Skip to main content
Version: 0.2.0 (Private Preview)

Admission and drift behavior

Nexo 0.2.0 relies on Operator validation, Kubernetes ownership, managed-resource signatures, and reconciliation for its supported custom-resource graph.

Available 0.2.0 controls

Control0.2.0 boundary
Registered-resource validationOperator validates managed signatures, fields, references, and readiness for its 18 registered kinds
Graph resolutionOperator computes the supported graph and reports status
OwnershipGenerated Deployments, Services, ConfigMaps, and Secret copies follow their owning Nexo resources
ReconciliationOperator converges generated resources and can replace unsupported direct edits
StatusGenerations, conditions, configuration hashes, and graph revision provide evidence

An installed CRD schema does not prove that Operator reconciles it, and a reconciled router resource does not prove that Proxy executes the router phase.

Unavailable in 0.2.0

The later fail-closed identity-focused admission webhook, dedicated managed-namespace scope, two-replica Manager default, webhook PodDisruptionBudget, Kyverno anti-tamper policy set, periodic Manager drift detector, automatic 30-second reversion, and binary integrity monitor were added after the immutable 0.2.0 baseline. Do not configure or claim them for 0.2.0 without a different release manifest.

Consequently, the retired table promising webhook rejection for direct edits, sidecars, security contexts, environment variables, volumes, and Deployment deletion is not a 0.2.0 guarantee.

Direct changes

Do not patch generated workloads as a normal deployment mechanism. Operator reconciliation may replace the edit and separate the running state from approved configuration history. Change the owning supported Nexo resource through the approved workflow and verify the active graph.

Management interruption

Existing Proxy pods can continue with their active configuration while Manager or hosted Control Plane connectivity is unavailable, subject to the rest of the data plane. 0.2.0 does not provide the later Manager drift-check promise when management returns.

Webhook TLS legacy material

The retired cert-manager and OpenSSL examples described a later admission design. They are not 0.2.0 installation steps.

The legacy tamperProtection values, fixed drift-log transcript, enforced/allowed field lists, cert-manager Certificate, and manual TLS Secret examples are all unavailable in the immutable 0.2.0 control set.

Search Nexo documentation

Type to search titles, headings, and page content.