A companion package (outside the network-free hux/ service package) that independently verifies and binds the whole release chain before any transition: reviewed proposal URL, Jenkins job/build/result and revision, immutable Harbor tag/digest equality, Flux kustomization and applied revision with pin containment, desired workload image, every Ready pod imageID, bounded-age health receipt, and rollback target. Pure injectable verifier core, HTTPS-only collectors (SA token for the Kubernetes API), and an evidence-trust driver that posts exactly one If-Match transition with deterministic idempotency. Rejects stale, replayed, downgraded, incomplete, cross-workload, mismatched, and self-asserted evidence. 100% line and branch coverage (71 tests). Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BvMSXH8VH2tMWXanb8SJdf
titan-iac
Flux-managed Kubernetes desired-state config for bstein.dev.
Canonical source URL:
ssh://git@scm.bstein.dev:2242/atlas/titan-iac.git
Scope
This repo contains cluster configuration consumed by Flux:
- platform/infrastructure manifests
- service manifests and kustomizations
- operational scripts for render/reconcile workflows
Apply model
I use Git + Flux as the source of truth and avoid manual in-cluster edits for durable changes.
Description
Languages
Python
74%
JavaScript
10.2%
Shell
6.2%
TypeScript
3.9%
Go
2.1%
Other
3.4%