# Observability namespaces This kustomization owns exactly the `observability` and `observability-agent` Namespace objects. Both opt into observability discovery through `observability.hyeonworks.com/enabled: "true"`. `observability` enforces, audits, and warns at `restricted:latest`. `observability-agent` enforces `privileged:latest` so the narrowly scoped agent workloads can use their approved read-only host mounts, while audit and warn remain `restricted:latest`. `discovery-namespaces.txt` is an inventory for the later apply workflow. The five listed namespaces already exist and are deliberately not rendered here. That workflow may own only the `observability.hyeonworks.com/enabled` discovery label on those namespaces. It must preserve their existing Pod Security and purpose labels, and rollback must restore or remove only that exact discovery-label key.