The second agent took an afternoon. The two bugs it surfaced were nowhere near the model.
Job tokens die with their jobs and deploy keys sprawl, so our agents stopped pushing entirely.
Kubernetes already replaces dead pods. Why were we running a manager, with a standing secrets-reader Role, to do it again?