| CCC.K8S.CP01 | Managed Kubernetes Control Plane | The service supplies a Kubernetes-conformant control plane whose foundational components, health, and availability are automatically maintained by the provider. | 1 |
| CCC.K8S.CP02 | Managed Worker Pools | The service can organize worker nodes into managed pools that provide Kubernetes with compute capacity for scheduling and running containerized workloads. | 5 |
| CCC.K8S.CP03 | Abstracted Worker Infrastructure | The service may be configured to abstract worker infrastructure so that provisioning, scaling, patching, and replacement occur without exposing individual nodes to the user. | 4 |
| CCC.K8S.CP04 | OCI Container Image Execution | The service always accepts OCI-compatible image references and executes their containerized workloads through a Kubernetes-compatible runtime. | 1 |
| CCC.K8S.CP05 | Container Registry Integration | The service can authenticate to private or public OCI-compatible registries and retrieve workload images with user-configured identities and credentials. | 1 |
| CCC.K8S.CP06 | Declarative Workload Orchestration | The service automatically reconciles Kubernetes workload resources toward their user-declared state by scheduling, restarting, and replacing containers as needed. | 1 |
| CCC.K8S.CP07 | Cluster Network Integration | The service can attach cluster, node, pod, and service connectivity to a user-configured cloud virtual network. | 1 |
| CCC.K8S.CP08 | Workload Traffic Routing | The service can expose and route internal or external traffic to Kubernetes workloads through services, load balancers, ingress controllers, and gateway components. | 1 |
| CCC.K8S.CP09 | Workload Network Policy | The service may be configured with Kubernetes network policies that enforce ingress and egress boundaries between workloads and external systems. | 1 |
| CCC.K8S.CP10 | Cloud Identity Integration | The service can authenticate cloud identities and authorize their access to cluster resources through Kubernetes and provider-native access controls. | 3 |
| CCC.K8S.CP11 | Workload Identity Federation | The service may be configured to exchange Kubernetes service-account identity for short-lived cloud credentials without placing long-lived credentials in workloads. | 2 |
| CCC.K8S.CP12 | Secrets Service Integration | The service can present secrets, keys, and certificates from a cloud secrets service to authorized Kubernetes workloads without embedding them in workload definitions. | 2 |
| CCC.K8S.CP13 | Kubernetes Storage Provisioning | The service can dynamically provision ephemeral and persistent workload storage through Kubernetes container storage interface integrations. | 1 |
| CCC.K8S.CP14 | Managed Cluster Extensions | The service can manage the installation and lifecycle of supported extensions for networking, storage, policy, observability, and workload management. | 2 |
| CCC.K8S.CP15 | Cluster Version Management | The service may be configured with upgrade channels and maintenance settings that keep control-plane and worker components within provider-defined compatibility and support periods. | 1 |
| CCC.K8S.CP16 | Kubernetes Audit Logging | The service may be configured to emit Kubernetes API audit and control-plane records to a cloud logging destination for monitoring and investigation. | 1 |
| CCC.K8S.CP17 | Cluster Monitoring Integration | The service can send cluster, node, workload, and network activity telemetry to cloud-native or Kubernetes-compatible monitoring components. | 1 |
| CCC.K8S.CP18 | Admission Policy Enforcement | The service may be configured with policies, admission controllers, and webhooks that validate, mutate, or reject Kubernetes API requests before persistence. | 3 |
| CCC.K8S.CP19 | Workload Isolation Controls | The service can separate workloads with security contexts, namespace boundaries, scheduling constraints, and runtime isolation settings. | 2 |
| CCC.K8S.CP20 | Hardware Accelerator Support | The service may be configured with worker pools equipped with supported hardware accelerators, enabling Kubernetes to schedule workloads that request those devices. | 0 |
| CCC.K8S.CP21 | Cluster Infrastructure Identity | The service may be configured with distinct cloud identities for control-plane, worker-node, and supporting components so their access to cloud resources can be independently authorized. | 1 |
| CCC.K8S.CP22 | Worker Node Integrity Protection | The service may be configured with trusted worker-node images and platform mechanisms that verify node boot integrity before workloads are executed. | 1 |