3 Orca clusters (breakpilot-edge / breakpilot-control / breakpilot-app), 1 plane each. Single-VM core with Keycloak co-tenant on vm-edge. App cluster gets prod + stage VMs. Manifests reorganized into clusters/<name>/services/; validator now enforces per-cluster node whitelist. Multi-VM rollout gated on legal entity.
Overlays
Per-env sparse deltas applied on top of manifests/. Concept: each overlay
file may set just the fields that differ from the base manifest. The merge
script in scripts/plan.sh produces the final per-env service set at
.orca-out/<env>/.
For now the overlays are placeholder structures — concrete deltas land with the milestones that introduce real images and replica counts (M4.1, M5.1, M6.x).