Skip to content

Decision log

A decision record answers the question code cannot: why this and not the obvious alternative. Configuration shows what is running. It never shows what was rejected, what constraint drove the shape, or what the decision cost — and those are the only things that let someone reverse a decision safely later.

Decision log — 471 architecture decision records

Snapshot taken — build-time, not live
471 of 471
ADRDecisionStatusDateDomains
0001Monitoring dependency chainsAccepted2026-06-18monitoring, zabbix, alertmanager
0002Paperless-ngx — LXC community script to docker01 compose stackAccepted2026-06-18paperless, docker, migration
0003Container resource metrics — Prometheus/cadvisor only, not ZabbixAccepted2026-06-19monitoring, prometheus, zabbix
0004Samba — LXC to docker01 compose stackAccepted2026-06-19samba, docker, migration
0005Explicit security floor pins for transitive Python dependencies in self-owned Docker imagesAccepted2026-06-19security, docker, python
0006docker01 — separate OS and Docker data disksAccepted2026-06-20docker, storage, infrastructure
0007Filesystem monitoring — direct items over template LLDAccepted2026-06-20monitoring, zabbix, storage
0008Decom soak tracking via PVE guest description fieldAccepted2026-06-20decommission, proxmox, automation
0009Infisical pg_dump backup to arch01/filesAccepted2026-06-20infisical, secrets, backup
0010Pi-hole DNS records as code via FTL config CLIAccepted2026-06-20dns, pihole, ansible
0011Internal HTTP readiness probes alongside external edge probesAccepted2026-06-20observability, monitoring, alerting
0012docker01: live-restore off + mount ordering for deterministic reboot recoveryAccepted2026-06-20docker, reliability, docker01
0013Cloudflare edge as code (tf-cloudflare)Accepted2026-06-20cloudflare, terraform, decommission
0014Generic secret-rotation role with pluggable per-source adaptersAccepted2026-06-21infisical, secrets, rotation
0015Single shared read-only deploy identity for Docker-Apps secret injectionAccepted2026-06-21infisical, secrets, identity
0016Agent memory scaling — flat-index discipline + file consolidation, not a vector DBAccepted2026-06-21claude, memory, aiops
0017Infisical infrastructure/network consumer & bootstrap modelAccepted2026-06-21infisical, secrets, bootstrap
0018Agent knowledge retrieval — RAG over docs-as-code via pit-memory MCP, not a parallel memory storeAccepted2026-06-21claude, memory, aiops
0019Enriched Pushover notifications for agent triageAccepted2026-06-21alertmanager, alerting, observability
0020cc-pool concurrency isolation — per-session worktrees, GitOps PRs as targetAccepted2026-06-21cc-pool, git, gitops
0021Terraform pipeline secret injection from InfisicalAccepted2026-06-21infisical, secrets, terraform
0022Deterministic technical-spec normalisation for the podcast pipelineAccepted2026-06-21podcast, tts, speech
0023Prometheus external exposure for working GeneratorURL links + probe-alert label hygieneAccepted2026-06-21alertmanager, alerting, observability
0024rclone runs as ephemeral container with env-var config, no rclone.conf on diskAccepted2026-06-21backup, rclone, docker
0025ITSM/CMDB as best-of-breed — NetBox + FreeScout + GitOps, not a single ITIL suiteAccepted2026-06-21itsm, cmdb, netbox
0026docker01 uses virtio-scsi-single + per-disk iothread to stop all-vCPU soft-lockupsAccepted2026-06-22proxmox, docker01, storage
0027Linux VMs use a UTC RTC (localtime=0), enforced via Ansible not TerraformAccepted2026-06-22proxmox, timekeeping, ansible
0028Validate Mermaid diagrams at docs-build time against the live mermaid majorAccepted2026-06-22docs, ci, mermaid
0029Lifecycle-driven agent-memory eviction, not TTL or LRUAccepted2026-06-22agent-memory, pit-memory, retention
0030Remediate a leaked on-LAN secret by rotating at source, not rewriting git historyAccepted2026-06-22secrets, infisical, security
0031Feedback-memory hygiene via three report-then-confirm brakes, not evictionSuperseded2026-06-22agent-memory, pit-memory, retention
0032Wrap-up work-delivery reports are published as navigable doc artifacts, not email-onlyAccepted2026-06-22docs-as-code, mkdocs, reporting
0033Notification channel policy — alerts via Pushover, work-delivery reports via emailAccepted2026-06-22notifications, pushover, email
0034All notifications carry a machine-readable header, emitted through one helperAccepted2026-06-22alerting, observability, aiops
0035Docs cross-linking — unify on a single wikilink syntax via a self-authored hookAccepted2026-06-23docs-as-code, knowledge-management, mkdocs
0036ADO pipeline failure + approval alerting stays in Zabbix, not a new Prometheus exporterAccepted2026-06-23zabbix, alerting, pushover
0037Alloy liveness alerting moves to a Prometheus self-scrape, not a Zabbix host-port probeAccepted2026-06-24observability, alloy, prometheus
0038Docs publish-completeness guardAccepted2026-06-24docs-as-code, ci, aiops
0039docker01 soft-lockups under Plex transcode load are fixed by CPU weighting, not core pinningAccepted2026-06-24proxmox, docker01, media
0040Sonarr/Radarr API key rotation edits config.xml directly because the arr REST API ignores apiKeyAccepted2026-06-24infisical, secrets, ansible
0041B2 file restore splits laptop GUI from a docker01 backend, and reinstates versions to decrypt themAccepted2026-06-24backup, restore, rclone
0042Zabbix alerts conform to the Notification Standard at the Pushover media type, with a 6→3 tier severity-to-priority mapAccepted2026-06-24zabbix, alerting, pushover
0043Plex iPad sync/download monitoring uses a custom Tautulli-API exporter, not an off-the-shelf Plex exporterAccepted2026-06-24plex, media, tautulli
0044pitbook12 config drift is remediated pull-based on the endpoint, enforce-invariants + report-restAccepted2026-06-24pitbook12, ansible, gitops
0045Per-service dashboards as code with a dynamic blackbox-driven rollup, on a RED+USE+logs baselineAccepted2026-06-24observability, grafana, dashboards
0046Secret scanning via gitleaks in ephemeral docker, gating CI and pre-commitAccepted2026-06-24security, secrets, ci
0047plex01 disk pressure is managed by isolation + predictive alerting, not garbage collectionAccepted2026-06-24plex, proxmox, zfs
0048Claude Code self-captures session reasoning traces into FreeScoutAccepted2026-06-25itsm, freescout, aiops
0049Claude Code config docs generated from ~/.claude, published to the corpus via a reconciliation loopAccepted2026-06-25claude, cc-pool, docs-as-code
0050Serve derived visualisation artifacts behind Access, don't commit themAccepted2026-06-25observability, vectormap, cloudflare
0051docker01 soft-lockups are an IPv6 router-solicitation timer storm on churning docker bridges, not the task named by the kernelAccepted2026-06-25docker01, networking, ipv6
0052vectormap live search via a server-side sidecar, not client-side embeddingAccepted2026-06-25observability, vectormap, rag
0053Pin the pitlab-docs MkDocs build toolchain and treat MkDocs 2.0 as an upstream fork to migrate away from, not upgrade intoAccepted2026-06-25docs-as-code, mkdocs, automation
0054Coalesce the pitlab-docs publish pipeline with a batched CI trigger, and shift cheap validation left to a pre-push hookAccepted2026-06-25docs-as-code, ci, pipelines
0055A service owns one canonical dashboard plus at most one linked operational drill-downAccepted2026-06-26observability, grafana, dashboards
0056Make the docs-pipeline pit-memory reindex step resilient — become-free rsync sync, non-fatal to the publish, freshness-alertedAccepted2026-06-26docs-as-code, ci, pipelines
0057Decouple host reboots from unattended-upgrades with a window-gated reboot coordinator (kured model)Accepted2026-06-27patching, maintenance, automation
0058Timezone standard — host schedules in local Australia/Melbourne, ADO pipeline crons in UTC, no hard-coded offsetsAccepted2026-06-27timezone, scheduling, cron
0059Service catalog — auto-generated per-service home pages from the Alloy probe inventoryAccepted2026-06-27docs-as-code, observability, grafana
0060Claude Pod runs a credential-free container on a slim base, with credential-bearing steps externalised to control01Accepted2026-06-27podcast, media, security
0061Self-healing schedule reconciliation — a declarative manifest enforced by a static author-time guard and a live post-deploy reconcilerAccepted2026-06-27scheduling, cron, timezone
0062A mandatory kb explainer link on every notification, resolved from a notification catalog as codeAccepted2026-06-27alerting, observability, notifications
0063Umbrella (parent) service catalog pages over duplicated or grouped componentsAccepted2026-06-28observability, docs-as-code, cmdb
0064Service-owned alert runbooks live on the service page, fleet-wide alerts stay in operationsAccepted2026-06-28alerting, observability, docs-as-code
0065ADO pipeline → pitlab-pool authorization is reconciled by a daily idempotent cron, not blanket-granted or Terraform-managedAccepted2026-06-28ado, pipelines, ci
