/ec-config

Preset policy configuration files for Enterprise Contract

Primary LanguageMakefile

Enterprise Contract Configuration Files

This repo contains a set of policy.yaml files which can be used with Enterprise Contract and the Red Hat Trusted Application Pipeline.

There is a predefined RHTAP Integration Test pipeline definition for each of these configs which can be used when creating an Integration Test in RHTAP as per the documentation here.

The policy configuration files are:

Default

Includes rules for levels 1, 2 & 3 of SLSA v0.1.

  • URL for Enterprise Contract: github.com/enterprise-contract/config//default
  • Source: default/policy.yaml
  • RHTAP Integration Test pipeline definition:

Minimal

Include a minimal set of basic checks.

  • URL for Enterprise Contract: github.com/enterprise-contract/config//minimal
  • Source: minimal/policy.yaml

SLSA1

The minimal rules plus the rules for level 1 of SLSA v0.1.

SLSA2

The minimal rules plus the rules for levels 1 & 2 of SLSA v0.1.

SLSA3

The minimal rules plus the rules for levels 1, 2 & 3 of SLSA v0.1.

Everything

Include every rule in the default policy source.

See also