| CPC G06F 8/65 (2013.01) [G06F 8/63 (2013.01)] | 20 Claims |

|
1. A system, comprising:
a processor; and
a memory coupled to the processor, comprising instructions that, in response to execution by the processor, cause the system to perform operations, comprising:
identifying, by a control plane of a computing cluster, that a base image has been registered to a first registry that is stored outside of the computing cluster;
identifying, by the control plane, a trust bundle that corresponds to the base image;
sending, by the control plane and to a secure pipeline that operates outside of the control plane, a message to update the base image;
creating, by the secure pipeline, an updated image based on the base image and the trust bundle;
sending, by the secure pipeline, the updated image to the control plane; and
storing, by the control plane, the updated image in a local registry that is stored on the computing cluster.
|