0066docker-stacks images are classified by blast radius — critical images digest-pinned with per-package, no-auto-merge Renovate policyAccepted2026-06-28docker, renovate, dependency-management
0067docker-stacks deploys end with a smoke gate that fails the pipeline if a container does not start and serveAccepted2026-06-28docker, ci, pipelines
0068Incident-resolution feed + two-tier retrieval — what belongs in the vector DBAccepted2026-06-29itsm, freescout, aiops
0069A staging/canary lane for the observability stack is declined — the post-deploy smoke gate plus merge-time review is the terminal pre-prod gateAccepted2026-06-29docker, ci, pipelines
0070Self-healing notification docs — capture, detect, propose-only remediationImplemented2026-06-29notifications, observability, aiops
0071FreeScout web-tier 500 — clear-first auto-heal over restart-onlyAccepted2026-06-29itsm, freescout, operations
0072FreeScout web-tier 500 — confirmed root cause (root-owned cache) and durable process-fixAccepted2026-06-30itsm, freescout, operations
0073NetBox hybrid source-of-truth — authority boundaries split by lifecycle stage, per host classAccepted2026-06-30netbox, cmdb, source-of-truth
0074Terraform NetBox provider — enforce the ADR-0073 boundary by import + ignore_changes, partition IP by allocation methodAccepted2026-06-30netbox, cmdb, terraform
0075Logging / Log-Capture Standard — Loki is mandatory, file-loggers must reach stdout, arrival is proven not assumedAccepted2026-06-30observability, loki, alloy
0076DNS Origin Pinning — pin cloudflared tunnel origins as local Pi-hole A records to remove the UDM single-upstream from origin resolutionAccepted2026-06-30dns, pihole, cloudflare
0077Tagging Standard with unified per-surface vocabularyAccepted2026-06-30tagging
0078Alerting severity taxonomy and routing contractAccepted2026-06-30alerting
0079Container / Compose Baseline — mandatory directives for every docker-stacks serviceAccepted2026-06-30containers
0080Terraform / IaC StandardAccepted2026-06-30terraform
0081Backup & Retention Standard — 3-2-1 framing, named tiers, a per-guest registry as code, retention asserted not just documentedAccepted2026-06-30backup
0082Functional host naming, deprecate legacy xt###/xv### schemeAccepted2026-06-30naming
0083Cause-level log alerts are per-service signatures, not a generic file-tail ruleAccepted2026-06-30alerting, observability
0084Alert window sizing & flap dampening — windows track condition duration, for: dampens flapsAccepted2026-06-30alerting, observability
0085The notification-catalog guard validates kb anchors against alert_runbooks.yml, not the async-regenerated markdownAccepted2026-06-30alerting, observability, docs-as-code
0086docker-stacks deploys end with a Loki log-shipping gate that fails the pipeline if a stack ships no logsAccepted2026-07-01docker, ci, pipelines
0087pit-memory reuses one HTTP client to stop a reindex DNS floodAccepted2026-07-01pit-memory, dns, observability
0088pit-memory image source moves into docker-stacks beside its deployAccepted2026-07-01pit-memory, ci, gitops
0089docker01 gets a local caching DNS resolver in the container pathAccepted2026-07-01dns, docker01, networking
0090Host config-as-code playbooks auto-deploy via path-triggered CIAccepted2026-07-01ansible, ci, gitops
0091Pit on the Verge moves from per-article episodes to per-topic daily digestsAccepted2026-07-02podcast, media, n8n
0092Secret-dependent ansible CI playbooks fetch from Infisical in-playbook, not via pipeline env injectionAccepted2026-07-01ansible, ci, infisical
0093HA-safe CI for Home-Assistant-touching config playbooks (split auto-apply / check-only)Accepted2026-07-01ansible, ci, gitops
0094n8n workflows managed as code via API reconciliation on community editionAccepted2026-07-01n8n, gitops, automation
0095Tune PlexTranscodeSaturated (for: 10m→30m) rather than delete it — low-value alerts are tuned, not removedAccepted2026-07-02plex, media, alerting
0096Pit on the Verge moves to weekly per-topic rollups on a staggered day-of-week scheduleAccepted2026-07-02podcast, media, n8n
0097Podcast inter-article separation via opposite-voice outros, and source sub-heading echo dedupUnstated2026-07-03podcast, tts
0098Guardian Audio — generalise five-great-reads to an all-Guardian-newsletter podcastUnstated2026-07-03podcast, media, n8n
0099Workload auto-remediation on docker01 via autohealUnstated2026-07-03observability, docker, self-healing
0100dtrack Jetty-listener hang — widen the resource envelope in place, defer the v5 migrationUnstated2026-07-03docker, security, observability
0101vulnscan — autonomous vulnerability remediation authority and boundaryUnstated2026-07-03security, devsecops, self-healing
0102Per-service test plans as an enforced post-deploy / post-remediation gateUnstated2026-07-03testing, ci, devsecops
0103Grafana is dashboards-only — unified alerting disabled at the config layerAccepted2026-07-04grafana, alerting, observability
0104Authenticated golden path — run-time secret injection into test plansUnstated2026-07-04testing, ci, devsecops
0105Host/LXC services gate their test plans via a scheduled synthetic run, not a deploy pipelineUnstated2026-07-04testing, ci, reliability
0106docker-stacks pipeline-gate scripts live in the docker-stacks repo, a scoped carve-out from RULE 6Accepted2026-07-04scripts, ci, pipelines
0107Base-image build-tool CVE remediation — upgrade pip, drop build-only npmUnstated2026-07-04security, devsecops, docker
0108qbittorrent WebUI crash-loop from a shared-netns QLockFile orphanUnstated2026-07-04media, observability
0109Mothball iptv-proxy (retain IaC, take offline) and adopt a Service Mothball standardUnstated2026-07-04media, observability, docs-as-code
0110qbittorrent persistent WebUI credential via Infisical injectionUnstated2026-07-04media, secrets, testing
0111vulnscan tidies by default — auto-retire superseded DT projects and prune old docker imagesUnstated2026-07-04security, devsecops, dependency-track
0112Generalise bounded autonomy into an Autonomous Remediation Authority StandardUnstated2026-07-04devsecops, self-healing, automation
0113Documentation architecture — mandatory overview hubs for cross-service capabilitiesUnstated2026-07-04docs-as-code, docs, architecture
0114PlexTranscodeSaturated measures per-job peak encode speed over non-throttled transcode jobs — Plex `speed` is instantaneous and bursty, so an instantaneous min misreads healthy idle as saturationAccepted2026-07-04plex, media, alerting
0115Monitoring-as-Code standard + live drift audit — mandate Zabbix objects as code and reconcile dailyAccepted2026-07-05zabbix, monitoring, gitops
0116Disabled-trigger zombie reaper — auto-close Zabbix problems stuck open on a disabled triggerAccepted2026-07-05zabbix, monitoring, alerting
0117Codify the 81 unverified Zabbix monitoring objects — attribute or write a source, correct don't enshrineAccepted2026-07-05zabbix, monitoring, gitops
0118Homelab start page (Homepage) with generated tiles + Infisical widget-secret injectionAccepted2026-07-05homepage, infrastructure, infisical
0119Credential Aggregation Standard — least-privilege posture for multi-service consumersAccepted2026-07-05security, secrets, devsecops
0120Homepage secret-rotation webhook via an authenticated n8n relay (not direct ADO, not unauthenticated)Accepted2026-07-05homepage, n8n, ado
0121Delegated session-scoped autonomy tier — extend the Autonomous Remediation Authority Standard for /justdoitSuperseded2026-07-05autonomy, automation, devsecops
0122PBS xt035 GC OOM — right-size VM 103, cap the GC digest cache, swap cushion + silent-failure watchdogAccepted2026-07-05pbs, backup, proxmox
0123Tag-only Zabbix convergence for attribution-only monitoring sources — drive untagged to zeroAccepted2026-07-05zabbix, monitoring, gitops
0124Stop the 90-day Sonarr/Radarr API-key rotation — keep internal-only keys staticAccepted2026-07-05infisical, secrets, media
0125One global ADO pipeline stuck alert — disable per-pipeline failure pagingAccepted2026-07-06zabbix, alerting, pushover
0126Fold docker01 bespoke apps into docker-stacks, with Infisical as the documented bootstrap carve-outUnstated2026-07-06docker, gitops, infisical
0127Terraform reconciles VM memory — remove the ignore_changes freeze, declare balloon to avoid churnAccepted2026-07-06terraform, proxmox, gitops
0128Codify full create-definitions for attribution-only Zabbix sources — rebuild-safetyAccepted2026-07-06zabbix, monitoring, gitops
0129The ADO pool-auth guardrail is a pool-aware detective folded into the existing reconciler, not a duplicateAccepted2026-07-06ado, gitops, monitoring
0130Codify the Home Assistant → Zabbix bridge as a committed template export + create-if-missing provisionAccepted2026-07-06zabbix, monitoring, gitops
