Chainguard Enforce User Onboarding
Create your own instance of the Rekor transparency log
Signing software bills of materials with Cosign
Using Policy Controller to prevent running pods with extra capabilities
Using Policy Controller to prevent running privileged pods
Using Policy Controller to prevent running pods as root
Maximum container image age with Policy Controller