Two questions, then I can plan:
1. Domain for the staging endpoints? (No default ships — this is a hard preflight gate.)
2. Region — prod is us-west-2; keep staging in the same region?
1 blocked: data_plane_cidr depends on your isolation answer — I won't assume it; unanswered dependencies block, they don't silently disappear.
I cannot mint my own approval token — a human accepts this specific plan, and the token is single-use, expiring, and bound to pl-4te7c2.
Root cause: search pods OOMKilled during the post-upgrade ingest replay — memory limit still at the pre-upgrade value while 0.1.90's ingest batches are 2× larger. The smoke test's search probe timed out as pods restarted.
Suggested remediation (becomes a plan — I don't hot-patch): raise search.resources.limits.memory 2Gi → 4Gi via the config workflow. Want me to render that plan for approval?
Diagnostics stayed inside your boundary. If support needs the bundle, EXPORT_DIAGNOSTICS is opt-in: redacted by profile, contents previewed, and released only with a confirm token.
COLLECT_CONFIGreadVALIDATE_PREREQSreadGENERATEworkspaceBUILD_VALIDATEworkspacePLAN_DEPLOYreadAPPLY_PLANapprovalDIAGNOSEreadEXPORT_DIAGNOSTICSapprovalYou are approving exactly this plan: 23 tasks creating a new staging environment for tern-aviation in aws/us-west-2, cost Δ +$1,120/mo. The approval token is single-use and bound to this plan's content hash — if any input changes, apply refuses.
Type approve to issue the token: