Registry Policies
Enforcing Signed Image Policies in Container Registries¶
Container registry policies are critical for ensuring that only signed images are pushed to or pulled from your repositories. By integrating signature validation into registry policies, you enforce trust at the infrastructure level, reducing the risk of deploying unsigned or tampered images. This section outlines how to configure AWS, Azure, and GCP registries to enforce mandatory signature checks.
AWS ECR: IAM Policies for Signature Enforcement¶
AWS Elastic Container Registry (ECR) allows you to enforce signature checks using IAM policies. By combining IAM roles with Cosign-signed images, you can ensure that only trusted images are processed.
Example: IAM Policy for Signed Image Pulls¶
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Deny",
"Action": "ecr:PullImage",
"Resource": "*",
"Condition": {
"NotEquals": {
"aws:ResourceTag/signed": "true"
}
}
}
]
}
signed: true tag.
CLI Command to Attach Policy¶
Diagram:
Azure ACR: Policy Definitions for Signature Checks¶
Azure Container Registry (ACR) uses Azure Policy to enforce signature requirements. You can define custom policies that validate image signatures during push/pull operations.
Example: Azure Policy for Signed Images¶
{
"if": {
"allOf": [
{
"field": "type",
"equals": "Microsoft.ContainerRegistry/registries/artifacts"
},
{
"field": "Microsoft.ContainerRegistry/registries/artifacts/content/properties/signed",
"notEquals": "true"
}
]
},
"then": {
"effect": "deny"
}
}
signed: true tag or have an invalid value.
CLI Command to Assign Policy¶
az policy assignment create --name "EnforceSignedImages" --scope /subscriptions/your-sub-id/resourceGroups/your-rg/providers/Microsoft.ContainerRegistry/registries/your-acr --policy ./signed-image-policy.json
Diagram:
GCP Container Registry: IAM and Artifact Validation¶
Google Cloud Platform (GCP) Container Registry (GCR) does not natively enforce signature checks via policies. However, you can use Cloud IAM to restrict access and integrate Cosign with Cloud Build pipelines to enforce signing before pushing.
Cloud Build Integration with Cosign¶
- Install Cosign: Use
cosign installto add the CLI to your environment. - Configure Cloud Build: Create a
cloudbuild.yamlfile with signing and pushing steps:steps: - name: 'gcr.io/cloud-builders/docker' args: ['build', '-t', 'gcr.io/your-project/your-image:latest', '.'] - name: 'gcr.io/cloud-builders/gcloud' args: ['container', 'images', 'sign', 'gcr.io/your-project/your-image:latest', '--key', 'path/to/private-key.pem'] - name: 'gcr.io/cloud-builders/gcloud' args: ['container', 'images', 'push', 'gcr.io/your-project/your-image:latest'] - Create Cloud Build Trigger: Set up a trigger to run this pipeline on code commits.
- IAM Policy Enforcement: Ensure IAM policies check for the
signed: truetag after signing.
Diagram:
Key takeaways¶
- AWS ECR: Use IAM policies with tag-based conditions to enforce signature checks.
- Azure ACR: Leverage Azure Policy to deny access to unsigned images.
- GCP GCR: Combine IAM access control with CI/CD pipelines to ensure pre-signed pushes.
- Always pair signature enforcement with image scanning and CI/CD automation for robust security.