Skip to content

Harden Kubernetes homelab agent for K8SHomelab - #7

Merged
Quazmoz merged 1 commit into
mainfrom
feat/harden-k8s-homelab-agent
Aug 24, 2026
Merged

Harden Kubernetes homelab agent for K8SHomelab#7
Quazmoz merged 1 commit into
mainfrom
feat/harden-k8s-homelab-agent

Conversation

@Quazmoz

@Quazmoz Quazmoz commented Aug 24, 2026

Copy link
Copy Markdown
Owner

Summary

Qualify the Kubernetes homelab agent specifically against the current Quazmoz/K8SHomelab repository.

Changes

  • rewrite the canonical homelab agent around current repo/runtime evidence rather than stale topology assumptions
  • enforce K8SHomelab's Graft-first AGENTS.md workflow with a truthful GitHub-only fallback
  • separate Git desired state, Flux controller state, Kubernetes runtime state, persistent data, and secret state
  • make Flux watched-branch writes and prune: true explicit mutation boundaries
  • add multi-cluster/kubeconfig safety and explicit context verification
  • make Oracle/WireGuard behavior conditional on current evidence
  • harden SOPS, destructive-action, retry/timeout, storage/network, and AI/MCP automation guardrails
  • add a GitHub Copilot wrapper, quickstart, and 20-case adversarial acceptance suite
  • update the GitOps change-management and homelab troubleshooting skills

Qualification target

The existing Validate AgentDefaults workflow must pass before merge. Runtime Kubernetes health is outside this repo-only change and is intentionally not claimed.

@Quazmoz
Quazmoz merged commit 3a3bd34 into main Aug 24, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant