Files
releases/Dockerfile.rego
T
Jasdeep Singh Bhalla 23a4e62676 Add Dockerfile.rego to validate image builds (#8744)
OPA's Docker images are built with `docker buildx`, which supports
Rego-based build policies via `Dockerfile.rego`. Adding this file lets
OPA validate its own image builds using OPA — enforcing that base images
come only from the approved chainguard namespace.

Adds `Dockerfile.rego` with a single deny rule: base images must come
from `docker.io/chainguard/`. This covers all four variants built in the
Makefile (`glibc-dynamic`, `glibc-dynamic:latest-dev`, `static`,
`busybox`). Local build context access (used by `COPY`) is allowed
implicitly when no deny rule fires.

The policy follows the same `decision` shape used by buildx's own
`policy/default.rego`. No changes to other files are needed — buildx
automatically evaluates `Dockerfile.rego` when present.

Closes #8401.

Signed-off-by: jasdeepbhalla <jasdeepbhalla@gmail.com>
2026-07-01 10:42:54 +02:00

17 lines
461 B
Rego

# regal ignore:directory-package-mismatch
package docker
import rego.v1
# Deny base images that are not from the approved chainguard namespace.
deny_msgs contains msg if {
input.image
not startswith(input.image.fullRepo, "docker.io/chainguard/")
msg := sprintf("base image %q is not allowed; only docker.io/chainguard images are permitted", [input.image.ref])
}
decision := {
"allow": count(deny_msgs) == 0,
"deny_msg": [msg | some msg in deny_msgs],
}