Platform
Every object-metadata type plans, carries the estate label, is swept for orphans, and is fenced by one admission policy that reads it; the gauntlet runs its stages on a kind cluster in a lane of its own, where the first estate clears every applicable stage, migration from a stock state included (#1073).
Every Kubernetes type with object metadata, and every custom resource through kubernetes_manifest, plans, carries the estate label on create, is swept for orphans by that label, and is fenced by one admission policy that reads it. These five pages say what is proven on a real cluster and what is refused by name, slot by slot, rather than saying “AWS only”.
The research is #1016. Everything below cites it or says it is unverified.
Everything on these five pages links down into the evidence: the runnable claims, the gauntlet, the measurements, and the per-type lookup.