Platform

Kubernetes

Every object-metadata type plans, carries the estate label, is swept for orphans, and is fenced by one admission policy that reads it; the gauntlet runs its stages on a kind cluster in a lane of its own, where the first estate clears every applicable stage, migration from a stock state included (#1073).

Every Kubernetes type with object metadata, and every custom resource through kubernetes_manifest, plans, carries the estate label on create, is swept for orphans by that label, and is fenced by one admission policy that reads it. These five pages say what is proven on a real cluster and what is refused by name, slot by slot, rather than saying “AWS only”.

The research is #1016. Everything below cites it or says it is unverified.

  1. Adopt What binds today, what a marker would look like, and the two shapes that are refused rather than guessed.
  2. Gate RBAC cannot express the fence. One admission policy on the label can, for writes, cluster-wide, and the grant is an ordinary ClusterRole.
  3. Operate Rename is a config edit, a version bump is not a move, and deletion is refused until controller-created objects are excluded.
  4. Compatibility Every object-metadata type plans through one rule; what is refused by name, and how a mixed EKS estate is reported.
  5. Proof Which claims are proven on a real cluster, which are restated, which do not apply, what a sweep costs, and the kind-cluster harness every Kubernetes unit runs against.

Everything on these five pages links down into the evidence: the runnable claims, the gauntlet, the measurements, and the per-type lookup.