Menampilkan semua artikel dengan tag "securitycontext"
Deployment.yaml di-hardened: non-root, read-only filesystem, cap drop ALL, probes, resources. 3 scanner: Kubesec 0→11, Checkov 20→0, Trivy 16→0. Pods tetap running.