Secure container images, registries, runtimes, Kubernetes or equivalent orchestration, admission, identities, networks, secrets, and multi-tenancy.