Repository navigation
Engineering intent
Extend the v0.7 local-runtime milestone with recovery, failure-injection and deeper runtime-security evidence while preserving the boundary between local Kubernetes proof and AWS/EKS proof.
New runtime evidence
Captured on kind / Kubernetes v1.36.4:
- signed immutable project image admitted by server-side policy evaluation
- mutable project tag denied by the digest policy
- syntactically valid but unknown project digest denied by
ImageValidatingPolicy - namespace Pod Security
restrictedenforcement confirmed - Prometheus 14/14 active targets UP, including
platform-demo2/2 - controlled error-burn injected 200 HTTP 503 responses and the Deployment recovered to 2/2
- PDB/HPA runtime state captured after recovery
- Velero backup Completed and namespace-mapped restore Completed, with the restored Deployment reaching 2/2 against local MinIO-backed storage
- OpenCost returned live namespace allocation data and VPA returned a measured recommendation in
Offmode - Falco produced a Kubernetes-attributed Critical event from a benign temporary runtime probe
- Trivy Operator was generating vulnerability/config/RBAC/compliance reports; the demo image had no vulnerability findings at capture time, while one medium configuration finding was retained in the evidence instead of hidden
Reproducibility
- Local Runtime Evidence
- Engineering Evidence
scripts/local-runtime-verify.shremains the safe/read-only verification path- destructive game-day and restore exercises remain explicit operator actions
Evidence boundary
This release proves local Kubernetes runtime behavior. It still does not claim:
- GitHub→AWS OIDC role assumption;
- S3/KMS Terraform state;
- EKS control plane or managed nodes;
- AWS load balancer/NAT behavior;
- AWS-priced OpenCost data;
- multi-region failover.
The Velero proof used local MinIO-backed storage and must not be represented as AWS backup evidence.