Deploy Falco for runtime detection and Kyverno for admission policies
Implement scheduled backups and DR test
Create Prometheus alerts for tenant burn-rate & quota exceed
Add billing UI to owner portal (assign credits, 100% discount)
Implement billing worker prototype (hourly aggregates + credits)
Deploy kube-state-metrics and configure per-namespace metrics
Create starter Terraform/OpenTofu templates for tenants
Implement plan → approval → apply workflow for IaC runs
Configure MinIO backend and Consul locking for OpenTofu runs
Automate tenant-scoped service accounts & kubeconfigs
Configure Forgejo runners for running OpenTofu jobs
Create tenant namespace template and enforcement
Deploy Cilium for policy + MetalLB for LB
Deploy Rook operator + Ceph cluster across C1–C3
Prepare C1, C2, C3: disk layout, NixOS base config
Deploy Prometheus + Grafana + Loki on M1 (central)
Deploy Postgres on M1 and schedule backups
Deploy Consul: 3-node cluster (M1 + C1 + C2) for locking
Deploy MinIO on M1 and secure for Terraform state