Control image deployment using trusted sources and signature verification

You can restrict which registries a cluster is allowed to pull from, and enable signature verification so that images are checked cryptographically before they run. Using the sigstore framework or Red Hat container signatures, unapproved or tampered images are rejected instead of deployed.