A financial services company is adopting cloud native practices and needs to ensure that all container images deployed to their production Kubernetes cluster are from a trusted, internal registry and have been scanned for critical vulnerabilities. Which combination of CNCF projects is best suited to enforce this policy at the time of deployment?