Decision records¶
Short notes on decisions that were not obvious, written when the decision was made.
Each one says what was decided, why, and what it costs. The point is that in two years nobody has to reverse-engineer the reasoning from the manifests, and that a decision can be revisited on purpose rather than drifted away from by accident.
Two of these go against what most of the community does. Those are the ones worth reading.
| Decision | Status | |
|---|---|---|
| 0001 | Talos Linux rather than k3s | Accepted |
| 0002 | Cilium's Gateway API rather than Envoy Gateway | Accepted |
| 0003 | SOPS and age rather than External Secrets | Accepted |
| 0004 | local-path rather than TopoLVM or Longhorn | Accepted |
| 0005 | One node, and what that gives up | Accepted |
| 0006 | Building v3 on the 2021 repository | Accepted |
| 0007 | Resource requests on cluster-critical pods, never BestEffort QoS | Accepted |
| 0008 | Headlamp: token login, not OIDC or auto-login | Accepted |
| 0009 | Etcd snapshots and machine-config backups from in-cluster CronJobs | Accepted |
| 0010 | tuppr for Talos and Kubernetes upgrades | Accepted |
| 0011 | Reconcile the machine-config backup credential onto the ServiceAccount CRD | Accepted |
| 0012 | The data disk was never mounted, and minSize is why | Accepted |
| 0013 | External exposure guardrails, and the four decisions behind them | Accepted |
| 0014 | Umami analytics on CNPG, with a private dashboard and narrow public ingest | Accepted |
| 0015 | actions-runner-controller for self-hosted GitHub Actions runners | Accepted |
| 0016 | Scheduled sync for new private-repo runner scale sets | Accepted |