0131Homelab SSO integrates apps directly with Entra, not via an Authentik/Keycloak brokerAccepted2026-07-07sso, entra, identity
0132Stateful-appliance config-export-as-code — tiered assert/snapshot, control01 pull, auto-commit on changeAccepted2026-07-07gitops, config-as-code, ansible
0133Podcast RSS feeds stay public + token-gated, excluded from Cloudflare Access SSOAccepted2026-07-07sso, cloudflare, podcast
0134Break-glass for Entra-gated services is LAN/VPN-only — no second IdP, no Access bypassAccepted2026-07-07sso, cloudflare, entra
0135Entra app registrations are code in Terraform, with client secrets minted to Infisical (never in TF state)Accepted2026-07-07sso, entra, identity
0136Codify the PBS backup-root config (xt035 + xv035 pair) as assert-tier config-as-codeAccepted2026-07-07gitops, config-as-code, ansible
0137Homepage hides headless services from the start page via a hide-list, not by removing them from the probe inventoryAccepted2026-07-07homepage, observability
0138Homepage widget auth — read the passwordless Pi-hole API keyless, and a dedicated read-only NetBox tokenAccepted2026-07-07homepage, pihole, netbox
0139Per-app Entra SSO integration follows a fixed nine-step standardAccepted2026-07-07sso, entra, identity
0140Dependency-Track splits into apiserver + frontend behind an nginx proxy to gain Entra OIDC (public SPA, no secret)Accepted2026-07-08sso, entra, identity
0141Build hooks and pipeline gates ship their own proven-red regression testAccepted2026-07-08testing, ci, docs-as-code
0142Config fields that reference an outside-defined entity ship a resolution gate that fails closedAccepted2026-07-08ci, pipelines, config-as-code
0143Any service with a web UI is exposed externally behind Entra Access and its start-page tile links out; headless services are hiddenAccepted2026-07-08cloudflare, entra, sso
0144Codify Dispatcharr config as snapshot-tier config-export-as-code (first snapshot appliance)Accepted2026-07-08gitops, config-as-code, ansible
0145Codify UrBackup config as snapshot-tier config-export-as-codeAccepted2026-07-08gitops, config-as-code, ansible
0146Codify iVentoy config as snapshot-tier config-export-as-code (opaque binary + sidecar)Accepted2026-07-08gitops, config-as-code, ansible
0147Codify Plex config as snapshot-tier — reclassified from split (assert is service-disruptive)Accepted2026-07-08gitops, config-as-code, ansible
0148docker01 is a governed two-tier deploy estate — docker-stacks + the ansible-deploy bespoke tierAccepted2026-07-08gitops, config-as-code, ansible
0149A Token-Optimization Standard grown from per-session wrap-up harvest, not a one-time guessAccepted2026-07-08automation, docs-as-code
0150External exposure requires a Cloudflare Access gate, or an approved register entryAccepted2026-07-08security, networking, cloudflare
0151Bespoke-app deploy playbooks converge in a single health-gated build task — no post-health recreate handlersAccepted2026-07-08ansible, docker, config-as-code
0152Migrate the xt035→xv035 PBS remote off root@pam onto a dedicated least-privilege tokenAccepted2026-07-09pbs, backup, security
0153pve01 ZFS/ARC/IO observability — activate the staged ZFS template and add windowed ARC + PSI tripwiresAccepted2026-07-10zabbix, zfs, proxmox
0154Zabbix agent↔server encryption via per-host PSK, generated host-localUnstated2026-07-10zabbix, encryption, tls
0155Title withheld — it contains an internal identifierUnstated2026-07-10encryption, tls, mtls
0156PVE guest boot order — tiered startup so control01/MCP comes up after docker01Accepted2026-07-11proxmox, terraform, lifecycle
0157Operational resilience — T0–T3 tolerance tiers and a capability-led critical-operations registerAccepted2026-07-11resilience, backup, netbox
0158Recoverability is proven by an automated restore drill, not chunk verificationAccepted2026-07-11resilience, backup, pbs
0159The restore drill runs from control01 and tears down by marker, not by VMID rangeAccepted2026-07-11resilience, backup, pbs
0160Qdrant encryption-in-transit cutover — native API key + split transport (same-host pki http, cross-host Caddy TLS)Unstated2026-07-11encryption, tls, security
0161Resilience observability — job-workload availability substitute, split alert surfaces, and a human IR/BC planAccepted2026-07-11resilience, observability, incidents
0162Alerting delivery failover — critical alerts fan out to Pushover AND email-of-last-resortAccepted2026-07-11alertmanager, resilience, monitoring
0163Testplan gate scopes auto-revert to the offending stack, and gates index freshness on staleness-vs-docs not age-since-reindexAccepted2026-07-11ci, pipelines, pit-memory
0164Prometheus + Alertmanager encryption-in-transit cutover — testplan-gate basic-auth primitive unblocks unpublishing :9090/:9093Unstated2026-07-11encryption, tls, security
0165Encryption-in-Transit Standard — trust-boundary policy, exceptions register, and a live conformance gateUnstated2026-07-14encryption, tls, security
0166Morning health runbook — an autonomous scheduled Claude digest on control01, not a cloud routineUnstated2026-07-14operations, monitoring, observability
0167Home Assistant entity metrics via the Prometheus integration (lights brightness + colour temperature)Accepted2026-07-15homeassistant, observability, prometheus
0168Podcast staleness alerts survive gauge resets, verge gains a consumer-side error alert and a backfill capabilityAccepted2026-07-15observability, prometheus, alerting
0169Home Assistant update-control pipeline (GitOps, assessed, auto-rollback)Implemented2026-07-15homeassistant, devsecops
0170Home Assistant automations use raw zha_event triggers on device_ieeeAccepted2026-07-15homeassistant, automation
0171Home Assistant Prometheus endpoint switches to authenticated (supersedes ADR-0167 exposure posture)Unstated2026-07-15homeassistant, observability, prometheus
0172Loki per-stream retention override for the Home Assistant log streamAccepted2026-07-15observability, loki, homeassistant
0173pit-mini text model migrated qwen2.5:14b → qwen3:8b; all Ollama models pinned; central model varAccepted2026-07-15ollama, llm, ai
0174Loki encryption-in-transit cutover — unpublishing :3100 required a full host-consumer sweep, macOS keychain trust, and a lokiq helperUnstated2026-07-15encryption, tls, security
0175vulnscan runs as a headless-Claude cron on control01, not a Claude cloud routineAccepted2026-07-15devsecops, scheduling, cron
0176Standard-Enforcement Standard — the meta-standard governing how every standard is mechanically enforcedAccepted2026-07-15standard-enforcement, policy-as-code, ci
0177Ollama wedge-watchdog detects via an active text-model generate probe (supersedes ADR-0168's log-only sketch), guards on runner CPU, and auto-recoversAccepted2026-07-15ollama, pit-mini, observability
0178EiT same-host residual ports collapse to pki container-name addressing (unpublish, not 127.0.0.1)Unstated2026-07-16encryption, tls, networking
0179Dependency-Track SBOM import reliability: verify the import landed, give the JVM heap headroom, and watchdog freshnessAccepted2026-07-16devsecops, dependency-track, vulnscan
0180Headless workloads register in the rollup via a synthetic probe_success recording rule, not a blackbox probeAccepted2026-07-16dashboards, grafana, observability
0181Zigbee mesh-health alerts use series-absence for offline, not last_updated ageImplemented2026-07-16homeassistant, observability, alertmanager
0182Dependency-Track large-BOM import/delete OOM is an in-transaction component-backlog operation, not the internal analyzer: fix by one-time backlog cleanup, keep 12g heap and the analyzer onAccepted2026-07-16devsecops, dependency-track, vulnscan
0183Disk-image header inspection uses a bounded read to disk, never a full expansion into tmpfsImplemented2026-07-16proxmox, zfs, reliability
0184Loki Log-Retention Standard: named tiers, ADR-backed per-stream overrides, bounded budgetAccepted2026-07-17observability, loki, logging
0185Home Assistant full lighting-telemetry model (behaviour + responsiveness)Accepted2026-07-17homeassistant, observability, lighting
0186Fleet Update Policy: one unified patch/update-management standard so every container, LXC, and VM auto-updates under governanceImplemented2026-08-05maintenance, patching, renovate
0187Dependency-Track project lifecycle: digest-stable project naming plus full-scan orphan reconciliation, so renamed/decommissioned images don't accumulate stale SBOM projectsAccepted2026-07-17devsecops, dependency-track, vulnscan
0188Renovate Docker Hub 429 tag-enumeration truncation: throttle the per-IP tag API, authenticate the registryAccepted2026-07-17renovate, docker, automation
0189The weekly vectormap render moves from a user-cron to a systemd timer with Persistent=true so a slot missed while the host was down is caught on next bootAccepted2026-07-17scheduling, cron, reliability
0190pit-mini Alloy uses local.file_match (polled glob) so a late-appearing log is discovered, not permanently skippedAccepted2026-07-17observability, loki, alloy
