railiance-cluster/workplans/ADHOC-2026-07-27.md
codex 105ea19ba9
All checks were successful
CI Smoke / host-smoke (push) Successful in 0s
CI Smoke / container-smoke (push) Successful in 0s
Bind Knative init-gate work record
2026-07-27 07:49:40 +02:00

1,007 B

id type title domain repo status owner topic_slug created updated state_hub_workstream_id
RAIL-BS-ADHOC-2026-07-27 workplan Knative fail-closed init-container support financials railiance-cluster finished codex railiance 2026-07-27 2026-07-27 23927620-bb42-4c9b-be95-48b4b17431e4

RAIL-BS-ADHOC-2026-07-27

Enable and verify Knative init containers

id: RAIL-BS-ADHOC-2026-07-27-T01
status: done
priority: high
state_hub_task_id: "7e2988c6-d6f4-46b6-8c88-148a9ed186a7"

Enable only kubernetes.podspec-init-containers in Knative config-features, persist the idempotent installer patch, and assert it in the verifier. This supports fail-closed workload admission after asynchronous NetworkPolicy reconciliation.

2026-07-27: Enabled the feature on railiance01 and validated a rapp-qonto Knative Service containing a restricted init container through the live admission webhook. A disposable same-policy pod proved gate=passed before application=admitted.