Skip to content

Post-review deferred items (from #9/#11 review) #15

Description

@snese

Deferred non-blocking findings from the #9/#11 review, batched:

  • SandboxTemplate hardcodes the gvisor toleration — parameterize the
    tier-owned scheduling fields (toleration + nodeSelector) from
    sandbox.runtimeClassName per the ADR-0007 extension contract, with a
    rendered-fixture test proving a values-only new tier schedules correctly
  • Conformance script: run in a dedicated conformance-${RUN_ID} namespace
    with run-scoped PVC names + cleanup trap; add a gVisor × NetworkPolicy
    combined probe (allowed 443 + denied non-443 under the gvisor RuntimeClass)
  • Amazon VPC CNI add-on: select an explicitly supported version for the
    declared EKS version and document the upgrade procedure (currently floats)
  • Fix EKS version drift in comments (1.34 → 1.35)
  • Evaluate NETWORK_POLICY_ENFORCING_MODE=strict with enumerated
    startup flows and rollback criteria (ADR-0008 startup-window caveat)

Metadata

Metadata

Assignees

No one assigned

    Labels

    area/runtimeSandbox runtime, gVisor, isolation tiersarea/securityNetworkPolicy, IAM, tenant isolation

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions