The preserved implementation has useful control definitions and selected historical positive and negative results. It also has gaps. A clear gap states what is unverified, why it matters, and what observation would improve confidence. It does not invent a vulnerability, a passing result, or a proposed feature as if it already existed.
| Question |
Available basis |
Missing observation |
| Unsigned regular sidecar beside a signed main image |
Mixed fixtures use unsigned init images |
An isolated regular-sidecar request and API response |
| Ephemeral container added to a running Pod |
No matching captured experiment |
Version-specific subresource test with installed webhook match |
| Signature present, SPDX attestation absent |
Baseline requires both; unsigned test lacks all claims |
Request isolating the missing SPDX claim |
| Signature/SBOM present, provenance absent or malformed |
Policy text and one local predicate fixture |
Independent authenticated malformed/missing-provenance requests |
| Wrong signer alone |
Combined subject and source mismatch capture |
One controlled request changing only subject expectation |
| Wrong provenance source alone |
Same combined capture |
One controlled request changing only source expectation |
| Unmatched registry image |
Policy only verifies configured image pattern |
Scoped live test and review of any separate allowlist controls |
| Excluded namespace |
Source lists five exclusions |
Owner-environment experiment clearly separated from upstream evidence |
not-verified · gapEphemeral-container updates, unmatched-image handling and verifier outages have no established live result in this catalogue.
Expected in this setup: Fresh isolated tests and installed configuration inspection are required to establish each behavior.
Recorded result: No recorded test found for ephemeral-container subresource, isolated unsigned regular sidecar, registry outage or controller outage.
Offline detached baseline inspection; no cloud mutation · observed date unknown · source revision unknown; not inferred from the documentation baseline
Transcript / inspected observation
No execution transcript exists for these cases.
What this does not establish
- Absence from reviewed evidence is not proof of a vulnerability or capability.
- Enforce and webhook name do not establish the complete version-specific outage contract.
Source inspected against the pinned baseline; execution scope stated explicitly. No screenshot or sensitive runtime state published.
Inspect the untouched, commit-pinned original →
These gaps qualify the scope of the catalogue. They do not imply Kyverno lacks a feature; an installed configuration, operation match, and tested result are necessary to establish the project’s effective behavior.
No new cloud connection was made for this task. The committed Kyverno values do not establish the installed chart/controller version or effective webhook failurePolicy. Controller unavailability, timeouts, verifier credential expiry, registry outage, metadata deletion, and transparency-service outage have no demonstrated result in the owner capture set.
The policy’s Enforce mode and a denial from a webhook named svc-fail do not replace those experiments. A reproduction should inspect effective configuration and deliberately test failure paths in an owned environment with recovery access. The historical troubleshooting text documents difficulties; this handbook does not claim a recovery procedure was executed or timed here.
Background reporting is not evidence of retroactive eviction. No recorded action removes already running Pods after an attestation changes, expires, or disappears. That is a different lifecycle question from admission.
The Dockerfile resolves tagged base images and package updates during builds. No reproducible or hermetic build is demonstrated. Provenance is workflow-generated and signed by the trusted workflow; no SLSA level follows from its schema. An authenticated SBOM’s package count is not proof of completeness or safety.
PR and image scans have configured thresholds and ignore behavior. Their passing result does not establish absence of vulnerabilities beyond scanner coverage. Remote branch protection, required reviewer settings, and immutable remote governance were not queried in this documentation task. CODEOWNERS and job gates are inspected source controls, while effective repository settings remain an external-state question.
CI and admission authenticate the same signing workflow and rely on registry evidence. A compromise of that approved workflow can correlate failures across several checks. No independent rebuild or isolated external provenance authority is claimed. See shared failures.
The controlled shell test demonstrates detection after successful execution. It does not demonstrate shell prevention, cryptographic checking by the runtime rule, exhaustive process coverage, automatic containment, or response completion. Its exact artifact-build association is unknown from the pictured tag metadata.
not-verified · gapDiscord delivery and incident response were not demonstrated in the recorded validation.
Expected in this setup: Only an enabled, configured and executed alert test could establish external delivery.
Recorded result: The validation README says the alerting path was disabled pending a real webhook; no Discord capture.
Historical optional GCP alerting path; disabled per validation README · observed date unknown · source revision unknown; not inferred from the documentation baseline
Transcript / inspected observation
Recorded statement: No Discord alert was captured because the alerting path is disabled until a real webhook is supplied.
What this does not establish
- Optional Terraform resources do not establish enabled deployment.
- A runtime log alone does not prove event delivery or response.
Source inspected against the pinned baseline; execution scope stated explicitly. No screenshot or sensitive runtime state published.
Inspect the untouched, commit-pinned original →
External Discord routing was disabled in the recorded validation. A future enabled delivery test must preserve event input, publication result, receiver observation, timestamps and source revision without exposing the webhook. A delivered notification would still be distinct from an investigation or recovery exercise.
Checking out a tag recreates source files, not the original cloud identities, registry objects, webhook versions, repository settings, or canonical main workflow context. The signer and source expectations bind the original repository and refs/heads/main; Argo also reads canonical main. A forked reproduction needs deliberate owned rebinding and should record those differences rather than presenting itself as the original environment.
A complete future evidence trace would connect one source revision, one built digest, authenticated claims, reviewed GitOps selection, installed admission contract, admitted Pod/status and runtime event. The present catalogue preserves the historical pieces that exist and states where that association is incomplete.