",{id:"second-prerequisites"})]}),"\n",(0,a.jsxs)(n.ul,{children:["\n",(0,a.jsxs)(n.li,{children:["Already created ACK managed/dedicated cluster, version ",(0,a.jsx)(n.code,{children:"1.20"})," or later is required."]}
1),"\n",(0,a.jsxs)(n.li,{children:["Gatekeeper-based policy governance is enabled in the cluster, refer to ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/ack/ack-managed-and-ack-dedicated/security-and-compliance/configure-and-enforce-ack-pod-security-policies#section-3k8-sl8-fi0",children:"Install or upgrade policy governance components"})]}),"\n"]}),"\n",(0,a.jsx)(n.h3,{id:"install-ratify",children:"Install Ratify"}),"\n",(0,a.jsxs)(n.ol,{children:["\n",(0,a.jsxs)(n.li,{children:["Log in to the Container Services Console, select ",(0,a.jsx)(n.strong,{children:"Marketplace"})," -> ",(0,a.jsx)(n.strong,{children:"App Catalog"})," in the left navigation bar, enter ",(0,a.jsx)(n.strong,{children:"ratify"})," in the search bar, and click ",(0,a.jsx)(n.strong,{children:"Deploy"})," in the upper right corner of the application page"]}),"\n",(0,a.jsx)(n.li,{children:"Select the target cluster, namespace, and release name for the installation."}),"\n",(0,a.jsx)(n.li,{children:"Configure custom parameters on the Parameter Configuration page, the following table lists the common custom configuration options and descriptions when deploying Ratify Helm Chart, note that the notationCerts parameter needs to be set to the list of certificates returned by the KMS service during the previous signing process, for more information about the parameters of Ratify Helm Chart, please refer to the parameter list in the description page of Ratify component in ACK Marketplace."}),"\n",(0,a.jsxs)(n.li,{children:["Click the ",(0,a.jsx)(n.strong,{children:"OK"})," button to complete the installation."]}),"\n"]}),"\n",(0,a.jsxs)(n.table,{children:[(0,a.jsx)(n.thead,{children:(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Parameter"})}),(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Description"})}),(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Default"})})]})}),(0,a.jsxs)(n.tbody,{children:[(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"notationCerts"}),(0,a.jsx)(n.td,{children:"An array of public certificate/certificate chain used to create inline certstore used by Notation verifier"}),(0,a.jsx)(n.td,{children:"``"})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"serviceAccount.create"}),(0,a.jsx)(n.td,{children:"Create new dedicated Ratify service account"}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"true"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"serviceAccount.name"}),(0,a.jsx)(n.td,{children:"Name of Ratify service account to create"}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"ratify-admin"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"serviceAccount.annotations"}),(0,a.jsx)(n.td,{children:"Annotations to add to the service account"}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"{}"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"oras.authProviders.k8secretsEnabled"}),(0,a.jsx)(n.td,{children:"Enables kubernetes secrets authentication provider for registry interactions"}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"false"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"oras.authProviders.alibabacloudAcrBasicEnabled"}),(0,a.jsx)(n.td,{children:"Enables Alibaba Cloud ACR basic authentication provider"}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"false"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"oras.cache.enabled"}),(0,a.jsx)(n.td,{children:"Enables ORAS store cache for ListReferrers and GetSubjectDescriptor. TTL-based cache may cause inconsistency between cache and data source. Please disable it if strong consistency is required.operations"}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"true"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"oras.cache.ttl"}),(0,a.jsx)(n.td,{children:"Sets the ttl for ORAS store in seconds. cache"}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"10"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"alibabacloudAcrConfig.defaultInstanceId"}),(0,a.jsx)(n.td,{children:"Default instance ID of the Alibaba Cloud Registry where the target artifacts stored"}),(0,a.jsx)(n.td,{children:"``"})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"alibabacloudAcrConfig.acrInstancesConfig"}),(0,a.jsxs)(n.td,{children:["When