8aa04f256cdfa0710bfae78373544a0a2a17d971
Reframe "Cilium Entity Identities for Monitoring Scraping" as cross-cutting -- the same entity table applies to any pod that needs to reach cluster infrastructure (apiserver, kubelets, node-exporter, host services), not just Prometheus. Add the gotcha that bit M22 Phase 7: standard NetworkPolicy ipBlock CIDR rules do NOT match cluster node IPs. Nodes carry the Cilium remote-node/kube-apiserver identity and ipBlock only matches off-cluster IPs. The misleading symptom is a 30s hang followed by a generic upstream error like "permission denied" (seen on OpenBao TokenReview, would also affect ESO+vault k8s auth, and any controller calling subjectaccessreviews). Same gotcha applies to namespaceSelector: kube-system -- the apiserver runs hostNetwork=true and is not selectable that way. Source incident: agent-runtimes M22 Phase 7 F-OPENBAO-K8S-AUTH-1 (homelab/openbao-deploy@f7bd64d). Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
best-practices
Cross-project best practices extracted from real project work via the /distill-best-practices skill.
How It Works
The knowledge distillation pipeline in claude-foundations processes session logs and memory files from all tracked projects, extracting generalisable practices into topic files here.
Pipeline
/log— Captures session decisions and gotchas into per-projectmemory/log//reflect-logs— Processes logs into structured topic memory files/distill-best-practices— Reads memory files across projects, proposes updates to this repo
For Humans
Browse BESTPRACTICES.md for the full index. Each topic file is self-contained.
For Agents
Container agents get this repo cloned to /best-practices. Read BESTPRACTICES.md for the index, then read only the topic files relevant to your task.
Topics
| File | Description |
|---|---|
ansible.md |
Inventory, templates, idempotency, credential safety |
database-selection.md |
SQLite vs PostgreSQL decision criteria |
debugging.md |
Systematic diagnosis, full-chain testing, common pitfalls |
docker.md |
gosu PID 1, GIT_SSH_COMMAND scope, slim image patterns |
docker-uid-matching.md |
UID wrapper entrypoint, gosu pattern |
documentation.md |
CLAUDE.md, MEMORY.md, FUTURE.md, README.md structure |
git-source-control.md |
Commit practices, GitOps workflows, remote conventions |
helm.md |
Schema validation, version verification, values structure |
kubernetes.md |
Volume mounts, deployment strategies, naming, bootstrap ordering |
linting.md |
Tool choices per language, PostToolUse hook, pre-commit |
milestones.md |
Milestone workflow, verification, reflection process |
networking.md |
nftables, systemd sockets, Docker forwarding, TLS |
octopus-process-templates.md |
OCL syntax, step templates, Platform Hub patterns |
scripting.md |
Shell conventions, verification scripts, idempotency |
secrets-management.md |
SOPS + age, credential handling, encryption gotchas |
security-architecture.md |
Server boundary rule, proxy patterns, defense in depth |
skills-development.md |
Skill authoring, context injection, tool restrictions |
spec-driven-development.md |
Spec structure, requirement numbering, test-first workflow |
test-driven-development.md |
Edge case discovery, property-based testing, AI agent patterns |
validation.md |
Validate locally, deploy once; full-chain testing |
Source Control
- Gitea:
skynet/best-practices - Remote:
git@gitea.oreillyit.nz-ai-enablement:skynet/best-practices.git
Description
Languages
Markdown
100%