Kritis is an admission controller that when you're deploying to Kubernetes specifically, it will run the policy checks that your cluster admin defines, then deny the pod to be launched if it finds very severe vulnerabilities in your image or it doesn't trust the image location.

Read more of this post