0191Renovate per-format regex versioning for the linuxserver media images so they produce update PRsAccepted2026-07-17renovate, ci, lifecycle
0192The WiFi congestion dashboard reads Zabbix directly via a Grafana Zabbix datasource, and is a rollup-exempt dashboard because Zabbix-only metrics cannot drive the Prometheus probe_success primitiveAccepted2026-07-18dashboards, grafana, zabbix
0193bun3d restores the newest UrBackup image by assembling the full+incremental differencing chain, gated by a boot-acceptance testAccepted2026-07-18backup, urbackup, bun3d
0194pit-mini UPS graceful-shutdown watchdogUnstated2026-07-18pit-mini, ups, apple
0195docker01 holds a static LAN IP instead of DHCP, because an infra node hosting the whole docker stack must not depend on DHCP being reachable at lease-renewalUnstatednetworking, docker01, proxmox
0196WiFi lighting alerts use HA entity-availability, not ICMP reachability/RTTUnstated2026-07-18homeassistant, observability, alertmanager
0197UrBackup client staleness alerts only when the client is online but not backing upImplemented2026-07-18backup, urbackup, zabbix
0198The B2 offsite copy is proven by a monthly restore-test, not a full chunk-verifyImplemented2026-07-18backup, pbs, backblaze
0199Patch+reboot coordinator: a control01 central orchestrator with a self-host carve-out, net-new composite gate, and mode-gated rolloutAccepted2026-07-18patching, maintenance, automation
0200The Trivy import-verify gate polls DT for async BOM ingestion before declaring systemic lossUnstated2026-07-18devsecops, dependency-track, trivy
0201Holding a fixed brightness under Adaptive Lighting requires the persistent adapt_brightness switch off, not a one-shot apply flagAccepted2026-07-18homeassistant, lighting
0202The schedule reconciler resolves each timer's host from the manifest and treats an unreachable surface as advisory, not driftAccepted2026-07-18scheduling, cron, automation
0203The docs pipeline self-heals its prebaked Mermaid-validator image, and docker-prune exempts prebaked build-tool images via a pitlab.keep labelAccepted2026-07-19docs-as-code, ci, pipelines
0204KB-draft review digest by email plus a standing backlog Epic, so the self-healing loop's output stops hiding under a closed EpicImplemented2026-07-19notifications, observability, aiops
0205Durable ADO pipeline-wait pattern: discover by SHA, follow detached, classify the resultImplemented2026-07-19ado, ci, aiops
0206docker01 gets a UDM local DNS record instead of removing the UDM tertiary resolver, because the UDM is the deliberate power-outage DNS fallbackAccepted2026-07-19dns, docker01, networking
0207control01 pins its deploy-critical DNS names in /etc/hosts, closing the Infisical fall-through gap ADR-0206 left openAccepted2026-07-19dns, control01, infisical
0208pipewait --silence: tag-scoped Zabbix muting of a pipeline's failed-alert during an agent-driven deploy waitImplemented2026-07-19ado, ci, alerting
0209n8n Code nodes read Infisical-injected secrets via $env (N8N_BLOCK_ENV_ACCESS_IN_NODE=false) instead of hardcoded literalsAccepted2026-07-19n8n, security, secrets
0210External dead-man's-snitch (Zabbix-health-gated heartbeat)Accepted2026-07-19monitoring, alerting, resilience
0211Entra MFA is a documented control (Security Defaults), not Conditional-Access-as-codeAccepted2026-07-19identity, security, entra
0212PBS agent credential moves from root@pam!claude (Admin) to a dedicated claude@pbs (Audit)Unstated2026-07-19pbs, security, identity
0213Paperless app-level signals restored via a pki-native Prometheus exporter, not an internal Caddy vhost + Zabbix HTTP-item repointAccepted2026-07-19paperless, observability, prometheus
0214NetBox off-box consumers get an internal Caddy vhost, not the pki-by-name collapseUnstated2026-07-20encryption, tls, networking
0215Decom snapshot pruning uses a dedicated claude-prune@pbs (DatastoreAdmin on /datastore), not a write grant on the agent's general PBS tokenUnstated2026-07-20pbs, security, identity
0216Dedicated alerts@ mailbox for the email failover, and Zabbix failover parity with AlertmanagerAccepted2026-07-20alertmanager, zabbix, resilience
0217Local root/system mail is routed to Pushover by an exim router, not bounced at the M365 smarthostAccepted2026-07-20exim4, mail, alerting
0218qbittorrent WebUI fronted over pki via gluetun on the pki bridge, so the raw :8090 LAN publish is retired for a verified step-ca TLS edgeAccepted2026-07-20qbittorrent, encryption-in-transit, caddy
0219Unattended scripts carry dual-signal observability (heartbeat + journald), by shapeAccepted2026-07-20scripts, observability, logging
0220Caddy-fronted Cloudflare tunnel origins MUST set http_host_header; edge probes must assert body contentUnstated2026-07-20cloudflare, caddy, encryption-in-transit
0221SMTP relay STARTTLS + verifiable Proxmox/PBS appliance certs (step-ca)Unstated2026-07-20encryption-in-transit, tls, step-ca
0222Notification-catalog guard coverage hardening + script-standard enterprise additionsAccepted2026-07-20scripts, notifications, pushover
0223Claude OAuth refresh-token expiry is watchdogged with lead-time alerting, not auto-renewedAccepted2026-07-21claude, cc-pool, identity
0224A Caddy-fronted cutover MUST reconcile the backend app's host-header allowlist against the rewritten HostAccepted2026-07-21cloudflare, caddy, encryption-in-transit
0225step-ca-fronted PBS storages trust the CA (no leaf-fingerprint pin) + FQDN serverUnstated2026-07-21backup, pbs, proxmox
0226Alloy config is syntax-validated before deploy (template validate hook + CI fmt gate)Accepted2026-07-21observability, alloy, logging
0227The EiT conformance gate encodes off-box-consumer pre-validation for port unpublishesUnstated2026-07-21encryption, tls, networking
0228Homepage proxmox/PBS widgets dial FQDN + trust step-ca, but app-layer TLS verification is not enforceableUnstated2026-07-21encryption, tls, homepage
0229RustDesk :21114 is the web console, not an anonymous-client port — TLS-front and unpublish itUnstated2026-07-21encryption, tls, caddy
0230Guest backups are governed by a placement/schedule/throttle standard, not left to default vzdumpAccepted2026-07-21backup, pbs, zfs
0231control01 OOM hardening — pre-OOM early warning, agent self-heal, bias the kill onto the agent, notifyAccepted2026-07-21zabbix, alerting, observability
0232Fleet memory-headroom monitoring standard — house template + data-driven per-host macrosAccepted2026-07-21zabbix, alerting, observability
0233Design-to-as-built traceability lifecycle — grillme design docs reconciled against ADRs at wrapupAccepted2026-07-21architecture, lifecycle, docs
0234systemd self-heal integrity — Restart=always requires a clean cgroup reap or a documented orphan-safe exceptionAccepted2026-07-22systemd, self-healing, ansible
0235CI playbooks must be memory-bounded — the single agent OOMs before more RAM can save itAccepted2026-07-22ansible, config-as-code, ci
0236CI shared-mirror sync converges to origin unconditionally — robust to any local state, including a stranded unmerged indexAccepted2026-07-22ci, pipelines, git
0237Ansible docs commit-back resets to origin then regenerates — never stash-reconciles — factored into one shared pipeline templateAccepted2026-07-22ci, pipelines, git
0238HA press-without-action detector tolerates marker-ordering skew and ignores unbound commandsAccepted2026-07-23homeassistant, observability, alerting
0239Go-runtime containers must declare GOMEMLIMIT — a cgroup mem_limit alone OOM-kills the GC that can't see itAccepted2026-07-23docker, containers, observability
0240The Monitoring-as-Code drift audit covers Zabbix actions, with a stock-default baseline allowlistAccepted2026-07-23zabbix, monitoring, config-as-code
0241Per-host Caddy TLS terminators for EiT Class-B cross-host cloudflared originsImplemented2026-07-23encryption, tls, pki
0242NFR doc type and the Requirements sectionAccepted2026-07-24docs-as-code, observability, aiops
0243Hysteresis on the Home Assistant low-battery Zabbix triggerAccepted2026-07-25monitoring, observability, homeassistant
0244claude-pod single-run failure observability and compose resilienceAccepted2026-07-25observability, prometheus, alerting
0245Alertable counter instrumentation — prime labelled children, gauge-back discrete-run alertsAccepted2026-07-25alerting, prometheus, observability
0246claude-pod streaming Ollama compose — durable per-chunk-timeout fixAccepted2026-07-25podcast, media, observability
0247Central Caddy TLS terminator SPOF — accepted and hardened, redundancy rejected as architecturally voidAccepted2026-07-25security, caddy, encryption-in-transit
0248Homepage curated extra-tiles overlay, proxyless widget-gate skip, Grafana embedAccepted2026-07-25infrastructure
0249Secure external API exposure via Cloudflare Access service tokens — risk-tieredAccepted2026-07-25cloudflare, security, identity
