--- id: RAIL-BS-ADHOC-2026-07-27 type: workplan title: "Knative fail-closed init-container support" domain: financials repo: railiance-cluster status: finished owner: codex topic_slug: railiance created: "2026-07-27" updated: "2026-07-27" state_hub_workstream_id: "23927620-bb42-4c9b-be95-48b4b17431e4" --- # RAIL-BS-ADHOC-2026-07-27 ## Enable and verify Knative init containers ```task id: RAIL-BS-ADHOC-2026-07-27-T01 status: done priority: high state_hub_task_id: "7e2988c6-d6f4-46b6-8c88-148a9ed186a7" ``` Enable only `kubernetes.podspec-init-containers` in Knative `config-features`, persist the idempotent installer patch, and assert it in the verifier. This supports fail-closed workload admission after asynchronous NetworkPolicy reconciliation. 2026-07-27: Enabled the feature on railiance01 and validated a `rapp-qonto` Knative Service containing a restricted init container through the live admission webhook. A disposable same-policy pod proved `gate=passed` before `application=admitted`.