4e9444d7

By: Michael Lynch <git@mtlynch.io>

Explain scoped Skopeo insecure policy

Document why the docker-archive policy can accept unsigned images safely: it only applies to the local archive built by the deploy script while the default policy rejects every other source.