Skip to content

Decision records

Short notes on decisions that were not obvious, written when the decision was made.

Each one says what was decided, why, and what it costs. The point is that in two years nobody has to reverse-engineer the reasoning from the manifests, and that a decision can be revisited on purpose rather than drifted away from by accident.

Two of these go against what most of the community does. Those are the ones worth reading.

Decision Status
0001 Talos Linux rather than k3s Accepted
0002 Cilium's Gateway API rather than Envoy Gateway Accepted
0003 SOPS and age rather than External Secrets Accepted
0004 local-path rather than TopoLVM or Longhorn Accepted
0005 One node, and what that gives up Accepted
0006 Building v3 on the 2021 repository Accepted
0007 Resource requests on cluster-critical pods, never BestEffort QoS Accepted
0008 Headlamp: token login, not OIDC or auto-login Accepted
0009 Etcd snapshots and machine-config backups from in-cluster CronJobs Accepted
0010 tuppr for Talos and Kubernetes upgrades Accepted
0011 Reconcile the machine-config backup credential onto the ServiceAccount CRD Accepted
0012 The data disk was never mounted, and minSize is why Accepted
0013 External exposure guardrails, and the four decisions behind them Accepted
0014 Umami analytics on CNPG, with a private dashboard and narrow public ingest Accepted
0015 actions-runner-controller for self-hosted GitHub Actions runners Accepted
0016 Scheduled sync for new private-repo runner scale sets Accepted