images need to be pulled from multiple instances of Aliababa Cloud Registry, the instanceName and instanceId of the instances need to be defined separately in the list, e.g. ",(0,a.jsx)("br",{}),"acrInstancesConfig:",(0,a.jsx)("br",{})," - instanceName: name1",(0,a.jsx)("br",{})," instanceId: cri-xxx1",(0,a.jsx)("br",{})," - instanceName: name2",(0,a.jsx)("br",{})," instanceId: cri-xxx2"]}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"[]"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"upgradeCRDs.enabled"}),(0,a.jsx)(n.td,{children:"Enable/disable Ratify CRD upgrades as pre-install chart hooks"}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"true"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"featureFlags.RATIFY_CERT_ROTATION"}),(0,a.jsx)(n.td,{children:"Enables/disables tls certificate rotation"}),(0,a.jsx)(n.td,{children:(0,a.jsx)(n.code,{children:"false"})})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"notationCert"}),(0,a.jsxs)(n.td,{children:[(0,a.jsx)(n.strong,{children:"DEPRECATED"})," Please switch to ",(0,a.jsx)(n.code,{children:"notationCerts"})," to specify an array of verification certificates. Public certificate/certificate chain used to create inline cert
1store used by Notation verifier."]}),(0,a.jsx)(n.td,{})]})]})]}),"\n",(0,a.jsx)(n.p,{children:(0,a.jsx)(n.img,{alt:"ratify-alibabacloud-marketplace",src:i(83783).A+"",width:"2588",height:"1432"})}),"\n",(0,a.jsx)(n.h3,{id:"deploy-ratifyverification-policy-instance",children:"Deploy RatifyVerification policy instance"}),"\n",(0,a.jsxs)(n.ol,{children:["\n",(0,a.jsxs)(n.li,{children:["Select ",(0,a.jsx)(n.strong,{children:"Security -> Policy Governance"})," in the left navigation bar, and refer to the ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/ack/ack-managed-and-ack-dedicated/security-and-compliance/configure-and-enforce-ack-pod-security-policies#88777ff753f72",children:"Work with the policy governance feature"})," to deploy the policy RatifyVerification, which is based on Gatekeeper's external data mechanism to invoke the Ratify as service provider."]}),"\n",(0,a.jsx)(n.li,{children:"Run the following kubectl command to see if the constrainttemplate and constraint instances corresponding to the Gatekeeper policy have been deployed in the cluster, or you can view the current status of the RatifyVerification policy on the Policy Governance page of the console:"}),"\n"]}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:"kubectl get constrainttemplate ratifyverification\n\nkubectl get constraint | grep ratify-constraint\n"})}),"\n",(0,a.jsx)(n.p,{children:(0,a.jsx)(n.img,{alt:"alibabacloud-policy-governance",src:i(16761).A+"",width:"2706",height:"1408"})}),"\n",(0,a.jsx)(n.h2,{id:"configure-ratify",children:"Configure Ratify"}),"\n",(0,a.jsx)(n.h3,{id:"configuring-a-verifier-to-validate-artifacts-notation-signature",children:"Configuring a verifier to validate artifact's Notation signature"}),"\n",(0,a.jsxs)(n.p,{children:["Ratify provides a variety of built-in and external verifier plug-ins. Users must define the ",(0,a.jsx)(n.code,{children:"name"})," and ",(0,a.jsx)(n.code,{children:"artifactType"})," fields in the verifier to specify the type of artifact that the verifier will process. verifiers support either cluster-wide resources(using the kind ",(0,a.jsx)(n.code,{children:"Verifier"}),") or namespaced resources(using the kind ",(0,a.jsx)(n.code,{children:"NamespacedVerifier"}),"). For more information on the verifier, please refer to the official ",(0,a.jsx)(n.a,{href:"https://ratify.dev/docs/reference/custom%20resources/verifiers/",children:"Ratify documentation"}),"."]}),"\n",(0,a.jsx)(n.p,{children:"After installing Ratify with the default configuration, the following notation verifier instance will be created in the cluster, and you can configure the specific trustPolicyDoc policy according to the actual usage requirements:"}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: Verifier\nmetadata:\n name: verifier-notation\nspec:\n artifactTypes: application/vnd.cncf.notary.signature\n name: notation\n parameters:\n trustPolicyDoc:\n trustPolicies:\n - name: default\n registryScopes:\n - '*'\n signatureVerification:\n level: strict\n trustStores:\n - ca:certs\n trustedIdentities:\n - '*'\n version: \"1.0\"\n verificationCertStores:\n certs:\n - ratify-notation-inline-cert\n version: 1.0.0\nstatus:\n issuccess: true\n"})}),"\n",(0,a.jsx)(n.h3,{id:"keymanagementprovider-configuration",children:"KeyManagementProvider Configuration"}),"\n",(0,a.jsx)(n.p,{children:"Ratify provides CRD KeyManagementProvider for defining keys or certificates used by verifiers for signature verification in different scenarios. Users can customize the KeyManagementProvider instances according to different signature verification requirements and define the public keys or x.509 certificates in the CR. Notation and Cosign verifiers can consume KeyManagementProvider resources to use during signature verification."