Provision cross-account IAM roles in the klanker AWS account that trust k8s clusters in other AWS accounts via IRSA (projected ServiceAccount tokens, auto-rotating 3600s sessions)
Operator CLI guide for the km command — creating sandboxes, running agents, learning traffic, managing lifecycle
Post messages from inside a sandbox to its per-sandbox Slack channel using km-slack — for end-of-task status, progress notes, operator pings, threaded transcript replies, and Block-Kit-rendered output
One-time platform setup for an operator workstation — km configure, km init, multi-instance resource_prefix isolation, Slack/Lambda bootstrap, and rollout sequences after sidecar/Lambda changes
Send, receive, and orchestrate email between sandboxes using km-send and km-recv
Request platform actions by emailing the operator inbox with natural language commands
Detect sandbox environment, discover email policy, verify email and Slack tooling
Connect local desktop VS Code to a sandbox via SSM port-forward + per-sandbox ed25519 keypair; rotate keys without destroying the sandbox