Binary Authorization
DeploymentAttestation
Enforce Attestation
Enable Policy
gcloud container binauthz policy export > $HOME/binauthz-policy.yamladmissionWhitelistPatterns:
- namePattern: gcr.io/google_containers/*
- namePattern: gcr.io/google-containers/*
- namePattern: k8s.gcr.io/*
- namePattern: gke.gcr.io/*
- namePattern: gcr.io/stackdriver-agents/*
defaultAdmissionRule:
enforcementMode: ENFORCED_BLOCK_AND_AUDIT_LOG
# Change evaluationMode to require attestation
evaluationMode: REQUIRE_ATTESTATION
# Add the policy, and reference the `default-attestor` created from
# Attestation section.
# Replace PROJECT_ID with your Project ID.
requireAttestationsBy:
- projects/PROJECT_ID/attestors/default-attestor
globalPolicyEvaluationMode: ENABLE
name: projects/PROJECT_ID/policyUnattested Container Image
Attested Container Image
Allow List
Last updated
Was this helpful?