- Architecture overview
- Architecture diagrams
- Runtimes
- A2A gateway (architecture)
- AGT boundary
- Per-sandbox identity (Entra Agent ID) — deep dive
- Multi-tenant model
- Egress proxy
- Security overview
- Feature maturity & status
- Control mapping
- STRIDE × trust boundaries
- Red team playbook
- CRD trust model
- Security validation
- Supply-chain posture & OpenSSF Scorecard
- MCP top-10
- Upstream alignment
- kars OpenClaw plugin
- kars Hermes plugin
@kars/meshplugin (local OpenClaw)- Channels & external plugins
- MCP servers
- Operator TUI
- Permissions model
- Per-sandbox identity (Entra Agent ID)
- Examples catalogue
- Operations overview
- A2A gateway (operations)
- BYO strict mode
- Branch protection
- Chaos tier
- GitOps
- Helm packaging
- Image versioning
- Upgrades & rollback
- Secret rotation
- Supply chain
- CRD reference
- KarsEval (operator guide)
- Lifecycle & reconciliation
- Conditions
- Policy canonical format