This project hardens the release boundary for a settlement API. Use a disposable cluster and synthetic ledger records. Produce a release packet that another operator can inspect before a candidate image reaches users; do not treat the output of one tool as the whole decision.
Project: harden a release boundary
Prepare the release
Build once and record the full image digest. Render a pinned chart with reviewed values, then compare the output with current objects. Include the Deployment, Service, resource requests, health probes, route, service account, and expected database schema version. Attach an SBOM and provenance to the image digest. Run the admission rule in warning mode first; after existing violations are fixed, change it to denial in the test namespace. Verify that an image reference without a digest is rejected and the approved digest is accepted.
Settlement release packet
Commit: reviewed revision
Image: full registry digest
Chart: reviewed revision and values checksum
Admission: warning inventory, then deny test
Flag: off by default; owner and expiry recorded
Trace: one synthetic write across API and ledger worker
Recovery: previous digest plus compatible schema confirmedExpose and recover
Deploy with the new path off. Confirm the Gateway route is accepted, then run a synthetic write through the public test hostname and inspect its trace. Enable the feature for one internal account, observe errors and ledger duplicates, and switch it off when a deliberate fault is injected. Check that the old behavior remains compatible with current data. Attempt an approved rollback in the disposable environment and record the result. Close the packet with a named operator, timestamps, and the reason to promote or stop.
Cost and verification
The project consumes temporary cluster capacity, trace storage, and operator review time. A warning-only admission rule does not block a bad release; a full digest reference does not establish provenance. A flag off switch cannot undo completed writes. Preserve the negative tests as evidence, then remove disposable resources. Report any control that could not be exercised instead of marking it passed.
Common Mistakes
- Do not deploy a rendered manifest that was not the one reviewed.
- Do not enable a feature before its off path has been tested.
- Do not use a trace as proof that a ledger write committed correctly.
Connected lessons
- Helm release review: render before applying
- Gateway API routing: accepted route versus working request
- Kubernetes admission policy: reject an unsafe workload before scheduling
- Feature flags: stop exposure without pretending code vanished
- Distributed traces: preserve context without leaking data
- DevOps projects
