Skip to content

E0: OCM substrate and falsification #18

Description

@gnanirahulnutakki

Goal. prove, in a lab, that OCM's cluster-proxy + managed-serviceaccount deliver outbound-only, cross-network, reach-cluster-local-services connectivity with scoped tokens — so the whole "build a transport/agent" scope can be deleted.

Phase / depends. M0 · Depends on: nothing · Nature: a spike, not product code. The only artifacts are a documented yes/no verdict and a reproducible runbook. No Sith product code is written until this passes.

Capabilities: minions (OCM outbound agents); the falsification that deleted bespoke-transport scope (ADR-0001 Accepted — M0 PASSED).

Features

  • F0.1 — hub + spoke lab provisioning
  • F0.2 — OCM addon enablement
  • F0.3 — reach a spoke-local service through the tunnel
  • F0.4 — scoped token projection
  • F0.5 — outbound-only verification
  • F0.6 — falsification verdict and runbook

Tracked issues (already filed)

Exit criteria

  • OCM hub + 2 spokes stand up, both Available; both addons healthy at pinned v0.10.0.
  • The hub reaches a spoke-local service through the cluster-proxy tunnel using a scoped MSA token, on both spokes, with no cluster-admin kubeconfig anywhere.
  • Spoke → hub traffic is verified outbound-only with no inbound port required.
  • ADR-0001 records the verdict and setup time; a redacted runbook and a demo capture exist.
  • The transport-build scope is deleted (on "yes"), or work stops for re-evaluation (on "no").

Source: docs/EPICS.md, docs/SITH-NOTION.md · part of the Sith implementation backlog (see the master roadmap issue).

Metadata

Metadata

Assignees

No one assigned

    Labels

    epicEpic tracking issuemilestone-0Milestone-0: OCM falsification testocmOpen Cluster Management substratespikeTime-boxed investigation / falsification experiment

    Type

    No type

    Projects

    No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions