Kubernetes made a promise engineers now take for granted: declare the desired state, and a controller will notice divergence and fix it. Meanwhile, pipeline security configuration — arguably more sensitive than most workloads — is still managed like 2010-era servers: configured once, verified never.
The loop, applied to pipeline security
- Desired state: which pipelines are enrolled, what Security Runtime settings apply, what policy mode is active — held in the control plane.
- Observation: scheduled synchronization reads what Azure DevOps and the provider actually show.
- Diff: divergence becomes a visible drift signal attached to the specific pipeline, not a vague health warning.
- Repair: Force Sync reapplies desired state as a deliberate, audited action.
Why repair must be explicit
Fully automatic re-convergence sounds attractive until it overwrites a change someone made for a live incident. Kangl treats repair as a governed operation — one click or one bulk action, recorded with actor and reason — so the loop closes fast, but never behind the operator's back.
What changes culturally
With a reconciliation loop, 'are we still covered?' stops being a quarterly investigation and becomes a dashboard state. Exceptions become visible decisions. And the estate's security configuration earns the same trust as declaratively-managed infrastructure — because it is managed the same way.

