/** * Read-only kubectl probes for the install advisor. * * Philosophy: * - Every probe is best-effort. A probe failing never aborts the rest — * we just record it in probeLog and move on. Most customers won't * give us cluster-wide RBAC on every kind, and the advisor should * still produce useful output from partial data. * - Never list huge verbs cluster-wide (e.g., `get pods -A`). Scope to * probed namespaces. Default: caller-supplied namespaces + `kube-system`. * - No writes. No --dry-run=server (still counts as a write for RBAC). */ import type { KubectlProbes, ProbeLogEntry } from './types.js'; export interface KubectlProbeOpts { /** Explicit namespaces to probe. If absent, we auto-pick up to 5. */ namespaces?: string[]; /** Per-call timeout. Default 10_000ms. */ timeoutMs?: number; } /** * Run the full set of kubectl probes. Returns a `KubectlProbes` record * plus the probe-log entries to append to the snapshot's audit log. */ export declare function probeKubectl(opts?: KubectlProbeOpts): Promise<{ probes: KubectlProbes; log: ProbeLogEntry[]; }>;