The audit found ~80 placeholders, and the damaging ones were where the
measuring apparatus itself was prose rather than a command:
a6 "( curl ... ) & 를 20개 띄우고 wait" — the 22.2s headline came from this
a3 "<로그인 반복, sid 를 /tmp/sids 에>" — the whole RPO measurement
a3 "<sid 목록>" — the control it is compared against
a5 "<수신 파드IP>" — the injection
a8 writes /tmp/tok, reads /tmp/rt — self-inconsistent, sent an empty token
b3 $KC / $RT / $NEW never assigned
c2 bare kcadm.sh with no kubectl exec
a1 conntrack tuples written by hand, though the direction flips per restart
Each is now a shell-expandable form: pod IPs from jsonpath, the admin password
from the secret, ids from kcadm --format csv, conntrack tuples derived from
"conntrack -L" with awk rather than transcribed.
Then the rewritten commands were executed against the live cluster, and one
of them failed — the 20-way load generator, written as "kubectl run --rm -i",
lost its output stream twice in a row. That is a trap this series already hit
once, and the rewrite reintroduced it. A-6 now uses a resident probe pod that
collects into a file and is cat-ed once; verified 20/20 lines.
Evidence: docs/evidence/followup/05-command-reproducibility.txt
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
The forward upgrade to 26.7.3 was zero downtime across 87 samples, and since databasechangelog stayed at 210 the rollback to 26.7.0 also succeeded, which narrows D-2's conclusion: rolling back fails when the schema moved, not because of the version number. The row count is the check.
Role changes never reach the upstream through request repetition; the session is a snapshot taken at login and only a new session picks up the new claim. Auditing the docs also surfaced that Prometheus scrapes only keycloak, kubelet, node-exporter and itself, so the B-layer experiments have no metrics to screenshot rather than missing screenshots.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>