THE NEXT DEPLOYMENT PATH · VALIDATED AT THE SOURCE
Built for Kubernetes.
Tested in Novska.
OpenShell v0.1.2 · Kyma driver v0.9.1
1 October 2026 · 11:00–11:24 UTC
Co-Tru's new source connector collects OpenShell events on Kubernetes. The Novska test verified collection, recovery after a crash and visibility of an interrupted handoff — using the open-source driver for SAP BTP Kyma.
21records received
4source streams observed
23unit tests passed
1incomplete handoff exposed
✓ COLLECTION
The records arrive.
The connector was added automatically beside the OpenShell supervisor. It read the event file and handed off every complete record up to the measured checkpoint, with zero backlog.
✓ CRASH RECOVERY
Pick up where you left off.
After a forced collector crash, Kubernetes restarted it. Collection resumed from the saved position without repeating the earlier request, then delivered five more records.
✓ LIFECYCLE
A new run gets its own trail.
Stop and delete closed the observed streams. Starting again created a new generation and pod identity, with the collector automatically attached to the new supervisor.
↗ FAILURE VISIBILITY
An unfinished handoff stays visible.
When the receiver was deliberately made unavailable before shutdown, the pod disappeared but its stream remained open. The test identified this as possible_loss.
TESTED IN NOVSKAOpenShell→Co-Tru source connector→Test receiver
This run validated the source connector on a kind Kubernetes cluster. Connecting it to Co-Tru's evidence intake and running the joint rail test are the next steps.
Inspect the test results and deployment scope
Observed source-connector scenarios · Novska, 1 October 2026| Scenario | Observed result |
| Automatic injection | The webhook added the native sidecar to the supervisor pod. |
| Driver compatibility | The sandbox remained Ready through collection and collector restart. |
| File access | The collector read the OCSF file using the supervisor's UID/GID, with a read-only log mount. |
| Record handoff | Three records reached the test receiver; its offset matched the 2,480-byte file. |
| Collector crash | A SIGKILL followed by a container restart preserved the cursor; five subsequent records advanced it to 7,082 bytes. |
| Stop, start and delete | Observed streams closed with FILE_END and STREAM_END; a new run received a new source identity. |
| Forced pod deletion | The tested stream closed cleanly. OpenShell then left that sandbox in Provisioning without a supervisor; this was recorded separately. |
| Receiver unavailable at shutdown | The final stream had no STREAM_END and no live pod: possible_loss was identified. |
The receiver was an in-memory test double. This run used process events generated by sandbox commands; it did not produce the ALLOWED/BLOCKED rail proofs displayed above. Those belong to the separate Telemach pilot. Live daily rotation, a lost acknowledgement, the real intake and the joint rail path remain follow-up checks. The run does not establish complete capture under every failure.
The source connector was built and tested in Claude Code; the existing Co-Tru evidence adapter and MCP connection were built in Codex. Codex also checked the running Novska infrastructure and the receiver's aggregate status before publication.
Download the public validation record ↗