Threat model
Protected:
- state reconciliation and service restart
- per-namespace policy application
- explicit deploy approvals
Operator responsibility:
- host hardening
- key lifecycle and secret distribution
- firewall ingress scope and SSH policy
- update cadence and patching