# Kubernetes triage sheet

Blank working document. Replace placeholders with your own evidence; an empty field is unknown, not a passing result.

Owner: [fill in]
Source revision: [fill in]
Environment: [fill in]
Evidence date: [fill in]

## Access scope

Context/cluster: ___
Namespace/workload: ___
Identity and RBAC: ___
Read-only TOML path/hash: ___

## Observation

Window/time zone: ___
Pod/event/log evidence: ___
Current rollout revision: ___
Sensitive data removed: ___

## Diagnosis

Manifest setting involved: ___
Supporting and contradictory observations: ___
Missing evidence: ___
Proposed minimal change: ___

## Operational handoff

Test environment and result: not run
Readiness/error checks: ___
Rollback condition/owner: ___
Cluster changes executed: not recorded
This inspection does not authorise cluster changes.

## Boundaries

- The SRE profile has edit and terminal capabilities; its prose does not prevent kubectl or Helm mutations. Keep inspection permissions restricted in the host and cluster.

- The server exposes management tools by default. Network listeners need their own binding/authentication controls, and log queries can reveal sensitive values.

Workflow: https://undominated.ai/workflows/#triage-a-kubernetes-workload

Original worksheet: MIT. Linked resources retain their own licences and setup requirements.