0250Client-side estate DNS pin needs two layers — global resolved scope plus per-link UseDomains=no — so a DHCP-supplied UDM resolver can never poison estate namesAccepted2026-07-25dns, pihole, infrastructure
0251Disable the Dependency-Track OSS Index analyzer — Sonatype Guide migration ended viable free-tier useAccepted2026-07-25security, devsecops
0252Standards consolidation — the unit of a standard is the domainAccepted2026-07-25docs-as-code, architecture, knowledge-management
0253Reboot coordinator defers for active Claude sessions, cappedAccepted2026-07-26patching, maintenance, automation
0254Zabbix config-as-code reconciles endpoint fields against spec; create-if-missing alone is non-conformingAccepted2026-07-26zabbix, monitoring, config-as-code
0255cloudflared tunnel credential is sourced from Infisical, not a hand-placed fileAccepted2026-07-26cloudflare, networking, infisical
0256Cloudflare account token carries the full free-tier permission set, IP-locked, re-permissioned only via an external break-glass credentialAccepted2026-07-26cloudflare, security, identity
0257Device-facing internal TLS — trust the internal CA on personal devices; Let's-Encrypt-for-devices rejected at this scaleUnstated2026-07-26encryption, tls, pki
0258The Encryption-in-Transit register covers off-docker01 hosts, inventoried by ss(8) against a derived host setAccepted2026-07-26encryption-in-transit, security, config-as-code
0259Import all remaining live Cloudflare config into tf-cloudflare (zero-drift edge-as-code)Accepted2026-07-26cloudflare, networking, config-as-code
0260Admin-tier Cloudflare Access apps require the Homelab Admins Entra groupAccepted2026-07-26cloudflare, security, identity
0261The agent's settings are split — endpoints tracked in settings.json, credentials in gitignored settings.local.jsonUnstated2026-07-26claude, config-as-code, secrets
0262The macOS TLS terminator is a separate launchd/Homebrew playbook, not an OS branch in the Debian roleUnstated2026-07-26encryption, encryption-in-transit, tls
0263Actionable page-until-acted alert archetype (ADO approval → emergency)Accepted2026-07-26alerting, zabbix, ado
0264Sleep quiet-hours is a rest-protection mute, distinct from planned maintenanceAccepted2026-07-26alerting, alertmanager, zabbix
0265Cloudflare config-completeness / drift gate in the tf-cloudflare pipelineAccepted2026-07-26cloudflare, terraform, config-as-code
0266tf-cloudflare pipeline uses a clean per-run checkout + canonical off-tree local stateAccepted2026-07-26terraform, cloudflare, ci
0267Home Assistant terminates TLS natively on :8123 with a 90-day step-ca leaf, not behind a proxyUnstated2026-07-26encryption, encryption-in-transit, tls
0268tf-cloudflare auto-applies posture-neutral plans; a plan-risk classifier gates only exposure/Access/WAF/deleteUnstated2026-07-26terraform, cloudflare, ci
0269The blog publishing-activity metric is a Zabbix trapper fed by history.push, not a UserParameterUnstated2026-07-26observability, zabbix, docs
0270a docker-stacks pipeline must trigger on the path of every gate script it runs (scripts/**)Accepted2026-07-27ci, pipelines, docker
0271Zigbee router offline is a positive reachability assertion, not metric series-absenceImplemented2026-07-27homeassistant, observability, alertmanager
0272Home Assistant :8123 stays plaintext as an accepted EiT exception — native http.ssl_certificate is the wrong shape for a HAOS applianceUnstated2026-07-27encryption, encryption-in-transit, tls
0273Home Assistant TLS via the core_nginx_proxy add-on + step-ca leaf — both protocols live, no restart taxUnstated2026-07-27encryption, encryption-in-transit, tls
0274Post-close findings are incidents, not backlog — Epic closure is operational acceptanceAccepted2026-07-28itsm, operations, ado
0275Memory eviction promotes reference-misfiled-as-project and anchors on an owning EpicUnstated2026-07-29memory, agent-memory, docs-as-code
0276Fixless ghost incidents soak auto-close after a quiet periodAccepted2026-07-29itsm, operations, freescout
0277Fleet-wide secret-scan coverage with a conformance gate — a declared control must be enforced everywhere, not wired onceAccepted2026-07-29security, devsecops, ci
0278HA :8123 stays an accepted, census-verified-unused residual — PVE per-VM firewall is estate-infeasibleUnstated2026-07-29homeassistant, firewall, proxmox
0279pve01 FORWARD-DROP made firewall-safe via a DOCKER-USER vmbr0 ACCEPT rule, not by removing DockerUnstated2026-07-30firewall, proxmox, pve01
0280Outbound Claude email splits into three sender personas (alerts / engineer / reports) so Arron can filter by message classUnstated2026-07-31notifications, email, alerting
0281EiT close-out — native-TLS hosts join the ss(8) inventory via a second derivation markerUnstated2026-07-31encryption-in-transit, security, pve01
0282Source homepage widget secrets from their canonical Infisical path, not a hand-filled copyAccepted2026-07-05homepage, infisical, secrets
0283A pipeline gate fails closed when a flag's required secret is unwiredAccepted2026-08-01ci, pipelines, encryption-in-transit
0284EiT gate closes two --check-zabbix-tls blind spots (macro URLs, plaintext items)Accepted2026-08-01encryption-in-transit, zabbix, monitoring
0285Monitoring-as-code rule-source attributions must be substantiated by their sourceAccepted2026-08-01monitoring, config-as-code, zabbix
0286control01 .git-credentials ownership self-healing tripwireAccepted2026-08-01cc-pool, secrets, ado
0287The agent's six service API keys are sourced live from Infisical, not held at-restAccepted2026-08-01secrets, config-as-code, control01
0288~/.claude.json mcpServers become config-as-code: a tracked secret-free fragment reconciled from InfisicalAccepted2026-08-01config-as-code, secrets, control01
0289EiT gate gains a macOS/Darwin netstat inventory branchUnstated2026-08-01encryption-in-transit, security, apple
0290pit-mini EiT enrollment — residual listener disposition + macOS/Pi Zabbix PSK stragglersUnstated2026-08-01encryption-in-transit, security, apple
0291Scheduled all-host deploys tolerate transient single-host unreachabilityAccepted2026-08-01ansible, ci, pipelines
0292CI gate flags increase()/rate() absence-guards (counter-birth) in alert rulesAccepted2026-08-01observability, ci, pipelines
0293Reboot coordinator guards and verification follow the blast radius, not the host boundaryAccepted2026-08-02patching, maintenance, automation
0294A successful overnight change is a morning report, not a 4am pageAccepted2026-08-02alerting, maintenance, observability
0295MCP server health is proven by a client-side JSON-RPC initialize handshake from control01, because /health and an unauthenticated /mcp probe are both answered before the MCP application is reachedAccepted2026-08-03observability, monitoring, alerting
02962.4GHz congestion monitoring decomposes channel airtime into own versus external, because total channel utilisation alone cannot distinguish our own traffic from a neighbour stealing the channelAccepted2026-08-03observability, monitoring, alerting
0297Under cron, stdout is an alerting channel, not a log channelAccepted2026-08-03observability, alerting, automation
0298A grab that neither imports nor fails is a silent task failure; detect it and re-search, not just alertAccepted2026-08-03observability, alerting, media
0299Feedback hygiene discovers its corpus fleet-wide, and cross-session re-learning is promotion pressureAccepted2026-08-03claude, memory, aiops
0300A 2.4GHz min_rssi floor is safe only where every client below it has a proven alternate AP, and proving that needs a 90-day session window validated by a controlAccepted2026-08-03networking, wifi, unifi
0301Critical-tier patch and digest bumps auto-merge, because a review gate the automation is separately authorised to bypass is latency, not controlAccepted2026-08-03docker, renovate, dependency-management
0302A vulnerability with no upstream fix path is risk-accepted with named controls, an expiry and an upstream watch — never left as a standing findingAccepted2026-08-03security, devsecops, dependency-track
0303Claude Pod sources the docs Blog via a control01-side clone+rsync, keeping the container credential-freeAccepted2026-06-26docker, podcast, security
0304Plex Wrapped is a self-hosted ansible cron emailing each subscriber a personalised year-in-review, not the Tautulli or Plex native reportsAccepted2026-07-02plex, tautulli, media
0305Absence must never be encoded as a value inside a metric's alertable range, and a sustained-threshold trigger must match its comparison operatorAccepted2026-08-03monitoring, zabbix, alerting
0306Household WiFi reliability is measured by a client-weighted SLI (share of 2.4GHz clients at or above -75 dBm), with the SLO calibrated from measured baseline rather than chosenAccepted2026-08-03monitoring, zabbix, alerting
