Disconnected updates, backup, and recovery
Promote platform updates through internal channels and test workload, configuration, data, and evidence recovery.
Internalize the update graph
Platform updates can include operating-system packages, cluster releases, operators, images, policies, drivers, firmware, runtimes, models, charts, and configuration. Import their dependency closure through the controlled SAI-200 supply chain.
Promotion
Declare the current and candidate compatibility sets. Verify provenance, scan and evaluate, rehearse in a representative environment, approve, transfer exact artifacts, stage, roll out within capacity limits, validate, and preserve rollback. Block hidden downloads and external catalog resolution.
Backup scope
Classify and protect cluster configuration, application declarations, internal repositories, model metadata, source data, indexes, evidence, keys, and stateful services. Some derived indexes may be rebuilt, but the source, recipe, permissions, and versions must be recoverable.
Recovery exercise
Test loss of a node, namespace, storage service, registry, model store, cluster control plane, and complete site as applicable. Validate restored identity, policy, network, secrets, model, data, evidence, and application behavior.
Record recovery time, recovery point, manual steps, unavailable dependencies, data loss, integrity results, and approval. Feed gaps into the change backlog.