{
  "description": "Cluster-scoped ImageTrustPolicy: the same spec plus a\nnamespaceSelector (nil or {} matches every namespace). Report\nonly, like ImageTrustPolicy.\n",
  "properties": {
    "apiVersion": {
      "type": "string"
    },
    "kind": {
      "type": "string"
    },
    "metadata": {
      "type": "object"
    },
    "spec": {
      "properties": {
        "attestations": {
          "description": "Attestations that must also be attached, verified, and\nsigned by one of the authorities.\n",
          "items": {
            "properties": {
              "builderIdRegExp": {
                "maxLength": 1024,
                "type": "string"
              },
              "predicateType": {
                "maxLength": 512,
                "type": "string"
              },
              "sourceRepoRegExp": {
                "maxLength": 1024,
                "type": "string"
              }
            },
            "required": [
              "predicateType"
            ],
            "type": "object",
            "additionalProperties": false
          },
          "maxItems": 16,
          "type": "array"
        },
        "authorities": {
          "description": "An image is trusted when a signature from any one of\nthese verified. Exactly one of keyless and key each.\n",
          "items": {
            "oneOf": [
              {
                "required": [
                  "keyless"
                ]
              },
              {
                "required": [
                  "key"
                ]
              }
            ],
            "properties": {
              "key": {
                "description": "A public key (PEM) or the sha256 (hex) of its DER\nSubjectPublicKeyInfo. The supplychain component must\nhold the same key to verify such signatures\n(supplychain.signatureDiscovery.publicKeys).\n",
                "properties": {
                  "fingerprint": {
                    "pattern": "^[0-9a-fA-F]{64}$",
                    "type": "string"
                  },
                  "publicKey": {
                    "maxLength": 16384,
                    "type": "string"
                  }
                },
                "type": "object",
                "additionalProperties": false
              },
              "keyless": {
                "description": "Fulcio certificate identity. issuer (or\nissuerRegExp) and subject (or subjectRegExp) are\nboth required; regular expressions must match the\nwhole value.\n",
                "properties": {
                  "issuer": {
                    "maxLength": 1024,
                    "type": "string"
                  },
                  "issuerRegExp": {
                    "maxLength": 1024,
                    "type": "string"
                  },
                  "subject": {
                    "maxLength": 1024,
                    "type": "string"
                  },
                  "subjectRegExp": {
                    "maxLength": 1024,
                    "type": "string"
                  }
                },
                "type": "object",
                "additionalProperties": false
              },
              "name": {
                "maxLength": 128,
                "type": "string"
              }
            },
            "type": "object",
            "additionalProperties": false
          },
          "maxItems": 32,
          "minItems": 1,
          "type": "array"
        },
        "images": {
          "description": "Glob patterns over the image repository\n(docker.io/library/nginx, ghcr.io/org/app). \"*\" matches\nwithin one path segment, \"**\" across segments. Empty\nmatches every image.\n",
          "items": {
            "maxLength": 512,
            "type": "string"
          },
          "maxItems": 64,
          "type": "array"
        },
        "namespaceSelector": {
          "description": "Namespaces this policy applies to (nil or {} = all).",
          "type": "object",
          "x-kubernetes-preserve-unknown-fields": true
        }
      },
      "required": [
        "authorities"
      ],
      "type": "object",
      "additionalProperties": false
    },
    "status": {
      "description": "Written by the kguardian evaluator.",
      "properties": {
        "conditions": {
          "description": "BrokerRead (True once running containers were read; False with NeverRead, BrokerUnavailable or BrokerUnauthorized).",
          "items": {
            "properties": {
              "lastTransitionTime": {
                "format": "date-time",
                "type": "string"
              },
              "message": {
                "maxLength": 32768,
                "type": "string"
              },
              "observedGeneration": {
                "format": "int64",
                "minimum": 0,
                "type": "integer"
              },
              "reason": {
                "maxLength": 1024,
                "minLength": 1,
                "type": "string"
              },
              "status": {
                "enum": [
                  "True",
                  "False",
                  "Unknown"
                ],
                "type": "string"
              },
              "type": {
                "maxLength": 316,
                "type": "string"
              }
            },
            "required": [
              "type",
              "status",
              "lastTransitionTime",
              "reason",
              "message"
            ],
            "type": "object",
            "additionalProperties": false
          },
          "type": "array",
          "x-kubernetes-list-map-keys": [
            "type"
          ],
          "x-kubernetes-list-type": "map"
        },
        "error": {
          "type": "string"
        },
        "evaluation": {
          "properties": {
            "containers": {
              "format": "int64",
              "type": "integer"
            },
            "findings": {
              "items": {
                "properties": {
                  "container": {
                    "type": "string"
                  },
                  "digest": {
                    "type": "string"
                  },
                  "namespace": {
                    "type": "string"
                  },
                  "reason": {
                    "type": "string"
                  },
                  "repository": {
                    "type": "string"
                  },
                  "verdict": {
                    "type": "string"
                  },
                  "workload": {
                    "type": "string"
                  }
                },
                "type": "object",
                "additionalProperties": false
              },
              "type": "array"
            },
            "lastChanged": {
              "format": "date-time",
              "type": "string"
            },
            "lastEvaluated": {
              "format": "date-time",
              "type": "string"
            },
            "state": {
              "enum": [
                "evaluated",
                "never-read",
                "broker-unavailable",
                "broker-unauthorized"
              ],
              "type": "string"
            },
            "truncated": {
              "type": "boolean"
            },
            "trusted": {
              "format": "int64",
              "type": "integer"
            },
            "unknown": {
              "format": "int64",
              "type": "integer"
            },
            "wouldDeny": {
              "format": "int64",
              "type": "integer"
            }
          },
          "type": "object",
          "additionalProperties": false
        },
        "message": {
          "description": "Why containers are Unknown because the broker could not be read, with the last successful read.",
          "type": "string"
        },
        "observedGeneration": {
          "format": "int64",
          "type": "integer"
        }
      },
      "type": "object",
      "additionalProperties": false
    }
  },
  "required": [
    "spec"
  ],
  "type": "object"
}
