You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Deferred non-blocking findings from the #9/#11 review, batched:
SandboxTemplate hardcodes the gvisor toleration — parameterize the
tier-owned scheduling fields (toleration + nodeSelector) from sandbox.runtimeClassName per the ADR-0007 extension contract, with a
rendered-fixture test proving a values-only new tier schedules correctly
Conformance script: run in a dedicated conformance-${RUN_ID} namespace
with run-scoped PVC names + cleanup trap; add a gVisor × NetworkPolicy
combined probe (allowed 443 + denied non-443 under the gvisor RuntimeClass)
Amazon VPC CNI add-on: select an explicitly supported version for the
declared EKS version and document the upgrade procedure (currently floats)
Fix EKS version drift in comments (1.34 → 1.35)
Evaluate NETWORK_POLICY_ENFORCING_MODE=strict with enumerated
startup flows and rollback criteria (ADR-0008 startup-window caveat)
Deferred non-blocking findings from the #9/#11 review, batched:
SandboxTemplatehardcodes thegvisortoleration — parameterize thetier-owned scheduling fields (toleration + nodeSelector) from
sandbox.runtimeClassNameper the ADR-0007 extension contract, with arendered-fixture test proving a values-only new tier schedules correctly
conformance-${RUN_ID}namespacewith run-scoped PVC names + cleanup trap; add a gVisor × NetworkPolicy
combined probe (allowed 443 + denied non-443 under the gvisor RuntimeClass)
declared EKS version and document the upgrade procedure (currently floats)
NETWORK_POLICY_ENFORCING_MODE=strictwith enumeratedstartup flows and rollback criteria (ADR-0008 startup-window caveat)