1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[1208],{28453(e,t,r){r.d(t,{R:()=>a,x:()=>o});var n=r(96540);const i={},s=n.createContext(i);function a(e){const t=n.useContext(s);return n.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function o(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(i):e.components||i:a(e.components),n.createElement(s.Provider,{value:t},e.children)}},36117(e,t,r){r.r(t),r.d(t,{assets:()=>l,contentTitle:()=>o,default:()=>f,frontMatter:()=>a,metadata:()=>n,toc:()=>c});const n=JSON.parse('{"id":"reference/rego-templates","title":"Rego Templates","description":"Rego Policy is much more powerful than Config Poliy, but it\'s also more complex. To make it easier to write Rego Policy, we provide a few templates for common use cases.","source":"@site/versioned_docs/version-1.4/reference/rego-templates.md","sourceDirName":"reference","slug":"/reference/rego-templates","permalink":"/docs/reference/rego-templates","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/versioned_docs/version-1.4/reference/rego-templates.md","tags":[],"version":"1.4","frontMatter":{},"sidebar":"tutorialSidebar","previous":{"title":"Store/Verifier Providers","permalink":"/docs/reference/providers"},"next":{"title":"Security","permalink":"/docs/reference/security"}}');var i=r(74848),s=r(28453);const a={},o="Rego Templates",l={},c=[{value:"Rego Policy Requirements",id:"rego-policy-requirements",level:2},{value:"Examples",id:"examples",level:2},{value:"Example 1",id:"example-1",level:3},{value:"Example 2",id:"example-2",level:3},{value:"Example 3",id:"example-3",level:3}];function p(e){const t={a:"a",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",ol:"ol",p:"p",pre:"pre",...(0,s.R)(),...e.components};return(0,i.jsxs)(i.Fragment,{children:[(0,i.jsx)(t.header,{children:(0,i.jsx)(t.h1,{id:"rego-templates",children:"Rego Templates"})}),"\n",(0,i.jsx)(t.p,{children:"Rego Policy is much more powerful than Config Poliy, but it's also more complex. To make it easier to write Rego Policy, we provide a few templates for common use cases."}),"\n",(0,i.jsx)(t.h2,{id:"rego-policy-requirements",children:"Rego Policy Requirements"}),"\n",(0,i.jsxs)(t.p,{children:["There are some special requirements on Rego policy used by Ratify. The package declaration MUST be ",(0,i.jsx)(t.code,{children:"package ratify.policy"}),", and there MUST be a boolean variable ",(0,i.jsx)(t.code,{children:"valid"})," declared. The variable ",(0,i.jsx)(t.code,{children:"valid"})," MUST be set to ",(0,i.jsx)(t.code,{children:"true"})," if the overall verification is successful, and ",(0,i.jsx)(t.code,{children:"false"})," otherwise. The ",(0,i.jsx)(t.code,{children:"input"})," is a Json object that contains the verification results of all reference artifacts."]}),"\n",(0,i.jsx)(t.h2,{id:"examples",children:"Examples"}),"\n",(0,i.jsxs)(t.p,{children:["Here is a sample of the ",(0,i.jsx)(t.code,{children:"input"}),":"]}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{className:"language-json",children:'{\n "verifierReports": [\n {\n "artifactType": "org.example.sbom.v0",\n "subject": "test.azurecr.io/test/hello-world:v1",\n "referenceDigest": "test.azurecr.io/test/hello-world@sha256:22222",\n "verifierReports": [\n {\n "verifierName": "sbom",\n "verifierType": "sbom-verifier",\n "isSuccess": false,\n "message": "error msg",\n "extensions": {}\n },\n {\n "verifierName": "schemavalidator",\n "verifierType": "verifier-schemavalidator",\n "isSuccess": true,\n "message": "",\n "extensions": {}\n }\n ],\n "nestedReports": [\n {\n "artifactType": "application/vnd.cncf.notary.signature",\n "subject": "test.azurecr.io/test/hello-world@sha256:123",\n "referenceDigest": "test.azurecr.io/test/hello-world@sha256:33333",\n "verifierReports": [\n {\n "verifierName": "notation",\n "verifierType": "verifier-notation",\n "isSuccess": true,\n "message": "",\n "extensions": {\n "Issuer": "testIssuer",\n "SN": "testSN"\n }\n }\n ],\n "nestedReports": []\n }\n ]\n } \n ]\n}\n'})}),"\n",(0,i.jsx)(t.h3,{id:"example-1",children:"Example 1"}),"\n",(0,i.jsxs)(t.p,{children:["Require all reference artifacts associated with subject image to be verify successfully.\nCheck equivalent ",(0,i.jsx)(t.a,{href:"/docs/reference/providers#config-policy-examples",children:"Config Policy"})]}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{className:"language-rego",children:'package ratify.policy\ndefault valid := false\nvalid {\n not failed_verify(input)\n}\nfailed_verify(reports) {\n [path, value] := walk(reports)\n value == false\n path[c
