build1 publisher
One kubectl run of nginx:latest tests whether a cluster enforces signed images
k8s-secure-supply-chain, a kind-based reference build, uses five Kyverno checks to refuse at admission any image that CI did not sign and attest. Its author argues that CI scans and signatures stay advisory until the cluster enforces them.
Publishers:dev.to
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives20
- Confidence50