This guide demonstrates how to enforce signed container image verification in an Amazon EKS cluster using:
- Kyverno – Kubernetes policy engine
- AWS Notation (kyverno-notation-aws) – signature verification
- AWS Signer – image signing
- IRSA (IAM Roles for Service Accounts) – secure AWS access