1ount(path) - 1] == "isSuccess"\n}\nfailed_verify(reports) {\n [path, value] := walk(reports)\n path[count(path) - 1] == "verifierReports"\n count(value) == 0\n}\n'})}),"\n",(0,i.jsx)(t.h3,{id:"example-2",children:"Example 2"}),"\n",(0,i.jsxs)(t.p,{children:["Require at least one reference artifact of the same type to verify succesfully. (relaxes the default policy to 'any').\nCheck equivalent ",(0,i.jsx)(t.a,{href:"/docs/reference/providers#config-policy-examples",children:"Config Policy"})]}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{className:"language-rego",children:'package ratify.policy\ndefault valid := false\nvalid if {\n\tnot failed_verify(input)\n}\nfailed_verify(reports) if {\n\tnewReports := {"nestedReports": reports.verifierReports}\n\thas_subject_failed_verify(newReports)\n}\nhas_subject_failed_verify(nestedReports) if {\n\t[path, value] := walk(nestedReports)\n\tnot artifact_type_pass_verify(value)\n\tpath[count(path) - 1] == "nestedReports"\n}\n# at least one artifact of the same type passed verification\nartifact_type_pass_verify(nestedReports) if {\n\tcount_artifact_type(nestedReports) == count_successful_artifact_type(nestedReports)\n}\ncount_artifact_type(nestedReports) := number if {\n\tartifact_types := {x |\n\t\tsome i\n\t\tx := nestedReports[i].artifactType\n\t}\n\tnumber := count(artifact_types)\n}\ncount_successful_artifact_type(nestedReports) := number if {\n\tartifact_types := {x |\n\t\tsome i\n\t\tx := nestedReports[i].artifactType\n\t\tartifact_pass_verify(nestedReports[i].verifierReports)\n\t}\n\tnumber := count(artifact_types)\n}\n# an artifact has at least one successful report\nartifact_pass_verify(verifierReports) if {\n\tverifierReports[_].isSuccess == true\n}\n# should be at least one verifier report that is successful\nfailed_verify(reports) if {\n\t[path, value] := walk(reports)\n\tpath[count(path) - 1] == "verifierReports"\n\tcount(value) == 0\n}\n'})}),"\n",(0,i.jsx)(t.h3,{id:"example-3",children:"Example 3"}),"\n",(0,i.jsx)(t.p,{children:"I trust multiple identities, and need to find at least one valid signature signed by any identity."}),"\n",(0,i.jsx)(t.p,{children:"Prerequisites:"}),"\n",(0,i.jsxs)(t.ol,{children:["\n",(0,i.jsx)(t.li,{children:"The artifact is only signed by Notation, there might be a few signatures attached to the artifact."}),"\n",(0,i.jsx)(t.li,{children:"Users has configured different Notation verfiers, and each verifier has a different identity."}),"\n"]}),"\n",(0,i.jsx)(t.pre,{children:(0,i.jsx)(t.code,{className:"language-rego",children:'package ratify.policy\nimport future.keywords.in\ndefault valid := false\nvalid {\n not failed_verify(input)\n}\n# Fail the verification if no signatures are signed by trusted identity.\nfailed_verify(reports) {\n not has_trusted_signature(reports.verifierReports)\n}\n# Fail the verification if no signatures are present.\nfailed_verify(reports) {\n [path, value] := walk(reports)\n path[count(path) - 1] == "verifierReports"\n count(value) == 0\n}\n# There is a signature signed by trusted identity.\nhas_trusted_signature(reports) {\n\tsome report in reports\n report.artifactType == "application/vnd.cncf.notary.signature"\n pass_validation(report.verifierReports)\n}\npass_validation(reports) {\n\tsome report in reports\n report.isSuccess == true\n}\n'})})]})}function f(e={}){const{wrapper:t}={...(0,s.R)(),...e.components};return t?(0,i.jsx)(t,{...e,children:(0,i.jsx)(p,{...e})}):p(e)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.