Reframe "Cilium Entity Identities for Monitoring Scraping" as
cross-cutting -- the same entity table applies to any pod that
needs to reach cluster infrastructure (apiserver, kubelets,
node-exporter, host services), not just Prometheus.
Add the gotcha that bit M22 Phase 7: standard NetworkPolicy
ipBlock CIDR rules do NOT match cluster node IPs. Nodes carry
the Cilium remote-node/kube-apiserver identity and ipBlock only
matches off-cluster IPs. The misleading symptom is a 30s hang
followed by a generic upstream error like "permission denied"
(seen on OpenBao TokenReview, would also affect ESO+vault k8s
auth, and any controller calling subjectaccessreviews).
Same gotcha applies to namespaceSelector: kube-system -- the
apiserver runs hostNetwork=true and is not selectable that way.
Source incident: agent-runtimes M22 Phase 7 F-OPENBAO-K8S-AUTH-1
(homelab/openbao-deploy@f7bd64d).
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Adds 3 new topic files (ai-parallel-agents, api-integration,
python-patterns) and extends 21 existing topic files with new gotchas
and patterns surfaced from memory across tracked projects. Index
updated accordingly.
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
Add 37 new entries and update 7 existing entries across 13 topic files.
Major contributions from agent-runtimes (K8s secrets, CI, Docker gotchas),
cluster-bootstrap (ArgoCD SSA, etcd tuning, DB migrations, Compose networking),
and cluster-apps/octopus-deploy (Helm vs raw manifests, ArgoCD source types).
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Migrates 20 topic files from claude-foundations/best-practices/ to this
standalone repo. Adds BESTPRACTICES.md index, CLAUDE.md conventions, and
updated README.md. Container agents clone this repo to /best-practices.
Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>