Infrastructure & security · DC Bar

How this estate is built and kept running

Documentation for the platform, the network it sits on, the controls that protect it and the plans for when something fails. Written while doing the work, so the traps are recorded where they were found.

Platform

How the Kubernetes estate was built, how the two sites relate, and how to put an application into it.

4 documents →

Security

Identity, access control and credentials — who can reach what, and how that is enforced.

3 documents →

Network

Addressing, routing, DNS and the paths traffic takes between the internet, HQ and AWS.

Nothing written up yet →

Continuity

Backups, replication and failover, and which parts of recovery are proven rather than assumed.

1 document →

Vendors

Accounts, subscriptions, licences and renewal dates for the services this estate depends on.

1 document →

Incidents

What went wrong, why, and what was changed as a result.

1 document →

How to read these

Each document distinguishes what has been verified from what is merely intended, because that distinction is the whole value of a runbook. Where something has been tested, it says so and gives the command that tested it. Where it has not, it says that too — a step marked as unproven is a step that will surprise you at three in the morning.

Most also carry a “traps” section. Those entries are not general advice; each one cost real time to find in this specific environment, and none of them produced an obvious error message. They are the parts most worth reading before you need them.

Sections that are empty

One of the six headings above has nothing under it yet. They are listed anyway, because a visible gap is more useful than a tidy page that implies the area is covered. Network documentation exists in people’s heads and in scattered notes; moving it here is the work in front of us.

Keeping them current

These pages live in the k8srunbooks repository and are published by Cloudflare Pages, so a correction is a commit rather than an edit somewhere nobody else can see. If you fix something in the infrastructure, fix the document in the same change — a runbook that has drifted is worse than no runbook, because it is trusted.

Anything with a date attached is a claim about a moment. Revised in a document’s masthead is the date someone last checked it against reality, not the date it was last touched.