Skip to content

Registry Policies

Enforcing Signed Image Policies in Container Registries

Container registry policies are critical for ensuring that only signed images are pushed to or pulled from your repositories. By integrating signature validation into registry policies, you enforce trust at the infrastructure level, reducing the risk of deploying unsigned or tampered images. This section outlines how to configure AWS, Azure, and GCP registries to enforce mandatory signature checks.


AWS ECR: IAM Policies for Signature Enforcement

AWS Elastic Container Registry (ECR) allows you to enforce signature checks using IAM policies. By combining IAM roles with Cosign-signed images, you can ensure that only trusted images are processed.

Example: IAM Policy for Signed Image Pulls

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Effect": "Deny",
      "Action": "ecr:PullImage",
      "Resource": "*",
      "Condition": {
        "NotEquals": {
          "aws:ResourceTag/signed": "true"
        }
      }
    }
  ]
}
Apply this policy to an IAM role, and ECR will deny pulls unless the image has a signed: true tag.

CLI Command to Attach Policy

aws ecr put-image-policy --repository-name my-repo --policy-text file://signed-image-policy.json

Diagram:

[User] → [IAM Role] → [ECR] → [Pull Image]  
                ↓                        ↓  
               [Signed Tag]           [Deny/Allow]


Azure ACR: Policy Definitions for Signature Checks

Azure Container Registry (ACR) uses Azure Policy to enforce signature requirements. You can define custom policies that validate image signatures during push/pull operations.

Example: Azure Policy for Signed Images

{
  "if": {
    "allOf": [
      {
        "field": "type",
        "equals": "Microsoft.ContainerRegistry/registries/artifacts"
      },
      {
        "field": "Microsoft.ContainerRegistry/registries/artifacts/content/properties/signed",
        "notEquals": "true"
      }
    ]
  },
  "then": {
    "effect": "deny"
  }
}
This policy denies access to images that lack the signed: true tag or have an invalid value.

CLI Command to Assign Policy

az policy assignment create --name "EnforceSignedImages" --scope /subscriptions/your-sub-id/resourceGroups/your-rg/providers/Microsoft.ContainerRegistry/registries/your-acr --policy ./signed-image-policy.json

Diagram:

[User] → [ACR] → [Push/Pull Image]  
                ↓                        ↓  
               [Signature Check]     [Deny/Allow]


GCP Container Registry: IAM and Artifact Validation

Google Cloud Platform (GCP) Container Registry (GCR) does not natively enforce signature checks via policies. However, you can use Cloud IAM to restrict access and integrate Cosign with Cloud Build pipelines to enforce signing before pushing.

Cloud Build Integration with Cosign

  1. Install Cosign: Use cosign install to add the CLI to your environment.
  2. Configure Cloud Build: Create a cloudbuild.yaml file with signing and pushing steps:
    steps:
    - name: 'gcr.io/cloud-builders/docker'
      args: ['build', '-t', 'gcr.io/your-project/your-image:latest', '.']
    - name: 'gcr.io/cloud-builders/gcloud'
      args: ['container', 'images', 'sign', 'gcr.io/your-project/your-image:latest', '--key', 'path/to/private-key.pem']
    - name: 'gcr.io/cloud-builders/gcloud'
      args: ['container', 'images', 'push', 'gcr.io/your-project/your-image:latest']
    
  3. Create Cloud Build Trigger: Set up a trigger to run this pipeline on code commits.
  4. IAM Policy Enforcement: Ensure IAM policies check for the signed: true tag after signing.

Diagram:

[CI/CD] → [Cosign Sign] → [Push to GCR] → [Pull by IAM]


Key takeaways

  • AWS ECR: Use IAM policies with tag-based conditions to enforce signature checks.
  • Azure ACR: Leverage Azure Policy to deny access to unsigned images.
  • GCP GCR: Combine IAM access control with CI/CD pipelines to ensure pre-signed pushes.
  • Always pair signature enforcement with image scanning and CI/CD automation for robust security.