{
  "description": "Who must have signed the images this namespace's workloads run.\nReport only: the kguardian evaluator compares every running\ncontainer's image with the signatures kguardian verified and\nrecords in status what would be denied. Nothing is admitted or\nblocked and there is no webhook. Generate the enforcing Kyverno\nor policy-controller policy with kguardian when ready.\n",
  "properties": {
    "apiVersion": {
      "type": "string"
    },
    "kind": {
      "type": "string"
    },
    "metadata": {
      "type": "object"
    },
    "spec": {
      "properties": {
        "attestations": {
          "description": "Attestations that must also be attached, verified, and\nsigned by one of the authorities.\n",
          "items": {
            "properties": {
              "builderIdRegExp": {
                "maxLength": 1024,
                "type": "string"
              },
              "predicateType": {
                "maxLength": 512,
                "type": "string"
              },
              "sourceRepoRegExp": {
                "maxLength": 1024,
                "type": "string"
              }
            },
            "required": [
              "predicateType"
            ],
            "type": "object",
            "additionalProperties": false
          },
          "maxItems": 16,
          "type": "array"
        },
        "authorities": {
          "description": "An image is trusted when a signature from any one of\nthese verified. Exactly one of keyless and key each.\n",
          "items": {
            "oneOf": [
              {
                "required": [
                  "keyless"
                ]
              },
              {
                "required": [
                  "key"
                ]
              }
            ],
            "properties": {
              "key": {
                "description": "A public key (PEM) or the sha256 (hex) of its DER\nSubjectPublicKeyInfo. The supplychain component must\nhold the same key to verify such signatures\n(supplychain.signatureDiscovery.publicKeys).\n",
                "properties": {
                  "fingerprint": {
                    "pattern": "^[0-9a-fA-F]{64}$",
                    "type": "string"
                  },
                  "publicKey": {
                    "maxLength": 16384,
                    "type": "string"
                  }
                },
                "type": "object",
                "additionalProperties": false
              },
              "keyless": {
                "description": "Fulcio certificate identity. issuer (or\nissuerRegExp) and subject (or subjectRegExp) are\nboth required; regular expressions must match the\nwhole value.\n",
                "properties": {
                  "issuer": {
                    "maxLength": 1024,
                    "type": "string"
                  },
                  "issuerRegExp": {
                    "maxLength": 1024,
                    "type": "string"
                  },
                  "subject": {
                    "maxLength": 1024,
                    "type": "string"
                  },
                  "subjectRegExp": {
                    "maxLength": 1024,
                    "type": "string"
                  }
                },
                "type": "object",
                "additionalProperties": false
              },
              "name": {
                "maxLength": 128,
                "type": "string"
              }
            },
            "type": "object",
            "additionalProperties": false
          },
          "maxItems": 32,
          "minItems": 1,
          "type": "array"
        },
        "images": {
          "description": "Glob patterns over the image repository\n(docker.io/library/nginx, ghcr.io/org/app). \"*\" matches\nwithin one path segment, \"**\" across segments. Empty\nmatches every image.\n",
          "items": {
            "maxLength": 512,
            "type": "string"
          },
          "maxItems": 64,
          "type": "array"
        }
      },
      "required": [
        "authorities"
      ],
      "type": "object",
      "additionalProperties": false
    },
    "status": {
      "description": "Written by the kguardian evaluator.",
      "properties": {
        "conditions": {
          "description": "BrokerRead (True once running containers were read; False with NeverRead, BrokerUnavailable or BrokerUnauthorized).",
          "items": {
            "properties": {
              "lastTransitionTime": {
                "format": "date-time",
                "type": "string"
              },
              "message": {
                "maxLength": 32768,
                "type": "string"
              },
              "observedGeneration": {
                "format": "int64",
                "minimum": 0,
                "type": "integer"
              },
              "reason": {
                "maxLength": 1024,
                "minLength": 1,
                "type": "string"
              },
              "status": {
                "enum": [
                  "True",
                  "False",
                  "Unknown"
                ],
                "type": "string"
              },
              "type": {
                "maxLength": 316,
                "type": "string"
              }
            },
            "required": [
              "type",
              "status",
              "lastTransitionTime",
              "reason",
              "message"
            ],
            "type": "object",
            "additionalProperties": false
          },
          "type": "array",
          "x-kubernetes-list-map-keys": [
            "type"
          ],
          "x-kubernetes-list-type": "map"
        },
        "error": {
          "type": "string"
        },
        "evaluation": {
          "properties": {
            "containers": {
              "format": "int64",
              "type": "integer"
            },
            "findings": {
              "items": {
                "properties": {
                  "container": {
                    "type": "string"
                  },
                  "digest": {
                    "type": "string"
                  },
                  "namespace": {
                    "type": "string"
                  },
                  "reason": {
                    "type": "string"
                  },
                  "repository": {
                    "type": "string"
                  },
                  "verdict": {
                    "type": "string"
                  },
                  "workload": {
                    "type": "string"
                  }
                },
                "type": "object",
                "additionalProperties": false
              },
              "type": "array"
            },
            "lastChanged": {
              "format": "date-time",
              "type": "string"
            },
            "lastEvaluated": {
              "format": "date-time",
              "type": "string"
            },
            "state": {
              "enum": [
                "evaluated",
                "never-read",
                "broker-unavailable",
                "broker-unauthorized"
              ],
              "type": "string"
            },
            "truncated": {
              "type": "boolean"
            },
            "trusted": {
              "format": "int64",
              "type": "integer"
            },
            "unknown": {
              "format": "int64",
              "type": "integer"
            },
            "wouldDeny": {
              "format": "int64",
              "type": "integer"
            }
          },
          "type": "object",
          "additionalProperties": false
        },
        "message": {
          "description": "Why containers are Unknown because the broker could not be read, with the last successful read.",
          "type": "string"
        },
        "observedGeneration": {
          "format": "int64",
          "type": "integer"
        }
      },
      "type": "object",
      "additionalProperties": false
    }
  },
  "required": [
    "spec"
  ],
  "type": "object"
}
