- 01Application and process behavior
- Executable processes, runtimes, system libraries, file and device needs, startup and shutdown, signals, concurrency, background work, scheduled work, request handling, dependencies, protocols, ports, temporary storage, durable data, caches, transactions, idempotency, partial work, compatibility, and recovery behavior.
- 02Build, image, and distribution path
- Source, build definitions, base images, platforms and architectures, packages, dependency locks, generated assets, image layers, users and permissions, image configuration, labels, digests, provenance, signatures, vulnerability findings, SBOMs, registry access, retention, replication, revocation, and release promotion.
- 03Runtime and workload controls
- Runtime implementation, kernel and host assumptions, identity, secrets, configuration, filesystem, capabilities, privilege, sandboxing, networks, policies, service discovery, ingress and egress, resources, quotas, startup, readiness, liveness, termination, jobs, placement, disruption, scaling, rollout, exposure, logs, metrics, traces, and events.
- 04Platform operation and lifecycle
- Control planes, nodes or managed services, accounts, clusters and namespaces, tenancy, access, admission, policy, certificates, registries, storage systems, DNS, load balancing, autoscaling, upgrades, version skew, add-ons, capacity, cost, backups, disaster recovery, incidents, support, documentation, maintenance, and ownership boundaries.