feat(sre): register privileged authority and isolate Kubernetes credentials - #551
feat(sre): register privileged authority and isolate Kubernetes credentials#551Pal Lakatos-Toth (pallakatos) wants to merge 64 commits into
Conversation
…tials Introduce operator-controlled UID enrollment, reviewed legacy-grant migration, renewable router-private Kubernetes identity and a filtered HTTPS compatibility proxy. Preserve Azure identity and pinned Hermes interfaces; block legacy token aliases and Secret-watch authority. Add lifecycle preflights, retained admission gates and real Kind acceptance coverage. Live API qualification and genuine sign-offs remain pending. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Dependency Review✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.OpenSSF Scorecard
Scanned Files
|
Restore the external-mesh no-probe rejection contract while keeping authority preflight ahead of artifact resolution and every deployment write. Cover a valid core target whose SRE preflight fails without mutation. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Publish real standard conditions and CRD metadata, distinguish immutable Secret type rejection from admission-policy denial, and make CLI fixture resource matching exact. Add hostile-input regressions for the CodeQL-reported readiness flows without changing flagged production paths, destinations or authentication. Specific false-positive dispositions still require approval. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Select the existing AWS-LC provider before this test creates TLS clients or servers, so nextest isolation does not rely on another test initializing process state. Record the user-approved dispositions for the four specific CodeQL HTTP-flow false positives; production proxy paths and destinations remain unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Supply the required inference reference in both legacy control-consumer and reserved-source admission fixtures so real API tests reach their intended policy boundary. Report only harness source coordinates, exit code and an allowlisted category when commands fail; keep credentials and response bodies out of diagnostics. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…ests Use the existing pinned Kind/kubectl/Helm tools and identical node configuration for a fast independent API-server dry-run. Preserve only allowlisted 422 causes for the exact public SRE CRD, retain generic command privacy, and classify native kubectl CRD Invalid errors. No production or schema change; root cause remains to be established by hosted API evidence. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Hosted Kubernetes v1.31.0 rejected the public CRD with HTTP 422: both custom namespace field accesses are undefined. Add a diagnostic-only escaped-accessor candidate and real positive/negative instance checks in the disposable schema job. The unchanged production schema must still pass its own gate; candidate success cannot turn that failure green. Production/schema files remain unchanged pending parent review. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Kubernetes v1.31 rejects the custom namespace accesses as undefined fields. Use the schema's CEL-escaped accessors while keeping the wire fields, namespace equality and singleton checks unchanged. Disposable API evidence accepts the corrected CRD and canonical instance and rejects foreign-namespace and noncanonical instances. Full SRE migration qualification remains required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Helm 4.2.4 in real Kind acceptance rejects the removed list --all flag before staging. Retain Helm 3 behavior; retry only its exact unsupported-flag error after confirming Helm 4, whose default inventory includes all statuses. Share this bounded compatibility path across SRE install and authority stage. Propagate all other discovery errors and preserve context, existing releases, ownership checks and staging semantics. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The staged legacy fixtures cannot acknowledge inference policies before enrollment. During this setup only, use Helm 4 legacy built-in readiness waits, retaining Helm 3 behavior. The immediately following real SRE migration gate remains mandatory and fatal before unrelated tests; no production readiness or policy is relaxed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Retarget the next prerequisite to kars-bridge. Carry only predecessor audit records and merge ancestry; retain all SRE schema, CLI and acceptance repairs. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Add a disposable image-free controller Pod admission proof and bounded policy/ReplicaSet diagnostics. Preserve migration/readiness gates and publish no workload specs, credentials, argv or generic API bodies. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Handle adjacent JSON objects as well as Lists and expose only fixed diagnostic stages before parsing. No policy or runtime behavior changes. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
