Workloads: Stable? Secure? Observable? Security: - Namespace isolation - API access limitation - RBAC/ServiceAccounts - PSS/PSA
Observability: - Tool stack - Cluster & workload info - Logs, metrics & traces Network (inboud traffic): - Ingress controller selection - Gateway API - Own custom implementation Traffic control: Network policies Encryption Advanced routing
Infrastructure: - Provide underlying hardware - VMs for cluster - Storage (classes) for PVs - Provide backup (cluster & workloads) - Access to managed services - High-scale of nodes req. network tuning