Skip to content

Conversation

@tonistiigi
Copy link
Member

Add support for dynamic source policies via client session.

Client session can allow or deny specific source or ask additional metadata information via sourcemetaresolver if that is needed to make the decision.

Still lots of things to complete. Opening draft for early feedback. cc @cpuguy83

Add support for dynamic source policies via client session.

Client session can allow or deny specific source or
ask additional metadata information via sourcemetaresolver if
that is needed to make the decision.

Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
Signed-off-by: Tonis Tiigi <tonistiigi@gmail.com>
@cpuguy83
Copy link
Member

cpuguy83 commented Oct 9, 2025

What use-cases were you look at for this?
What I was thinking was image signature validation.

@tonistiigi
Copy link
Member Author

What use-cases were you look at for this?
What I was thinking was image signature validation.

Yes, that is one of the cases. ResolveSourceMetadata can be updated with more support for other sources and things like resolving image signature. Some related ongoing work https://github.com/docker/github-builder-experimental/tree/build-reusable-workflow moby/moby#51012

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants