Decision log
A decision record answers the question code cannot: why this and not the obvious alternative. Configuration shows what is running. It never shows what was rejected, what constraint drove the shape, or what the decision cost — and those are the only things that let someone reverse a decision safely later.
Decision log — 471 architecture decision records
Snapshot taken — build-time, not live| ADR | Decision | Status | Date | Domains |
|---|---|---|---|---|
| 0001 | Monitoring dependency chains | Accepted | 2026-06-18 | monitoring, zabbix, alertmanager |
| 0002 | Paperless-ngx — LXC community script to docker01 compose stack | Accepted | 2026-06-18 | paperless, docker, migration |
| 0003 | Container resource metrics — Prometheus/cadvisor only, not Zabbix | Accepted | 2026-06-19 | monitoring, prometheus, zabbix |
| 0004 | Samba — LXC to docker01 compose stack | Accepted | 2026-06-19 | samba, docker, migration |
| 0005 | Explicit security floor pins for transitive Python dependencies in self-owned Docker images | Accepted | 2026-06-19 | security, docker, python |
| 0006 | docker01 — separate OS and Docker data disks | Accepted | 2026-06-20 | docker, storage, infrastructure |
| 0007 | Filesystem monitoring — direct items over template LLD | Accepted | 2026-06-20 | monitoring, zabbix, storage |
| 0008 | Decom soak tracking via PVE guest description field | Accepted | 2026-06-20 | decommission, proxmox, automation |
| 0009 | Infisical pg_dump backup to arch01/files | Accepted | 2026-06-20 | infisical, secrets, backup |
| 0010 | Pi-hole DNS records as code via FTL config CLI | Accepted | 2026-06-20 | dns, pihole, ansible |
| 0011 | Internal HTTP readiness probes alongside external edge probes | Accepted | 2026-06-20 | observability, monitoring, alerting |
| 0012 | docker01: live-restore off + mount ordering for deterministic reboot recovery | Accepted | 2026-06-20 | docker, reliability, docker01 |
| 0013 | Cloudflare edge as code (tf-cloudflare) | Accepted | 2026-06-20 | cloudflare, terraform, decommission |
| 0014 | Generic secret-rotation role with pluggable per-source adapters | Accepted | 2026-06-21 | infisical, secrets, rotation |
| 0015 | Single shared read-only deploy identity for Docker-Apps secret injection | Accepted | 2026-06-21 | infisical, secrets, identity |
| 0016 | Agent memory scaling — flat-index discipline + file consolidation, not a vector DB | Accepted | 2026-06-21 | claude, memory, aiops |
| 0017 | Infisical infrastructure/network consumer & bootstrap model | Accepted | 2026-06-21 | infisical, secrets, bootstrap |
| 0018 | Agent knowledge retrieval — RAG over docs-as-code via pit-memory MCP, not a parallel memory store | Accepted | 2026-06-21 | claude, memory, aiops |
| 0019 | Enriched Pushover notifications for agent triage | Accepted | 2026-06-21 | alertmanager, alerting, observability |
| 0020 | cc-pool concurrency isolation — per-session worktrees, GitOps PRs as target | Accepted | 2026-06-21 | cc-pool, git, gitops |
| 0021 | Terraform pipeline secret injection from Infisical | Accepted | 2026-06-21 | infisical, secrets, terraform |
| 0022 | Deterministic technical-spec normalisation for the podcast pipeline | Accepted | 2026-06-21 | podcast, tts, speech |
| 0023 | Prometheus external exposure for working GeneratorURL links + probe-alert label hygiene | Accepted | 2026-06-21 | alertmanager, alerting, observability |
| 0024 | rclone runs as ephemeral container with env-var config, no rclone.conf on disk | Accepted | 2026-06-21 | backup, rclone, docker |
| 0025 | ITSM/CMDB as best-of-breed — NetBox + FreeScout + GitOps, not a single ITIL suite | Accepted | 2026-06-21 | itsm, cmdb, netbox |
| 0026 | docker01 uses virtio-scsi-single + per-disk iothread to stop all-vCPU soft-lockups | Accepted | 2026-06-22 | proxmox, docker01, storage |
| 0027 | Linux VMs use a UTC RTC (localtime=0), enforced via Ansible not Terraform | Accepted | 2026-06-22 | proxmox, timekeeping, ansible |
| 0028 | Validate Mermaid diagrams at docs-build time against the live mermaid major | Accepted | 2026-06-22 | docs, ci, mermaid |
| 0029 | Lifecycle-driven agent-memory eviction, not TTL or LRU | Accepted | 2026-06-22 | agent-memory, pit-memory, retention |
| 0030 | Remediate a leaked on-LAN secret by rotating at source, not rewriting git history | Accepted | 2026-06-22 | secrets, infisical, security |
| 0031 | Feedback-memory hygiene via three report-then-confirm brakes, not eviction | Superseded | 2026-06-22 | agent-memory, pit-memory, retention |
| 0032 | Wrap-up work-delivery reports are published as navigable doc artifacts, not email-only | Accepted | 2026-06-22 | docs-as-code, mkdocs, reporting |
| 0033 | Notification channel policy — alerts via Pushover, work-delivery reports via email | Accepted | 2026-06-22 | notifications, pushover, email |
| 0034 | All notifications carry a machine-readable header, emitted through one helper | Accepted | 2026-06-22 | alerting, observability, aiops |
| 0035 | Docs cross-linking — unify on a single wikilink syntax via a self-authored hook | Accepted | 2026-06-23 | docs-as-code, knowledge-management, mkdocs |
| 0036 | ADO pipeline failure + approval alerting stays in Zabbix, not a new Prometheus exporter | Accepted | 2026-06-23 | zabbix, alerting, pushover |
| 0037 | Alloy liveness alerting moves to a Prometheus self-scrape, not a Zabbix host-port probe | Accepted | 2026-06-24 | observability, alloy, prometheus |
| 0038 | Docs publish-completeness guard | Accepted | 2026-06-24 | docs-as-code, ci, aiops |
| 0039 | docker01 soft-lockups under Plex transcode load are fixed by CPU weighting, not core pinning | Accepted | 2026-06-24 | proxmox, docker01, media |
| 0040 | Sonarr/Radarr API key rotation edits config.xml directly because the arr REST API ignores apiKey | Accepted | 2026-06-24 | infisical, secrets, ansible |
| 0041 | B2 file restore splits laptop GUI from a docker01 backend, and reinstates versions to decrypt them | Accepted | 2026-06-24 | backup, restore, rclone |
| 0042 | Zabbix alerts conform to the Notification Standard at the Pushover media type, with a 6→3 tier severity-to-priority map | Accepted | 2026-06-24 | zabbix, alerting, pushover |
| 0043 | Plex iPad sync/download monitoring uses a custom Tautulli-API exporter, not an off-the-shelf Plex exporter | Accepted | 2026-06-24 | plex, media, tautulli |
| 0044 | pitbook12 config drift is remediated pull-based on the endpoint, enforce-invariants + report-rest | Accepted | 2026-06-24 | pitbook12, ansible, gitops |
| 0045 | Per-service dashboards as code with a dynamic blackbox-driven rollup, on a RED+USE+logs baseline | Accepted | 2026-06-24 | observability, grafana, dashboards |
| 0046 | Secret scanning via gitleaks in ephemeral docker, gating CI and pre-commit | Accepted | 2026-06-24 | security, secrets, ci |
| 0047 | plex01 disk pressure is managed by isolation + predictive alerting, not garbage collection | Accepted | 2026-06-24 | plex, proxmox, zfs |
| 0048 | Claude Code self-captures session reasoning traces into FreeScout | Accepted | 2026-06-25 | itsm, freescout, aiops |
| 0049 | Claude Code config docs generated from ~/.claude, published to the corpus via a reconciliation loop | Accepted | 2026-06-25 | claude, cc-pool, docs-as-code |
| 0050 | Serve derived visualisation artifacts behind Access, don't commit them | Accepted | 2026-06-25 | observability, vectormap, cloudflare |
| 0051 | docker01 soft-lockups are an IPv6 router-solicitation timer storm on churning docker bridges, not the task named by the kernel | Accepted | 2026-06-25 | docker01, networking, ipv6 |
| 0052 | vectormap live search via a server-side sidecar, not client-side embedding | Accepted | 2026-06-25 | observability, vectormap, rag |
| 0053 | Pin the pitlab-docs MkDocs build toolchain and treat MkDocs 2.0 as an upstream fork to migrate away from, not upgrade into | Accepted | 2026-06-25 | docs-as-code, mkdocs, automation |
| 0054 | Coalesce the pitlab-docs publish pipeline with a batched CI trigger, and shift cheap validation left to a pre-push hook | Accepted | 2026-06-25 | docs-as-code, ci, pipelines |
| 0055 | A service owns one canonical dashboard plus at most one linked operational drill-down | Accepted | 2026-06-26 | observability, grafana, dashboards |
| 0056 | Make the docs-pipeline pit-memory reindex step resilient — become-free rsync sync, non-fatal to the publish, freshness-alerted | Accepted | 2026-06-26 | docs-as-code, ci, pipelines |
| 0057 | Decouple host reboots from unattended-upgrades with a window-gated reboot coordinator (kured model) | Accepted | 2026-06-27 | patching, maintenance, automation |
| 0058 | Timezone standard — host schedules in local Australia/Melbourne, ADO pipeline crons in UTC, no hard-coded offsets | Accepted | 2026-06-27 | timezone, scheduling, cron |
| 0059 | Service catalog — auto-generated per-service home pages from the Alloy probe inventory | Accepted | 2026-06-27 | docs-as-code, observability, grafana |
| 0060 | Claude Pod runs a credential-free container on a slim base, with credential-bearing steps externalised to control01 | Accepted | 2026-06-27 | podcast, media, security |
| 0061 | Self-healing schedule reconciliation — a declarative manifest enforced by a static author-time guard and a live post-deploy reconciler | Accepted | 2026-06-27 | scheduling, cron, timezone |
| 0062 | A mandatory kb explainer link on every notification, resolved from a notification catalog as code | Accepted | 2026-06-27 | alerting, observability, notifications |
| 0063 | Umbrella (parent) service catalog pages over duplicated or grouped components | Accepted | 2026-06-28 | observability, docs-as-code, cmdb |
| 0064 | Service-owned alert runbooks live on the service page, fleet-wide alerts stay in operations | Accepted | 2026-06-28 | alerting, observability, docs-as-code |
