install.sh now renders the checksum-verified upstream assets through kustomize overlays: CRDs first and verbatim, then serving-core and kourier with the six CPU requests lowered live on 2026-09-21, the Kourier Service as ClusterIP and the Envoy image pinned. verify.sh checks the requests read-only, and tests/test_knative_render.py proves the render offline against upstream and rail-knative's declaration. Not run against the cluster. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com> Assistant: claude-code Assistant-Model: opus Assistant-Process: 63291@bnt-lap001 Assistant-Session: 8bd77868-ca68-4f49-bb1e-d539ecc0d703
10 lines
328 B
YAML
10 lines
328 B
YAML
# Kourier stays ClusterIP; public entry needs separate reef admission evidence.
|
|
# Declared here rather than patched after apply, so a re-run never flips the
|
|
# live Service to the upstream LoadBalancer type, even briefly.
|
|
apiVersion: v1
|
|
kind: Service
|
|
metadata:
|
|
name: kourier
|
|
namespace: kourier-system
|
|
spec:
|
|
type: ClusterIP
|