A missing observation on an unrelated resource policy must not suppress controller Pod creation diagnostics. Wait first, collect actual admission evidence, and still fail the observation gate. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The actual API admits the public Pod and Deployment but the Deployment remains unobserved. Record controller-manager restart/exit metadata and only fixed panic categories plus public Go frame names, stripping all log contents and arguments. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
After the unchanged production probe fails, test only the API-evidenced additionalProperties:true adapter candidate in disposable Kind. Preserve all admission policies, require actual controller Pod creation and exact tenant/private denials, and verify arbitrary JSON params survive. Production schemas and readiness gates remain unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Use a field-local preserved-unknown object schema in both Rust generation and Helm instead of boolean additionalProperties. Actual Kubernetes 1.31 A/B evidence restores controller-manager and Pod creation while preserving nine ordinary/private admission and JSON round-trip outcomes; no policy is relaxed. Run the admission cases against the successful shipped schema and fix test imports for real harness discovery. Rust, schema drift and full migration qualification remain required in hosted CI before readiness. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Bind synthetic token Secrets to real fixture ServiceAccount UIDs with complete public CA and namespace data, preventing healthy TokenController garbage collection or JWT generation. Preserve precise admission and immutable-type denials, prove unowned same-name identity quarantine and replacement, and retain primary failures during fenced cleanup. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The real token fixture lifecycle now passes on hosted Kind, but a later reviewed migration is Blocked. Identify exact checked-in controller rejection sites and numeric Kubernetes statuses before teardown without printing status detail, API bodies or credentials; keep the fatal acceptance gate unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Do not delete a fixture ServiceAccount if Secret cleanup fails: native TokenController could otherwise garbage-collect a foreign token Secret replacement. Independent cleanup continues and the original acceptance failure remains primary. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Run a bearer-only actual controller ServiceAccount UID proof against the unchanged chart policies and roles, using pinned historical reader bindings with unrelated survivors. Compare exact UID/RV-fenced retirement dry-runs before, during and after a disposable exact-named reader bind grant. Preserve custom-role denials, pending-only admission and all persistent reviewed resources; never execute images or publish credentials. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The hosted proof found that the immutable legacy chart has no helpers template. Render only its three actual required files, and report sanitized public diagnostic source coordinates without exception text or request data. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Hosted Kind proved the same controller-principal retirement PATCH is denied by RBAC without named reader bind and accepted with only that bind, while the custom role remains denied. The wrong-UID control is Kubernetes 422 immutable-field validation, not resourceVersion Conflict; require that exact metadata.uid cause without counting arbitrary 422s as proof. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Actual Kubernetes proof requires the named default reader bind permission even for subtractive updates. Add only that name; never grant wildcard bind, escalation, cluster-admin or custom-role authority. Prepare identical UID/RV-fenced patches and dry-run every retirement before any real mutation, preserving unrelated subjects and the legacy consumer on preflight failure. Keep API races fail-closed without claiming multi-resource rollback. Full hosted Rust and migration qualification remain required before readiness. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Create only the 18 CRDs rendered from the exact historical archive after validating inventory, schema content and absence. Attach legitimate release ownership and wait for Established plus API discovery before the unchanged historical post-install hook. Reject adoption, conflicting creates and unrelated API errors; preserve migration ordering and production guards. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Read-only saved tables show ACCEPT policies and zero UID-1000 rule hits despite UID-1001 transport failure. Compare exact-source full guard, filter-only (retaining every agent DROP restriction), and legacy-backend full guard in new no-credential/no-mount same-node controls. Never alter the SRE Pod's guard; reject unreviewed command/image/extra inputs and fence cleanup by UID/RV. Missing legacy tools are explicitly unavailable, not accepted. Python: 79 passed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Exact-source full nft, filter-only and full legacy guard controls all connect, so do not change the production firewall on a guess. Copy SRE policy only onto a uniquely selected no-credential control Pod, alongside a separate deny-all control, allowing bounded propagation before TCP checks. Never modify the SRE policy or unrelated Pods; UID/RV-fence cleanup. Python: 