Picture this. It’s 2 a.m. and an engineer means to restart one container in production. One stray command later, the entire cluster is gone. The postmortem is awkward, the pager channel is full of regret, and someone mutters, “We really need better SSH command inspection and prevention of