}),"\n",(0,a.jsxs)(n.p,{children:["Key Management Provider can be defined as cluster-wide resources(using the kind ",(0,a.jsx)(n.code,{children:"KeyManagementProvider"}),") or namespaced resources(using the kind ",(0,a.jsx)(n.code,{children:"NamespacedKeyManagementProvider"}),"). For more information about KeyManagementProvider (KMP), please refer to ",(0,a.jsx)(n.a,{href:"https://ratify.dev/docs/reference/custom%20resources/key-management-providers/",children:"documentation"}),"."]}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: KeyManagementProvider\nmetadata:\n name: ratify-notation-inline-cert\nspec:\n parameters:\n contentType: certificate\n value: |\n -----BEGIN CERTIFICATE-----\n XXXXXX\n XXXXXX\n XXXXXX\n -----END CERTIFICATE-----\n type: inline\n"})}),"\n",(0,a.jsx)(n.h3,{id:"pulling-acr-private-image-signature-manifest-with-rrsa",children:"Pulling ACR private image signature manifest with RRSA"}),"\n",(0,a.jsxs)(n.p,{children:["Ratify provides Store for discovering and obtaining metadata of the associated type in the subject field of the OCI v1.1 specification. Users can configure the relevant configurations for c
1onnecting to the ACR private repository in the ",(0,a.jsx)(n.code,{children:"authProvider"})," field of the default oras store instance, where the ",(0,a.jsx)(n.code,{children:"name"})," field needs to be specified as ",(0,a.jsx)(n.strong,{children:"alibabacloudAcrBasic"}),", ",(0,a.jsx)(n.code,{children:"acrInstancesConfig"})," field supports configuration of multiple ACR repository instances. Ratify will try to get the repository's corresponding instance ID from the list of mapping relationships defined in ",(0,a.jsx)(n.code,{children:"acrInstancesConfig"}),"according to the given workload image name, and if no one found, Ratify will use the instance ID value specified in the ",(0,a.jsx)(n.code,{children:"defaultInstanceId"})," field and then obtains a",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/acr/developer-reference/api-cr-2018-12-01-getauthorizationtoken",children:" temporary username and token"})," for logging in to the ACR repository instance based on the ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/sdk/developer-reference/v2-manage-python-access-credentials",children:"Alibaba Cloud Credentials"})," configured in the environment."]}),"\n",(0,a.jsx)(n.p,{children:"An example configuration is shown below:"}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:"apiVersion: config.ratify.deislabs.io/v1beta1\nkind: Store\
1nmetadata:\n name: store-oras\nspec:\n name: oras\n parameters:\n authProvider:\n acrInstancesConfig:\n - instanceName: name1\n instanceId: cri-aaaaaaaaaaaa\n - instanceName: name2\n instanceId: cri-bbbbbbbbbbbb\n defaultInstanceId: cri-ccccccccc\n name: alibabacloudAcrBasic\n"})}),"\n",(0,a.jsxs)(n.table,{children:[(0,a.jsx)(n.thead,{children:(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Parameter"})}),(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Required"})}),(0,a.jsx)(n.th,{children:(0,a.jsx)(n.strong,{children:"Description"})})]})}),(0,a.jsxs)(n.tbody,{children:[(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"name"}),(0,a.jsx)(n.td,{children:"N"}),(0,a.jsx)(n.td,{children:"The authProvider name for ACR is fixed to alibabacloudAcrBasic"})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"acrInstancesConfig"}),(0,a.jsx)(n.td,{children:"N"}),(0,a.jsxs)(n.td,{children:["When images need to be pulled from multiple instances of Aliababa Cloud Registry, the instanceName and instanceId of the instances need to be defined separately in the list, e.g. ",(0,a.jsx)("br",{}),"acrInstancesConfig:",(0,a.jsx)("br",{})," - instanceName: name1",(0,a.jsx)("br",{})," instanceId: cri-xxx1",(0,a.jsx)("br",{})," - instanceName: name2",(0,a.jsx)("br",{})," instanceId: