You are configuring Flux to manage a multi-tenant cluster. You need to ensure that specific namespaces only allow images from an internal registry. Which tool should you use to enforce this at admission time?
Trap 1: ArgoCD Notifications
Notifications provide alerts but do not block unauthorized resource creation.
Trap 2: Sealed Secrets
Sealed Secrets is strictly for secret management.
Trap 3: Flux Image Automation Controller
This controller handles image updates, not runtime admission policy.
- A
ArgoCD Notifications
Why wrong: Notifications provide alerts but do not block unauthorized resource creation.
- B
Kyverno
Kyverno policies can validate image registry sources during admission.
- C
Sealed Secrets
Why wrong: Sealed Secrets is strictly for secret management.
- D
Flux Image Automation Controller
Why wrong: This controller handles image updates, not runtime admission policy.