GithubHelp home page GithubHelp logo

Container Image Policy about enhancements HOT 18 CLOSED

philips avatar philips commented on July 18, 2024 2
Container Image Policy

from enhancements.

Comments (18)

idvoretskyi avatar idvoretskyi commented on July 18, 2024

cc @kubernetes/sig-auth

from enhancements.

erictune avatar erictune commented on July 18, 2024

@soltysh you were interested in this issue too.

from enhancements.

soltysh avatar soltysh commented on July 18, 2024

@erictune thx

from enhancements.

philips avatar philips commented on July 18, 2024

Status update: design proposal is merged: kubernetes/kubernetes#27129

from enhancements.

philips avatar philips commented on July 18, 2024

Also, @ecordell intends to work on the code for this feature now that the code has been merged. @Q-Lee @erictune @alex-mohr

from enhancements.

philips avatar philips commented on July 18, 2024

Updated the PRs for the current implementation kubernetes/kubernetes#30631 and API changes kubernetes/kubernetes#30241. Looks likely to land for v1.4. @Q-Lee and @ecordell how are y'all feeling?

from enhancements.

Q-Lee avatar Q-Lee commented on July 18, 2024

@philips It's looking good.

@philips The API is being tested in the merge queue atm, and the implementation is close to an lgtm. I'm setting up a test for gce/gci on top of ecordell's changes atm.

from enhancements.

ecordell avatar ecordell commented on July 18, 2024

@philips API is in! I'm hopeful the implementation will go through today

from enhancements.

ecordell avatar ecordell commented on July 18, 2024

kubernetes/kubernetes#30631 is merged

from enhancements.

janetkuo avatar janetkuo commented on July 18, 2024

@philips Are the docs ready? Please update the docs in https://github.com/kubernetes/kubernetes.github.io, and then add PR numbers and check the docs box in the issue description

from enhancements.

jaredbhatti avatar jaredbhatti commented on July 18, 2024

Ping. Any update on docs?

from enhancements.

Q-Lee avatar Q-Lee commented on July 18, 2024

@philips @ecordell What are the plans for the docs with this?

from enhancements.

ecordell avatar ecordell commented on July 18, 2024

@Q-Lee I'll work on them and have a PR soon

from enhancements.

ecordell avatar ecordell commented on July 18, 2024

Docs PR: kubernetes/website#1188

from enhancements.

ecordell avatar ecordell commented on July 18, 2024

For making image policy decisions, it's important that the backend be able to resolve tags to digests so that downstream services see a consistent view of approved images.

I've started sketching the changes here (no tests or codegen):

kubernetes/kubernetes@master...ecordell:imagereviewwebhook-digest

There is some overlap between this and kubernetes/community#132, but mutation is not in the scope of that proposal (simply planned for later).

from enhancements.

fejta-bot avatar fejta-bot commented on July 18, 2024

Issues go stale after 90d of inactivity.
Mark the issue as fresh with /remove-lifecycle stale.
Stale issues rot after an additional 30d of inactivity and eventually close.

Prevent issues from auto-closing with an /lifecycle frozen comment.

If this issue is safe to close now please do so with /close.

Send feedback to sig-testing, kubernetes/test-infra and/or @fejta.
/lifecycle stale

from enhancements.

erictune avatar erictune commented on July 18, 2024

I recommend further features requests for image policy first be attempted using validating webhooks.

from enhancements.

saschagrunert avatar saschagrunert commented on July 18, 2024

Hey folks, what is the future plan for this feature? I see that it may fit into a native sigstore container image validation support for Kubernetes.

from enhancements.

Related Issues (20)

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.