Skip to content

Architecture Decision Records

Historical ADRs were rendered from bd decision records (/adr skill), named <bd-id>-<slug>.md; those retain their adr-render provenance comment. That pipeline is retired (beads removed). Newer ADRs are hand-authored with a date-based <date>-<slug>.md name — edit the file directly, not a bd record.

DateADRStatus
2026-07-102026-07-10 — Send engram’s memory corpus to Google’s paid Gemini embedder (gemini-embedding-2), accepting a limited-retention, not-ZDR postureAccepted
2026-07-07hl-fyy5 — Router-hosts-generated unbound zone replaces dnsmasq overlayAccepted
2026-07-07hl-p5ck — Accept Control D endpoint-level attribution, not per-clientAccepted
2026-07-05hl-4z56 — Move oauth2-proxy to Valkey server-side session storeAccepted
2026-07-05hl-swfp — Split Tailscale ACL (gitops-acl-action) from tf/tailscale (Terraform)Accepted
2026-07-05hl-imbj — Standardize Tailscale node auth on TF-minted OAuth clients (not static keys)Accepted
2026-07-05hl-r9en — Declare telemetry disposable; greenfield table cutoverAccepted
2026-07-05hl-olui — Native CH BACKUP to RustFS replaces Velero CSI snapshotsAccepted
2026-07-05hl-hiiu — External CronJob watchdog, not an in-stack tile alertAccepted
2026-07-05hl-4pmu — Replicate ClickHouse without sharding via bootstrap JobAccepted
2026-07-03hl-zzmt — Document deprecated-read exceptions where no write-only sink existsAccepted
2026-07-03hl-ujwi — Migrate Vault KV reads per value-sensitivity, not via vault_generic_secretAccepted
2026-07-03hl-u103 — Split Keycloak OIDC secrets into TF-owned /oidc subpathsAccepted
2026-07-03hl-sqtn — Allow GitHub SSO to auto-create Keycloak accountsAccepted
2026-07-03hl-sqk9 — Mint per-resource MCP audiences via optional client scopesAccepted
2026-07-03hl-ndh5 — Deliver k8s groups via a scoped optional scope, not a blanket mapperAccepted
2026-07-03hl-iu87 — Hosted Terraform MCP is read-only; no MCP-triggered TFC runsAccepted
2026-07-03hl-d3y5 — Read public CA chain live from Vault PKI, not repo PEMAccepted
2026-07-03hl-bc94 — Hosted Kubernetes MCP uses Keycloak-OIDC identity passthrough, not a shared ServiceAccountAccepted
2026-07-03hl-94n1 — Use the resource URL as the hosted k8s MCP token audienceAccepted
2026-07-03hl-3328 — Retire Tandoor rather than migrate to KeycloakAccepted
2026-07-03hl-2jrh — Multi-route MCP OAuth discovery uses resource-specific well-known pathsAccepted
2026-07-03hl-1fia — Replace Authentik forward-auth with shared oauth2-proxy + per-route group gateAccepted
2026-07-02hl-ll5p — Restore cluster-internal-only Keycloak DCR (A1+trust)Accepted
2026-07-02hl-cnyd — Gate Keycloak admin console via Cloudflare Access, excluding Keycloak as IdPAccepted
2026-07-02hl-1e4w — Preserve real client IPs on Traefik Service (externalTrafficPolicy: Local)Accepted
2026-07-01hl-idws — Use single-issuer structured AuthenticationConfiguration for k8s OIDCAccepted
2026-06-30hl-toju — Decommission kube-prometheus-stack; migrate alerting to HyperDX TILE alertsAccepted
2026-06-30hl-tir8 — Use groups-claim model for Phase 2 OIDC authz; defer roles to Phase 4Accepted
2026-06-30hl-lil1 — Deploy kube-state-metrics standalone; replace node-exporter with OTel hostmetricsAccepted
2026-06-30hl-hssw — Inject HyperDX dnsConfig via kustomize helmCharts inflationAccepted
2026-06-30hl-hpbv — Collect Keycloak metrics via OTel-native OTLP push, not Prometheus scrapeAccepted
2026-06-30hl-6bib — Accept open-realm client access; defer per-client group gating to Keycloak authz servicesAccepted