| 0065 | ADO pipeline → pitlab-pool authorization is reconciled by a daily idempotent cron, not blanket-granted or Terraform-managed | Accepted | 2026-06-28 | ado, pipelines, ci |
| 0066 | docker-stacks images are classified by blast radius — critical images digest-pinned with per-package, no-auto-merge Renovate policy | Accepted | 2026-06-28 | docker, renovate, dependency-management |
| 0067 | docker-stacks deploys end with a smoke gate that fails the pipeline if a container does not start and serve | Accepted | 2026-06-28 | docker, ci, pipelines |
| 0068 | Incident-resolution feed + two-tier retrieval — what belongs in the vector DB | Accepted | 2026-06-29 | itsm, freescout, aiops |
| 0069 | A staging/canary lane for the observability stack is declined — the post-deploy smoke gate plus merge-time review is the terminal pre-prod gate | Accepted | 2026-06-29 | docker, ci, pipelines |
| 0070 | Self-healing notification docs — capture, detect, propose-only remediation | Implemented | 2026-06-29 | notifications, observability, aiops |
| 0071 | FreeScout web-tier 500 — clear-first auto-heal over restart-only | Accepted | 2026-06-29 | itsm, freescout, operations |
| 0072 | FreeScout web-tier 500 — confirmed root cause (root-owned cache) and durable process-fix | Accepted | 2026-06-30 | itsm, freescout, operations |
| 0073 | NetBox hybrid source-of-truth — authority boundaries split by lifecycle stage, per host class | Accepted | 2026-06-30 | netbox, cmdb, source-of-truth |
| 0074 | Terraform NetBox provider — enforce the ADR-0073 boundary by import + ignore_changes, partition IP by allocation method | Accepted | 2026-06-30 | netbox, cmdb, terraform |
| 0075 | Logging / Log-Capture Standard — Loki is mandatory, file-loggers must reach stdout, arrival is proven not assumed | Accepted | 2026-06-30 | observability, loki, alloy |
| 0076 | DNS Origin Pinning — pin cloudflared tunnel origins as local Pi-hole A records to remove the UDM single-upstream from origin resolution | Accepted | 2026-06-30 | dns, pihole, cloudflare |
| 0077 | Tagging Standard with unified per-surface vocabulary | Accepted | 2026-06-30 | tagging |
| 0078 | Alerting severity taxonomy and routing contract | Accepted | 2026-06-30 | alerting |
| 0079 | Container / Compose Baseline — mandatory directives for every docker-stacks service | Accepted | 2026-06-30 | containers |
| 0080 | Terraform / IaC Standard | Accepted | 2026-06-30 | terraform |
| 0081 | Backup & Retention Standard — 3-2-1 framing, named tiers, a per-guest registry as code, retention asserted not just documented | Accepted | 2026-06-30 | backup |
| 0082 | Functional host naming, deprecate legacy xt###/xv### scheme | Accepted | 2026-06-30 | naming |
| 0083 | Cause-level log alerts are per-service signatures, not a generic file-tail rule | Accepted | 2026-06-30 | alerting, observability |
| 0084 | Alert window sizing & flap dampening — windows track condition duration, for: dampens flaps | Accepted | 2026-06-30 | alerting, observability |
| 0085 | The notification-catalog guard validates kb anchors against alert_runbooks.yml, not the async-regenerated markdown | Accepted | 2026-06-30 | alerting, observability, docs-as-code |
| 0086 | docker-stacks deploys end with a Loki log-shipping gate that fails the pipeline if a stack ships no logs | Accepted | 2026-07-01 | docker, ci, pipelines |
| 0087 | pit-memory reuses one HTTP client to stop a reindex DNS flood | Accepted | 2026-07-01 | pit-memory, dns, observability |
| 0088 | pit-memory image source moves into docker-stacks beside its deploy | Accepted | 2026-07-01 | pit-memory, ci, gitops |
| 0089 | docker01 gets a local caching DNS resolver in the container path | Accepted | 2026-07-01 | dns, docker01, networking |
| 0090 | Host config-as-code playbooks auto-deploy via path-triggered CI | Accepted | 2026-07-01 | ansible, ci, gitops |
| 0091 | Pit on the Verge moves from per-article episodes to per-topic daily digests | Accepted | 2026-07-02 | podcast, media, n8n |
| 0092 | Secret-dependent ansible CI playbooks fetch from Infisical in-playbook, not via pipeline env injection | Accepted | 2026-07-01 | ansible, ci, infisical |
| 0093 | HA-safe CI for Home-Assistant-touching config playbooks (split auto-apply / check-only) | Accepted | 2026-07-01 | ansible, ci, gitops |
| 0094 | n8n workflows managed as code via API reconciliation on community edition | Accepted | 2026-07-01 | n8n, gitops, automation |
| 0095 | Tune PlexTranscodeSaturated (for: 10m→30m) rather than delete it — low-value alerts are tuned, not removed | Accepted | 2026-07-02 | plex, media, alerting |
| 0096 | Pit on the Verge moves to weekly per-topic rollups on a staggered day-of-week schedule | Accepted | 2026-07-02 | podcast, media, n8n |
| 0097 | Podcast inter-article separation via opposite-voice outros, and source sub-heading echo dedup | Unstated | 2026-07-03 | podcast, tts |
| 0098 | Guardian Audio — generalise five-great-reads to an all-Guardian-newsletter podcast | Unstated | 2026-07-03 | podcast, media, n8n |
| 0099 | Workload auto-remediation on docker01 via autoheal | Unstated | 2026-07-03 | observability, docker, self-healing |
| 0100 | dtrack Jetty-listener hang — widen the resource envelope in place, defer the v5 migration | Unstated | 2026-07-03 | docker, security, observability |
| 0101 | vulnscan — autonomous vulnerability remediation authority and boundary | Unstated | 2026-07-03 | security, devsecops, self-healing |
| 0102 | Per-service test plans as an enforced post-deploy / post-remediation gate | Unstated | 2026-07-03 | testing, ci, devsecops |
| 0103 | Grafana is dashboards-only — unified alerting disabled at the config layer | Accepted | 2026-07-04 | grafana, alerting, observability |
| 0104 | Authenticated golden path — run-time secret injection into test plans | Unstated | 2026-07-04 | testing, ci, devsecops |
| 0105 | Host/LXC services gate their test plans via a scheduled synthetic run, not a deploy pipeline | Unstated | 2026-07-04 | testing, ci, reliability |
| 0106 | docker-stacks pipeline-gate scripts live in the docker-stacks repo, a scoped carve-out from RULE 6 | Accepted | 2026-07-04 | scripts, ci, pipelines |
| 0107 | Base-image build-tool CVE remediation — upgrade pip, drop build-only npm | Unstated | 2026-07-04 | security, devsecops, docker |
| 0108 | qbittorrent WebUI crash-loop from a shared-netns QLockFile orphan | Unstated | 2026-07-04 | media, observability |
| 0109 | Mothball iptv-proxy (retain IaC, take offline) and adopt a Service Mothball standard | Unstated | 2026-07-04 | media, observability, docs-as-code |
| 0110 | qbittorrent persistent WebUI credential via Infisical injection | Unstated | 2026-07-04 | media, secrets, testing |
| 0111 | vulnscan tidies by default — auto-retire superseded DT projects and prune old docker images | Unstated | 2026-07-04 | security, devsecops, dependency-track |
| 0112 | Generalise bounded autonomy into an Autonomous Remediation Authority Standard | Unstated | 2026-07-04 | devsecops, self-healing, automation |
| 0113 | Documentation architecture — mandatory overview hubs for cross-service capabilities | Unstated | 2026-07-04 | docs-as-code, docs, architecture |
| 0114 | PlexTranscodeSaturated measures per-job peak encode speed over non-throttled transcode jobs — Plex `speed` is instantaneous and bursty, so an instantaneous min misreads healthy idle as saturation | Accepted | 2026-07-04 | plex, media, alerting |
| 0115 | Monitoring-as-Code standard + live drift audit — mandate Zabbix objects as code and reconcile daily | Accepted | 2026-07-05 | zabbix, monitoring, gitops |
| 0116 | Disabled-trigger zombie reaper — auto-close Zabbix problems stuck open on a disabled trigger | Accepted | 2026-07-05 | zabbix, monitoring, alerting |
| 0117 | Codify the 81 unverified Zabbix monitoring objects — attribute or write a source, correct don't enshrine | Accepted | 2026-07-05 | zabbix, monitoring, gitops |
| 0118 | Homelab start page (Homepage) with generated tiles + Infisical widget-secret injection | Accepted | 2026-07-05 | homepage, infrastructure, infisical |
| 0119 | Credential Aggregation Standard — least-privilege posture for multi-service consumers | Accepted | 2026-07-05 | security, secrets, devsecops |
| 0120 | Homepage secret-rotation webhook via an authenticated n8n relay (not direct ADO, not unauthenticated) | Accepted | 2026-07-05 | homepage, n8n, ado |
| 0121 | Delegated session-scoped autonomy tier — extend the Autonomous Remediation Authority Standard for /justdoit | Superseded | 2026-07-05 | autonomy, automation, devsecops |
| 0122 | PBS xt035 GC OOM — right-size VM 103, cap the GC digest cache, swap cushion + silent-failure watchdog | Accepted | 2026-07-05 | pbs, backup, proxmox |
| 0123 | Tag-only Zabbix convergence for attribution-only monitoring sources — drive untagged to zero | Accepted | 2026-07-05 | zabbix, monitoring, gitops |
| 0124 | Stop the 90-day Sonarr/Radarr API-key rotation — keep internal-only keys static | Accepted | 2026-07-05 | infisical, secrets, media |
| 0125 | One global ADO pipeline stuck alert — disable per-pipeline failure paging | Accepted | 2026-07-06 | zabbix, alerting, pushover |
| 0126 | Fold docker01 bespoke apps into docker-stacks, with Infisical as the documented bootstrap carve-out | Unstated | 2026-07-06 | docker, gitops, infisical |
| 0127 | Terraform reconciles VM memory — remove the ignore_changes freeze, declare balloon to avoid churn | Accepted | 2026-07-06 | terraform, proxmox, gitops |
| 0128 | Codify full create-definitions for attribution-only Zabbix sources — rebuild-safety | Accepted | 2026-07-06 | zabbix, monitoring, gitops |
| 0129 | The ADO pool-auth guardrail is a pool-aware detective folded into the existing reconciler, not a duplicate | Accepted | 2026-07-06 | ado, gitops, monitoring |
| 0130 | Codify the Home Assistant → Zabbix bridge as a committed template export + create-if-missing provision | Accepted | 2026-07-06 | zabbix, monitoring, gitops |
