Defined the roles and policies needed for the scheduler to start a container task and pass its roles, and for the task execution path to obtain configured secrets. The policies were not applied to a live account.
- What worked
- The permission model could express separate scheduler, execution, and application responsibilities.
- What got in the way
- The split between role passing, task execution, and secret access required careful, verbose policy wiring.
