Skip to content

v0.7.1 — Local Recovery & Runtime Security Evidence

Latest

Choose a tag to compare

@fadyy2k fadyy2k released this 22 Sep 14:34
c559a15

Engineering intent

Extend the v0.7 local-runtime milestone with recovery, failure-injection and deeper runtime-security evidence while preserving the boundary between local Kubernetes proof and AWS/EKS proof.

New runtime evidence

Captured on kind / Kubernetes v1.36.4:

  • signed immutable project image admitted by server-side policy evaluation
  • mutable project tag denied by the digest policy
  • syntactically valid but unknown project digest denied by ImageValidatingPolicy
  • namespace Pod Security restricted enforcement confirmed
  • Prometheus 14/14 active targets UP, including platform-demo 2/2
  • controlled error-burn injected 200 HTTP 503 responses and the Deployment recovered to 2/2
  • PDB/HPA runtime state captured after recovery
  • Velero backup Completed and namespace-mapped restore Completed, with the restored Deployment reaching 2/2 against local MinIO-backed storage
  • OpenCost returned live namespace allocation data and VPA returned a measured recommendation in Off mode
  • Falco produced a Kubernetes-attributed Critical event from a benign temporary runtime probe
  • Trivy Operator was generating vulnerability/config/RBAC/compliance reports; the demo image had no vulnerability findings at capture time, while one medium configuration finding was retained in the evidence instead of hidden

Reproducibility

Evidence boundary

This release proves local Kubernetes runtime behavior. It still does not claim:

  • GitHub→AWS OIDC role assumption;
  • S3/KMS Terraform state;
  • EKS control plane or managed nodes;
  • AWS load balancer/NAT behavior;
  • AWS-priced OpenCost data;
  • multi-region failover.

The Velero proof used local MinIO-backed storage and must not be represented as AWS backup evidence.