Infrastructure Hardening Pass
Announcement · 2026-03-24
Details
We completed a production infrastructure review. Kubernetes network policies now default-deny between namespaces. Rate limits were added at the ingress layer for every public endpoint. Pod security admissions were raised to the restricted profile, and every container runs as non-root. Observability dashboards light up any policy violation instantly. No user-visible change, just a quieter, safer platform to run your workforce on.
What changed
- Default-deny network policies between Kubernetes namespaces
- Per-endpoint rate limits at the ingress layer
- Pod Security Admission raised to restricted profile
- Every container runs as non-root