A financial services company is building a CI/CD pipeline using Cloud Build and Cloud Deploy. To comply with internal security policies, they must ensure that only container images that have passed all vulnerability scans and integration tests are deployable to their production GKE clusters. Furthermore, the mechanism enforcing this must be resistant to tampering, even by users with project owner roles. Which combination of services should be implemented to meet these requirements?