Limitations¶
The operator is deliberately read-only and conservative: it never fabricates a violation from evidence it cannot trust. The boundaries below follow directly from that stance.
Read-only¶
The operator never modifies workloads, restarts pods or changes cluster state. It observes and reports only.
Observation boundaries¶
Several dimensions resolve to Unsupported (which reads as Unknown, never
NonCompliant) rather than guess:
- External or non-Pacto Services -- a dependency backed by an
ExternalNameService, or a Service the operator does not manage, cannot be reached reliably and is reportedUnsupported. - Non-HTTP capability bindings -- health and metrics probing supports HTTP
bindings only; gRPC capability probing is not implemented and returns
Unsupported. - Unbound interfaces and capabilities -- when an interface has no
interfaceBindingsentry (and name-match discovery is off), or a capability's owning interface has no binding, the target port cannot be resolved and the result isUnsupported.
Opt-in features¶
Some observation is off by default because it costs cluster calls or opens an in-cluster request surface:
- Metrics observation requires
--enable-metrics-observation; otherwise the metrics dimension returnsUnsupported. - Active health probing (Tier A) requires
--enable-probing; otherwise health uses only passive readiness-probe and EndpointSlice signals (Tier B). - Interface name-match discovery requires
--interface-name-match-discoveryand only ever assists positive availability -- it never produces an absent or error result.
See Operator configuration for these flags.
NotEvaluated is reserved¶
NotEvaluated is a valid contractStatus enum value that the operator does not
currently emit. A valid, targeted contract with no runtime evidence yields
Unknown, not NotEvaluated. The value exists for parity with the engine
dashboard, which uses it for offline OCI or local sources that were never
runtime-evaluated.
Stabilization delay¶
Confirmed runtime-drift violations only surface after the stabilization window
(--stabilization-window, default two minutes). This trades immediacy for
resistance to transient blips: a single negative observation reads Unknown until
the negative streak spans the whole window.
API version¶
The CRDs are served at v1alpha1. Fields are added conservatively and
additively; see the CRD reference for the current schema.