Putting an LLM on a Leash: Gates, Budgets and Prompt Injection in a Kubernetes Operator

Part 2 built a gate: a content-addressed fingerprint that says whether a Finding’s content has changed since anything expensive last looked at it. There was no expensive thing yet. This part adds it. Wiring an LLM call into a reconcile loop is about twenty lines. Everything worth writing about is the constraints around those twenty lines: what the interface looks like, what stops the call happening, what happens when the budget runs out, and what stops third-party scanner output from issuing instructions to your model. ...

28 September 2026 · 9 min · Albert Asawaroengchai