cri-xxx2"]})]}),(0,a.jsxs)(n.tr,{children:[(0,a.jsx)(n.td,{children:"defaultInstanceId"}),(0,a.jsx)(n.td,{children:"Y"}),(0,a.jsx)(n.td,{children:"Default instance ID of the Alibaba Cloud Registry where the target artifacts stored"})]})]})]}),"\n",(0,a.jsx)(n.p,{children:"An example of the parameter configuration snippet that should be configured in Marketplace is shown below:"}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:"alibabacloudAcrConfig:\n defaultInstanceId: cri-ccccccccc\n acrInstancesConfig:\n - name1: cri-aaaaaaaaaaaa\n - name2: cri-bbbbbbbbbbbb\n\noras:\n useHttp: false\n authProviders:\n k8secretsEnabled: false\n alibabacloudAcrBasicEnabled: true\n"})}),"\n",(0,a.jsxs)(n.p,{children:["When using the authProvider of type ",(0,a.jsx)(n.code,{children:"alibabacloudAcrBasic"}),", Ratify supports pulling signature manifest from the ACR private repository with RRSA (RAM Roles for Service Accounts). The summary of the configuration process is as follows. For more detailed configuration and usage instructions, please refer to ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/ack/serverless-kubernetes/user-guide/use-rrsa-to-authorize-pods-to-access-different-cloud-services#section-rmr-eeh-878",children:"Work with RRSA"}),":"]}),"\n",(0,a.jsxs)(n.ol,{children:["\n",(0,a.jsxs)(n.li,{children:["Install the ",(0,a.jsx)(n.a,{href:"https://www.alibabacloud.com/help/en/ack/product-overview/ack-pod-identity-webhook#task-2295049",children:"ack-pod-identity-webhook"})," component on the Operations -> Add-ons page of the specified cluster."]}),"\n",(0,a.jsxs)(n.li,{children:["Create the specified RAM role, and modify the trust policy of the RAM role based on the following template, or you can use the ",(0,a.jsx)(n.a,{href:"https://github.com/AliyunContainerService/ack-ram-tool",children:"ack-ram-tool"})," CLI tool to complete the automated configuration."]}),"\n"]}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:'{\n "Action": "sts:AssumeRole",\n "Condition": {\n "StringEquals": {\n "oidc:aud": "sts.aliyuncs.com",\n "oidc:iss": "<oidc_issuer_url>",\n "oidc:sub": "system:serviceaccount:<namespace>:<service_account>"\n }\n },\n "Effect": "Allow",\n "Principal": {\n "Federated": [\n "<oidc_provider_arn>"\n ]\n }\n}\n'})}),"\n",(0,a.jsxs)(n.ol,{start:"3",children:["\n",(0,a.jsx)(n.li,{children:"Authorize the above RAM roles"}),"\n",(0,a.jsx)(n.li,{children:"Create a serviceaccount before deploying Ratify, and set the serviceaccount annotations and the namespace labels where Ratify will be deployed:"}),"\n"]}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:"---\napiVersion: v1\nkind: Namespace\nmetadata:\n name: ratify #Specify the name of the namespace\n labels:\n pod-identity.alibabacloud.com/injection: 'on'\n\n---\napiVersion: v1\nkind: ServiceAccount\nmetadata:\n name: ratify-sa #Specify the name of the serviceaccount\n namespace: ratify #Specify the name of the namespace\n annotations:\n pod-identity.alibabacloud.com/role-name: ratify-role #The RAM Role name created in step 2\n\n---\n"})}),"\n",(0,a.jsxs)(n.ol,{start:"5",children:["\n",(0,a.jsxs)(n.li,{children:["After deploying Ratify, you can check whether the Env in the Pod instance template of Ratify has been injected with the specified environment variables: ",(0,a.jsx)(n.code,{children:"ALIBABA_CLOUD_ROLE_ARN"}),", ",(0,a.jsx)(n.code,{children:"ALIBABA_CLOUD_OIDC_PROVIDER_ARN"})," and ",(0,a.jsx)(n.code,{children:"ALIBABABA_CLOUD_OIDC_TOKEN_FILE"}),"."]}),"\n"]}),"\n",(0,a.jsx)(n.h2,{id:"deploying-application-in-an-ack-cluster-with-a-specified-image",children:"Deploying application in an ACK cluster with a specified image"}),"\n",(0,a.jsx)(n.p,{children:"After completing the above deployment and configuration, try to deploy the application in the cluster. When deploying a signed image, the workload was verified successfully and deployed to the target cluster. When deploying an unsigned image, you can check if Ratify has denied the deployment. You can view the Ratify pod logs for details."}),"\n",(0,a.jsx)(n.pre,{children:(0,a.jsx)(n.code,{className:"language-plain",children:"kubectl logs -l app.kubernetes.io/name=ratify --tail=100 -n ratify-service\n"})})]})}function h(e={}){const{wrapper:n}={...(0,s.R)(),...e.components};return n?(0,a.jsx)(n,{...e,children:(0,a.jsx)(d,{...e})}):d(e)}},83783(e,n,i){i.d(n,{A:()=>t});const t=i.p+"assets/images/ratify-alibabacloud-marketplace-efa95ddb8fbb8129e5b68f27b63c77a7.png"}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.