Checkpoint Restore: Destination Policy Was Never Reapplied
A checkpoint restore can rebuild a process from saved state without passing that state back through the destination’s normal policy translation. When it does, the security context on the Pod spec describes the workload that was approved, and the process on the node is the one that was saved. That is a boundary problem before…