Pod Security is verified by Conftest in CI, and by Gatekeeper in the cluster.
See this repository for policy details.
Application images are managed by DockerHub's private repository.
Certificates are managed by cert-manager.
Secrets are managed by AWS Secret Manager, and injected by External Secrets Operator.
Global network policy is managed by Calico.
TLS termination is managed by Ingress NGINX.
mTLS is managed by Linkerd.
Traffic control is managed by Linkerd.
Authentication is enabled with X509 Client Certs.
RBAC authorization is also enabled.