Add Dockerfile.rego to validate image builds (#8744)

OPA's Docker images are built with `docker buildx`, which supports
Rego-based build policies via `Dockerfile.rego`. Adding this file lets
OPA validate its own image builds using OPA — enforcing that base images
come only from the approved chainguard namespace.

Adds `Dockerfile.rego` with a single deny rule: base images must come
from `docker.io/chainguard/`. This covers all four variants built in the
Makefile (`glibc-dynamic`, `glibc-dynamic:latest-dev`, `static`,
`busybox`). Local build context access (used by `COPY`) is allowed
implicitly when no deny rule fires.

The policy follows the same `decision` shape used by buildx's own
`policy/default.rego`. No changes to other files are needed — buildx
automatically evaluates `Dockerfile.rego` when present.

Closes #8401.

Signed-off-by: jasdeepbhalla <jasdeepbhalla@gmail.com>
This commit is contained in:
Jasdeep Singh Bhalla
2026-07-01 01:42:54 -07:00
committed by GitHub
parent 39811e50db
commit 23a4e62676
+16
View File
@@ -0,0 +1,16 @@
# regal ignore:directory-package-mismatch
package docker
import rego.v1
# Deny base images that are not from the approved chainguard namespace.
deny_msgs contains msg if {
input.image
not startswith(input.image.fullRepo, "docker.io/chainguard/")
msg := sprintf("base image %q is not allowed; only docker.io/chainguard images are permitted", [input.image.ref])
}
decision := {
"allow": count(deny_msgs) == 0,
"deny_msg": [msg | some msg in deny_msgs],
}