--- id: RAIL-BS-ADHOC-2026-07-27 type: workplan title: "Knative fail-closed init-container support" domain: financials repo: railiance-cluster status: finished owner: codex topic_slug: railiance created: "2026-07-27" updated: "2026-07-27" state_hub_workstream_id: "9a77bc91-f457-5545-996f-04f49707f54b" --- # RAIL-BS-ADHOC-2026-07-27 ## Enable and verify Knative init containers ```task id: RAIL-BS-ADHOC-2026-07-27-T01 status: done priority: high state_hub_task_id: "fd47a55b-233d-53ec-8005-7e24b2a98e42" ``` Enable only `kubernetes.podspec-init-containers` in Knative `config-features`, persist the idempotent installer patch, and assert it in the verifier. This supports fail-closed workload admission after asynchronous NetworkPolicy reconciliation. 2026-07-27: Enabled the feature on railiance01 and validated a `rapp-qonto` Knative Service containing a restricted init container through the live admission webhook. A disposable same-policy pod proved `gate=passed` before `application=admitted`.