Skip to content

v0.7.0 — Local Runtime Evidence

Choose a tag to compare

@fadyy2k fadyy2k released this 22 Sep 11:39
· 1 commit to main since this release
1f002ca

Engineering intent

Add real Kubernetes runtime evidence without requiring AWS. Phase 7 proves that the GitOps, admission, observability, runtime-security, resilience and cost/right-sizing paths actually execute in a disposable Kubernetes 1.36 environment while keeping AWS-specific claims separate.

Runtime evidence

Captured on a local kind cluster running Kubernetes v1.36.4:

  • Argo CD applications for the demo, security policies, VPA and cost controls reached Healthy / Synced
  • the signed immutable project image was admitted by Kyverno server-side admission
  • nginx:1.27 was denied by the project image policy
  • Prometheus reported both platform-demo scrape targets 2/2 up and loaded the SLO alert/recording groups
  • Trivy Operator produced an in-cluster report for the pinned digest with 0 critical / 0 high / 0 medium / 0 low findings at capture time
  • a benign temporary-pod probe triggered Falco's Read sensitive file untrusted rule with Kubernetes attribution
  • a controlled pod-failure game day recovered the Deployment to 2/2 while Argo remained Healthy/Synced
  • VPA stayed non-mutating (updateMode: Off) and returned a measured recommendation
  • OpenCost returned live namespace allocation data from the in-cluster Prometheus service

Reproducibility

Evidence boundary

This release proves local Kubernetes runtime behavior, not AWS/EKS behavior. It does not claim GitHub→AWS OIDC, S3/KMS Terraform state, EKS managed nodes, AWS networking/load balancers, AWS-priced OpenCost data or multi-region failover.

OpenCost values from the local cluster use a local/default provider model and are explicitly not an AWS bill.