Reference¶
Cross-cutting material that doesn't belong to a single layer — the why behind the component choices, and the methodology that keeps upgrades and networking predictable.
- Component overview — the major building blocks and why each was chosen.
- Upgrade methodology — how the OS and Kubernetes versions are coupled and gated, and the graceful node-drain approach for node-local volumes.
- Networking model — Cilium as CNI and kube-proxy replacement, the host firewall, and how north-south and east-west traffic are separated.
- Edge firewall — the HA OPNsense pair at the perimeter: what it serves, the CARP single-active design, and the config-as-code that manages it.
- Repository tooling — the local scripts each GitOps repo ships to scaffold, lint, and diff chart changes before pushing.
See also: Architecture · Operations · Runbooks.