You want to allow only images from a specific registry (e.g., myregistry.io) to be deployed in your cluster. Which tool or approach is best suited for this requirement?
OPA/Gatekeeper operates as a validating admission controller that can evaluate the entire Pod spec before creation. By writing a ConstraintTemplate and a Constraint with Rego logic, you can inspect every container's image field, including initContainers and ephemeral containers, and enforce that the image reference begins with your approved registry host. This is the correct approach because admission control is the only layer that can consistently reject non-compliant workloads across all nodes and namespaces.
Why this answer
OPA/Gatekeeper allows you to define a ConstraintTemplate and a Constraint that validates the image registry in pod specs via a Rego rule. This approach enforces admission control at the API server level, rejecting any pod that references an image from an unauthorized registry before it is persisted in etcd.
Exam trap
A common misconception is that NetworkPolicy can control image sources, but NetworkPolicy operates on network traffic, not on admission of pod specifications.
How to eliminate wrong answers
Option B is wrong because NetworkPolicy controls network traffic between pods and external endpoints at layer 3/4, not image pull sources; it cannot prevent a pod from being created with an image from a disallowed registry. Option C is wrong because ImagePolicyWebhook is a deprecated admission controller that validates image signatures or policies, but it does not natively restrict which registry an image comes from without custom webhook logic, and it is not the recommended or best-suited tool for this specific registry allowlisting requirement. Option D is wrong because modifying the kubelet configuration to restrict image pulls is not a cluster-wide admission control mechanism; it only affects that specific node and can be bypassed by other nodes, and kubelet does not have a native setting to allow only a specific registry.