This container can be pulled via:
  docker pull registry.opensuse.org/opensuse/keylime-control-plane:7.11.0-4.1029

Set DOCKER_CONTENT_TRUST=1 to enable image tag verification.