/k8s-onboard — assess a new cluster (monitoring mode)
Acest conținut nu este încă disponibil în limba selectată.
Context: $ARGUMENTS
Invoke kubernetes-platform-ops. Document first, change nothing. Sweep in this order, logging every command as read-only:
- Nodes & versions — count, roles (single master = SPOF), k8s version + EOL, OS/runtime, pressure
- Namespaces and what runs in each
- Workloads & images — versions, EOL, floating tags, requests/limits, replicas, PDBs
- Network — CNI, ingress class + TLS, LB pools (one announcer?), NetworkPolicies (any?)
- Storage — StorageClasses (a default?), PVs + reclaim policy, backups (any?)
- GitOps — ArgoCD apps: are they actually reconciling? prune/selfHeal posture
- Security — cluster-admin bindings, plaintext secrets, TLS coverage, PSA/Kyverno
- Observability — is anything actually alerting? (metrics-server? Prometheus/VM?)
Produce a findings list with severity + evidence for each item. Nothing is “fixed” without observed
proof. This mirrors the ChisinauGaz cg-stage onboarding — see docs/CG-Stage/ if present.