0307Work handed to an asynchronous executor must be asserted to reach a terminal state; absence past a deadline is a failure, not pendingAccepted2026-08-04alerting, observability, standard-enforcement
0308Health-check expressions assert the shape of a healthy response rather than an exact mutable value, because a value pin fires on every routine upgrade and silently turns the check into a no-opAccepted2026-08-04observability, monitoring, alerting
0309Stack-deploy tag taxonomy — rebuild is a superset of restartAccepted2026-08-04ansible, gitops, docker01
0310A batch script's partial failure is a correctness fault, not a liveness oneAccepted2026-08-04scripts, observability, monitoring
0311Pipeline trigger economy — batch:true estate-wide, cross-repo triggers path-scopedUnstated2026-08-04ci, pipelines, gitops
0312Ansible always-on guards consolidated into one ansible-ci pipelineUnstated2026-08-04ci, pipelines, gitops
0313Vulnerability management gets a standard with numbers, because a loop with no deadline cannot breach anythingAccepted2026-08-05security, devsecops, vulnscan
0314Every machine-readable config that governs deploys ships a CI validator, in two layers — schema and semanticAccepted2026-08-05ci, pipelines, gitops
0315Dependencies with an inter-version constraint are grouped into one Renovate PR, and their acceptance test is the rendered artifactAccepted2026-08-05renovate, dependency-management, gitops
0316Defer the Material for MkDocs → Zensical migration to a 2026-10-01 review, with named trigger conditionsAccepted2026-08-05docs-as-code, mkdocs, automation
0317Guardrails assert the real artifact and fail closedAccepted2026-08-05standard-enforcement, reliability, patching
0318Terminal job failures keep their incident record during quiet-hoursAccepted2026-08-05alerting, alertmanager, observability
0319pit-memory binds before indexing and swaps a shadow index inAccepted2026-08-05app, observability
0320Test-plan auto-rollback requires proof of persistence when causality cannot be proven structurallyAccepted2026-08-05ci, pipelines, observability
0321Run-to-completion workloads are gated on their produced artifact, not their exit codeAccepted2026-08-05ci, pipelines, observability
0322Pipeline job economy — a deploy pipeline spends one job, because jobs are the unit of preemptionUnstated2026-08-05ci, pipelines, gitops
0323Decommission the five-great-reads-podcast (Guardian Audio) featureUnstated2026-08-06podcast, media, decommission
0324A build-time dependency is a first-class dependency — pitlab-docs joins Renovate, and the docs build image joins SBOM coverageAccepted2026-08-06renovate, dependency-management, docs-as-code
0325The docs link/backlink/tag gate is generator-independent — only rendering stays bound to the MkDocs hooks APIAccepted2026-08-06docs-as-code, mkdocs, ci
0326Never wake the operator — no notification exceeds Pushover priority 0Accepted2026-08-05alerting, pushover, notifications
0327pit-mini is scanned locally in SBOM-only mode, not delegated to control01Accepted2026-08-06security, devsecops, trivy
0328vulnerability SLA conformance is measured daily, and the backlog alert is a burn-rateAccepted2026-08-06security, devsecops, dependency-track
0329CI trigger gaps are detected by a reconciler, and pipeline liveness is derived from the ADO APIAccepted2026-08-06ci, pipelines, ado
0330Terraform state and CI cross-host artifacts live on a bind-mounted ZFS dataset, and same-target pipeline runs serialise on itAccepted2026-08-07ci, pipelines, terraform
0331The CI queue-time SLO, one collector behind it, and a parity gate that holds the pool togetherAccepted2026-08-07ci, pipelines, ado
0332ansible-ci collapses to one job, retiring the last job-boundary exemptionAccepted2026-08-07ci, pipelines, ado
0333The CI pool is plural — gate-script location and pipeline-fed liveness stop assuming one agentAccepted2026-08-07ci, pipelines, ado
0334A pool's agents must actually be interchangeable — composition, parity, and the sub-tables nobody was enforcingUnstated2026-08-07ci, pipelines, ado
0335Fleet account uids are pinned, and a shared filesystem is shared by gid, never by ownerAccepted2026-08-07standard, config-as-code, proxmox
0336Prime Directive 1 gets a helper, because the pvesh snapshot form fails silently on a bind-mounted guestAccepted2026-08-07proxmox, zfs, operations
0337The HAOS deploy pipelines are made peers of the pool, not pinned to control01 — and pipelines gain a portability classUnstated2026-08-07ci, pipelines, ado
0338ansible-ci's run count is ACCEPTED on the measured SLI, and the one trigger change goes the other wayAccepted2026-08-07ci, pipelines, ado
0339pipewait distinguishes a skipped commit from a lost trigger, sizes discovery to measured queue latency, and names the agentAccepted2026-08-07ci, pipelines, ado
0340A control is only proven against the real artifact — fixtures, fallbacks and the content a gate readsUnstated2026-08-07ci, pipelines, standard
0341Service transition is a gated deliverable — the test plan is the handover artifact and the gate is fail-closedAccepted2026-08-07standard, testing, reliability
0342Guardian automations must observe attribute drift and self-heal on a sweepAccepted2026-08-07homeassistant, lighting, automation
0343Home Assistant Automation Standard — a bare delay is not a timerUnstated2026-08-07homeassistant, automation, appliance
0344Lighting Standard ratified — switch-off beats manual_control, and a real gate beats an advisory rowUnstated2026-08-07homeassistant, lighting, automation
0345Pipeline stack-list completeness is gated, because the enumeration of what to gate was itself ungatedAccepted2026-08-08standard, ci, pipelines
0346Service application code lives beside its stack and is mounted, not bakedAccepted2026-08-08standard, scripts, docker
0347Country-level charts, because per-provider top-3 is not sourceable and fails silentlyAccepted2026-08-08media, arr, observability
0348*arr import lists are config as code, reconciled read-only on a scheduleAccepted2026-08-08standard, media, arr
0349Container-internal schedules are declarable, and must carry an artifact dead-manAccepted2026-08-08standard, scheduling, observability
0350Destructive auto-remediation must alert below its action threshold and abort on no progressUnstated2026-08-08standard, alerting, observability
0351Standards adherence gap analysis and monthly assurance reportingAccepted2026-08-08standard-enforcement, audit, policy-as-code
0352Compliance & Assurance Standard and the control catalogue as codeAccepted2026-08-08standard-enforcement, audit, compliance
0353Corpus retrieval technique is a governed standard, not agent habitAccepted2026-08-08standard, docs-as-code, automation
0354The pre-push link gate stages a local assembled corpusAccepted2026-08-08docs-as-code, pipelines, standard-enforcement
0355Split relief path: the arr API owns retention deletes, pve01 moves the bytes for pressure reliefAccepted2026-08-08media, storage, automation
0356media_cleanup guard: per-item deterministic assertions replace the pool-free byte-deltaAccepted2026-08-08automation, storage, testing
0357Amendment to ADR-0350 clause 2: progress must be measured in a counter only your own action changesAccepted2026-08-08standard, automation, storage
0358Container cpus caps are sized from observation, not chosen by eyeAccepted2026-08-08containers, observability
0359servicemap: a derived, fail-closed service-dependency explorerAccepted2026-08-08observability, docs-as-code, source-of-truth
0360Browser-delivered JavaScript is a managed dependencyAccepted2026-08-08security, devsecops, vulnscan
0361the remediation-backlog alert is a dated ceiling, not a burn-rate — the backlog ages upward on its ownAccepted2026-08-08security, devsecops, dependency-track
0362pve01's one privileged path is sudo-over-SSH — the claude@pam API token stays audit-only, and Prime Directive 1's documented command is correctedAccepted2026-08-08proxmox, pve01, security
0363a Dependency-Track project identity is per deployed instance, not per image name — namespace the image plane by owning hostAccepted2026-08-08security, devsecops, dependency-track
0364the open-dependency-PR merge/defer clause becomes a machine check — branch prefix, renovate.json tier, and a dated deferral labelAccepted2026-08-08security, devsecops, renovate
0365Zabbix agent restart must precede the item-health proof, and must survive a failed runAccepted2026-08-08monitoring, zabbix, ansible
0366ADR number claiming runs in a private clone, never a shared checkoutAccepted2026-08-08docs-as-code, automation, git
0367pipewait derives the expected pipeline set from changed paths and reports NOT_TRIGGEREDUnstated2026-08-08ci, pipelines, ado
0368Host-to-repo stack-source reconciliation, because every other gate enumerates from the repoUnstated2026-08-09standard, ci, pipelines
