Skip to main content
Prove the plane’s security and operational contracts hold

Synopsis

ACTIVE, where plane status is passive. It asks the world rather than the plane: is the state reachable, are the two keys two keys, does each identity hold exactly the authority the design gives it and nothing it does not, can the plane still assume every connected account. Both directions, on purpose. An identity that has quietly gained kms:Decrypt on the artifact key passes every positive check and is caught only by the negative one — which is why dx.md §16 exists: “this prevents another 7/7 healthy while the system is broken”. The plane’s own identity is read off the ManagementPlane — the SVID it holds, what STS made of it, whether the issuer publishes the signing key — because the pod is the only place the SVID is. What this command cannot prove itself is LISTED with what does. A failure names the violated invariant first: what was required, what was seen, how much it matters.

Options

Global options

See global options.

SEE ALSO

  • kubox plane - Describe and build a management plane from one document