| 0131 | Homelab SSO integrates apps directly with Entra, not via an Authentik/Keycloak broker | Accepted | 2026-07-07 | sso, entra, identity |
| 0132 | Stateful-appliance config-export-as-code — tiered assert/snapshot, control01 pull, auto-commit on change | Accepted | 2026-07-07 | gitops, config-as-code, ansible |
| 0133 | Podcast RSS feeds stay public + token-gated, excluded from Cloudflare Access SSO | Accepted | 2026-07-07 | sso, cloudflare, podcast |
| 0134 | Break-glass for Entra-gated services is LAN/VPN-only — no second IdP, no Access bypass | Accepted | 2026-07-07 | sso, cloudflare, entra |
| 0135 | Entra app registrations are code in Terraform, with client secrets minted to Infisical (never in TF state) | Accepted | 2026-07-07 | sso, entra, identity |
| 0136 | Codify the PBS backup-root config (xt035 + xv035 pair) as assert-tier config-as-code | Accepted | 2026-07-07 | gitops, config-as-code, ansible |
| 0137 | Homepage hides headless services from the start page via a hide-list, not by removing them from the probe inventory | Accepted | 2026-07-07 | homepage, observability |
| 0138 | Homepage widget auth — read the passwordless Pi-hole API keyless, and a dedicated read-only NetBox token | Accepted | 2026-07-07 | homepage, pihole, netbox |
| 0139 | Per-app Entra SSO integration follows a fixed nine-step standard | Accepted | 2026-07-07 | sso, entra, identity |
| 0140 | Dependency-Track splits into apiserver + frontend behind an nginx proxy to gain Entra OIDC (public SPA, no secret) | Accepted | 2026-07-08 | sso, entra, identity |
| 0141 | Build hooks and pipeline gates ship their own proven-red regression test | Accepted | 2026-07-08 | testing, ci, docs-as-code |
| 0142 | Config fields that reference an outside-defined entity ship a resolution gate that fails closed | Accepted | 2026-07-08 | ci, pipelines, config-as-code |
| 0143 | Any service with a web UI is exposed externally behind Entra Access and its start-page tile links out; headless services are hidden | Accepted | 2026-07-08 | cloudflare, entra, sso |
| 0144 | Codify Dispatcharr config as snapshot-tier config-export-as-code (first snapshot appliance) | Accepted | 2026-07-08 | gitops, config-as-code, ansible |
| 0145 | Codify UrBackup config as snapshot-tier config-export-as-code | Accepted | 2026-07-08 | gitops, config-as-code, ansible |
| 0146 | Codify iVentoy config as snapshot-tier config-export-as-code (opaque binary + sidecar) | Accepted | 2026-07-08 | gitops, config-as-code, ansible |
| 0147 | Codify Plex config as snapshot-tier — reclassified from split (assert is service-disruptive) | Accepted | 2026-07-08 | gitops, config-as-code, ansible |
| 0148 | docker01 is a governed two-tier deploy estate — docker-stacks + the ansible-deploy bespoke tier | Accepted | 2026-07-08 | gitops, config-as-code, ansible |
| 0149 | A Token-Optimization Standard grown from per-session wrap-up harvest, not a one-time guess | Accepted | 2026-07-08 | automation, docs-as-code |
| 0150 | External exposure requires a Cloudflare Access gate, or an approved register entry | Accepted | 2026-07-08 | security, networking, cloudflare |
| 0151 | Bespoke-app deploy playbooks converge in a single health-gated build task — no post-health recreate handlers | Accepted | 2026-07-08 | ansible, docker, config-as-code |
| 0152 | Migrate the xt035→xv035 PBS remote off root@pam onto a dedicated least-privilege token | Accepted | 2026-07-09 | pbs, backup, security |
| 0153 | pve01 ZFS/ARC/IO observability — activate the staged ZFS template and add windowed ARC + PSI tripwires | Accepted | 2026-07-10 | zabbix, zfs, proxmox |
| 0154 | Zabbix agent↔server encryption via per-host PSK, generated host-local | Unstated | 2026-07-10 | zabbix, encryption, tls |
| 0155 | Title withheld — it contains an internal identifier | Unstated | 2026-07-10 | encryption, tls, mtls |
| 0156 | PVE guest boot order — tiered startup so control01/MCP comes up after docker01 | Accepted | 2026-07-11 | proxmox, terraform, lifecycle |
| 0157 | Operational resilience — T0–T3 tolerance tiers and a capability-led critical-operations register | Accepted | 2026-07-11 | resilience, backup, netbox |
| 0158 | Recoverability is proven by an automated restore drill, not chunk verification | Accepted | 2026-07-11 | resilience, backup, pbs |
| 0159 | The restore drill runs from control01 and tears down by marker, not by VMID range | Accepted | 2026-07-11 | resilience, backup, pbs |
| 0160 | Qdrant encryption-in-transit cutover — native API key + split transport (same-host pki http, cross-host Caddy TLS) | Unstated | 2026-07-11 | encryption, tls, security |
| 0161 | Resilience observability — job-workload availability substitute, split alert surfaces, and a human IR/BC plan | Accepted | 2026-07-11 | resilience, observability, incidents |
| 0162 | Alerting delivery failover — critical alerts fan out to Pushover AND email-of-last-resort | Accepted | 2026-07-11 | alertmanager, resilience, monitoring |
| 0163 | Testplan gate scopes auto-revert to the offending stack, and gates index freshness on staleness-vs-docs not age-since-reindex | Accepted | 2026-07-11 | ci, pipelines, pit-memory |
| 0164 | Prometheus + Alertmanager encryption-in-transit cutover — testplan-gate basic-auth primitive unblocks unpublishing :9090/:9093 | Unstated | 2026-07-11 | encryption, tls, security |
| 0165 | Encryption-in-Transit Standard — trust-boundary policy, exceptions register, and a live conformance gate | Unstated | 2026-07-14 | encryption, tls, security |
| 0166 | Morning health runbook — an autonomous scheduled Claude digest on control01, not a cloud routine | Unstated | 2026-07-14 | operations, monitoring, observability |
| 0167 | Home Assistant entity metrics via the Prometheus integration (lights brightness + colour temperature) | Accepted | 2026-07-15 | homeassistant, observability, prometheus |
| 0168 | Podcast staleness alerts survive gauge resets, verge gains a consumer-side error alert and a backfill capability | Accepted | 2026-07-15 | observability, prometheus, alerting |
| 0169 | Home Assistant update-control pipeline (GitOps, assessed, auto-rollback) | Implemented | 2026-07-15 | homeassistant, devsecops |
| 0170 | Home Assistant automations use raw zha_event triggers on device_ieee | Accepted | 2026-07-15 | homeassistant, automation |
| 0171 | Home Assistant Prometheus endpoint switches to authenticated (supersedes ADR-0167 exposure posture) | Unstated | 2026-07-15 | homeassistant, observability, prometheus |
| 0172 | Loki per-stream retention override for the Home Assistant log stream | Accepted | 2026-07-15 | observability, loki, homeassistant |
| 0173 | pit-mini text model migrated qwen2.5:14b → qwen3:8b; all Ollama models pinned; central model var | Accepted | 2026-07-15 | ollama, llm, ai |
| 0174 | Loki encryption-in-transit cutover — unpublishing :3100 required a full host-consumer sweep, macOS keychain trust, and a lokiq helper | Unstated | 2026-07-15 | encryption, tls, security |
| 0175 | vulnscan runs as a headless-Claude cron on control01, not a Claude cloud routine | Accepted | 2026-07-15 | devsecops, scheduling, cron |
| 0176 | Standard-Enforcement Standard — the meta-standard governing how every standard is mechanically enforced | Accepted | 2026-07-15 | standard-enforcement, policy-as-code, ci |
| 0177 | Ollama wedge-watchdog detects via an active text-model generate probe (supersedes ADR-0168's log-only sketch), guards on runner CPU, and auto-recovers | Accepted | 2026-07-15 | ollama, pit-mini, observability |
| 0178 | EiT same-host residual ports collapse to pki container-name addressing (unpublish, not 127.0.0.1) | Unstated | 2026-07-16 | encryption, tls, networking |
| 0179 | Dependency-Track SBOM import reliability: verify the import landed, give the JVM heap headroom, and watchdog freshness | Accepted | 2026-07-16 | devsecops, dependency-track, vulnscan |
| 0180 | Headless workloads register in the rollup via a synthetic probe_success recording rule, not a blackbox probe | Accepted | 2026-07-16 | dashboards, grafana, observability |
| 0181 | Zigbee mesh-health alerts use series-absence for offline, not last_updated age | Implemented | 2026-07-16 | homeassistant, observability, alertmanager |
| 0182 | Dependency-Track large-BOM import/delete OOM is an in-transaction component-backlog operation, not the internal analyzer: fix by one-time backlog cleanup, keep 12g heap and the analyzer on | Accepted | 2026-07-16 | devsecops, dependency-track, vulnscan |
| 0183 | Disk-image header inspection uses a bounded read to disk, never a full expansion into tmpfs | Implemented | 2026-07-16 | proxmox, zfs, reliability |
| 0184 | Loki Log-Retention Standard: named tiers, ADR-backed per-stream overrides, bounded budget | Accepted | 2026-07-17 | observability, loki, logging |
| 0185 | Home Assistant full lighting-telemetry model (behaviour + responsiveness) | Accepted | 2026-07-17 | homeassistant, observability, lighting |
| 0186 | Fleet Update Policy: one unified patch/update-management standard so every container, LXC, and VM auto-updates under governance | Implemented | 2026-08-05 | maintenance, patching, renovate |
| 0187 | Dependency-Track project lifecycle: digest-stable project naming plus full-scan orphan reconciliation, so renamed/decommissioned images don't accumulate stale SBOM projects | Accepted | 2026-07-17 | devsecops, dependency-track, vulnscan |
| 0188 | Renovate Docker Hub 429 tag-enumeration truncation: throttle the per-IP tag API, authenticate the registry | Accepted | 2026-07-17 | renovate, docker, automation |
| 0189 | The weekly vectormap render moves from a user-cron to a systemd timer with Persistent=true so a slot missed while the host was down is caught on next boot | Accepted | 2026-07-17 | scheduling, cron, reliability |
