Deterministic identity/admission installer for containment substrate validation.
- Kubernetes v1.26+ (ValidatingAdmissionPolicy GA)
- AdmissionRegistration enabled
- Cluster-admin privileges for installation
- Conformant Kubernetes API server (no CRD bootstrapping performed by this repo)
This repository does not provision Kubernetes. This repository does not install Kubernetes-owned CRDs.
- Assumes an existing Kubernetes cluster (Kubernetes v1.26+)
- Assumes AdmissionRegistration is enabled
- Does not provision a cluster
- Uses Kustomize only (no Helm)
- Does not include data-plane services, observability stack, storage systems, or research platform components
- Installs minimal identity + admission plane required for containment checks
make installmake validatemake uninstall