Goal. prove, in a lab, that OCM's cluster-proxy + managed-serviceaccount deliver outbound-only, cross-network, reach-cluster-local-services connectivity with scoped tokens — so the whole "build a transport/agent" scope can be deleted.
Phase / depends. M0 · Depends on: nothing · Nature: a spike, not product code. The only artifacts are a documented yes/no verdict and a reproducible runbook. No Sith product code is written until this passes.
Capabilities: minions (OCM outbound agents); the falsification that deleted bespoke-transport scope (ADR-0001 Accepted — M0 PASSED).
Features
Tracked issues (already filed)
Exit criteria
- OCM hub + 2 spokes stand up, both
Available; both addons healthy at pinned v0.10.0.
- The hub reaches a spoke-local service through the
cluster-proxy tunnel using a scoped MSA token, on both spokes, with no cluster-admin kubeconfig anywhere.
- Spoke → hub traffic is verified outbound-only with no inbound port required.
- ADR-0001 records the verdict and setup time; a redacted runbook and a demo capture exist.
- The transport-build scope is deleted (on "yes"), or work stops for re-evaluation (on "no").
Source: docs/EPICS.md, docs/SITH-NOTION.md · part of the Sith implementation backlog (see the master roadmap issue).
Goal. prove, in a lab, that OCM's
cluster-proxy+managed-serviceaccountdeliver outbound-only, cross-network, reach-cluster-local-services connectivity with scoped tokens — so the whole "build a transport/agent" scope can be deleted.Phase / depends. M0 · Depends on: nothing · Nature: a spike, not product code. The only artifacts are a documented yes/no verdict and a reproducible runbook. No Sith product code is written until this passes.
Capabilities: minions (OCM outbound agents); the falsification that deleted bespoke-transport scope (ADR-0001 Accepted — M0 PASSED).
Features
Tracked issues (already filed)
Exit criteria
Available; both addons healthy at pinned v0.10.0.cluster-proxytunnel using a scoped MSA token, on both spokes, with no cluster-admin kubeconfig anywhere.Source:
docs/EPICS.md,docs/SITH-NOTION.md· part of the Sith implementation backlog (see the master roadmap issue).