1"use strict";(globalThis.webpackChunkratify=globalThis.webpackChunkratify||[]).push([[414],{28453(e,i,t){t.d(i,{R:()=>c,x:()=>l});var n=t(96540);const r={},s=n.createContext(r);function c(e){const i=n.useContext(s);return n.useMemo(function(){return"function"==typeof e?e(i):{...i,...e}},[i,e])}function l(e){let i;return i=e.disableParentContext?"function"==typeof e.components?e.components(r):e.components||r:c(e.components),n.createElement(s.Provider,{value:i},e.children)}},41099(e,i,t){t.r(i),t.d(i,{assets:()=>a,contentTitle:()=>l,default:()=>p,frontMatter:()=>c,metadata:()=>n,toc:()=>o});const n=JSON.parse('{"id":"reference/crds/policies","title":"policies","description":"A Policy resource defines a policy evaluating the verification results for a subject.","source":"@site/versioned_docs/version-1.1/reference/crds/policies.md","sourceDirName":"reference/crds","slug":"/reference/crds/policies","permalink":"/docs/1.1/reference/crds/policies","draft":false,"unlisted":false,"editUrl":"https://github.com/ratify-project/ratify-web/blob/main/versioned_docs/version-1.1/reference/crds/policies.md","tags":[],"version":"1.1","frontMatter":{},"sidebar":"tutorialSidebar","previous":{"title":"certificate-stores","permalink":"/docs/1.1/reference/crds/certificate-stores"},"next":{"title":"stores","permalink":"/docs/1.1/reference/crds/stores"}}');var r=t(74848),s=t(28453);const c={},l=void 0,a={},o=[{value:"configpolicy",id:"configpolicy",level:2},{value:"regopolicy",id:"regopolicy",level:2}];function d(e){const i={a:"a",code:"code",h2:"h2",p:"p",pre:"pre",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,s.R)(),...e.components};return(0,r.jsxs)(r.Fragment,{children:[(0,r.jsxs)(i.p,{children:["A ",(0,r.jsx)(i.code,{children:"Policy"})," resource defines a policy evaluating the verification results for a subject."]}),"\n",(0,r.jsxs)(i.p,{children:["View more CRD samples ",(0,r.jsx)(i.a,{href:"https://github.com/ratify-project/ratify/tree/main/config/samples/policy",children:"here"}),". The ",(0,r.jsx)(i.code,{children:"metadata.name"})," MUST be set to ",(0,r.jsx)(i.code,{children:"ratify-policy"})," for Ratify to apply. Ratify will ensure that only one policy is actively under evaluation by limiting the ",(0,r.jsx)(i.code,{children:"metadata.name"})," to ",(0,r.jsx)(i.code,{children:"ratify-policy"}),". Common properties:"]}),"\n",(0,r.jsx)(i.pre,{children:(0,r.jsx)(i.code,{className:"language-yml",children:'apiVersion: config.ratify.deislabs.io/v1beta1\nkind: Policy\nmetadata:\n name: "ratify-policy"\nspec:\n type: "rego-policy"\n parameters: required. Parameters specific to this policy\n'})}),"\n",(0,r.jsxs)(i.p,{children:["Note: ",(0,r.jsx)(i.code,{children:"spec.type"})," MUST be ",(0,r.jsx)(i.code,{children:"config-policy"})," or ",(0,r.jsx)(i.code,{children:"rego-policy"})," per the usage."]}),"\n",(0,r.jsx)(i.h2,{id:"configpolicy",children:"configpolicy"}),"\n",(0,r.jsx)(i.p,{children:"Sample spec:"}),"\n",(0,r.jsx)(i.pre,{children:(0,r.jsx)(i.code,{className:"language-yml",children:'apiVersion: config.ratify.deislabs.io/v1beta1\nkind: Policy\nmetadata:\n name: "ratify-policy"\nspec:\n spec: "config-policy"\n parameters:\n artifactVerificationPolicies:\n "application/vnd.cncf.notary.signature": "any"\n default: "any"\n'})}),"\n",(0,r.jsxs)(i.table,{children:[(0,r.jsx)(i.thead,{children:(0,r.jsxs)(i.tr,{children:[(0,r.jsx)(i.th,{children:"Name"}),(0,r.jsx)(i.th,{children:"Required"}),(0,r.jsx)(i.th,{children:"Description"}),(0,r.jsx)(i.th,{children:"Default Value"})]})}),(0,r.jsxs)(i.tbody,{children:[(0,r.jsxs)(i.tr,{children:[(0,r.jsx)(i.td,{children:"artifactVerificationPolicies"}),(0,r.jsx)(i.td,{children:"yes"}),(0,r.jsx)(i.td,{children:"Map of artifact type to policy; each entry in the map's policy must be satisfied for Ratify to return true"}),(0,r.jsx)(i.td,{children:'""'})]}),(0,r.jsxs)(i.tr,{children:[(0,r.jsx)(i.td,{children:"default"}),(0,r.jsx)(i.td,{children:"no"}),(0,r.jsxs)(i.td,{children:["The ",(0,r.jsx)(i.code,{children:"default"})," policy applies to unspecified artifact types."]}),(0,r.jsx)(i.td,{children:'"all"'})]}),(0,r.jsxs)(i.tr,{children:[(0,r.jsx)(i.td,{children:(0,r.jsx)(i.co
1de,{children:"application/vnd.cncf.notary.signature"})}),(0,r.jsx)(i.td,{children:"no"}),(0,r.jsx)(i.td,{children:"It could be any artifact type that is supported by Ratify."}),(0,r.jsxs)(i.td,{children:["There is no default value, users must specify ",(0,r.jsx)(i.code,{children:"any"})," or ",(0,r.jsx)(i.code,{children:"all"})]})]})]})]}),"\n",(0,r.jsx)(i.h2,{id:"regopolicy",children:"regopolicy"}),"\n",(0,r.jsx)(i.p,{children:"Sample spec:"}),"\n",(0,r.jsx)(i.pre,{children:(0,r.jsx)(i.code,{className:"language-yml",children:'apiVersion: config.ratify.deislabs.io/v1beta1\nkind: Policy\nmetadata:\n name: "ratify-policy"\nspec:\n spec: "rego-policy"\n parameters:\n passthroughEnabled: false\n policy: |\n package ratify.policy\n\n default valid := false\n\n # all artifacts MUST be valid\n valid {\n not failed_verify(input)\n }\n\n # all reports MUST pass the verification\n failed_verify(reports) {\n [path, value] := walk(reports)\n value == false\n path[count(path) - 1] == "isSuccess"\n }\n\n # each artifact MUST have at least one report\n failed_verify(reports) {\n [path, value] := walk(reports)\n path[count(path) - 1] == "verifierReports"\n count(value) == 0\n }\n'})}),"\n",(0,r.jsxs)(i.table,{children:[(0,r.jsx)(i.thead,{children:(0,r.jsxs)(i.tr,{children:[(0,r.jsx)(i.th,{children:"Name"}),(0,r.jsx)(i.th,{children:"Required"}),(0,r.jsx)(i.th,{children:"Description"}),(0,r.jsx)(i.th,{children:"Default Value"})]})}),(0,r.jsxs)(i.tbody,{children:[(0,r.jsxs)(i.tr,{children:[(0,r.jsx)(i.td,{children:"passthroughEnabled"}),(0,r.jsx)(i.td,{children:"no"}),(0,r.jsx)(i.td,{children:"If set to true, Ratify will NOT make the decision but pass verifier reports to Gatekeeper."}),(0,r.jsx)(i.td,{children:"false"})]}),(0,r.jsxs)(i.tr,{children:[(0,r.jsx)(i.td,{children:"policy"}),(0,r.jsx)(i.td,{children:"no"}),(0,r.jsx)(i.td,{children:"The policy language that defines the policy."}),(0,r.jsx)(i.td,{children:'""'})]}),(0,r.jsxs)(i.tr,{children:[(0,r.jsx)(i.td,{children:"policyPath"}),(0,r.jsx)(i.td,{children:"no"}),(0,r.jsx)(i.td,{children:"The path to the policy file if policy is mounted as a volume"}),(0,r.jsx)(i.td,{children:'""'})]})]})]}),"\n",(0,r.jsxs)(i.p,{children:["Note: Users MUST provide at least one of ",(0,r.jsx)(i.code,{children:"policy"})," and ",(0,r.jsx)(i.code,{children:"policyPath"}),". If both are specified, ",(0,r.jsx)(i.code,{children:"policy"})," will be used."]})]})}function p(e={}){const{wrapper:i}={...(0,s.R)(),...e.components};return i?(0,r.jsx)(i,{...e,children:(0,r.jsx)(d,{...e})}):d(e)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.