A compliance officer wants to continuously audit Kubernetes resource manifests for misconfigurations against security best practices before they are applied. Which tool type is best suited for this shift-left compliance approach?
Admission controllers enforce policy compliance at deployment time.
Why this answer
Policy-as-code engines like OPA Gatekeeper or Kyverno validate and audit Kubernetes manifests prior to admission into the cluster.