Hardening Kubernetes GitOps with Admission Control and Image Provenance

GitOps makes Kubernetes delivery repeatable, but repeatability is not the same as trust. A practical admission-control and provenance workflow can stop unsigned images, risky manifests, and policy drift before they reach production clusters.