| 0190 | pit-mini Alloy uses local.file_match (polled glob) so a late-appearing log is discovered, not permanently skipped | Accepted | 2026-07-17 | observability, loki, alloy |
| 0191 | Renovate per-format regex versioning for the linuxserver media images so they produce update PRs | Accepted | 2026-07-17 | renovate, ci, lifecycle |
| 0192 | The WiFi congestion dashboard reads Zabbix directly via a Grafana Zabbix datasource, and is a rollup-exempt dashboard because Zabbix-only metrics cannot drive the Prometheus probe_success primitive | Accepted | 2026-07-18 | dashboards, grafana, zabbix |
| 0193 | bun3d restores the newest UrBackup image by assembling the full+incremental differencing chain, gated by a boot-acceptance test | Accepted | 2026-07-18 | backup, urbackup, bun3d |
| 0194 | pit-mini UPS graceful-shutdown watchdog | Unstated | 2026-07-18 | pit-mini, ups, apple |
| 0195 | docker01 holds a static LAN IP instead of DHCP, because an infra node hosting the whole docker stack must not depend on DHCP being reachable at lease-renewal | Unstated | — | networking, docker01, proxmox |
| 0196 | WiFi lighting alerts use HA entity-availability, not ICMP reachability/RTT | Unstated | 2026-07-18 | homeassistant, observability, alertmanager |
| 0197 | UrBackup client staleness alerts only when the client is online but not backing up | Implemented | 2026-07-18 | backup, urbackup, zabbix |
| 0198 | The B2 offsite copy is proven by a monthly restore-test, not a full chunk-verify | Implemented | 2026-07-18 | backup, pbs, backblaze |
| 0199 | Patch+reboot coordinator: a control01 central orchestrator with a self-host carve-out, net-new composite gate, and mode-gated rollout | Accepted | 2026-07-18 | patching, maintenance, automation |
| 0200 | The Trivy import-verify gate polls DT for async BOM ingestion before declaring systemic loss | Unstated | 2026-07-18 | devsecops, dependency-track, trivy |
| 0201 | Holding a fixed brightness under Adaptive Lighting requires the persistent adapt_brightness switch off, not a one-shot apply flag | Accepted | 2026-07-18 | homeassistant, lighting |
| 0202 | The schedule reconciler resolves each timer's host from the manifest and treats an unreachable surface as advisory, not drift | Accepted | 2026-07-18 | scheduling, cron, automation |
| 0203 | The docs pipeline self-heals its prebaked Mermaid-validator image, and docker-prune exempts prebaked build-tool images via a pitlab.keep label | Accepted | 2026-07-19 | docs-as-code, ci, pipelines |
| 0204 | KB-draft review digest by email plus a standing backlog Epic, so the self-healing loop's output stops hiding under a closed Epic | Implemented | 2026-07-19 | notifications, observability, aiops |
| 0205 | Durable ADO pipeline-wait pattern: discover by SHA, follow detached, classify the result | Implemented | 2026-07-19 | ado, ci, aiops |
| 0206 | docker01 gets a UDM local DNS record instead of removing the UDM tertiary resolver, because the UDM is the deliberate power-outage DNS fallback | Accepted | 2026-07-19 | dns, docker01, networking |
| 0207 | control01 pins its deploy-critical DNS names in /etc/hosts, closing the Infisical fall-through gap ADR-0206 left open | Accepted | 2026-07-19 | dns, control01, infisical |
| 0208 | pipewait --silence: tag-scoped Zabbix muting of a pipeline's failed-alert during an agent-driven deploy wait | Implemented | 2026-07-19 | ado, ci, alerting |
| 0209 | n8n Code nodes read Infisical-injected secrets via $env (N8N_BLOCK_ENV_ACCESS_IN_NODE=false) instead of hardcoded literals | Accepted | 2026-07-19 | n8n, security, secrets |
| 0210 | External dead-man's-snitch (Zabbix-health-gated heartbeat) | Accepted | 2026-07-19 | monitoring, alerting, resilience |
| 0211 | Entra MFA is a documented control (Security Defaults), not Conditional-Access-as-code | Accepted | 2026-07-19 | identity, security, entra |
| 0212 | PBS agent credential moves from root@pam!claude (Admin) to a dedicated claude@pbs (Audit) | Unstated | 2026-07-19 | pbs, security, identity |
| 0213 | Paperless app-level signals restored via a pki-native Prometheus exporter, not an internal Caddy vhost + Zabbix HTTP-item repoint | Accepted | 2026-07-19 | paperless, observability, prometheus |
| 0214 | NetBox off-box consumers get an internal Caddy vhost, not the pki-by-name collapse | Unstated | 2026-07-20 | encryption, tls, networking |
| 0215 | Decom snapshot pruning uses a dedicated claude-prune@pbs (DatastoreAdmin on /datastore), not a write grant on the agent's general PBS token | Unstated | 2026-07-20 | pbs, security, identity |
| 0216 | Dedicated alerts@ mailbox for the email failover, and Zabbix failover parity with Alertmanager | Accepted | 2026-07-20 | alertmanager, zabbix, resilience |
| 0217 | Local root/system mail is routed to Pushover by an exim router, not bounced at the M365 smarthost | Accepted | 2026-07-20 | exim4, mail, alerting |
| 0218 | qbittorrent WebUI fronted over pki via gluetun on the pki bridge, so the raw :8090 LAN publish is retired for a verified step-ca TLS edge | Accepted | 2026-07-20 | qbittorrent, encryption-in-transit, caddy |
| 0219 | Unattended scripts carry dual-signal observability (heartbeat + journald), by shape | Accepted | 2026-07-20 | scripts, observability, logging |
| 0220 | Caddy-fronted Cloudflare tunnel origins MUST set http_host_header; edge probes must assert body content | Unstated | 2026-07-20 | cloudflare, caddy, encryption-in-transit |
| 0221 | SMTP relay STARTTLS + verifiable Proxmox/PBS appliance certs (step-ca) | Unstated | 2026-07-20 | encryption-in-transit, tls, step-ca |
| 0222 | Notification-catalog guard coverage hardening + script-standard enterprise additions | Accepted | 2026-07-20 | scripts, notifications, pushover |
| 0223 | Claude OAuth refresh-token expiry is watchdogged with lead-time alerting, not auto-renewed | Accepted | 2026-07-21 | claude, cc-pool, identity |
| 0224 | A Caddy-fronted cutover MUST reconcile the backend app's host-header allowlist against the rewritten Host | Accepted | 2026-07-21 | cloudflare, caddy, encryption-in-transit |
| 0225 | step-ca-fronted PBS storages trust the CA (no leaf-fingerprint pin) + FQDN server | Unstated | 2026-07-21 | backup, pbs, proxmox |
| 0226 | Alloy config is syntax-validated before deploy (template validate hook + CI fmt gate) | Accepted | 2026-07-21 | observability, alloy, logging |
| 0227 | The EiT conformance gate encodes off-box-consumer pre-validation for port unpublishes | Unstated | 2026-07-21 | encryption, tls, networking |
| 0228 | Homepage proxmox/PBS widgets dial FQDN + trust step-ca, but app-layer TLS verification is not enforceable | Unstated | 2026-07-21 | encryption, tls, homepage |
| 0229 | RustDesk :21114 is the web console, not an anonymous-client port — TLS-front and unpublish it | Unstated | 2026-07-21 | encryption, tls, caddy |
| 0230 | Guest backups are governed by a placement/schedule/throttle standard, not left to default vzdump | Accepted | 2026-07-21 | backup, pbs, zfs |
| 0231 | control01 OOM hardening — pre-OOM early warning, agent self-heal, bias the kill onto the agent, notify | Accepted | 2026-07-21 | zabbix, alerting, observability |
| 0232 | Fleet memory-headroom monitoring standard — house template + data-driven per-host macros | Accepted | 2026-07-21 | zabbix, alerting, observability |
| 0233 | Design-to-as-built traceability lifecycle — grillme design docs reconciled against ADRs at wrapup | Accepted | 2026-07-21 | architecture, lifecycle, docs |
| 0234 | systemd self-heal integrity — Restart=always requires a clean cgroup reap or a documented orphan-safe exception | Accepted | 2026-07-22 | systemd, self-healing, ansible |
| 0235 | CI playbooks must be memory-bounded — the single agent OOMs before more RAM can save it | Accepted | 2026-07-22 | ansible, config-as-code, ci |
| 0236 | CI shared-mirror sync converges to origin unconditionally — robust to any local state, including a stranded unmerged index | Accepted | 2026-07-22 | ci, pipelines, git |
| 0237 | Ansible docs commit-back resets to origin then regenerates — never stash-reconciles — factored into one shared pipeline template | Accepted | 2026-07-22 | ci, pipelines, git |
| 0238 | HA press-without-action detector tolerates marker-ordering skew and ignores unbound commands | Accepted | 2026-07-23 | homeassistant, observability, alerting |
| 0239 | Go-runtime containers must declare GOMEMLIMIT — a cgroup mem_limit alone OOM-kills the GC that can't see it | Accepted | 2026-07-23 | docker, containers, observability |
| 0240 | The Monitoring-as-Code drift audit covers Zabbix actions, with a stock-default baseline allowlist | Accepted | 2026-07-23 | zabbix, monitoring, config-as-code |
| 0241 | Per-host Caddy TLS terminators for EiT Class-B cross-host cloudflared origins | Implemented | 2026-07-23 | encryption, tls, pki |
| 0242 | NFR doc type and the Requirements section | Accepted | 2026-07-24 | docs-as-code, observability, aiops |
| 0243 | Hysteresis on the Home Assistant low-battery Zabbix trigger | Accepted | 2026-07-25 | monitoring, observability, homeassistant |
| 0244 | claude-pod single-run failure observability and compose resilience | Accepted | 2026-07-25 | observability, prometheus, alerting |
| 0245 | Alertable counter instrumentation — prime labelled children, gauge-back discrete-run alerts | Accepted | 2026-07-25 | alerting, prometheus, observability |
| 0246 | claude-pod streaming Ollama compose — durable per-chunk-timeout fix | Accepted | 2026-07-25 | podcast, media, observability |
| 0247 | Central Caddy TLS terminator SPOF — accepted and hardened, redundancy rejected as architecturally void | Accepted | 2026-07-25 | security, caddy, encryption-in-transit |
| 0248 | Homepage curated extra-tiles overlay, proxyless widget-gate skip, Grafana embed | Accepted | 2026-07-25 | infrastructure |
