Skip to content

Conversation

@st3penta
Copy link
Contributor

My Rego logic proposal, based on rule matchers, for the following rules format:

trusted_task_rules:
  allow:
    - name: "rule name"
      pattern: "oci://quay.io/konflux-ci/tekton-catalog/*"
      versions: [">0.1", "<=0.5"]     # optional
      effective_on: 2025-11-15        # optional
      expires_on: 2026-11-15          # optional
      signing_key: abcde              # optional (require if set)
    - ...
  deny:
    - name: "rule name"
      pattern: "oci://quay.io/konflux-ci/tekton-catalog/task-buildah"
      versions: ["<0.3"]              # optional
      effective_on: 2025-11-15        # optional
      expires_on: 2026-11-15          # optional
    - ...

@st3penta st3penta force-pushed the trusted_tasks_proposal branch from cdaa1be to 5c30c74 Compare October 13, 2025 09:55
@st3penta st3penta closed this Oct 22, 2025
@st3penta st3penta deleted the trusted_tasks_proposal branch October 22, 2025 10:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant