Activation-layer staging, fail-closed until enablement: a per-tenant hux-evidence-producer sidecar on the exact reviewed WebUI image runs hux_producer.run_once on a 60s loop, inert until the Vault-staged evidence key (tolerant init, tmpfs, 0400, staged only for the hux service and producer containers - never hermes or webui), the policy ConfigMap, and the scope ConfigMap exist. Adds least-privilege read-only RBAC (pods+statefulset in hermes, the single named Flux Kustomization), tenant egress to the Kubernetes API ClusterIP and the traefik edge, the policy allowlist, hux_producer packaging in the WebUI image, and a third expected WebUI consumer in the Flux release renderer. Delivery and image-automation gates enforce the boundary. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01BvMSXH8VH2tMWXanb8SJdf
titan-iac
Flux-managed Kubernetes desired-state config for bstein.dev.
Canonical source URL:
ssh://git@scm.bstein.dev:2242/atlas/titan-iac.git
Scope
This repo contains cluster configuration consumed by Flux:
- platform/infrastructure manifests
- service manifests and kustomizations
- operational scripts for render/reconcile workflows
Apply model
I use Git + Flux as the source of truth and avoid manual in-cluster edits for durable changes.
Description
Languages
Python
74%
JavaScript
10.2%
Shell
6.2%
TypeScript
3.9%
Go
2.1%
Other
3.4%