Policy and runtime security — defense in depth from admission to syscall
How the homelab layers Kyverno admission policies, Policy Reporter visibility, Tetragon eBPF runtime observability, and Cilium-enforced network policy into one defense-in-depth story — what each layer catches, what is enforced versus audited, and where the deliberate gaps are.