HA install copies Firecracker pins from the repo root, API-path --docker trusts the recorded k7d version, and k7 exec takes one sh -c string. README product name is k7 (Katakate is the org).
HTTPS-by-default for k7-api, cluster-wide Cilium isolation, first-class --docker on Kata and k7d, and RuntimeClass k7-fc. Playbook pins k7d 0.6.0.