Policy content in this repository is published as OCI artifacts to Quay.io. These are not container images — they are multi-layer OCI bundles assembled by go-gemara and must be pulled with an OCI-native tool such as ORAS, skopeo, or complyctl.
Each published artifact is a Gemara bundle built from a root Policy YAML
under governance/policies/. The bundle contains multiple layers representing
the policy and all of its resolved dependencies:
| Layer | Example file | Description |
|---|---|---|
| Policy | cis-fedora-l1-workstation-policy.yaml |
Root policy defining controls and their mapping references |
| Catalog | cis-fedora-l1-workstation-catalog.yaml |
Security control catalog resolved from the policy's mapping-references |
| Guidance | cis-fedora-l1-guidance.yaml |
Best-practice guidance resolved from the policy's mapping-references |
| Property | Value |
|---|---|
| Manifest media type | application/vnd.oci.image.manifest.v1+json |
| Artifact type | application/vnd.gemara.bundle.v1 |
| Layer media type (YAML content) | application/vnd.gemara.layer.v1+yaml |
Each bundle is published to its own repository under the organization namespace.
| Registry | Purpose | Example reference |
|---|---|---|
ghcr.io |
Staging (internal) | ghcr.io/complytime/complytime-policies/policies-cis-fedora-l1-workstation:latest |
quay.io |
Public destination | quay.io/complytime/policies-cis-fedora-l1-workstation:latest |
See ADR-0001 for the rationale behind one repository per bundle.
| Bundle | Quay repository | Provider |
|---|---|---|
ampel-branch-protection |
quay.io/complytime/policies-ampel-branch-protection |
ampel |
cis-fedora-l1-workstation |
quay.io/complytime/policies-cis-fedora-l1-workstation |
openscap |
cis-fedora-l1-server |
quay.io/complytime/policies-cis-fedora-l1-server |
openscap |
Publishing happens automatically on push to main (when bundles/ or
governance/ files change) and can also be triggered manually via
workflow_dispatch.
| Tag | Mutability | Use case |
|---|---|---|
latest |
Mutable | Tracks the most recent publish from main |
v1.0.0 (semver) |
Immutable | Versioned releases via workflow_dispatch with version input |
@sha256:... (digest) |
Immutable | Strongest guarantee — always returns exact bytes |
For production and compliance use cases, prefer a digest-pinned or
semver-pinned reference over latest.
Use ORAS CLI (v1.2+):
oras pull quay.io/complytime/policies-cis-fedora-l1-workstation:latest -o ./outputThe extracted files are the raw Gemara YAML layers (policy, catalog, guidance).
oras resolve quay.io/complytime/policies-cis-fedora-l1-workstation:latestThis returns the sha256:… digest, which you can use for immutable references:
oras pull quay.io/complytime/policies-cis-fedora-l1-workstation@sha256:<digest> -o ./outputNote: All tools — ORAS, cosign, curl, and
complyctl— use standard OCI reference syntax (:tagand@sha256:digest).
All artifacts are signed with keyless Cosign via GitHub Actions OIDC. Verify with:
cosign verify \
--certificate-identity-regexp="https://github.com/complytime/complytime-policies/.github/workflows/" \
--certificate-oidc-issuer="https://token.actions.githubusercontent.com" \
quay.io/complytime/policies-cis-fedora-l1-workstation:latestA successful output confirms the artifact was produced by the
complytime/complytime-policies GitHub Actions workflow and has not been
tampered with since signing.
Tip: Replace
:latestwith a@sha256:<digest>reference for the strongest verification guarantee.
Quay's package UI may appear sparse for custom OCI media types. The ORAS CLI checks below are authoritative.
oras manifest fetch quay.io/complytime/policies-cis-fedora-l1-workstation:latest \
| jq '{mediaType, artifactType, layers: [.layers[] | {mediaType, digest, size}]}'oras manifest fetch quay.io/complytime/policies-cis-fedora-l1-workstation:latest \
| jq -r '.layers[].digest' \
| while read -r d; do
echo "checking $d"
oras blob fetch quay.io/complytime/policies-cis-fedora-l1-workstation@"$d" --output /dev/null \
&& echo " ok" || echo " FAILED"
doneIf these checks pass but the Quay UI still looks sparse, treat the artifact as valid.
complyctl can consume Gemara
bundles directly from the OCI registry. Point the policy source at a
published bundle in complytime.yaml:
# complytime.yaml
policies:
- url: quay.io/complytime/policies-ampel-branch-protection:latest
id: ampel-bpThen fetch and scan:
complyctl get
complyctl scan --policy-id ampel-bpSee the
complyctl Quick Start
for installation, full complytime.yaml reference, and output formats.
Each provider has its own prerequisites, complytime.yaml variables, and
setup instructions:
| Bundle | Provider | What it evaluates |
|---|---|---|
ampel-branch-protection |
ampel | GitHub / GitLab branch protection rules |
cis-fedora-l1-workstation |
openscap | CIS Fedora L1 Workstation benchmark |
cis-fedora-l1-server |
openscap | CIS Fedora L1 Server benchmark |
- complyctl Quick Start — installation,
complytime.yamlreference, output formats - ampel provider docs — variables, token auth, granular policies
- openscap provider docs — variables, profiles, prerequisites
- complytime-demos — automated VM setup with sample policies
- Quickstart for maintainers — how to run the publish workflow
- Pipeline contract — action inputs, secrets, and outputs
- gemara-registry-cli — the composite action that produces the artifact
- go-gemara — the SDK that assembles bundles