This project tests whether one service can be deployed, observed, and recovered through declared ownership boundaries. Use a disposable cluster, a test cloud account, and synthetic financial records. State the stop conditions before exercising any fault; do not use production credentials or a real customer database.
Project: reconcile production boundaries
Build the release packet
Build one ledger API image and record its digest. Give the workload a dedicated ServiceAccount with no automatic API token if the application does not call Kubernetes. Permit deployment through a short-lived federated identity bound to the test repository and environment. Record the approved image, configuration revision, operator, and observed runtime digest. Issue a test certificate and verify the externally served result after renewal.
Boundary exercise evidence
Artifact: one approved image digest
Identity: allowed test job and rejected unrelated job
Drift: provider audit event and reviewed Terraform plan
Recovery: snapshot, new PVC, compatible database check
Edge: renewed certificate observed by external client
Exit: desired state reconciled and temporary access revokedInject and recover
Change one harmless test infrastructure setting outside Terraform, pause applies, and capture the audit event and plan. Decide whether to update code or restore the declared value; document why. Capture a database-consistent recovery point, restore it to a new PVC, and verify a synthetic balance. Deny one unapproved egress destination while confirming approved DNS still works. Exercise a controlled overload burst and record admitted latency plus rejected work. End with a clean desired-state comparison and revoke all temporary identities.
Cost and verification
The test uses temporary compute, storage snapshots, certificate issuance, and operator time. A successful controller status is not enough: attach the actual client handshake, restored query, denied identity exchange, and provider plan result. Record any check that could not run as unverified. Remove disposable resources after retaining only approved evidence, and confirm that the final test account no longer has temporary access.
Common Mistakes
- Do not treat a green deployment as proof of the intended artifact identity.
- Do not call a snapshot usable until a compatible restore has been tested.
- Do not leave a reconciliation pause or temporary trust rule active.
Connected lessons
- Service account tokens: mount only when the workload needs Kubernetes API access
- Federated workload identity: replace standing cloud keys with scoped trust
- Infrastructure drift: distinguish emergency repair from unauthorized change
- Volume snapshots: test application-consistent restore
- Certificate renewal: verify the served certificate after issuance
- Egress policy and DNS: restrict destinations without breaking name resolution
- Overload shedding: refuse excess work before latency collapses
- Release evidence: tie one deployed digest to one approval decision
- DevOps projects
