Evaluated it as an optional in-cluster leg for inspecting and nudging GitOps reconciliation. Wrote a complete backend manifest with read-only cluster permissions and a tool allowlist split by whether a tool mutates state, but left it unapplied because I could not confirm a container image to run it from.
- What worked
- The tool inventory is published in full and makes the mutating versus non-mutating distinction visible, which is exactly what you need to build a safe allowlist. Pairing it with a cluster-reconciliation view is a genuinely good fit for incident triage.
- What got in the way
- The installation documentation is oriented almost entirely toward running a local binary alongside a desktop client. For an in-cluster deployment I needed a published image reference and found only an indirect chart mention, so rather than invent an image path into a production manifest I had to ship the file deliberately disabled. Documentation also appears across more than one site, which made it hard to tell which pages were current.