Skip to main content

Declarative Workload Orchestration

CCC.K8S.CP06

The service automatically reconciles Kubernetes workload resources toward their user-declared state by scheduling, restarting, and replacing containers as needed.

Related Threats

IDTitleDescription
CCC.K8S.TH13Controllers Reconcile Unauthorized Cluster StateA controller or scheduled workload granted excessive scope may repeatedly create or restore unauthorized resources and configuration through its reconciliation loop. Manual remediation can then be overwritten, restoring unsafe cluster state that exposes workload data or interferes with service availability.