Kubernetes graph · bounded planning · repair
- Role
- Creator and engineer
Private beta · benchmark evidence
The YAML is valid.
The runtime path still broke.
I built a local compiler that renders GitOps sources, reconstructs relationships, and proves what a PR changes before a cluster sees it.
- Render
- Map
- Review
- Plan
- Simulate
- Prove
- VALID YAMLObjects render
- GRAPH002targetPort missing
- BLOCKNew path is broken
Not a policy-engine replacement
- Local tools are truth
Helm and Kustomize are rendered before the tool reasons about objects.
SOURCERaw YAML / chart / overlayRENDERNative tool boundaryOBJECTSMaterialized resources - Local consequence graph
Workloads, Services, ports, secrets, volumes, routes, and policies become typed relationships.
WORKLOADPods + controllersNETWORKServices + portsSTATESecrets + volumes - Not a policy-engine replacement
Changed operational paths are separated from baseline debt and promoted into a merge receipt.
VALID YAMLObjects renderGRAPH002targetPort missingBLOCKNew path is broken - Plan does not edit
Task text becomes a recipe, typed slots, desired graph delta, and validation plan before editing.
TASKRequested changeRECIPESupported familySLOTSResolved from graph - Bounded recipe families
Patch IR runs only in a temporary workspace, then render and graph checks decide whether to keep, repair, or refuse.
IRSemantic operationTEMPIsolated workspaceVALIDATEYAML + render + graphKEEP / REFUSEEvidence decision - Claim level: benchmark
Registered capability and mutation gates define exactly what each claim supports.
31 / 31Graph mutations123Real-diff recipe casesBLOCKEDBroader Plan V1