Skip to content

Conversation

@rurikudo
Copy link
Contributor

@rurikudo rurikudo commented Oct 1, 2021

Signed-off-by: ruriko [email protected]

  • enable sigstore signing
  • use the core logic of k8s-manifest-sigstore for verification
  • integration with gatekeepers
  • add observer for verify existing resources

tphee and others added 30 commits October 14, 2020 09:31
rurikudo and others added 29 commits September 8, 2021 13:53
* change IntegrityShield CRD apiVersion to v1

Signed-off-by: Hirokuni-Kitahara1 <[email protected]>

* update Makefile

Signed-off-by: Hirokuni-Kitahara1 <[email protected]>
* add image package and implement image profile

Signed-off-by: Hirokuni-Kitahara1 <[email protected]>

* update image verification

Signed-off-by: Hirokuni-Kitahara1 <[email protected]>

* add sample constraint with image profile

Signed-off-by: Hirokuni-Kitahara1 <[email protected]>

* update image verify codes

Signed-off-by: Hirokuni-Kitahara1 <[email protected]>

* update image verify codes

Signed-off-by: Hirokuni-Kitahara1 <[email protected]>
Signed-off-by: ruriko <[email protected]>
* move constraint enforce setting into constraint parameter

Signed-off-by: ruriko <[email protected]>

* update operator-sdk version

Signed-off-by: ruriko <[email protected]>
* rename custom resource for reporting observation results

Signed-off-by: ruriko <[email protected]>

* fix action param name

Signed-off-by: ruriko <[email protected]>

* update bundle

Signed-off-by: ruriko <[email protected]>

* remove 'server' from all parameters

Signed-off-by: ruriko <[email protected]>

* fix value in local cr

Signed-off-by: ruriko <[email protected]>
* enable inScopeUsers

Signed-off-by: ruriko <[email protected]>

* fix err message

Signed-off-by: ruriko <[email protected]>

* resolve cosign warning message

Signed-off-by: ruriko <[email protected]>
* fix crd scope

Signed-off-by: ruriko <[email protected]>

* add e2e-test

Signed-off-by: ruriko <[email protected]>

* remove unneeded files

Signed-off-by: ruriko <[email protected]>

* remove unneeded variable

Signed-off-by: ruriko <[email protected]>
* add unit-test

Signed-off-by: ruriko <[email protected]>

* fix Makefile for unit-test

Signed-off-by: ruriko <[email protected]>

* fix image registry name in unit-test

Signed-off-by: ruriko <[email protected]>
Fixes to make travis build complete successfully
Signed-off-by: ruriko <[email protected]>
Fixes to make travis build complete successfully
* add image verification to observer

Signed-off-by: ruriko <[email protected]>

* add param to change provenance option, update observer result detail for web ui

Signed-off-by: ruriko <[email protected]>

* fix operator

Signed-off-by: ruriko <[email protected]>

* update csv

Signed-off-by: ruriko <[email protected]>

* remove vulnerable pacakge

Signed-off-by: ruriko <[email protected]>
* change to use tmp cr to test with latest image tag

Signed-off-by: ruriko <[email protected]>

* update to use csv version as image tag

Signed-off-by: ruriko <[email protected]>

* fix csv

Signed-off-by: ruriko <[email protected]>
* enable to handle unexpected value in image fields

Signed-off-by: ruriko <[email protected]>

* fix the handling of incorrect image definitions

Signed-off-by: ruriko <[email protected]>

* fix build func for observer deployment

Signed-off-by: ruriko <[email protected]>

* update e2e-test for support remote env

Signed-off-by: ruriko <[email protected]>

* updated not to create psp

Signed-off-by: ruriko <[email protected]>

* fixed implementation error

Signed-off-by: ruriko <[email protected]>

* unify ISHIELD_OP_NS with ISHIELD_NS

Signed-off-by: ruriko <[email protected]>

* fixed implementation error

Signed-off-by: ruriko <[email protected]>

* fix makefile

Signed-off-by: ruriko <[email protected]>
Signed-off-by: ruriko <[email protected]>
Signed-off-by: ruriko <[email protected]>
@rurikudo rurikudo merged commit 73c46f4 into master Oct 1, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants