Skip to main content

Command Module: Decide Who Can Act

Security asks a different question at every boundary. Who is making an API request? What may that identity do? Which objects may enter the cluster? Which network paths are allowed? Who can read a credential? The answers live in different enforcement points, so one control cannot stand in for the others.

Apollo’s security lab remains planned. That makes this a theory mission with a useful discipline: learn the model now, and describe planned controls as planned until the source snapshot proves them.

What you will understand​

  1. Identity and authorization
  2. Admission and runtime
  3. Network policy
  4. Secrets and supply chain

The Stage 8 roadmap remains the place to track runnable Apollo work. These chapters do not manufacture a lab or imply that security settings inherit across snapshots.

Mission status​

Read Stage 8: Security Enforcement Roadmap for the current Apollo boundary and the evidence a future mission must produce.