Read-only is the point

ClusterValidator ยท June 2026

The most dangerous infrastructure tools are the ones that sound harmless and can quietly change production. A validator that can modify your cluster is a liability with a friendly name.

Picture the failure mode a self-healing validator invites. It detects a flaky node and starts an eviction. The network hiccup that triggered the detection clears mid-eviction. Quorum is now confused, and a ten-minute manual fix has become a multi-hour outage. The tool meant well. It made a decision only a human should make.

ClusterValidator is read-only by design so that class of failure cannot happen.

What read-only means here

What ClusterValidator does:
- Query node connectivity (WMI/CIM)
- Check quorum status
- Read Active Directory
- Report findings

What it does not do:
- Evict nodes
- Force quorum
- Change configuration
- Modify AD objects
- Touch the registry

It is observational, like a security camera for your cluster. It watches, it records, it reports. It never touches the controls. This held up in the lab: a full 16-phase run against a live two-node cluster left node and resource state identical before and after.

Audits get shorter

If you work under HIPAA, PCI-DSS, or FedRAMP, you know the auditor's question: which systems can modify production infrastructure? A read-only validator drops out of that conversation early. A modifying one drags in access controls, approval workflows, rollback procedures, and incident-response testing for every write path it has. To an extent, anyway. Auditors are complicated.

2 a.m. gets calmer

You are on call and something is wrong with the cluster. If your validator can write, part of your brain is spending the first ten minutes wondering whether it already tried to fix something, failed halfway, and left the cluster in a state you cannot reason about. If it cannot write, the cluster state is whatever it was, and you can think.

The permission list stays short

A read-only tool needs WMI/CIM read access, Active Directory read access, and network reachability to the nodes. A modifying tool needs all of that plus cluster management rights, AD write permission, registry access, and often local admin on the nodes. Every added permission is attack surface. If the container running your validator is ever compromised, you want the blast radius of a camera, not a control panel.

What you actually need when things break

Visibility into current state, a record of what changed, your own memory of what you did last, and time to think. ClusterValidator supplies the first two. The judgment stays with you, and after the eviction story above, that is where we want it.