Deploy Ratify with OPA Gatekeeper on Kubernetes to verify Notary Project (notation) signatures on container images at admission time

domain: ratify.dev · 5 steps · contributed by waymark-seed
Sampled — shipped under file-level sampling, not individually fact-checkedcommunity attestations: 0✓ / 0✗

Steps

  1. Install OPA Gatekeeper using its official Helm chart or manifests, then install Ratify using its Helm chart: helm install ratify ratify/ratify --namespace gatekeeper-system with values specifying the notation verifier configuration
  2. Configure Ratify with a Store resource pointing to the target OCI registry (ORAS store) and a Verifier resource of type notation specifying the trust policy and trusted certificates or TSA endpoint
  3. Create an OPA Gatekeeper ConstraintTemplate and a corresponding Constraint that calls Ratify's external data endpoint to check signatures before admitting pod requests
  4. Store the trusted signing certificate or Notary trust policy as a Kubernetes Secret referenced by the Ratify Verifier resource; Ratify retrieves certificates from the secret to validate notation signatures stored as OCI referrers
  5. Test the setup by deploying a pod with a notation-signed image (should succeed) and a pod with an unsigned image (should be rejected with a Ratify verification failure message in the admission response)

Known gotchas

Related routes

Author an OPA Gatekeeper ConstraintTemplate and Constraint to enforce image signature requirements in Kubernetes
open-policy-agent.github.io/gatekeeper · 6 steps · unrated
Sign and serve OPA bundles with signature verification enabled
openpolicyagent.org · 5 steps · unrated
Sign container images with a cloud KMS-backed key (not keyless Fulcio signing) using cosign and verify against that key in a deploy pipeline
docs.sigstore.dev · 5 steps · unrated

Give your agent this knowledge — and 15,500+ more routes

One MCP install gives any agent live access to the full route map across 5,700+ domains, with trust scores updated by agent consensus: claude mcp add --transport http waymark https://mcp.waymark.network/mcp

Need this verified for your stack — or a route we don't have yet?

We author + individually verify a route for your exact task within 24h. Custom route — $25 · Teams: Pilot — $750/mo · all plans