80 passed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The copied SRE policy and separate deny-all policy both block the otherwise-working controls. In an owned empty control only, append exact ready API endpoint IP/HTTPS-port rules, retain the complete unchanged guard, and test actual UID 1001 connectivity alongside UID 1000 denial. No SRE production policy is changed. Preserve source policy bytes except the candidate rule/isolated selector and fence cleanup. Python: 81 passed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Real Kind policy controls prove that the Service VIP allowance misses the translated API endpoint. Adding only the exact endpoint IP/HTTPS port restores UID-1001 connectivity while UID 1000 remains blocked with the unchanged full guard. Discover only canonical live Service/Endpoints, validate the configured HTTPS target, bound/deduplicate ready same-family endpoint pairs, and fail closed on bad/incomplete data. Grant only named kubernetes Endpoints GET to the existing authority controller; refresh SRE reconciliation every 30s. Restore normal same-run CI build dependency and remove temporary verbose progress logging. Python 81 and Helm lint pass; all Rust compilation/tests remain hosted, no local Cargo. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The post-DNAT correction passes actual install and router readiness; the next unchanged-Hermes Secret GET raises HTTPStatusError. Report only HTTP status, allowed Status reason, checked-in response-source coordinates and harness call site; never exception text/URLs/headers/body data. Collect bounded authority facts from Ready routers too. Temporarily replay full Kind with verified source-equivalent 6b01d03 CI binaries while Rust gates run independently. Python: 82 passed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Actual unchanged-Hermes GET succeeds; LIST returns 502 from the per-item Secret validator. Accept omitted kind/apiVersion only within a typed SecretList envelope, reject conflicting explicit types and malformed metadata, and retain the exact metadata whitelist/value erasure. Exercise native typeless list items in the HTTPS integration fixture and record only owned synthetic-Secret wire-shape booleans in real Kind. Restore normal same-run CI binaries; Python 83 passed, no local Cargo. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Real Hermes GET/LIST filtering now passes. Record only the unchanged log reader's status/known rejection source and marker booleans, never log contents or error bodies. Compare text/plain, application/json and wildcard Accept against a bounded one-line log request on the owned Kind control-plane Pod. Production code and all normal CI dependencies remain unchanged; 84 Python tests pass. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Real Kind API proof: Accept text/plain returns 406 for Pod logs, while application/json and wildcard return 200. Use wildcard only on the bounded upstream log path; keep the facade's plain-text response, byte/query caps, private authority checks and all JSON/media boundaries unchanged. Add HTTPS regression reproducing the native 406 before verifying raw log delivery. Python: 84 passed; no local Cargo, normal CI dependencies retained. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Real legacy acceptance now passes reads, logs, metrics, Pending proposals and denial paths, reaches Retired, then stalls deleting the namespace with Deployment/sre still present. Add sanitized namespace conditions and real UID/RV-fenced DELETE dry-runs comparing the existing namespace-controller and Kars controller principals. Preserve the consumer guard and grant no new permissions. Python: 85 passed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The prior binding experiment already owns the canonical no-execution consumer. Reuse it only with exact captured UID and unchanged spec after that experiment completes; never adopt an arbitrary existing Deployment. Extend safe failure coordinates to the case module. Production cleanup candidate remains local pending actual API proof. Python: 86 passed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Add actual dry-run CREATE/UPDATE cases for namespaced tenant attempts using the approved private parent's real UID, private ReplicaSet owner-reference edits, trusted Deployment-controller updates and private parent Deployment updates. Retain all existing tenant negative and real built-in UID-chain cases. Fix DELETE dry-run proof to set DeleteOptions.dryRun in the body. No production code or policy changes in this commit; pending cleanup repair remains local for parent review. Python: 89 passed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Real Kind reaches Retired but namespace cleanup stalls with Deployment/sre retained. Real API DELETE proof confirms namespace-controller is correctly denied while the existing registrar-authorized Kars controller is allowed. Delete only the captured UID-owned, still-owned, replicas-zero Deployment with current UID/RV preconditions after Pod quiescence; wait for actual removal and preserve foreign namespaces, replacements, ownership changes and finalizers. Already-Retired audit records can finish this owned cleanup without reissuing authority. Add focused retirement race/error/idempotence tests; no new RBAC or admission exception. Python 89 pass; Rust validation remains hosted with no local Cargo. