We should make the controller tenant aware so each container image request does not have visibility to images created by another tenant. Example of tenants: - namespace - user (for the as a service mode)