-
Story
-
Resolution: Done
-
Undefined
-
None
-
None
-
None
-
None
-
Product / Portfolio Work
-
False
-
-
False
-
3
-
None
-
None
-
OCP Node Sprint 274 (green)
As mentioned in the feature https://issues.redhat.com/browse/OCPSTRAT-2073 tests should also cover the current supported policyType: "PublicKey", "FulcioCAWithRekor". In this story, we're going to detail some pass/fail scenarios to cover that.
On Chapter 12. Manage secure signatures with sigstore there are some definitions explaining how the CRs should look like.
Once ClusterImagePolicy and ImagePolicy were already tested on previous stories, OCPNODE-3116 and respectively OCPNODE-3115, the goal for this story is a simple Pass and Fail check scenarios to make sure FulcioCAWithRekor CR accepts the values and works as expected.
Pass scenario: OCP-83666 - ClusterImagePolicy CR pulls image successfully after FulcioCAWithRekor validation
Fail scenario: OCP-83710 - ClusterImagePolicy CR fails to pull image after FulcioCAWithRekor validation