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Real namespace conditions report no remaining content/finalizers but ContentDeletionFailed from no-such-key name in private-identity/role match conditions. Kubernetes 1.31 collection deletion preserves an empty request name while validating each actual oldObject. Resolve optional request/object/oldObject names safely in exactly three match conditions; retain all authorization predicates and Deny bindings byte-identical. Add real ordinary/protected collection DELETE dry-runs proving namespace-controller cleanup is allowed only for ordinary objects and protected targets still require registrar authority. Python: 91 passed; Helm lint and exact guard-diff checks passed. No namespace finalizer force or new privileges. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The API rejected optional-chain name selection at policy creation. Use explicit has-guarded request/object/oldObject names instead, retaining protected oldObject matching and every authorization predicate. Add only bounded compiler field/token/category diagnostics for known public policies; never error bodies. Python 92 passed and Helm lint passed; real API compilation/collection tests remain mandatory. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
The API still rejects the collection match condition before execution. Capture its first compiler-description line using only fixed compiler vocabulary and identifiers from the exact public expression; redact all other tokens and retain no arbitrary error body. This is harness-only; all failing technical gates remain enforced. Python: 92 passed. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Actual CEL compiler evidence reports expected string but found dyn for the temporary list of request/object names. Replace that list/comprehension with direct presence-guarded OR comparisons, retaining each protected request/object/oldObject name and every registrar authorization condition. No coercion, collection bypass, new privileges or finalizer changes. Python 92 and Helm lint pass; actual API compile/collection cases remain mandatory. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Full Kind now completes legacy and fresh SRE acceptance, including namespace cleanup; its sole remaining failure is the ordinary Hermes image-name check conflicting with the explicit SRE stand-in pin. Verify the exact controller-configured HERMES_RUNTIME_IMAGE plus actual Hermes dispatch instead of requiring a substring. Keep the unconfigured fallback and reject wrong/missing images or BYO dispatch; do not blanket-accept stand-ins or skip the assertion. Python: 93 passed; shell syntax checks passed. No production change. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Full Kind on 6ec8542 passes 161 tests with complete legacy/fresh SRE retirement and namespace cleanup. The isolated API proof exposed a deployment-status RV race, not an authorization failure. Keep UID/RV preconditions on every dry-run and retry at most twice only after confirming an actual RV change and no content/identity change beyond status/managedFields. Never retry authorization failures, unchanged-RV conflicts, production writes or cleanup writes. Pause only the zero-replica collection fixture to avoid unrelated rollout bookkeeping. Python: 95 passed; existing focused CLI SRE tests: 11 passed with unchanged timeout limits. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Maintainer approval and delegated review authorityRecorded by GitHub Copilot from Pal Lakatos-Toth (@pallakatos)'s instruction in the current publication session. The maintainer approved the author audit for source head
Additional independent-context reviews are now covering:
Any delegated AI audit attestation will explicitly identify it as AI review, record its scope and outcome, and cite this maintainer authorization. It will not claim that another human reviewed or signed the change. The repository's normal two-person process is not being silently reinterpreted; the final record must disclose this maintainer-authorized delegation for the publication work. This comment records authorization, not completion of the additional reviews. Blocking findings must be repaired and re-reviewed before delegated sign-off. Technical/security gates remain required; no failed outcome may be rewritten or waived by this authorization. The destination remains protected |
…et cluster Use the Helm 3/4 built-in waiter before explicit enrollment, and repair only the exact historical action params schema with UID/resourceVersion fences before dependent policies. Preserve mandatory migration and policy readiness gates. Bind resource-group deletion to a pinned subscription, complete AKS resourceUID inventory and ARM-issued private kubeconfigs. Reject context mismatches and --all --local; never modify global kubeconfig. