{
  "schema": "co-tru-public-validation-v1",
  "title": "Kubernetes source connector — Novska validation",
  "status": "SOURCE_CONNECTOR_VALIDATED_WITH_TEST_RECEIVER",
  "test_window_utc": {
    "start": "2026-10-01T11:00:00Z",
    "end": "2026-10-01T11:24:00Z"
  },
  "publication_checked_at_utc": "2026-10-01T11:38:22.717358+00:00",
  "environment": {
    "location": "Novska, Croatia",
    "deployment": "kind Kubernetes cluster in an isolated Linux VM",
    "openshell": "v0.1.2",
    "kyma_driver": "v0.9.1",
    "kyma_driver_commit": "13daeb242ebae0c848faa4508c7ee9dd504f93eb",
    "source_commit": "12dbef1a1cdbe97275026bfddff42e70c82c6d1a",
    "sap_btp_tenant": false
  },
  "scope": {
    "source": "OpenShell process events generated by sandbox commands",
    "receiver": "in-memory test double",
    "rail_submission_in_this_run": false,
    "source_completeness": "not_established"
  },
  "aggregate_observation": {
    "requests": 11,
    "records": 21,
    "streams": 4,
    "closed_streams": 3,
    "open_streams_without_a_live_pod": 1,
    "incomplete_stream_classification": "possible_loss",
    "unit_tests_reported_passed": 23
  },
  "checks": [
    {
      "name": "Automatic sidecar injection",
      "result": "passed",
      "observation": "Webhook inserted the native source sidecar beside the supervisor."
    },
    {
      "name": "Driver compatibility",
      "result": "passed",
      "observation": "Sandbox reached Ready and remained Ready during source collection and sidecar restart."
    },
    {
      "name": "Source permissions",
      "result": "passed",
      "observation": "Source read OCSF from a read-only log mount using the supervisor UID/GID."
    },
    {
      "name": "Complete-line handoff",
      "result": "passed",
      "observation": "Three records delivered; acknowledged offset and source size both 2480 bytes at the measured checkpoint."
    },
    {
      "name": "Source crash recovery",
      "result": "passed",
      "observation": "SIGKILL followed by a container restart preserved the cursor without repeating the preceding request; five later records advanced the offset to 7082."
    },
    {
      "name": "Stop, start, delete",
      "result": "passed",
      "observation": "Observed streams closed with FILE_END and STREAM_END; a new start created a new pod identity and source stream."
    },
    {
      "name": "Forced pod deletion",
      "result": "observed_clean_close",
      "observation": "The tested stream closed with near-zero backlog. OpenShell then left the sandbox in Provisioning without a supervisor; this does not establish lossless forced deletion in general."
    },
    {
      "name": "Receiver unavailable at shutdown",
      "result": "incomplete_handoff_visible",
      "observation": "Receiver Service removed before pod deletion; the recorded stream stayed open without STREAM_END and no live source pod remained."
    }
  ],
  "publication_verification": {
    "method": "Read-only Kubernetes status plus GET /status inside the test receiver",
    "observed": "Driver/gateway, webhook and test receiver running; aggregate counts 11 requests, 21 records, 4 streams with 3 ended and 1 open; no supervisor pod remained",
    "raw_events_included": false,
    "credentials_included": false
  },
  "next_checks": [
    "Live daily rotation",
    "Lost acknowledgement and repeated handoff against the real intake",
    "Durable owner intake and duplicate handling",
    "Joint path to the existing rail with a dedicated test identity",
    "Deployment in an agreed SAP BTP Kyma test namespace"
  ],
  "existing_pilot": {
    "location": "Telemach",
    "public_proofs_url": "https://cotrugli.tech/co-tru/evidence/public-proofs.json",
    "proof_scope": "Separate BASE/WAW WITNESSED pilot; not generated by this Novska run"
  },
  "collaboration": {
    "source_connector": "Built and tested in Claude Code",
    "existing_adapter_and_mcp": "Built in Codex",
    "publication": "Codex reviewed the reported test and checked the running infrastructure and receiver aggregates"
  }
}
