mirror of
https://github.com/open-policy-agent/opa.git
synced 2026-08-12 19:32:48 -06:00
Add Dockerfile.rego to validate image builds (#8744)
OPA's Docker images are built with `docker buildx`, which supports Rego-based build policies via `Dockerfile.rego`. Adding this file lets OPA validate its own image builds using OPA — enforcing that base images come only from the approved chainguard namespace. Adds `Dockerfile.rego` with a single deny rule: base images must come from `docker.io/chainguard/`. This covers all four variants built in the Makefile (`glibc-dynamic`, `glibc-dynamic:latest-dev`, `static`, `busybox`). Local build context access (used by `COPY`) is allowed implicitly when no deny rule fires. The policy follows the same `decision` shape used by buildx's own `policy/default.rego`. No changes to other files are needed — buildx automatically evaluates `Dockerfile.rego` when present. Closes #8401. Signed-off-by: jasdeepbhalla <jasdeepbhalla@gmail.com>
This commit is contained in:
committed by
GitHub
parent
39811e50db
commit
23a4e62676
@@ -0,0 +1,16 @@
|
|||||||
|
# regal ignore:directory-package-mismatch
|
||||||
|
package docker
|
||||||
|
|
||||||
|
import rego.v1
|
||||||
|
|
||||||
|
# Deny base images that are not from the approved chainguard namespace.
|
||||||
|
deny_msgs contains msg if {
|
||||||
|
input.image
|
||||||
|
not startswith(input.image.fullRepo, "docker.io/chainguard/")
|
||||||
|
msg := sprintf("base image %q is not allowed; only docker.io/chainguard images are permitted", [input.image.ref])
|
||||||
|
}
|
||||||
|
|
||||||
|
decision := {
|
||||||
|
"allow": count(deny_msgs) == 0,
|
||||||
|
"deny_msg": [msg | some msg in deny_msgs],
|
||||||
|
}
|
||||||
Reference in New Issue
Block a user