Keep the range in its own account

Use a dedicated lab account and operate only infrastructure you own and are authorized to test. Keep production identities, secrets, data and trust relationships outside the exercise. The scenario's identities, business records and vulnerable paths are synthetic.

The legacy workflow documented here uses IAM Identity Center, MFA and temporary sessions. Do not use the AWS root user or create a permanent access key specifically for the range. Establish billing alerts before creation and identify who owns cleanup. An isolated VPC does not replace account separation, cost oversight or explicit exercise scope.

Separate provisioning from cluster operation

The provisioner creates AWS resources. The EKS operator accesses Kubernetes. Workload roles and the load balancer controller have their own responsibilities. These identities should not all inherit one broad role.

The first bootstrap documentation allows temporary administrator access for a complete test cycle in an isolated account. It is not the permanent permissions model. Afterwards derive and review a constrained provisioner policy from observed actions, use permission boundaries and restrict role passing to the concrete required roles.

Configure EKS with a stable IAM role ARN, not an STS session ARN. An explicit access entry avoids relying on the creating session. Older configurations retain a compatibility fallback, so the CLI blocks changing the operator principal on an existing active run. Plan a new run instead of bypassing that guard.

Limit the reachable surface

The legacy CLI accepts a single canonical safe IPv4 /32 for operator access. Security groups constrain ALB, SSH and the EKS public API to that configured address. Terraform rejects unrestricted public access. S3 public access is blocked; tiered storage exposure is represented through lab IAM policies.

The telecom chart uses default deny, DNS and service path policies scoped to the same release. The behavior Pod can reach the customer portal and DNS, has no inbound Service and receives no Kubernetes API token. The referenced chart uses standard VPC CNI enforcement mode. A claim of cluster wide strict enforcement would need its own bootstrap policies and conformance evidence.

Make intentional weaknesses explicit

The legacy telecom runtime contains a controlled object ownership exercise using synthetic customer records. The secure default enforces ownership, while an explicitly configured training variant represents a failed ownership check.

The declared exercise is a bounded read of in memory lab data. The response and service logs identify the training condition. A review should examine the ownership decision and its enforcement across the service chain.

The deterministic exercise profile remains inside this declared scope. Its configuration does not authorize testing systems or records outside the range.

Keep credentials out of public evidence

Runtime installation sends the internal token and behavior plan to Helm through standard input instead of process arguments. The local run record stores plan provenance and its digest, not raw header values. Generated tokens still exist in Kubernetes Secrets and Helm release state, so access to those stores remains sensitive.

Runtime behavior events omit request headers and bodies. The separate offline agent and effect work also keeps raw arguments and private target projections out of public evidence. Target output is treated as untrusted data. These boundaries reduce unintended disclosure; they are not a claim that an LLM cannot be influenced by hostile content.

Treat cleanup as a security operation

Each run records ownership information and Terraform state checkpoints. Destruction is bound to the selected run and reviewed state, with application cleanup preceding the controller and infrastructure. Completion requires empty Terraform inventory and root outputs.

TTL tags do not automatically destroy a run. Independently inspect AWS after teardown because this legacy procedure does not perform independent provider side residual discovery. Preserve state while resolving failures and review emergency cleanup overrides before using them.

The candidate supervisor, signed contracts and replay examples referenced here are local or offline components. Their scope does not specify planned Managed Verse isolation, evidence delivery or certification. Read cloud deployment and legacy references and the agent evaluation reference with that distinction in mind.