**实现示例** ```ts type Image = { registry: string; repo: string; tag: string; digest?: string } type Policy = { allowRegistries: Set; requireDigest: boolean } function validImage(i: Image, p: Policy): boolean { const okReg = p.allowRegistries.has(i.registry) const hasDig = p.requireDigest ? !!i.digest && /^[A-Fa-f0-9]{64}$/.test(i.digest) : true return okReg && hasDig && !!i.repo && !!i.tag } ``` **审计与运行治理** - 准入策略审计来源域与摘要固定;异常阻断并输出修复建议。 - 策略变更需审批与归档。

镜像准入控制

通过准入控制器实现镜像签名验证与白名单校验,防止未授权镜像运行。

  • cosign / notation 签名集成
  • 白名单与正则匹配策略
点赞(0) 打赏

评论列表 共有 0 条评论

暂无评论
立即
投稿
网站二维码

微信公众账号

微信扫一扫加关注

发表
评论
返回
顶部
/* 跳过导航链接 (无障碍) */ position: absolute; top: -100px; left: 15px; z-index: 99999; padding: 8px 16px; background: #007bff; color: #fff; font-size: 14px; border-radius: 0 0 4px 4px; text-decoration: none; transition: top 0.2s; } top: 0; outline: 3px solid #0056b3; }