Infrastructure & security · DC Bar
Documentation for the platform, the network it sits on, the controls that protect it and the plans for when something fails. Written while doing the work, so the traps are recorded where they were found.
How the Kubernetes estate was built, how the two sites relate, and how to put an application into it.
4 documents →Identity, access control and credentials — who can reach what, and how that is enforced.
3 documents →Addressing, routing, DNS and the paths traffic takes between the internet, HQ and AWS.
Nothing written up yet →Backups, replication and failover, and which parts of recovery are proven rather than assumed.
1 document →Accounts, subscriptions, licences and renewal dates for the services this estate depends on.
1 document →What went wrong, why, and what was changed as a result.
1 document →Each document distinguishes what has been verified from what is merely intended, because that distinction is the whole value of a runbook. Where something has been tested, it says so and gives the command that tested it. Where it has not, it says that too — a step marked as unproven is a step that will surprise you at three in the morning.
Most also carry a “traps” section. Those entries are not general advice; each one cost real time to find in this specific environment, and none of them produced an obvious error message. They are the parts most worth reading before you need them.
One of the six headings above has nothing under it yet. They are listed anyway, because a visible gap is more useful than a tidy page that implies the area is covered. Network documentation exists in people’s heads and in scattered notes; moving it here is the work in front of us.
These pages live in the k8srunbooks repository and are published by Cloudflare Pages, so a correction is a commit rather than an edit somewhere nobody else can see. If you fix something in the infrastructure, fix the document in the same change — a runbook that has drifted is worse than no runbook, because it is trusted.
Anything with a date attached is a claim about a moment. Revised in a document’s masthead is the date someone last checked it against reality, not the date it was last touched.