Repository navigation
feat(deployment): verify Kubernetes first-boot observations - #24
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add a read-only Kubernetes first-boot verifier that compares rendered workloads with explicitly scoped observations. It checks ownership, pod configuration, image digests, PVC configuration/capacity, and readiness; missing application evidence stays blocked, and application acceptance always remains
not_qualified.The CLI supports offline JSON and bounded AnyIO collection with fixed GET arguments, explicit context/namespace, streaming byte limits, deadlines, and cancellation cleanup. API-injected service-account mounts are accepted only when their matching projected volume is validated. Collection inherits the operator's trusted environment and kubeconfig, whose credential plugins may execute locally.
Validation: 95 offline cases, full pytest, environment mypy, normal commit checks, and strict docs passed locally. The clone repair also passed jscpd differential/census on the committed candidate against current main
2abb9ebb3905e2daedc3e4c5e83dc5682c13f2bd. Hosted CI run 37175887401 passed gates, scanner quality, and build on exact head80a4c66e071862f1335f2e3487090005f728d62e. No live-cluster acceptance is claimed.