Kubernetes-native policy management
Policies are managed as Kubernetes resources
Kyverno manages community policies
These policies are searchable
Require specific labels on resources
Allowlist for image registries
Require attestations of security scans