Skip to content

Kubblai · Doctrine Archive

The Library

An ordered archive of doctrine and advanced practice: control planes, reconciliation, policy, scheduling, isolation, and institutional governance—written for operators who have carried real clusters through failure.

Orientation

This archive is ceremonial in tone and rigorous in content.

Kubblai is fictional. The doctrine is not. Each page is written as an institutional document: opinionated, technically specific, and shaped by production tradeoffs. You will find no beginner fluff—only operational reality rendered with controlled gravity.

If you are new here, begin with the Primer and the Five Tenets. If you are already fluent, enter the Library directly and follow the cross-links as an internal curriculum.

Archive Index

40 canonical pages · grouped by discipline

Section

Doctrine / Theology

4 texts

Marker

Section

Sacred Systems

5 texts

Marker

Section

Governance & Power

9 texts

Marker

Governance & Power

Library

Admission Control and the Rite of Judgment

Admission is where governance becomes enforceable. It is also a place where outages are born.

Governance & Power

Library

Policy as Doctrine, Not Suggestion

Policy is what makes a platform institutional. Without it, every incident is negotiated from scratch.

Governance & Power

Library

Namespaces, Boundaries, and the Shape of Order

Namespaces are not security by themselves. They are the primary unit of operational containment and governance.

Governance & Power

Library

Secrets, Sealing, and the Cost of Exposure

Secrets are not ‘data.’ They are risk with a lifecycle. Treat them as such or they will own your platform.

Governance & Power

Library

Service Accounts and Delegated Identity

Identity is how the cluster knows who is acting. Delegation is how it limits what they can do.

Governance & Power

Library

RBAC and the Governance of Power

RBAC is the cluster’s constitution. Poorly written, it becomes silent catastrophe during incident response.

Governance & Power

Library

Pod Security Admission and the Hierarchy of Trust

Pod security is a boundary between ‘works’ and ‘safe to run.’ The hierarchy of trust must be explicit and enforced.

Governance & Power

Library

The Orders of the Faithful Platform Engineer

Rank is a promise of behavior under pressure. In Kubblai, advancement is measured by governance and restraint.

Governance & Power

Library

The Covenant of Cluster Stewards

Stewardship is a commitment to make systems legible and survivable. The covenant is the operator’s constitution.

Section

Advanced Disciplines

18 texts

Marker

Advanced Disciplines

Library

The Scheduler and the Ethics of Placement

Placement is policy made physical. When you schedule, you are allocating failure domains, cost, and contention.

Advanced Disciplines

Library

Taints, Tolerations, and the Law of Affinity

Affinity is desire; taints are refusal. Together they define where work may live and where it must never settle.

Advanced Disciplines

Library

CRDs as New Scripture

CRDs extend the cluster’s language. They also extend its liabilities: storage, watch load, and governance surface area.

Advanced Disciplines

Library

Controllers as Living Interpreters of Intent

A controller is the interpreter that turns declarations into durable outcomes—if it is designed to survive conflict and load.

Advanced Disciplines

Library

Network Policy and the Discipline of Isolation

Isolation is not paranoia; it is how you keep a single compromised workload from becoming a platform incident.

Advanced Disciplines

Library

Ingress, Egress, and the Borders of the Mesh

Ingress is not a convenience; it is the public boundary of your system. Egress is the boundary you forget until it becomes the breach.

Advanced Disciplines

Library

StatefulSets and the Burden of Memory

StatefulSets are not Deployments with disks. They encode identity and order—and therefore encode risk.

Advanced Disciplines

Library

DaemonSets and the Ministry of Every Node

DaemonSets are the cluster’s distributed nervous tissue. When they fail, every node feels it.

Advanced Disciplines

Library

Probes, Liveness, Readiness, and the Test of Worthiness

A probe is a contract between the workload and the cluster. Poor probes turn minor latency into systemic failure.

Advanced Disciplines

Library

HPA, VPA, and the Limits of Elasticity

Elasticity is not free. It is a control system built on noisy signals and hard limits.

Advanced Disciplines

Library

Cluster Autoscaling and the Economics of Expansion

Adding nodes is not ‘scale.’ It is a controlled expansion of failure domains, cost, and operational surface area.

Advanced Disciplines

Library

Multi-Cluster Federation and the Politics of Sovereignty

Multi-cluster is not an architecture trophy. It is an institutional choice to pay governance costs for reduced blast radius and improved locality.

Advanced Disciplines

Library

GitOps as Liturgical Deployment

GitOps is the practice of writing intent where it can be audited, reconciled, and recovered. It is deployment as ceremony: repeatable, reviewed, and recorded.

Advanced Disciplines

Library

Observability as Revelation

Observability is the discipline of evidence. Without it, incident response becomes storytelling.

Advanced Disciplines

Library

Traces, Metrics, and the Reading of Omens

Telemetry is a system. If you do not govern cardinality and cost, observability becomes its own outage.

Advanced Disciplines

Library

Upgrade Strategy and the Ritual of Continuity

Upgrades are inevitable. The ritual is continuity: the platform changes while service remains intact.

Advanced Disciplines

Library

Runtime Security and the Defense of the Sacred Plane

Security is not a feature; it is an operational discipline. Controls must be enforceable and survivable under load.

Advanced Disciplines

Library

Supply Chain Integrity and the Lineage of Artifacts

Your cluster runs what your pipeline produces. If lineage is unclear, you cannot prove what you deployed.

Section

Canonical Texts

2 texts

Marker

Section

Dark Council

1 texts

Marker

Section

Join & Initiation

1 texts

Marker

Path to entry

Prominent, selective, and disciplined—without coercion.

This site is selective in tone, not coercive in behavior. No demands. No dependency. The standard is simply high: the ability to govern distributed systems with evidence-first discipline.

Library count: 40 pages.