| 0249 | Secure external API exposure via Cloudflare Access service tokens — risk-tiered | Accepted | 2026-07-25 | cloudflare, security, identity |
| 0250 | Client-side estate DNS pin needs two layers — global resolved scope plus per-link UseDomains=no — so a DHCP-supplied UDM resolver can never poison estate names | Accepted | 2026-07-25 | dns, pihole, infrastructure |
| 0251 | Disable the Dependency-Track OSS Index analyzer — Sonatype Guide migration ended viable free-tier use | Accepted | 2026-07-25 | security, devsecops |
| 0252 | Standards consolidation — the unit of a standard is the domain | Accepted | 2026-07-25 | docs-as-code, architecture, knowledge-management |
| 0253 | Reboot coordinator defers for active Claude sessions, capped | Accepted | 2026-07-26 | patching, maintenance, automation |
| 0254 | Zabbix config-as-code reconciles endpoint fields against spec; create-if-missing alone is non-conforming | Accepted | 2026-07-26 | zabbix, monitoring, config-as-code |
| 0255 | cloudflared tunnel credential is sourced from Infisical, not a hand-placed file | Accepted | 2026-07-26 | cloudflare, networking, infisical |
| 0256 | Cloudflare account token carries the full free-tier permission set, IP-locked, re-permissioned only via an external break-glass credential | Accepted | 2026-07-26 | cloudflare, security, identity |
| 0257 | Device-facing internal TLS — trust the internal CA on personal devices; Let's-Encrypt-for-devices rejected at this scale | Unstated | 2026-07-26 | encryption, tls, pki |
| 0258 | The Encryption-in-Transit register covers off-docker01 hosts, inventoried by ss(8) against a derived host set | Accepted | 2026-07-26 | encryption-in-transit, security, config-as-code |
| 0259 | Import all remaining live Cloudflare config into tf-cloudflare (zero-drift edge-as-code) | Accepted | 2026-07-26 | cloudflare, networking, config-as-code |
| 0260 | Admin-tier Cloudflare Access apps require the Homelab Admins Entra group | Accepted | 2026-07-26 | cloudflare, security, identity |
| 0261 | The agent's settings are split — endpoints tracked in settings.json, credentials in gitignored settings.local.json | Unstated | 2026-07-26 | claude, config-as-code, secrets |
| 0262 | The macOS TLS terminator is a separate launchd/Homebrew playbook, not an OS branch in the Debian role | Unstated | 2026-07-26 | encryption, encryption-in-transit, tls |
| 0263 | Actionable page-until-acted alert archetype (ADO approval → emergency) | Accepted | 2026-07-26 | alerting, zabbix, ado |
| 0264 | Sleep quiet-hours is a rest-protection mute, distinct from planned maintenance | Accepted | 2026-07-26 | alerting, alertmanager, zabbix |
| 0265 | Cloudflare config-completeness / drift gate in the tf-cloudflare pipeline | Accepted | 2026-07-26 | cloudflare, terraform, config-as-code |
| 0266 | tf-cloudflare pipeline uses a clean per-run checkout + canonical off-tree local state | Accepted | 2026-07-26 | terraform, cloudflare, ci |
| 0267 | Home Assistant terminates TLS natively on :8123 with a 90-day step-ca leaf, not behind a proxy | Unstated | 2026-07-26 | encryption, encryption-in-transit, tls |
| 0268 | tf-cloudflare auto-applies posture-neutral plans; a plan-risk classifier gates only exposure/Access/WAF/delete | Unstated | 2026-07-26 | terraform, cloudflare, ci |
| 0269 | The blog publishing-activity metric is a Zabbix trapper fed by history.push, not a UserParameter | Unstated | 2026-07-26 | observability, zabbix, docs |
| 0270 | a docker-stacks pipeline must trigger on the path of every gate script it runs (scripts/**) | Accepted | 2026-07-27 | ci, pipelines, docker |
| 0271 | Zigbee router offline is a positive reachability assertion, not metric series-absence | Implemented | 2026-07-27 | homeassistant, observability, alertmanager |
| 0272 | Home Assistant :8123 stays plaintext as an accepted EiT exception — native http.ssl_certificate is the wrong shape for a HAOS appliance | Unstated | 2026-07-27 | encryption, encryption-in-transit, tls |
| 0273 | Home Assistant TLS via the core_nginx_proxy add-on + step-ca leaf — both protocols live, no restart tax | Unstated | 2026-07-27 | encryption, encryption-in-transit, tls |
| 0274 | Post-close findings are incidents, not backlog — Epic closure is operational acceptance | Accepted | 2026-07-28 | itsm, operations, ado |
| 0275 | Memory eviction promotes reference-misfiled-as-project and anchors on an owning Epic | Unstated | 2026-07-29 | memory, agent-memory, docs-as-code |
| 0276 | Fixless ghost incidents soak auto-close after a quiet period | Accepted | 2026-07-29 | itsm, operations, freescout |
| 0277 | Fleet-wide secret-scan coverage with a conformance gate — a declared control must be enforced everywhere, not wired once | Accepted | 2026-07-29 | security, devsecops, ci |
| 0278 | HA :8123 stays an accepted, census-verified-unused residual — PVE per-VM firewall is estate-infeasible | Unstated | 2026-07-29 | homeassistant, firewall, proxmox |
| 0279 | pve01 FORWARD-DROP made firewall-safe via a DOCKER-USER vmbr0 ACCEPT rule, not by removing Docker | Unstated | 2026-07-30 | firewall, proxmox, pve01 |
| 0280 | Outbound Claude email splits into three sender personas (alerts / engineer / reports) so Arron can filter by message class | Unstated | 2026-07-31 | notifications, email, alerting |
| 0281 | EiT close-out — native-TLS hosts join the ss(8) inventory via a second derivation marker | Unstated | 2026-07-31 | encryption-in-transit, security, pve01 |
| 0282 | Source homepage widget secrets from their canonical Infisical path, not a hand-filled copy | Accepted | 2026-07-05 | homepage, infisical, secrets |
| 0283 | A pipeline gate fails closed when a flag's required secret is unwired | Accepted | 2026-08-01 | ci, pipelines, encryption-in-transit |
| 0284 | EiT gate closes two --check-zabbix-tls blind spots (macro URLs, plaintext items) | Accepted | 2026-08-01 | encryption-in-transit, zabbix, monitoring |
| 0285 | Monitoring-as-code rule-source attributions must be substantiated by their source | Accepted | 2026-08-01 | monitoring, config-as-code, zabbix |
| 0286 | control01 .git-credentials ownership self-healing tripwire | Accepted | 2026-08-01 | cc-pool, secrets, ado |
| 0287 | The agent's six service API keys are sourced live from Infisical, not held at-rest | Accepted | 2026-08-01 | secrets, config-as-code, control01 |
| 0288 | ~/.claude.json mcpServers become config-as-code: a tracked secret-free fragment reconciled from Infisical | Accepted | 2026-08-01 | config-as-code, secrets, control01 |
| 0289 | EiT gate gains a macOS/Darwin netstat inventory branch | Unstated | 2026-08-01 | encryption-in-transit, security, apple |
| 0290 | pit-mini EiT enrollment — residual listener disposition + macOS/Pi Zabbix PSK stragglers | Unstated | 2026-08-01 | encryption-in-transit, security, apple |
| 0291 | Scheduled all-host deploys tolerate transient single-host unreachability | Accepted | 2026-08-01 | ansible, ci, pipelines |
| 0292 | CI gate flags increase()/rate() absence-guards (counter-birth) in alert rules | Accepted | 2026-08-01 | observability, ci, pipelines |
| 0293 | Reboot coordinator guards and verification follow the blast radius, not the host boundary | Accepted | 2026-08-02 | patching, maintenance, automation |
| 0294 | A successful overnight change is a morning report, not a 4am page | Accepted | 2026-08-02 | alerting, maintenance, observability |
| 0295 | MCP server health is proven by a client-side JSON-RPC initialize handshake from control01, because /health and an unauthenticated /mcp probe are both answered before the MCP application is reached | Accepted | 2026-08-03 | observability, monitoring, alerting |
| 0296 | 2.4GHz congestion monitoring decomposes channel airtime into own versus external, because total channel utilisation alone cannot distinguish our own traffic from a neighbour stealing the channel | Accepted | 2026-08-03 | observability, monitoring, alerting |
| 0297 | Under cron, stdout is an alerting channel, not a log channel | Accepted | 2026-08-03 | observability, alerting, automation |
| 0298 | A grab that neither imports nor fails is a silent task failure; detect it and re-search, not just alert | Accepted | 2026-08-03 | observability, alerting, media |
| 0299 | Feedback hygiene discovers its corpus fleet-wide, and cross-session re-learning is promotion pressure | Accepted | 2026-08-03 | claude, memory, aiops |
| 0300 | A 2.4GHz min_rssi floor is safe only where every client below it has a proven alternate AP, and proving that needs a 90-day session window validated by a control | Accepted | 2026-08-03 | networking, wifi, unifi |
| 0301 | Critical-tier patch and digest bumps auto-merge, because a review gate the automation is separately authorised to bypass is latency, not control | Accepted | 2026-08-03 | docker, renovate, dependency-management |
| 0302 | A vulnerability with no upstream fix path is risk-accepted with named controls, an expiry and an upstream watch — never left as a standing finding | Accepted | 2026-08-03 | security, devsecops, dependency-track |
| 0303 | Claude Pod sources the docs Blog via a control01-side clone+rsync, keeping the container credential-free | Accepted | 2026-06-26 | docker, podcast, security |
| 0304 | Plex Wrapped is a self-hosted ansible cron emailing each subscriber a personalised year-in-review, not the Tautulli or Plex native reports | Accepted | 2026-07-02 | plex, tautulli, media |
| 0305 | Absence must never be encoded as a value inside a metric's alertable range, and a sustained-threshold trigger must match its comparison operator | Accepted | 2026-08-03 | monitoring, zabbix, alerting |
| 0306 | Household WiFi reliability is measured by a client-weighted SLI (share of 2.4GHz clients at or above -75 dBm), with the SLO calibrated from measured baseline rather than chosen | Accepted | 2026-08-03 | monitoring, zabbix, alerting |
