About This Architecture
End-to-end container image lifecycle from Dockerfile through multi-stage build, vulnerability scanning with Trivy (with CVE threshold gate), cryptographic image signing with Cosign, SBOM generation, and push to an OCI-compliant registry with semantic versioning. Deployment to Kubernetes includes admission controller signature verification.