Image Scanning + Admission Control: Stop Vulnerable Images
How to scan container images with Trivy or Grype and enforce results with Kyverno or Gatekeeper admission policies, plus an exception workflow that won't get abused.
Read the post2 posts about admission-control in the conndeck blog — field notes on local-first Kubernetes operations, GitOps, and production debugging.
How to scan container images with Trivy or Grype and enforce results with Kyverno or Gatekeeper admission policies, plus an exception workflow that won't get abused.
Read the postA field-tested rollout plan for Pod Security Standards: audit mode first, baseline before restricted, and exemptions that don't become permanent.
Read the post