Problem Statement
What practices keep a container registry safe and tidy?
Explanation
Require auth for pull and push. Enforce signed images. Scan on push and block critical findings. Use immutable tags or content digests. Prune old images on a schedule. Keep secrets out of build args and labels. Monitor download patterns to catch abuse.
Code Solution
SolutionRead Only
Policy: signed-only, immutable tags, block HIGH/CRITICAL, retention 90 days