| 0307 | Work handed to an asynchronous executor must be asserted to reach a terminal state; absence past a deadline is a failure, not pending | Accepted | 2026-08-04 | alerting, observability, standard-enforcement |
| 0308 | Health-check expressions assert the shape of a healthy response rather than an exact mutable value, because a value pin fires on every routine upgrade and silently turns the check into a no-op | Accepted | 2026-08-04 | observability, monitoring, alerting |
| 0309 | Stack-deploy tag taxonomy — rebuild is a superset of restart | Accepted | 2026-08-04 | ansible, gitops, docker01 |
| 0310 | A batch script's partial failure is a correctness fault, not a liveness one | Accepted | 2026-08-04 | scripts, observability, monitoring |
| 0311 | Pipeline trigger economy — batch:true estate-wide, cross-repo triggers path-scoped | Unstated | 2026-08-04 | ci, pipelines, gitops |
| 0312 | Ansible always-on guards consolidated into one ansible-ci pipeline | Unstated | 2026-08-04 | ci, pipelines, gitops |
| 0313 | Vulnerability management gets a standard with numbers, because a loop with no deadline cannot breach anything | Accepted | 2026-08-05 | security, devsecops, vulnscan |
| 0314 | Every machine-readable config that governs deploys ships a CI validator, in two layers — schema and semantic | Accepted | 2026-08-05 | ci, pipelines, gitops |
| 0315 | Dependencies with an inter-version constraint are grouped into one Renovate PR, and their acceptance test is the rendered artifact | Accepted | 2026-08-05 | renovate, dependency-management, gitops |
| 0316 | Defer the Material for MkDocs → Zensical migration to a 2026-10-01 review, with named trigger conditions | Accepted | 2026-08-05 | docs-as-code, mkdocs, automation |
| 0317 | Guardrails assert the real artifact and fail closed | Accepted | 2026-08-05 | standard-enforcement, reliability, patching |
| 0318 | Terminal job failures keep their incident record during quiet-hours | Accepted | 2026-08-05 | alerting, alertmanager, observability |
| 0319 | pit-memory binds before indexing and swaps a shadow index in | Accepted | 2026-08-05 | app, observability |
| 0320 | Test-plan auto-rollback requires proof of persistence when causality cannot be proven structurally | Accepted | 2026-08-05 | ci, pipelines, observability |
| 0321 | Run-to-completion workloads are gated on their produced artifact, not their exit code | Accepted | 2026-08-05 | ci, pipelines, observability |
| 0322 | Pipeline job economy — a deploy pipeline spends one job, because jobs are the unit of preemption | Unstated | 2026-08-05 | ci, pipelines, gitops |
| 0323 | Decommission the five-great-reads-podcast (Guardian Audio) feature | Unstated | 2026-08-06 | podcast, media, decommission |
| 0324 | A build-time dependency is a first-class dependency — pitlab-docs joins Renovate, and the docs build image joins SBOM coverage | Accepted | 2026-08-06 | renovate, dependency-management, docs-as-code |
| 0325 | The docs link/backlink/tag gate is generator-independent — only rendering stays bound to the MkDocs hooks API | Accepted | 2026-08-06 | docs-as-code, mkdocs, ci |
| 0326 | Never wake the operator — no notification exceeds Pushover priority 0 | Accepted | 2026-08-05 | alerting, pushover, notifications |
| 0327 | pit-mini is scanned locally in SBOM-only mode, not delegated to control01 | Accepted | 2026-08-06 | security, devsecops, trivy |
| 0328 | vulnerability SLA conformance is measured daily, and the backlog alert is a burn-rate | Accepted | 2026-08-06 | security, devsecops, dependency-track |
| 0329 | CI trigger gaps are detected by a reconciler, and pipeline liveness is derived from the ADO API | Accepted | 2026-08-06 | ci, pipelines, ado |
| 0330 | Terraform state and CI cross-host artifacts live on a bind-mounted ZFS dataset, and same-target pipeline runs serialise on it | Accepted | 2026-08-07 | ci, pipelines, terraform |
| 0331 | The CI queue-time SLO, one collector behind it, and a parity gate that holds the pool together | Accepted | 2026-08-07 | ci, pipelines, ado |
| 0332 | ansible-ci collapses to one job, retiring the last job-boundary exemption | Accepted | 2026-08-07 | ci, pipelines, ado |
| 0333 | The CI pool is plural — gate-script location and pipeline-fed liveness stop assuming one agent | Accepted | 2026-08-07 | ci, pipelines, ado |
| 0334 | A pool's agents must actually be interchangeable — composition, parity, and the sub-tables nobody was enforcing | Unstated | 2026-08-07 | ci, pipelines, ado |
| 0335 | Fleet account uids are pinned, and a shared filesystem is shared by gid, never by owner | Accepted | 2026-08-07 | standard, config-as-code, proxmox |
| 0336 | Prime Directive 1 gets a helper, because the pvesh snapshot form fails silently on a bind-mounted guest | Accepted | 2026-08-07 | proxmox, zfs, operations |
| 0337 | The HAOS deploy pipelines are made peers of the pool, not pinned to control01 — and pipelines gain a portability class | Unstated | 2026-08-07 | ci, pipelines, ado |
| 0338 | ansible-ci's run count is ACCEPTED on the measured SLI, and the one trigger change goes the other way | Accepted | 2026-08-07 | ci, pipelines, ado |
| 0339 | pipewait distinguishes a skipped commit from a lost trigger, sizes discovery to measured queue latency, and names the agent | Accepted | 2026-08-07 | ci, pipelines, ado |
| 0340 | A control is only proven against the real artifact — fixtures, fallbacks and the content a gate reads | Unstated | 2026-08-07 | ci, pipelines, standard |
| 0341 | Service transition is a gated deliverable — the test plan is the handover artifact and the gate is fail-closed | Accepted | 2026-08-07 | standard, testing, reliability |
| 0342 | Guardian automations must observe attribute drift and self-heal on a sweep | Accepted | 2026-08-07 | homeassistant, lighting, automation |
| 0343 | Home Assistant Automation Standard — a bare delay is not a timer | Unstated | 2026-08-07 | homeassistant, automation, appliance |
| 0344 | Lighting Standard ratified — switch-off beats manual_control, and a real gate beats an advisory row | Unstated | 2026-08-07 | homeassistant, lighting, automation |
| 0345 | Pipeline stack-list completeness is gated, because the enumeration of what to gate was itself ungated | Accepted | 2026-08-08 | standard, ci, pipelines |
| 0346 | Service application code lives beside its stack and is mounted, not baked | Accepted | 2026-08-08 | standard, scripts, docker |
| 0347 | Country-level charts, because per-provider top-3 is not sourceable and fails silently | Accepted | 2026-08-08 | media, arr, observability |
| 0348 | *arr import lists are config as code, reconciled read-only on a schedule | Accepted | 2026-08-08 | standard, media, arr |
| 0349 | Container-internal schedules are declarable, and must carry an artifact dead-man | Accepted | 2026-08-08 | standard, scheduling, observability |
| 0350 | Destructive auto-remediation must alert below its action threshold and abort on no progress | Unstated | 2026-08-08 | standard, alerting, observability |
| 0351 | Standards adherence gap analysis and monthly assurance reporting | Accepted | 2026-08-08 | standard-enforcement, audit, policy-as-code |
| 0352 | Compliance & Assurance Standard and the control catalogue as code | Accepted | 2026-08-08 | standard-enforcement, audit, compliance |
| 0353 | Corpus retrieval technique is a governed standard, not agent habit | Accepted | 2026-08-08 | standard, docs-as-code, automation |
| 0354 | The pre-push link gate stages a local assembled corpus | Accepted | 2026-08-08 | docs-as-code, pipelines, standard-enforcement |
| 0355 | Split relief path: the arr API owns retention deletes, pve01 moves the bytes for pressure relief | Accepted | 2026-08-08 | media, storage, automation |
| 0356 | media_cleanup guard: per-item deterministic assertions replace the pool-free byte-delta | Accepted | 2026-08-08 | automation, storage, testing |
| 0357 | Amendment to ADR-0350 clause 2: progress must be measured in a counter only your own action changes | Accepted | 2026-08-08 | standard, automation, storage |
| 0358 | Container cpus caps are sized from observation, not chosen by eye | Accepted | 2026-08-08 | containers, observability |
| 0359 | servicemap: a derived, fail-closed service-dependency explorer | Accepted | 2026-08-08 | observability, docs-as-code, source-of-truth |
| 0360 | Browser-delivered JavaScript is a managed dependency | Accepted | 2026-08-08 | security, devsecops, vulnscan |
| 0361 | the remediation-backlog alert is a dated ceiling, not a burn-rate — the backlog ages upward on its own | Accepted | 2026-08-08 | security, devsecops, dependency-track |
| 0362 | pve01's one privileged path is sudo-over-SSH — the claude@pam API token stays audit-only, and Prime Directive 1's documented command is corrected | Accepted | 2026-08-08 | proxmox, pve01, security |
| 0363 | a Dependency-Track project identity is per deployed instance, not per image name — namespace the image plane by owning host | Accepted | 2026-08-08 | security, devsecops, dependency-track |
| 0364 | the open-dependency-PR merge/defer clause becomes a machine check — branch prefix, renovate.json tier, and a dated deferral label | Accepted | 2026-08-08 | security, devsecops, renovate |
| 0365 | Zabbix agent restart must precede the item-health proof, and must survive a failed run | Accepted | 2026-08-08 | monitoring, zabbix, ansible |
| 0366 | ADR number claiming runs in a private clone, never a shared checkout | Accepted | 2026-08-08 | docs-as-code, automation, git |
| 0367 | pipewait derives the expected pipeline set from changed paths and reports NOT_TRIGGERED | Unstated | 2026-08-08 | ci, pipelines, ado |
| 0368 | Host-to-repo stack-source reconciliation, because every other gate enumerates from the repo | Unstated | 2026-08-09 | standard, ci, pipelines |