2026-06-29hl-amad — Remove Traefik DCR deny; loopback Trusted-Hosts as sole DCR controlSuperseded by hl-ll5p
2026-06-28hl-zrbh — NAS Kopia v1 backs up live datasets, deferring snapshot consistencyAccepted
2026-06-28hl-xktj — Enable Keycloak anonymous DCR via Trusted-Hosts policySuperseded by hl-amad
2026-06-28hl-wxz2 — Build nas-otel derived image in CI/GHCR, not on-boxAccepted
2026-06-28hl-ptnd — B2 Object Lock in GOVERNANCE mode with an offline bypass key for v1Accepted
2026-06-28hl-mx5n — Fix Keycloak issuer at id.fzymgc.house from day oneAccepted
2026-06-28hl-jecc — Scoped CiliumNetworkPolicy as sole Phase-1 access control for fovea auditAccepted
2026-06-28hl-gww0 — Self-managed Kopia to Backblaze B2 with Object Lock for NAS irreplaceable-data backupAccepted
2026-06-28hl-cbln — Run model: scheduled-CLI Kopia in the nas-support LXC, not a server or Docker appAccepted
2026-06-28hl-buts — Accept velero PVC backup for fovea audit data, no native Qdrant snapshotAccepted
2026-06-28hl-9uzu — NAS Kopia snapshot consistency via TrueNAS snapshot-task plus per-leaf .zfs readSuperseded by hl-zrbh
2026-06-28hl-9rhj — Use k8s structured auth config for dual-issuer OIDC transitionSuperseded by hl-idws
2026-06-28hl-2vsw — Sign nas-otel GHCR image with keyless cosignAccepted
2026-06-28hl-12i8 — Migrate cluster IdP from Authentik to KeycloakAccepted
2026-06-27hl-wo1m — Ship NAS telemetry via a dedicated nas-otel-collector TrueNAS custom appAccepted
2026-06-27hl-hghu — Build NAS containers on TrueNAS libvirt-LXC, not IncusAccepted
2026-06-27hl-akt3 — Manage the TrueNAS NAS exclusively via the middleware APIAccepted
2026-06-27hl-3ek7 — Grant NAS sandbox dataset access via DEFAULT idmap plus per-dataset ACLsAccepted
2026-06-26hl-osb5 — Expression-policy audit alerts excluding the GitOps automation actorAccepted
2026-06-26hl-a1uh — Invitation email via ak_send_email, not NotificationTransportAccepted
2026-06-25hl-93me — Tier fovea scout aspects across two models via the closed scout/deepdive role setAccepted
2026-06-25hl-5xgq — Adopt HyperDX/ClickStack as cluster observability platform; retire Grafana-LabsAccepted
2026-06-25hl-0ah0 — Route fovea LLM roles to ZDR open models via path-prefix agentgateway lanesAccepted
2026-06-23hl-poj0 — Transparent credential pass-through; no Headroom auth layerAccepted
2026-06-23hl-k1am — Disable the Headroom semantic response cache on both instancesAccepted
2026-06-23hl-g0fn — Split Headroom into two instances by run modeAccepted
2026-06-23hl-8ycr — Use official GHCR Headroom images; do not build cluster-owned imagesAccepted
2026-06-22hl-1pwl — Scrape agentgateway metrics via otel-scraper; push traces directlyAccepted
2026-06-20hl-v4vo — Add dedicated transparent OpenRouter passthrough host on agentgatewayAccepted
2026-06-20hl-rzrg — Split read and write Firewalla MCP routes at the gateway for topology-enforced blast-radiusAccepted
2026-06-20hl-nmix — Use VK + static upstream bearer auth for Firewalla MCP (not per-user OIDC)Accepted
2026-06-20hl-l875 — Use Detect not Passthrough for the generic OpenRouter lane (preserve OTel telemetry)Accepted
2026-06-20hl-d5lu — Select the ZDR lane via two HTTPRoutes + Gateway API header-count tiebreakerAccepted
2026-06-20hl-93zf — Build Firewalla MCP server rather than adopt off-the-shelf amittell serverAccepted
2026-06-19hl-qra1 — Use per-name dnsmasq local=+address= records for the authoritative internal fzymgc.house zoneSuperseded by hl-fyy5
2026-06-18hl-2t4o — Use dnsmasq local= for an authoritative internal fzymgc.house zoneSuperseded by hl-qra1
