Your application services are managed within Google Kubernetes Engine (GKE). How can you ensure that only images from your centrally-controlled Google Container Registry (GCR) in the altostrat-images project are deployed to the cluster, while minimizing development overhead?