Minimal hardening plan for production deployment: NetworkPolicy (default-deny + explicit allow), SecurityContext on all pods, secret scoping (split monolithic foxhunt-secrets), and Trivy image scanning in CI pipeline. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>