A superb image will have a health check endpoint set up in the dockerfile.
A good image will have a health check endpoint on either the service or another port that you can set up manually.
Most images will require you to manually devise some convoluted health check procedure using automated auth tokens.
All of my images fall into that latter category. You’re welcome.
(Ok, ok, I’m sorry. But you did just remind me that I need to code a health check endpoint and put it in the dockerfile.)
Physical access is a pretty hefty requirement if we’re talking about taking something over. It’s also very difficult to defend against.