# Triage a Kubernetes workload — acceptance checklist

Record evidence for every checked item. Unchecked or untested is not a pass. This checklist does not execute an integration or authorise external actions.

## Required inputs

- [ ] Cluster/context and namespace identifiers with a restricted kubeconfig or service account.

- [ ] The affected workload, incident window and recent deployment or manifest change.

## Output checks

- [ ] Context, account and namespace are verified before every operational session.

- [ ] Read-only server configuration and RBAC are both recorded.

- [ ] The diagnosis cites actual events/logs and preserves contrary evidence.

- [ ] No rollout success is claimed without an observed readiness and error-rate window.

## Deliverables

- [ ] Context and RBAC record

- [ ] Workload event timeline

- [ ] Manifest-linked diagnosis

- [ ] Remediation and rollback proposal

## Evidence and decision

Evidence links: [fill in]
Untested paths: [fill in]
Unresolved findings: [fill in]
Reviewer: [fill in]
Decision and scope: [fill in]

## Boundaries

- The SRE profile has edit and terminal capabilities; its prose does not prevent kubectl or Helm mutations. Keep inspection permissions restricted in the host and cluster.

- The server exposes management tools by default. Network listeners need their own binding/authentication controls, and log queries can reveal sensitive values.

Workflow: https://undominated.ai/workflows/#triage-a-kubernetes-workload
