Repository navigation
v0.7.0 — Local Runtime Evidence
Engineering intent
Add real Kubernetes runtime evidence without requiring AWS. Phase 7 proves that the GitOps, admission, observability, runtime-security, resilience and cost/right-sizing paths actually execute in a disposable Kubernetes 1.36 environment while keeping AWS-specific claims separate.
Runtime evidence
Captured on a local kind cluster running Kubernetes v1.36.4:
- Argo CD applications for the demo, security policies, VPA and cost controls reached Healthy / Synced
- the signed immutable project image was admitted by Kyverno server-side admission
nginx:1.27was denied by the project image policy- Prometheus reported both
platform-demoscrape targets 2/2 up and loaded the SLO alert/recording groups - Trivy Operator produced an in-cluster report for the pinned digest with 0 critical / 0 high / 0 medium / 0 low findings at capture time
- a benign temporary-pod probe triggered Falco's
Read sensitive file untrustedrule with Kubernetes attribution - a controlled pod-failure game day recovered the Deployment to 2/2 while Argo remained Healthy/Synced
- VPA stayed non-mutating (
updateMode: Off) and returned a measured recommendation - OpenCost returned live namespace allocation data from the in-cluster Prometheus service
Reproducibility
- Local Runtime Evidence
- Engineering Evidence
- Local Runtime Admission CI
scripts/local-runtime-verify.shreproduces the read-only/runtime checks on a runningkindenvironment- GitHub Actions now creates a disposable Kubernetes 1.36 cluster and proves signed-image admission plus untrusted-image denial on every relevant change
Evidence boundary
This release proves local Kubernetes runtime behavior, not AWS/EKS behavior. It does not claim GitHub→AWS OIDC, S3/KMS Terraform state, EKS managed nodes, AWS networking/load balancers, AWS-priced OpenCost data or multi-region failover.
OpenCost values from the local cluster use a local/default provider model and are explicitly not an AWS bill.