2026-06-15hl-cujh — Use hybrid autodiscoverFilter + App-install fence for multi-account Renovate governanceAccepted
2026-06-15hl-6fu4 — Use inline config.js baseline over a shared preset repo for Renovate policyAccepted
2026-06-14hl-v808 — Use SQLite on a Longhorn PVC for Renovate CE state, not CNPG PostgresAccepted
2026-06-14hl-qovi — Use Cilium WireGuard pod-to-pod encryption cluster-wideAccepted
2026-06-14hl-5sr0 — Expose Renovate CE via dual trigger: scheduler plus webhookAccepted
2026-06-14hl-543e — Use a single public GitHub App for multi-org Renovate CEAccepted
2026-06-13hl-fvje — Traefik metrics: pure-OTLP push; disable the Prometheus endpointAccepted
2026-06-13hl-aek4 — Inject Traefik OTLP auth headers via TRAEFIK_* env vars, not Helm valuesAccepted
2026-06-13hl-5z4x — Use the native experimental OTLP access-log exporter on cluster ingressAccepted
2026-06-13hl-57x5 — Upgrade engram embedding model to Qwen3-Embedding-8B (4096-dim) via OpenRouter ZDRSuperseded by 2026-07-10-engram-gemini-embedder-retention-posture
2026-06-13hl-0gol — Exclude the orphaned (vestigial-Flux) wildcard cert from the new ArgoCD sourceAccepted
2026-06-12hl-cgb4 — Choose Miniflux over FreshRSS as the cluster feedreaderAccepted
2026-06-12hl-27xf — Authenticate Miniflux with native Authentik OIDC, not forward-authAccepted
2026-06-08hl-fk0 — Gating split: env-gate recency scan, ship doc-aware analysis unconditionally (refines hl-78b)Accepted
2026-06-08hl-bit.30 — Use symlinked content collection + stock docsLoader for Starlight docsAccepted
2026-06-08hl-26y — null (never now()) as the absent-recency sentinel for lastModifiedAtAccepted
2026-06-08hl-0d4 — Per-file recency via bare blob-less git clone at index time (octopus fork)Accepted
2026-06-07hl-yrh — Cluster cross-check is advisory only; never a CI gateAccepted
2026-06-07hl-nhi — Per-server path-routed MCP gateway with per-upstream client-auth choice (OAuth or VK)Accepted
2026-06-07hl-m3c — Deploy agentgateway via k8s-native Gateway-API/CRD control plane (supersedes standalone)Accepted
2026-06-07hl-bc5 — Phase 1 audit harness in Python/uv reusing pinned clients; Node deferred to Phase 3Accepted
2026-06-07hl-6iz — Use isolated website/ subproject with externalDocsLoader for Starlight docsSuperseded by hl-bit.30
2026-06-07hl-25z — Serve llms.txt artifacts from the build; enforce coverage via custom CI gateAccepted
2026-06-07hl-0eb — ZDR via structured field-override (ai.overrides); CEL only for drop_paramsAccepted
2026-06-06hl-pvn — Pin self-owned images by short-SHA, not mutable tagsAccepted
2026-06-06hl-msh — Dedicate Qdrant + CNPG database to octopus, isolated from engramAccepted
2026-06-06hl-jd4 — Deploy agentgateway in standalone mode, not the K8s Gateway-API control planeSuperseded by hl-m3c
2026-06-06hl-hv3 — Use agentgateway as the unified LLM + MCP data plane (replace LiteLLM)Accepted
2026-06-06hl-env — ZDR and drop_params via CEL config transformations (no custom binary/plugin)Superseded by hl-0eb
2026-06-06hl-8g4 — Split octopus across two hostnames: public webhook + internal UIAccepted
2026-06-06hl-78b — Fork octopus as thin staging ground; upstream the EMBEDDING_DIM patchAccepted
2026-06-06hl-6nm — Split model routing: OpenRouter reviews + in-cluster bge-m3 embeddings (1024-dim)Accepted
2026-06-06hl-23m — agentgateway is the MCP auth enforcement point + DCR short-circuit (engram stays the Resource Server)Accepted
2026-06-02hl-cy3 — Use dual backup paths for Qdrant memory storeAccepted