0369A pending handler must survive a failed play, and every restart-notifying play must declare its postureAccepted2026-08-09ansible, config-as-code, reliability
0370Dashboard conformance asserts baseline panels return data across the Prometheus and Loki tiersAccepted2026-08-09observability, monitoring, standard-enforcement
0371servicemap freshness SLO and error-budget policyAccepted2026-08-09observability, monitoring, reliability
0372Mid-delivery findings accumulate on one snag list per Epic and are adjudicated at close-out — the agent never creates an EpicAccepted2026-08-09ado, operations, itsm
0373Estate DNS resolves through systemd-resolved, and estate records are cacheableAccepted2026-08-09dns
0374Session-destroying reboots get 72h advance notice, not a better idleness heuristicAccepted2026-08-09patching, maintenance, automation
0375A repo script invoked by a play executes controller-side, never out of a target's own checkoutAccepted2026-08-09ansible, config-as-code, ci
0376SSH pipelining is enabled fleet-wide, because it removes a per-task round trip and fixes unprivileged becomeAccepted2026-08-10ansible, performance, config-as-code
0377cc-pool sessions drain and auto-resume across a reboot, verified by content parentageAccepted2026-08-10patching, maintenance, automation
0378The ADR index row is gated on its shape, not only on its numberUnstated2026-08-10standard-enforcement, docs, ci
0379Returning device control to another controller is conditional; only taking it may be unconditionalAccepted2026-08-10homeassistant, automation, lighting
0380A cross-repo gate lands non-blocking first — there is no atomic repair commitAccepted2026-08-10standard-enforcement, ci, pipelines
0381A shared-queue-blocking gate owes a proven local counterpart, and the coverage is gatedAccepted2026-08-10ci, pipelines, docs-as-code
0382A gate aggregating over a discovered set must distinguish empty from satisfiedAccepted2026-08-10ci, pipelines, reliability
0383Domestic hot water reaches Prometheus by extending Home Assistant's allow-list, not a new exporterAccepted2026-08-10observability, homeassistant, iot
0384A household physical capability belongs in the Critical Operations RegisterAccepted2026-08-10resilience, audit, netbox
0385Link an LLD template before any static trigger over its discovered keysAccepted2026-08-10standard, monitoring, observability
0386Room ownership model as the single engine for the conflict gate and the room docsAccepted2026-08-10homeassistant, automation, lighting
0387A deployed script executes no working-tree code, and a success marker names the code version that produced itAccepted2026-08-10ansible, config-as-code, ci
0388Destructive-automation clauses apply by shape: retention is not remediationAccepted2026-08-11standard, alerting, observability
0389Hypercare is an enforced delivery stage with an evidence-based exitUnstated2026-08-11delivery, ado, monitoring
0390An alert that can be read after it clears needs retrospective diagnosticsUnstated2026-08-11monitoring, observability, alerting
0391A safety precondition that logs and proceeds is not a preconditionAccepted2026-08-12automation, reliability, patching
0392Agent lesson corpus — amending ADR-0018's single-native-store assumptionAccepted2026-08-12agent-memory, cc-pool, knowledge-management
0393Bulk artifact creation uses one generator script, not N Write callsAccepted2026-08-12agent-memory, docs, aiops
0394Burn-rate alert windows are sized from measured traffic, not copied from the SRE bookAccepted2026-08-12alerting, observability, reliability
0395Bulk file deployment uses synchronize — ansible.builtin.copy round-trips per file, not per taskAccepted2026-08-12ansible, infrastructure, ci
0396An SLO attainment figure states its window and run count, or it is not a measurementAccepted2026-08-12reliability, observability, standard
0397Retiring an analyzer requires disposing of its findings — they do not expire on their ownAccepted2026-08-13security, vulnscan, devsecops
0398A secret the platform will not encrypt is controlled by scope, not by confidentialityAccepted2026-08-13security, secrets, dependency-track
0399Epic tags are four flat lifecycle labels; queue position and hypercare date live in the titleUnstated2026-08-13ado, delivery, lifecycle
0400A guest metric must be proven virtualised before it is alerted, dashboarded or sized onAccepted2026-08-13monitoring, observability, alerting
0401The self-hosted agent pool is authorized for all pipelines, because per-pipeline authorization was a formality that failed silentlyAccepted2026-08-13ci, pipelines, security
0402The agent constitution is governed by an enumerated rule inventory and a diff gateAccepted2026-08-14ci, claude, config-as-code
0403Withdraw /justdoit's delegated autonomy tier and re-grant it to /go with a circuit breakerAccepted2026-08-14autonomy, automation, devsecops
0404A container memory level is not a finding without its slope; and a threaded Python service caps MALLOC_ARENA_MAXUnstated2026-08-15monitoring, observability, alerting
0405External control of a light is not an ownership anomalyUnstated2026-08-15homeassistant, alerting, observability
0406pve01 memory capacity policy and weekly PBS GCAccepted2026-08-15pve01, proxmox, pbs
04075GHz co-channel interference is measured as spectral overlap of (channel, bandwidth), not channel equality — and alerts non-paging because the overlap is latent risk, not active faultAccepted2026-08-15networking, wifi, unifi
0408A long serial write chain needs a retry, not a wider timeout; and a per-request error rate must be read against the chain lengthAccepted2026-08-15observability, reliability, docker
0409pve01 runs with no swap deviceAccepted2026-08-15pve01, proxmox, performance
0410An ownership verdict requires an intact attribution joinAccepted2026-08-16homeassistant, alerting, observability
0411A Wi-Fi alert must name a condition that is both fault-bearing and reachable — count the resources the desired state needs before asserting it is reachableAccepted2026-08-16networking, wifi, unifi
0412An alert condition inferred from a failed lookup needs a stated preconditionAccepted2026-08-16alerting, observability
0413The agent's permission set is governed config, its deny list is a mistake-guard rather than a security boundary, and patterns are promoted to deterministic enforcement on stated criteriaAccepted2026-08-16claude, security, least-privilege
0414A harness-blocked action defers rather than halts, and the end-of-run script is a standing sub-grantAccepted2026-08-16autonomy, automation, devsecops
0415/go passes its Production Readiness Review into a measured soak, and its decisions are gradedAccepted2026-08-16autonomy, automation, observability
0416Retire the weekly feedback-hygiene sweep — its corpus moved, and the successor design refuses a scheduled sweepAccepted2026-08-17operations, claude, memory
0417Automation regenerates in a private worktree, never in a shared checkoutAccepted2026-08-17git, automation, docs-as-code
0418Dependency-Track triage decisions are carried forward before a superseded project is retiredAccepted2026-08-17devsecops, dependency-track, vulnscan
0419hass.pitbun.com serves Home Assistant over the cloudflared tunnel, not a proxied CNAME to Nabu CasaImplemented2026-08-17cloudflare, homeassistant, networking
0420Grafana trusts the Cloudflare Access JWT so the embedded rollup panel authenticates without a second loginImplemented2026-08-17cloudflare, grafana, observability
0421A blackbox probe on an Access-gated host is edge evidence only, and neither standard may claim otherwiseAccepted2026-08-17observability, blackbox, cloudflare
0422A missing agent helper is a finding to raise, not a throwaway script to writeAccepted2026-08-17agent-memory, autonomy, scripts
0423An app behind the tunnel trusts its own public hostname for origin checks, because the tunnel rewrites HostImplemented2026-08-17cloudflare, grafana, networking
0424Trivy's system-file filter is starved and selectively re-applied, so a vendor deb's Go binary keeps its vulnerability coverageAccepted2026-08-17devsecops, trivy, dependency-track
0425Informational severity is never sent to Pushover — it is recorded to Loki insteadAccepted2026-08-18alerting, notifications, pushover
0426The agent access contract is an installable package in its own repo, with disjoint read and write verb surfacesAccepted2026-08-18autonomy, api, scripts
0427The five helpers migrate reads-first onto the access contract, keeping their published stdout byte-identicalAccepted2026-08-18autonomy, api, scripts
0428Twenty systems join the read tier as declared data — trust anchors, unverified exceptions and the PostgreSQL gap are all stated rather than worked aroundAccepted2026-08-18autonomy, api, secrets
0429The media and app tier meets three APIs the read transport's guarantee does not cover — query-string credentials, GET-mutating verbs, and three systems that stay out of the registerAccepted2026-08-18autonomy, api, secrets
