Skip to main content
Version: main-dev

registry-domain-whitelist

Checks if requested image registry domain is in the domains list.

ProviderLevelTags
coreCriticalsecurity

Parameters

NameDefault ValueDescription
domains['docker.io', 'registry-1.docker.io', 'quay.io', 'ghcr.io']n/a

Messages

TypeMessage
PassImage registry domain '${request.registry}' is in the domains list.
FailImage registry domain '${request.registry}' is not in the domains list.

Playbook Example

rules:
- provider: core
rule: registry-domain-whitelist
options:
domains:
- docker.io
- registry-1.docker.io
- quay.io
- ghcr.io

Condition

{
"in": [
{
"var": "request.registry"
},
{
"var": "rule.params.domains"
}
]
}