← AgentPlane contents

Restricted Kubernetes Manifest Lab

The renderer outputs JSON, which Kubernetes accepts as an object representation. It does not call kubectl, install a runtime or run a container. Choose a real, reviewed OCI image digest, installed RuntimeClass and supported Pod Security version in your disposable environment.

python3 examples/kubernetes/render.py --help
python3 -m unittest discover -s examples/kubernetes -v

Generate a manifest by supplying all three required arguments. Inspect the output before any manual apply. The image's configured entrypoint runs as UID 10001; it must support that identity and the limited writable paths. There is no DNS or internet allowance. Test fixtures use example.invalid and are not pullable.

The default-deny NetworkPolicy needs an enforcing CNI. Restricted pod settings and a RuntimeClass name do not prove hostile-code containment. The ordinary Pod here is a small teaching specimen, not the production Agent Sandbox adapter. Do not deploy it to a shared or production cluster. Its workspace is ephemeral.