| 0369 | A pending handler must survive a failed play, and every restart-notifying play must declare its posture | Accepted | 2026-08-09 | ansible, config-as-code, reliability |
| 0370 | Dashboard conformance asserts baseline panels return data across the Prometheus and Loki tiers | Accepted | 2026-08-09 | observability, monitoring, standard-enforcement |
| 0371 | servicemap freshness SLO and error-budget policy | Accepted | 2026-08-09 | observability, monitoring, reliability |
| 0372 | Mid-delivery findings accumulate on one snag list per Epic and are adjudicated at close-out — the agent never creates an Epic | Accepted | 2026-08-09 | ado, operations, itsm |
| 0373 | Estate DNS resolves through systemd-resolved, and estate records are cacheable | Accepted | 2026-08-09 | dns |
| 0374 | Session-destroying reboots get 72h advance notice, not a better idleness heuristic | Accepted | 2026-08-09 | patching, maintenance, automation |
| 0375 | A repo script invoked by a play executes controller-side, never out of a target's own checkout | Accepted | 2026-08-09 | ansible, config-as-code, ci |
| 0376 | SSH pipelining is enabled fleet-wide, because it removes a per-task round trip and fixes unprivileged become | Accepted | 2026-08-10 | ansible, performance, config-as-code |
| 0377 | cc-pool sessions drain and auto-resume across a reboot, verified by content parentage | Accepted | 2026-08-10 | patching, maintenance, automation |
| 0378 | The ADR index row is gated on its shape, not only on its number | Unstated | 2026-08-10 | standard-enforcement, docs, ci |
| 0379 | Returning device control to another controller is conditional; only taking it may be unconditional | Accepted | 2026-08-10 | homeassistant, automation, lighting |
| 0380 | A cross-repo gate lands non-blocking first — there is no atomic repair commit | Accepted | 2026-08-10 | standard-enforcement, ci, pipelines |
| 0381 | A shared-queue-blocking gate owes a proven local counterpart, and the coverage is gated | Accepted | 2026-08-10 | ci, pipelines, docs-as-code |
| 0382 | A gate aggregating over a discovered set must distinguish empty from satisfied | Accepted | 2026-08-10 | ci, pipelines, reliability |
| 0383 | Domestic hot water reaches Prometheus by extending Home Assistant's allow-list, not a new exporter | Accepted | 2026-08-10 | observability, homeassistant, iot |
| 0384 | A household physical capability belongs in the Critical Operations Register | Accepted | 2026-08-10 | resilience, audit, netbox |
| 0385 | Link an LLD template before any static trigger over its discovered keys | Accepted | 2026-08-10 | standard, monitoring, observability |
| 0386 | Room ownership model as the single engine for the conflict gate and the room docs | Accepted | 2026-08-10 | homeassistant, automation, lighting |
| 0387 | A deployed script executes no working-tree code, and a success marker names the code version that produced it | Accepted | 2026-08-10 | ansible, config-as-code, ci |
| 0388 | Destructive-automation clauses apply by shape: retention is not remediation | Accepted | 2026-08-11 | standard, alerting, observability |
| 0389 | Hypercare is an enforced delivery stage with an evidence-based exit | Unstated | 2026-08-11 | delivery, ado, monitoring |
| 0390 | An alert that can be read after it clears needs retrospective diagnostics | Unstated | 2026-08-11 | monitoring, observability, alerting |
| 0391 | A safety precondition that logs and proceeds is not a precondition | Accepted | 2026-08-12 | automation, reliability, patching |
| 0392 | Agent lesson corpus — amending ADR-0018's single-native-store assumption | Accepted | 2026-08-12 | agent-memory, cc-pool, knowledge-management |
| 0393 | Bulk artifact creation uses one generator script, not N Write calls | Accepted | 2026-08-12 | agent-memory, docs, aiops |
| 0394 | Burn-rate alert windows are sized from measured traffic, not copied from the SRE book | Accepted | 2026-08-12 | alerting, observability, reliability |
| 0395 | Bulk file deployment uses synchronize — ansible.builtin.copy round-trips per file, not per task | Accepted | 2026-08-12 | ansible, infrastructure, ci |
| 0396 | An SLO attainment figure states its window and run count, or it is not a measurement | Accepted | 2026-08-12 | reliability, observability, standard |
| 0397 | Retiring an analyzer requires disposing of its findings — they do not expire on their own | Accepted | 2026-08-13 | security, vulnscan, devsecops |
| 0398 | A secret the platform will not encrypt is controlled by scope, not by confidentiality | Accepted | 2026-08-13 | security, secrets, dependency-track |
| 0399 | Epic tags are four flat lifecycle labels; queue position and hypercare date live in the title | Unstated | 2026-08-13 | ado, delivery, lifecycle |
| 0400 | A guest metric must be proven virtualised before it is alerted, dashboarded or sized on | Accepted | 2026-08-13 | monitoring, observability, alerting |
| 0401 | The self-hosted agent pool is authorized for all pipelines, because per-pipeline authorization was a formality that failed silently | Accepted | 2026-08-13 | ci, pipelines, security |
| 0402 | The agent constitution is governed by an enumerated rule inventory and a diff gate | Accepted | 2026-08-14 | ci, claude, config-as-code |
| 0403 | Withdraw /justdoit's delegated autonomy tier and re-grant it to /go with a circuit breaker | Accepted | 2026-08-14 | autonomy, automation, devsecops |
| 0404 | A container memory level is not a finding without its slope; and a threaded Python service caps MALLOC_ARENA_MAX | Unstated | 2026-08-15 | monitoring, observability, alerting |
| 0405 | External control of a light is not an ownership anomaly | Unstated | 2026-08-15 | homeassistant, alerting, observability |
| 0406 | pve01 memory capacity policy and weekly PBS GC | Accepted | 2026-08-15 | pve01, proxmox, pbs |
| 0407 | 5GHz co-channel interference is measured as spectral overlap of (channel, bandwidth), not channel equality — and alerts non-paging because the overlap is latent risk, not active fault | Accepted | 2026-08-15 | networking, wifi, unifi |
| 0408 | A long serial write chain needs a retry, not a wider timeout; and a per-request error rate must be read against the chain length | Accepted | 2026-08-15 | observability, reliability, docker |
| 0409 | pve01 runs with no swap device | Accepted | 2026-08-15 | pve01, proxmox, performance |
| 0410 | An ownership verdict requires an intact attribution join | Accepted | 2026-08-16 | homeassistant, alerting, observability |
| 0411 | A Wi-Fi alert must name a condition that is both fault-bearing and reachable — count the resources the desired state needs before asserting it is reachable | Accepted | 2026-08-16 | networking, wifi, unifi |
| 0412 | An alert condition inferred from a failed lookup needs a stated precondition | Accepted | 2026-08-16 | alerting, observability |
| 0413 | The agent's permission set is governed config, its deny list is a mistake-guard rather than a security boundary, and patterns are promoted to deterministic enforcement on stated criteria | Accepted | 2026-08-16 | claude, security, least-privilege |
| 0414 | A harness-blocked action defers rather than halts, and the end-of-run script is a standing sub-grant | Accepted | 2026-08-16 | autonomy, automation, devsecops |
| 0415 | /go passes its Production Readiness Review into a measured soak, and its decisions are graded | Accepted | 2026-08-16 | autonomy, automation, observability |
| 0416 | Retire the weekly feedback-hygiene sweep — its corpus moved, and the successor design refuses a scheduled sweep | Accepted | 2026-08-17 | operations, claude, memory |
| 0417 | Automation regenerates in a private worktree, never in a shared checkout | Accepted | 2026-08-17 | git, automation, docs-as-code |
| 0418 | Dependency-Track triage decisions are carried forward before a superseded project is retired | Accepted | 2026-08-17 | devsecops, dependency-track, vulnscan |
| 0419 | hass.pitbun.com serves Home Assistant over the cloudflared tunnel, not a proxied CNAME to Nabu Casa | Implemented | 2026-08-17 | cloudflare, homeassistant, networking |
| 0420 | Grafana trusts the Cloudflare Access JWT so the embedded rollup panel authenticates without a second login | Implemented | 2026-08-17 | cloudflare, grafana, observability |
| 0421 | A blackbox probe on an Access-gated host is edge evidence only, and neither standard may claim otherwise | Accepted | 2026-08-17 | observability, blackbox, cloudflare |
| 0422 | A missing agent helper is a finding to raise, not a throwaway script to write | Accepted | 2026-08-17 | agent-memory, autonomy, scripts |
| 0423 | An app behind the tunnel trusts its own public hostname for origin checks, because the tunnel rewrites Host | Implemented | 2026-08-17 | cloudflare, grafana, networking |
| 0424 | Trivy's system-file filter is starved and selectively re-applied, so a vendor deb's Go binary keeps its vulnerability coverage | Accepted | 2026-08-17 | devsecops, trivy, dependency-track |
| 0425 | Informational severity is never sent to Pushover — it is recorded to Loki instead | Accepted | 2026-08-18 | alerting, notifications, pushover |
| 0426 | The agent access contract is an installable package in its own repo, with disjoint read and write verb surfaces | Accepted | 2026-08-18 | autonomy, api, scripts |
| 0427 | The five helpers migrate reads-first onto the access contract, keeping their published stdout byte-identical | Accepted | 2026-08-18 | autonomy, api, scripts |
| 0428 | Twenty systems join the read tier as declared data — trust anchors, unverified exceptions and the PostgreSQL gap are all stated rather than worked around | Accepted | 2026-08-18 | autonomy, api, secrets |
| 0429 | The media and app tier meets three APIs the read transport's guarantee does not cover — query-string credentials, GET-mutating verbs, and three systems that stay out of the register | Accepted | 2026-08-18 | autonomy, api, secrets |
