Skip to content
About

Decide whether the workload may enter

The Kubernetes API boundary sees the workload an actor is requesting now. It must not assume that a green CI run somewhere authorized that request. Kyverno supplies the local image contract: a matching image must have a valid trusted signature and both required attestations before it is admitted.

Allow and deny within the policy scope
Allow and deny within the policy scopeUnmatched image registries or excluded namespaces do not gain protection from this policy. Matching Pod images must be digest pinned and have required signature and attestations. Configured issuer, subject and selected provenance fields must satisfy the policy. A trust mismatch denies a matching request; success permits admission, not permanent safety.Scope match?Digest & claimsTrust matches?Allow or deny
Enforce mode applies to matched images and namespaces; outage failurePolicy is a separate operational question.
  1. Unmatched image registries or excluded namespaces do not gain protection from this policy.
  2. Matching Pod images must be digest pinned and have required signature and attestations.
  3. Configured issuer, subject and selected provenance fields must satisfy the policy.
  4. A trust mismatch denies a matching request; success permits admission, not permanent safety.

Solid arrows indicate the stated handoff, not a claim of independent trust. Optional relationships are described in the text equivalent. Historical components are labeled in the caption.

The ClusterPolicy matches Pods outside kube-system, kyverno, argocd, crossplane-system, and cert-manager. Each image verification rule matches:

europe-west1-docker.pkg.dev/valiant-house-502004-k2/supply-chain-security/*

“ClusterPolicy” describes the Kubernetes resource’s reach, not universal image protection. An image outside that prefix does not receive this rule’s signature/attestation contract. An excluded namespace bypasses these rule matches. Falco and other nonexcluded namespaces are not automatically rejected for unrelated registry images; image matching still applies.

All three rules set required: true, verifyDigest: true, and mutateDigest: false. The chart already supplies the digest; the policy is not documented as a tag-to-digest mutator. It fetches statements from a separate historical metadata repository and requires the accepted signing workflow subject, GitHub issuer, and configured Rekor trust.

Rule 1 requires a valid keyless image signature. Rule 2 requires a valid https://spdx.dev/Document attestation from the same identity. It does not parse package content for vulnerability policy. Rule 3 requires https://slsa.dev/provenance/v0.2 from that identity and compares:

  • invocation.configSource.entryPoint to .github/workflows/sign-attest.yml.
  • builder.id to https://github.com/actions/runner.
  • invocation.configSource.uri to the canonical repository at refs/heads/main.

Kyverno’s attestation conditions evaluate within the predicate body, so the source expressions omit a predicate. prefix. The regression check evaluates those actual expressions against the stored fixture. It is a local condition-shape check, not a full admission test.

The policy does not compare the source commit or materials to an expected promotion source. CI’s contract is stronger on those fields. An accepted admission request therefore establishes the configured image contract, rather than proving its relationship to a particular currently approved source commit.

validationFailureAction: Enforce configures violations to deny matching requests. Missing signatures, wrong identity, absent attestation types, or mismatched required provenance fields should follow the deny path. The owner record reports trusted acceptance and unsigned/mixed/init-container denials. The test-only wrong-trust policy changed signer and source expectations together, so that historical result is one combined negative experiment.

The Helm values annotate the admission controller’s Kubernetes ServiceAccount with the verifier GSA. Terraform grants repository reader roles and the narrow KSA impersonation binding. Registry authentication is essential because the metadata repository must be readable even when the application image itself is available.

The stored values do not explicitly configure webhook failurePolicy or timeout. Enforce establishes violation handling; it does not, by itself, prove how the API behaves if the webhook is unavailable. Historical decision records identify Kyverno chart 3.9.0/application 1.19.0, but version-specific defaults and installed webhook configuration must be checked before claiming an outage is fail-closed. This edition leaves that outage behavior unverified.

The background: true setting supports evaluation/reporting of existing resources. It does not retroactively evict running Pods merely because a claim becomes invalid later.

Recorded tests establish regular-container, mixed-container, and unsigned-initContainer outcomes for their specific fixtures. There is no recorded ephemeral-container test. Admission acceptance does not establish that the program will behave safely after it starts, or that policy administrators cannot weaken the rules.

Inspect admission scope and availability trade-offs for limits, then cross into runtime detection. The accepted artifact remains a running program with behavior that must be observed.