Command Module: Decide Who Can Act
Security asks a different question at every boundary. Who is making an API request? What may that identity do? Which objects may enter the cluster? Which network paths are allowed? Who can read a credential? The answers live in different enforcement points, so one control cannot stand in for the others.
Apollo’s security lab remains planned. That makes this a theory mission with a useful discipline: learn the model now, and describe planned controls as planned until the source snapshot proves them.
What you will understand
The Stage 8 roadmap remains the place to track runnable Apollo work. These chapters do not manufacture a lab or imply that security settings inherit across snapshots.
Mission status
Read Stage 8: Security Enforcement Roadmap for the current Apollo boundary and the evidence a future mission must produce.