railiance-cluster/workplans/ADHOC-2026-07-27.md
codex f1a32bd5a7
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 1s
Enable Knative fail-closed init gates
2026-07-27 07:18:07 +02:00

885 B

id type title domain repo status owner topic_slug created updated
RAIL-BS-ADHOC-2026-07-27 workplan Knative fail-closed init-container support financials railiance-cluster finished codex railiance 2026-07-27 2026-07-27

RAIL-BS-ADHOC-2026-07-27

Enable and verify Knative init containers

id: RAIL-BS-ADHOC-2026-07-27-T01
status: done
priority: high

Enable only kubernetes.podspec-init-containers in Knative config-features, persist the idempotent installer patch, and assert it in the verifier. This supports fail-closed workload admission after asynchronous NetworkPolicy reconciliation.

2026-07-27: Enabled the feature on railiance01 and validated a rapp-qonto Knative Service containing a restricted init container through the live admission webhook. A disposable same-policy pod proved gate=passed before application=admitted.