| 0430 | A write verb's authority class is enforced at the tool boundary, not remembered by the agent | Accepted | 2026-08-18 | autonomy, api, scripts |
| 0431 | The pitlab-access write set is derived from live automation, not listed — and a path parameter keeps a per-object write out of wildcard territory | Accepted | 2026-08-18 | autonomy, api, scripts |
| 0432 | Credential scoping is measured, not assumed — and where an API cannot scope, the residual risk is recorded and the frozen read tier is the compensating control | Accepted | 2026-08-18 | autonomy, api, secrets |
| 0433 | A policy-excluded credential is prepared, staged and proven refused — never provisioned, and never deferred into an unattended script | Accepted | 2026-08-18 | autonomy, secrets, least-privilege |
| 0434 | The MCP gateway mounts a pinned contract into a stock image and resolves every credential in its own process | Accepted | 2026-08-18 | mcp, autonomy, api |
| 0435 | A wait concludes or refuses — it never hangs | Accepted | 2026-08-18 | automation, reliability, observability |
| 0436 | A multi-guard CI job reports every guard's verdict, because a skipped guard is indistinguishable from a passing one | Accepted | 2026-08-18 | ci, pipelines, ansible |
| 0437 | Agent-access conformance is a DECLARED register, a gate over it, and a discovery sweep beside it — because a gate can only check what is declared | Accepted | 2026-08-18 | mcp, autonomy, api |
| 0438 | A pipeline gate that drives production code suppresses that code's notifications — a green gate is silent | Accepted | 2026-08-18 | ci, alerting, observability |
| 0439 | Agent system access is a gated standard, not a convention — and the helper-absence clause is promoted from advisory to machine | Accepted | 2026-08-18 | autonomy, api, secrets |
| 0440 | Shared library code that must run on a host AND in a container is a fourth script home — a versioned package in its own repo | Accepted | 2026-08-18 | scripts, automation, standard-enforcement |
| 0441 | A gate that reads a tree it does not refresh is a blind watcher — gates prove the currency of every tree they read | Accepted | 2026-08-19 | ci, security, observability |
| 0442 | Recording what is wrong must not assert that it is fixed — incident analysis notes are a distinct verb | Accepted | 2026-08-19 | incidents, freescout |
| 0443 | Keyword adjacency cannot see a positional credential — the secret scan covers basic-auth shapes | Accepted | 2026-08-19 | security, secrets, ci |
| 0444 | When you need a position, ask for the position — locate by line number, never print the line | Accepted | 2026-08-19 | claude, docs-as-code |
| 0445 | An unattended red is a separate signal from a failure | Accepted | 2026-08-19 | alerting, observability, ci |
| 0446 | Stuck-alert detection is per-surface — age on Prometheus, cause on Zabbix | Accepted | 2026-08-19 | alerting, observability, zabbix |
| 0447 | A gate piped through tail reports the pipe's exit code, not the gate's | Accepted | 2026-08-19 | ci, claude, agent-memory |
| 0448 | Every Epic board column transition has a named owning skill and a trigger moment | Accepted | 2026-08-19 | ado, delivery, lifecycle |
| 0449 | A dated review owed outside the Hypercare column still gets summoned | Accepted | 2026-08-19 | delivery, alerting, automation |
| 0450 | Publishing to the public showcase is an opt-in front-matter flag backed by a fail-closed scrub gate | Accepted | 2026-08-19 | docs-as-code, security, ci |
| 0451 | Public set-piece data is a sanitised build-time snapshot, and every published field is screened by the same gate that governs the pages | Accepted | 2026-08-20 | security, docs-as-code, observability |
| 0452 | External exposure is information-based, not origin-based | Accepted | 2026-08-20 | security, cloudflare, compliance |
| 0453 | Two-tier data classification: internal by default, public by explicit flag | Accepted | 2026-08-20 | security, compliance, docs |
| 0454 | A blocked capability that will recur becomes a bounded helper, not a repeated /tmp handoff | Accepted | 2026-08-20 | operations, security, claude |
| 0455 | The Wait Standard's arm-time clauses bind pipewait, not just waitfor | Accepted | 2026-08-20 | ci, pipelines, reliability |
| 0456 | Pre-render site diagrams to both-theme SVG at build time | Accepted | 2026-08-20 | docs, ci, mermaid |
| 0457 | Duplicate incident records collapse onto the oldest, and each container detects only its own namespace | Accepted | 2026-08-21 | incidents, observability, reliability |
| 0458 | Historical duplicate incident records are archived to a second mailbox, not deleted | Accepted | 2026-08-21 | incidents, freescout, itsm |
| 0459 | The prototype preview path runs the production publish controls, in the same order | Accepted | 2026-08-21 | ci, cloudflare, security |
| 0460 | A skill's authority envelope follows its invocation, not the skill | Unstated | 2026-08-21 | autonomy, automation, cc-pool |
| 0461 | Home Assistant friendly names are ASCII-normalised, because the conversation agent matches them exactly | Unstated | 2026-08-21 | homeassistant, naming, observability |
| 0462 | The morning routine gains an unattended agentic run, reversing ADR-0166 decision 2 | Unstated | 2026-08-21 | autonomy, automation, alerting |
| 0463 | The send gate audits the previous message rather than blocking the next | Unstated | 2026-08-22 | claude, cc-pool, standard-enforcement |
| 0464 | Two CI planes run on one runner during the GitHub migration, and the org 2FA control is asserted rather than set | Unstated | 2026-08-22 | ci, github, security |
| 0465 | The warning tier is recorded, not paged | Unstated | 2026-08-22 | alerting, observability, alertmanager |
| 0466 | ADO pipelines are converted to Actions workflows by a gated generator, never hand-ported | Unstated | 2026-08-22 | ci, github, pipelines |
| 0467 | Measured operational tuning is exempt from the grill gate (REJECTED) | Unstated | 2026-08-22 | claude, standard-enforcement |
| 0468 | The two CI planes get their own checkouts by path prefix, not their own HOME | Unstated | 2026-08-23 | ci, github, ado |
| 0469 | Epics carry one domain tag — smart-home or pitlab — alongside their lifecycle tag | Unstated | 2026-08-23 | claude, standard-enforcement |
| 0470 | Terraform applies are approved by an issue comment, because GitHub's own approval gate is Enterprise-only on a private repo | Unstated | 2026-08-23 | ci, github, terraform |
| 0471 | A prototyped delta is accepted on user-validated criteria, not on the design it outgrew | Accepted | 2026-08-23 | delivery, agent-memory |
No decision matches that filter.
† the record states no date in its header, so the date shown is when the file first appeared in the corpus — 104 of 471 rows. 82 state no status; they show Unstated rather than an assumed one. 49 of these decisions are published here in full — the rest exist, and are listed, but are not part of the public set. 1 title's own words contain an internal identifier and are withheld by the same gate that decides which pages may ship; the record is still listed, with its number, status and date.
What is here and what is not
Section titled “What is here and what is not”Every decision in the corpus is listed. A subset is published in full on this site and links through to its text; the rest are listed by title only, because publication is opt-in per page and most of the corpus contains identifiers that must not leave the estate. Listing the whole log rather than only the public part is deliberate: a decision log with the awkward entries filtered out is a marketing document.
Two fields are derived rather than stated, and the panel marks both rather than smoothing them over:
- Dates. Not every record states a machine-readable date — the corpus grew three different header shapes over its life. Those rows carry the date the file first appeared in version control, marked with a dagger. The alternatives were to invent a date or to drop the decision from the log, and both are worse than a marked derivation.
- Status. A record whose header states no status shows
Unstated, never an assumedAccepted. That is a real gap in the corpus, and it is visible here because making gaps visible is what this panel is for.
What a decision record has to contain
Section titled “What a decision record has to contain”Status, date, context, the decision, the alternatives considered, and the consequences. The alternatives section is the one that earns its keep — a record listing only what was chosen is a changelog entry.
They are written at the time the decision is made, not reconstructed at wrap-up, because the reasoning is the part that evaporates. A record written a week later contains what the author remembers deciding, which is reliably a tidier story than what actually happened.
Some of these records reverse earlier ones, and those are the most useful entries in the log: an autonomy tier that was granted and then withdrawn, a gate whose diagnosis turned out to be wrong, a threshold re-derived from measurement after a borrowed number failed. A decision log with no reversals in it is a log nobody is reading back.
The publish control behind this page
Section titled “The publish control behind this page”Nothing here reaches the internet by default. A corpus page is published only if its front matter carries an explicit opt-in flag, and a second, independent control scans everything that would ship — the rendered source and the built bundle — and fails the build on any internal address, internal hostname, known endpoint, estate mailbox or secret-shaped string. It reds; it never rewrites, because an automatic redaction turns a loud failure into a silent transformation and leaves an unproven sanitiser standing between a private corpus and the open internet.