0430A write verb's authority class is enforced at the tool boundary, not remembered by the agentAccepted2026-08-18autonomy, api, scripts
0431The pitlab-access write set is derived from live automation, not listed — and a path parameter keeps a per-object write out of wildcard territoryAccepted2026-08-18autonomy, api, scripts
0432Credential scoping is measured, not assumed — and where an API cannot scope, the residual risk is recorded and the frozen read tier is the compensating controlAccepted2026-08-18autonomy, api, secrets
0433A policy-excluded credential is prepared, staged and proven refused — never provisioned, and never deferred into an unattended scriptAccepted2026-08-18autonomy, secrets, least-privilege
0434The MCP gateway mounts a pinned contract into a stock image and resolves every credential in its own processAccepted2026-08-18mcp, autonomy, api
0435A wait concludes or refuses — it never hangsAccepted2026-08-18automation, reliability, observability
0436A multi-guard CI job reports every guard's verdict, because a skipped guard is indistinguishable from a passing oneAccepted2026-08-18ci, pipelines, ansible
0437Agent-access conformance is a DECLARED register, a gate over it, and a discovery sweep beside it — because a gate can only check what is declaredAccepted2026-08-18mcp, autonomy, api
0438A pipeline gate that drives production code suppresses that code's notifications — a green gate is silentAccepted2026-08-18ci, alerting, observability
0439Agent system access is a gated standard, not a convention — and the helper-absence clause is promoted from advisory to machineAccepted2026-08-18autonomy, api, secrets
0440Shared library code that must run on a host AND in a container is a fourth script home — a versioned package in its own repoAccepted2026-08-18scripts, automation, standard-enforcement
0441A gate that reads a tree it does not refresh is a blind watcher — gates prove the currency of every tree they readAccepted2026-08-19ci, security, observability
0442Recording what is wrong must not assert that it is fixed — incident analysis notes are a distinct verbAccepted2026-08-19incidents, freescout
0443Keyword adjacency cannot see a positional credential — the secret scan covers basic-auth shapesAccepted2026-08-19security, secrets, ci
0444When you need a position, ask for the position — locate by line number, never print the lineAccepted2026-08-19claude, docs-as-code
0445An unattended red is a separate signal from a failureAccepted2026-08-19alerting, observability, ci
0446Stuck-alert detection is per-surface — age on Prometheus, cause on ZabbixAccepted2026-08-19alerting, observability, zabbix
0447A gate piped through tail reports the pipe's exit code, not the gate'sAccepted2026-08-19ci, claude, agent-memory
0448Every Epic board column transition has a named owning skill and a trigger momentAccepted2026-08-19ado, delivery, lifecycle
0449A dated review owed outside the Hypercare column still gets summonedAccepted2026-08-19delivery, alerting, automation
0450Publishing to the public showcase is an opt-in front-matter flag backed by a fail-closed scrub gateAccepted2026-08-19docs-as-code, security, ci
0451Public set-piece data is a sanitised build-time snapshot, and every published field is screened by the same gate that governs the pagesAccepted2026-08-20security, docs-as-code, observability
0452External exposure is information-based, not origin-basedAccepted2026-08-20security, cloudflare, compliance
0453Two-tier data classification: internal by default, public by explicit flagAccepted2026-08-20security, compliance, docs
0454A blocked capability that will recur becomes a bounded helper, not a repeated /tmp handoffAccepted2026-08-20operations, security, claude
0455The Wait Standard's arm-time clauses bind pipewait, not just waitforAccepted2026-08-20ci, pipelines, reliability
0456Pre-render site diagrams to both-theme SVG at build timeAccepted2026-08-20docs, ci, mermaid
0457Duplicate incident records collapse onto the oldest, and each container detects only its own namespaceAccepted2026-08-21incidents, observability, reliability
0458Historical duplicate incident records are archived to a second mailbox, not deletedAccepted2026-08-21incidents, freescout, itsm
0459The prototype preview path runs the production publish controls, in the same orderAccepted2026-08-21ci, cloudflare, security
0460A skill's authority envelope follows its invocation, not the skillUnstated2026-08-21autonomy, automation, cc-pool
0461Home Assistant friendly names are ASCII-normalised, because the conversation agent matches them exactlyUnstated2026-08-21homeassistant, naming, observability
0462The morning routine gains an unattended agentic run, reversing ADR-0166 decision 2Unstated2026-08-21autonomy, automation, alerting
0463The send gate audits the previous message rather than blocking the nextUnstated2026-08-22claude, cc-pool, standard-enforcement
0464Two CI planes run on one runner during the GitHub migration, and the org 2FA control is asserted rather than setUnstated2026-08-22ci, github, security
0465The warning tier is recorded, not pagedUnstated2026-08-22alerting, observability, alertmanager
0466ADO pipelines are converted to Actions workflows by a gated generator, never hand-portedUnstated2026-08-22ci, github, pipelines
0467Measured operational tuning is exempt from the grill gate (REJECTED)Unstated2026-08-22claude, standard-enforcement
0468The two CI planes get their own checkouts by path prefix, not their own HOMEUnstated2026-08-23ci, github, ado
0469Epics carry one domain tag — smart-home or pitlab — alongside their lifecycle tagUnstated2026-08-23claude, standard-enforcement
0470Terraform applies are approved by an issue comment, because GitHub's own approval gate is Enterprise-only on a private repoUnstated2026-08-23ci, github, terraform
0471A prototyped delta is accepted on user-validated criteria, not on the design it outgrewAccepted2026-08-23delivery, agent-memory

† the record states no date in its header, so the date shown is when the file first appeared in the corpus — 104 of 471 rows. 82 state no status; they show Unstated rather than an assumed one. 49 of these decisions are published here in full — the rest exist, and are listed, but are not part of the public set. 1 title's own words contain an internal identifier and are withheld by the same gate that decides which pages may ship; the record is still listed, with its number, status and date.

Every decision in the corpus is listed. A subset is published in full on this site and links through to its text; the rest are listed by title only, because publication is opt-in per page and most of the corpus contains identifiers that must not leave the estate. Listing the whole log rather than only the public part is deliberate: a decision log with the awkward entries filtered out is a marketing document.

Two fields are derived rather than stated, and the panel marks both rather than smoothing them over:

  • Dates. Not every record states a machine-readable date — the corpus grew three different header shapes over its life. Those rows carry the date the file first appeared in version control, marked with a dagger. The alternatives were to invent a date or to drop the decision from the log, and both are worse than a marked derivation.
  • Status. A record whose header states no status shows Unstated, never an assumed Accepted. That is a real gap in the corpus, and it is visible here because making gaps visible is what this panel is for.

Status, date, context, the decision, the alternatives considered, and the consequences. The alternatives section is the one that earns its keep — a record listing only what was chosen is a changelog entry.

They are written at the time the decision is made, not reconstructed at wrap-up, because the reasoning is the part that evaporates. A record written a week later contains what the author remembers deciding, which is reliably a tidier story than what actually happened.

Some of these records reverse earlier ones, and those are the most useful entries in the log: an autonomy tier that was granted and then withdrawn, a gate whose diagnosis turned out to be wrong, a threshold re-derived from measurement after a borrowed number failed. A decision log with no reversals in it is a log nobody is reading back.

Nothing here reaches the internet by default. A corpus page is published only if its front matter carries an explicit opt-in flag, and a second, independent control scans everything that would ship — the rendered source and the built bundle — and fails the build on any internal address, internal hostname, known endpoint, estate mailbox or secret-shaped string. It reds; it never rewrites, because an automatic redaction turns a loud failure into a silent transformation and leaves an unproven sanitiser standing between a private corpus and the open internet.