Security
Layers, each consuming the one before it: OpenBao is the cluster’s secrets and PKI backend; Secrets covers where a credential lives, who may read and write it, and what a developer writes to give an application one of its own; PKI & Secrets covers the certificate half — how cert-manager issues from the PKI — and the bootstrap tier that stays in the cloud’s managed store; Policies covers what’s enforced once a workload is running — Kyverno admission, CiliumNetworkPolicy default-deny, and pod security context.
The repository’s security policy covers reporting, the enforced posture in summary, and the limitations this platform accepts as a reference implementation — including the ones it would be more comfortable not to mention.
These pages describe how the platform implements security. The rules themselves — required security-context fields, RBAC conventions, IAM scoping — are the Platform Constitution; this section links to it rather than restating it.