跳转到内容

Threat model

Protected:

  • state reconciliation and service restart
  • per-namespace policy application
  • explicit deploy approvals

Operator responsibility:

  • host hardening
  • key lifecycle and secret distribution
  • firewall ingress scope and SSH policy
  • update cadence and patching