﻿# Signature verification policy for Docker images

> [HTML Version](docker-image-verification-policy.html)

The policy applies when it is necessary to ensure that the image is owned by a trusted publisher and has not been modified. Signing Docker images is a process to ensure their authenticity and consistency. This is accomplished by adding a digital signature to the Docker image that can be verified during deployment.

````
начало внимание

````
The policy is available from BRIX On-Premises version 2024.3.0 on.

````
конец внимание

````
The configuration file must be filled in for deployment.

## Fill in the configuration file

Fill in the \[OBJECT\] configuration file to install Kyverno.

1. Configure the signature verification policy for Docker images. The policy is disabled by default. To enable the policy, set \[OBJECT\] to \[OBJECT\].

2. If you have multiple BRIX On-Premises application instances installed in your Kubernetes cluster, but you only want to apply signature verification for Docker images to a subset of BRIX application instances, fill in the \[OBJECT\] parameter. This parameter specifies the **namespace** of the BRIX application instances.

3. Specify the namespace for the Kyverno service: in this case, it is \[OBJECT\]. To ensure high availability, specify the required number of replicas in the \[OBJECT\] parameter.

````
\# Configure kyverno  
kyverno:  
...  
  # signature verification policy for Docker images  
  checkImageSign:  
    enabled: false  
    # list of registries for which the signature policy for Docker images will be applied  
    registry:  
      - hub.brix365.com  
    # list of namespaces in which the signature policy for Docker images will be applied  
    # namespace:  
      # - brix365-dev  
      # - brix365-prod  
    # secret for accessing Docker images to apply the signature policy for Docker images  
    existingImagePullSecrets:  
      - yandexsecret  
  namespace: kyverno  
  # number of replicas to ensure high availability  
  replicaCount: 1  
  # crds installation (not required, added to the crds directory)  
  installCRDs: false  
...

````
Filling in parameters for connecting to a private registry to install Kyverno in a closed-loop environment without internet access

  
To connect to a private registry:

1. Download BRIX images and upload them to the local image registry. Read more about this in the [Download BRIX images](downloadin-images-elma365.md) article.

2. Set the address and path for the \[OBJECT\], \[OBJECT\], and \[OBJECT\] parameters.

3. Specify the name of the secret with access rights to the private registry in \[OBJECT\] and \[OBJECT\]. The secret must be created manually and encrypted in Base64.

````
\# Configure kyverno  
kyverno:  
...  
  # parameters for connecting to a private registry  
  image:  
\# address and path for the private registry  
    repository: registry.example.com/kyverno/kyverno  
    tag: v1.9.0  
\# secret with access rights to the private registry must be created manually, encrypted in Base64  
    pullSecrets:  
      - myRegistryKeySecretName  
  initImage:  
\# address and path for the private registry  
    repository: registry.example.com/kyverno/kyvernopre  
    tag: v1.9.0  
  cleanupController:  
    image:  
\# address and path for the private registry  
      repository: registry.example.com/kyverno/cleanup-controller  
      tag: v1.9.0  
\# secret with access rights to the private registry must be created manually, encrypted in Base64  
      pullSecrets:  
        - myRegistryKeySecretName

````
where \[OBJECT\] format is as follows:

- The address is \[OBJECT\].

- The path is \[OBJECT\].

- The address is \[OBJECT\].

- The path is \[OBJECT\].

- The address is \[OBJECT\].

- The path is \[OBJECT\].

