-
Notifications
You must be signed in to change notification settings - Fork 11
/
trustpolicy.yaml
37 lines (37 loc) · 960 Bytes
/
trustpolicy.yaml
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
apiVersion: notation.nirmata.io/v1alpha1
kind: TrustPolicy
metadata:
name: tp-test-notation
spec:
version: '1.0'
trustPolicyName: tp-test-notation
trustPolicies:
- name: aws-signer-tp
registryScopes:
- "844333597536.dkr.ecr.us-west-2.amazonaws.com/kyverno-demo"
signatureVerification:
level: strict
override: {}
trustStores:
- signingAuthority:aws-signer-ts
trustedIdentities:
- "arn:aws:signer:us-west-2:844333597536:/signing-profiles/kyvernodemo"
---
apiVersion: notation.nirmata.io/v1alpha1
kind: TrustPolicy
metadata:
name: tp-test-notation-fail
spec:
version: '1.0'
trustPolicyName: tp-test-notation-fail
trustPolicies:
- name: aws-signer-tp
registryScopes:
- "*"
signatureVerification:
level: strict
override: {}
trustStores:
- signingAuthority:aws-signer-ts-fail
trustedIdentities:
- "arn:aws:signer:us-west-2:844333597536:/signing-profiles/kyvernodemo"