Skip to content

feat(deployment): verify Kubernetes first-boot observations - #24

Merged
Knucklessg1 merged 4 commits into
mainfrom
codex/linux-firstboot-verifier
Oct 4, 2026
Merged

Knucklessg1 merged 4 commits into
mainfrom
codex/linux-firstboot-verifier

Conversation

@Knucklessg1

@Knucklessg1 Knucklessg1 commented Oct 4, 2026 •

Copy link
Copy Markdown
Member

Add a read-only Kubernetes first-boot verifier that compares rendered workloads with explicitly scoped observations. It checks ownership, pod configuration, image digests, PVC configuration/capacity, and readiness; missing application evidence stays blocked, and application acceptance always remains not_qualified.

The CLI supports offline JSON and bounded AnyIO collection with fixed GET arguments, explicit context/namespace, streaming byte limits, deadlines, and cancellation cleanup. API-injected service-account mounts are accepted only when their matching projected volume is validated. Collection inherits the operator's trusted environment and kubeconfig, whose credential plugins may execute locally.

Validation: 95 offline cases, full pytest, environment mypy, normal commit checks, and strict docs passed locally. The clone repair also passed jscpd differential/census on the committed candidate against current main 2abb9ebb3905e2daedc3e4c5e83dc5682c13f2bd. Hosted CI run 37175887401 passed gates, scanner quality, and build on exact head 80a4c66e071862f1335f2e3487090005f728d62e. No live-cluster acceptance is claimed.

@Knucklessg1
Knucklessg1 marked this pull request as ready for review October 4, 2026 04:20
@Knucklessg1
Knucklessg1 merged commit 0da5f74 into main Oct 4, 2026
4 checks passed
@Knucklessg1
Knucklessg1 deleted the codex/linux-firstboot-verifier branch October 6, 2026 14:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant