Skip to content

Reference

Cross-cutting material that doesn't belong to a single layer — the why behind the component choices, and the methodology that keeps upgrades and networking predictable.

  • Component overview — the major building blocks and why each was chosen.
  • Upgrade methodology — how the OS and Kubernetes versions are coupled and gated, and the graceful node-drain approach for node-local volumes.
  • Networking model — Cilium as CNI and kube-proxy replacement, the host firewall, and how north-south and east-west traffic are separated.
  • Edge firewall — the HA OPNsense pair at the perimeter: what it serves, the CARP single-active design, and the config-as-code that manages it.
  • Repository tooling — the local scripts each GitOps repo ships to scaffold, lint, and diff chart changes before pushing.

See also: Architecture · Operations · Runbooks.