Skip to main content

Topics

Long-form deep-dives. The pages here explain something that touches several layers of the stack at once — they don't fit into apps, platform, foundation, or fabric alone.

PageWhat it covers
GitOps flowHow a Renovate PR becomes a running container, end-to-end.
Three-tier backups end-to-endThe path from "byte written to a PVC" through warm / hot / cold tiers, and what each costs to restore.
Disaster recovery drillFrom "production is gone" back to a fully reconciled cluster — the documented procedure.
SOPS / age key rotationRotating the load-bearing age key without breaking Flux, including the two-recipient phase.
Renovate auto-merge policyWhen dependency PRs auto-merge and when they wait for a human.
Real client IPs across the chainPROXY-protocol-v2 wiring through netbird/SNAT and a multi-proxy chain, with Gitea as the example.
Hardware-backed SSH keysGenerate and use SSH keys whose private material never leaves a Nitrokey 3 or YubiKey 5.
Fedora LUKS2 + TPM2 + Secure BootSet up, manage, and recover full-disk encryption bound to TPM PCRs 7 and 14.