The Configurator exposes platform_kubernetes[*].debug_bastion, but users also need a bastion without a Kubernetes cluster.
Current root wiring calls src/modules/debug-bastion only through src/modules/platform-kubernetes/5-debug-bastion.tf, using the cluster project and SNA network. Moving the UI field alone would misrepresent the deployment contract.
Proposed scope:
- Add an independent root-level bastion configuration with explicit project/network/region references.
- Define supported SNA/network combinations and SSH/public-IP access explicitly.
- Preserve existing cluster-bound resource addresses; document opt-in state migration instead of recreating machines.
- Add native plan tests for independent use and invalid network references.
- Expose the independent component in Configurator only when supported by the pinned Accelerator contract.
This does not solve private Kubernetes runner reachability (#37).
The Configurator exposes
platform_kubernetes[*].debug_bastion, but users also need a bastion without a Kubernetes cluster.Current root wiring calls
src/modules/debug-bastiononly throughsrc/modules/platform-kubernetes/5-debug-bastion.tf, using the cluster project and SNA network. Moving the UI field alone would misrepresent the deployment contract.Proposed scope:
This does not solve private Kubernetes runner reachability (#37).