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Include core/v1 ReplicationController CREATE and UPDATE in the existing private-template admission boundary. Preserve the exact authority exemptions and keep the ReplicaSet handoff exception restricted to apps/replicasets. Handle selector-only RCs without a template without broadening any private-template path. Add image-free cases plus safe active-SRE CREATE/UPDATE coverage for secret volumes, projections, environment/init references and private ServiceAccount selection. Only an ordinary zero-replica object is stored; private requests are dry runs with no credential-reading payload or workload execution. Cleanup is UID/RV fenced. All 99 Python harness tests and Helm lint pass; native policy proof and independent security re-review remain required. No public push or signoff yet. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…epairs Combine the completed staging/target-binding fixes and ReplicationController boundary repair without altering the existing SRE runtime/privacy implementation. Focused final patch review and exact-head CI remain required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
…lers The actual Kubernetes 1.31 schema job admitted all new RC private/ordinary cases except the no-template fixture, which correctly returned 422. Kubernetes ValidatePodTemplateSpecForRC requires spec.template even at zero replicas. Assert the precise Invalid/spec.template/FieldValueRequired rejection rather than expecting 201 or accepting arbitrary errors. No production policy or authority changes. All 104 Python tests pass. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Record the maintainer's explicit author approval and delegation after focused independent-context AI reviews. Identify Copilot as delegated AI review, not a second human; preserve exact source/evidence scope and every required technical gate. The RC boundary and three staging/teardown fixes have final source review closure. Integration and customer rollout are not implied by the audit. Read temporary test kubeconfig permissions and contents through one open descriptor to address the new CodeQL test-only filesystem race without suppressing a query. All 111 affected CLI cases, typecheck and targeted lint pass with the existing compatible cache; exact-lockfile hosted qualification remains required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Refresh the existing RC fixture immediately before dry-run UPDATE instead of reusing the version read before a separate CREATE preview. Reuse the existing status-only snapshot comparison and permit at most three attempts solely for genuine 409/Conflict with a changed version. Reject identity, template or deletion changes; never retry other denials or count conflict as success. Emit only fixed variant/method/status diagnostics before the still-fatal assertions. The preceding full Kind run stopped at ordinary RC acceptance but did not retain the method/status detail. This repairs the proven stale-snapshot window and preserves diagnostics if a different cause remains; no production policy, timeout or guard is relaxed. All 107 Python harness tests pass; native qualification remains required. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Full native qualification completed the SRE legacy/fresh lifecycle and RC boundary cases, then an immediate smoke lookup raced NetworkPolicy creation after the namespace appeared. Reuse the existing bounded exact-resource helper for NetworkPolicy and ServiceAccount creation. Preserve failure when absent and all later policy-content assertions; do not replace actual enforcement proof with a wait. The preceding native job remains recorded as 164 passed/1 failed. All 108 Python harness tests and shell syntax checks pass after this test-only correction. Production controller, policy, authority and timeout values are unchanged. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Copilot-Session: eb3654cd-f1e0-445a-8734-430800af1903
Current integration candidate
Head:
6656927e8298f06bc4d499551453c327e74337fa, targeting protectedkars-bridge. The delegated audit is recorded and the unchanged audit gate passes. Final exact-head technical qualification is still required before merge.The maintainer approved the author audit and explicitly delegated subsequent sign-offs after additional focused reviews: authorization. The audit identifies Copilot as delegated AI review, not a second human reviewer. No technical check or security finding is waived.
Purpose and scope
Replace legacy SRE agent access to cluster-wide Secrets with explicitly enrolled, UID-bound authority and a compatible private diagnostic proxy. Preserve standalone Kars, the agent's Azure identity, safe Hermes diagnostic access, unrelated resources and reviewed retirement/rollback behavior.
KarsSRERegistration/canonicalbinds controller/release, Sandbox and Namespace identities; registrar permissions are unbound by default.Focused review repairs now included
apps/replicasets.Final focused static reviews reported no remaining significant issue in the repaired scopes. They are AI review evidence, not universal security assurance or native execution proof.
Qualification
security-audit-required, passed.203e2322passed full Kind, 161 cases; this is prerequisite evidence, not a replacement for this changed head's native checks.Audit and full provenance: registered SRE credential authority.
This prerequisite precedes #550. It is not complete Bridge publication, downstream budget/credential/CNI acceptance, a model-run demonstration, permission to promote
main, or a customer/H100 deployment. All normal merge safeguards remain required.