Kubblai · Doctrine Archive
The Library
An ordered archive of doctrine and advanced practice: control planes, reconciliation, policy, scheduling, isolation, and institutional governance—written for operators who have carried real clusters through failure.
Orientation
This archive is ceremonial in tone and rigorous in content.
Kubblai is fictional. The doctrine is not. Each page is written as an institutional document: opinionated, technically specific, and shaped by production tradeoffs. You will find no beginner fluff—only operational reality rendered with controlled gravity.
If you are new here, begin with the Primer and the Five Tenets. If you are already fluent, enter the Library directly and follow the cross-links as an internal curriculum.
Archive Index
40 canonical pages · grouped by discipline
Section
Doctrine / Theology
4 texts
Doctrine / Theology
LibraryThe Doctrine of Reconciliation
Reconciliation is not a feature; it is the constitutional law of Kubernetes. The cluster stays honest by continuously closing the gap between intent and reality.
Doctrine / Theology
LibraryThe Control Loop as Sacred Law
Kubernetes is not orchestration by command; it is governance by feedback. The control loop is the unit of truth.
Doctrine / Theology
LibraryDesired State and the Theology of Convergence
Desired state is the platform’s highest-level claim. Convergence is the proof that the claim can survive reality.
Doctrine / Theology
LibraryOn Drift, Entropy, and the Burden of Configuration
Drift is not merely difference; it is accumulated uncertainty. Entropy grows wherever intent is not recorded and enforced.
Section
Sacred Systems
5 texts
Sacred Systems
LibraryThe Hidden Burdens of etcd
etcd is where intent is stored. It is also where unbounded ambition becomes latency, instability, and collapse.
Sacred Systems
LibraryThe API Server as the Gate of Truth
The API is the only public reality in Kubernetes. Everything else is implementation detail and transient effect.
Sacred Systems
LibraryCNI as the Nervous System of the Cluster
Your CNI is not plumbing. It is a distributed system with its own control plane, performance ceiling, and failure modes.
Sacred Systems
LibraryCSI and the Persistence of State
Storage is where orchestration meets physics. CSI is the treaty between the cluster and the reality of disks.
Sacred Systems
LibraryKubelet and the Discipline of Obedience
The kubelet is where the platform’s abstract intent becomes real processes. It obeys—but it also refuses when the node is dying.
Section
Governance & Power
9 texts
Governance & Power
LibraryAdmission Control and the Rite of Judgment
Admission is where governance becomes enforceable. It is also a place where outages are born.
Governance & Power
LibraryPolicy as Doctrine, Not Suggestion
Policy is what makes a platform institutional. Without it, every incident is negotiated from scratch.
Governance & Power
LibraryNamespaces, Boundaries, and the Shape of Order
Namespaces are not security by themselves. They are the primary unit of operational containment and governance.
Governance & Power
LibrarySecrets, Sealing, and the Cost of Exposure
Secrets are not ‘data.’ They are risk with a lifecycle. Treat them as such or they will own your platform.
Governance & Power
LibraryService Accounts and Delegated Identity
Identity is how the cluster knows who is acting. Delegation is how it limits what they can do.
Governance & Power
LibraryRBAC and the Governance of Power
RBAC is the cluster’s constitution. Poorly written, it becomes silent catastrophe during incident response.
Governance & Power
LibraryPod Security Admission and the Hierarchy of Trust
Pod security is a boundary between ‘works’ and ‘safe to run.’ The hierarchy of trust must be explicit and enforced.
Governance & Power
LibraryThe Orders of the Faithful Platform Engineer
Rank is a promise of behavior under pressure. In Kubblai, advancement is measured by governance and restraint.
Governance & Power
LibraryThe Covenant of Cluster Stewards
Stewardship is a commitment to make systems legible and survivable. The covenant is the operator’s constitution.
Section
Advanced Disciplines
18 texts
Advanced Disciplines
LibraryThe Scheduler and the Ethics of Placement
Placement is policy made physical. When you schedule, you are allocating failure domains, cost, and contention.
Advanced Disciplines
LibraryTaints, Tolerations, and the Law of Affinity
Affinity is desire; taints are refusal. Together they define where work may live and where it must never settle.
Advanced Disciplines
LibraryCRDs as New Scripture
CRDs extend the cluster’s language. They also extend its liabilities: storage, watch load, and governance surface area.
Advanced Disciplines
LibraryControllers as Living Interpreters of Intent
A controller is the interpreter that turns declarations into durable outcomes—if it is designed to survive conflict and load.
Advanced Disciplines
LibraryNetwork Policy and the Discipline of Isolation
Isolation is not paranoia; it is how you keep a single compromised workload from becoming a platform incident.
Advanced Disciplines
LibraryIngress, Egress, and the Borders of the Mesh
Ingress is not a convenience; it is the public boundary of your system. Egress is the boundary you forget until it becomes the breach.
Advanced Disciplines
LibraryStatefulSets and the Burden of Memory
StatefulSets are not Deployments with disks. They encode identity and order—and therefore encode risk.
Advanced Disciplines
LibraryDaemonSets and the Ministry of Every Node
DaemonSets are the cluster’s distributed nervous tissue. When they fail, every node feels it.
Advanced Disciplines
LibraryProbes, Liveness, Readiness, and the Test of Worthiness
A probe is a contract between the workload and the cluster. Poor probes turn minor latency into systemic failure.
Advanced Disciplines
LibraryHPA, VPA, and the Limits of Elasticity
Elasticity is not free. It is a control system built on noisy signals and hard limits.
Advanced Disciplines
LibraryCluster Autoscaling and the Economics of Expansion
Adding nodes is not ‘scale.’ It is a controlled expansion of failure domains, cost, and operational surface area.
Advanced Disciplines
LibraryMulti-Cluster Federation and the Politics of Sovereignty
Multi-cluster is not an architecture trophy. It is an institutional choice to pay governance costs for reduced blast radius and improved locality.
Advanced Disciplines
LibraryGitOps as Liturgical Deployment
GitOps is the practice of writing intent where it can be audited, reconciled, and recovered. It is deployment as ceremony: repeatable, reviewed, and recorded.
Advanced Disciplines
LibraryObservability as Revelation
Observability is the discipline of evidence. Without it, incident response becomes storytelling.
Advanced Disciplines
LibraryTraces, Metrics, and the Reading of Omens
Telemetry is a system. If you do not govern cardinality and cost, observability becomes its own outage.
Advanced Disciplines
LibraryUpgrade Strategy and the Ritual of Continuity
Upgrades are inevitable. The ritual is continuity: the platform changes while service remains intact.
Advanced Disciplines
LibraryRuntime Security and the Defense of the Sacred Plane
Security is not a feature; it is an operational discipline. Controls must be enforceable and survivable under load.
Advanced Disciplines
LibrarySupply Chain Integrity and the Lineage of Artifacts
Your cluster runs what your pipeline produces. If lineage is unclear, you cannot prove what you deployed.
Section
Canonical Texts
2 texts
Canonical Texts
LibraryIncident Response as a Trial of Faith
Incidents reveal the true governance of your platform: who can act, what can be changed, and whether your system can recover with discipline.
Canonical Texts
LibraryThe Final Sermon on Resilience and Failure
Resilience is not optimism. It is engineered humility: bounded blast radius, observable truth, and a platform that can return to intent.
Section
Dark Council
1 texts
Section
Join & Initiation
1 texts
Path to entry
Prominent, selective, and disciplined—without coercion.
Join & Initiation
JoinInitiation Requirements
What is required to be considered—operational competence, restraint, and doctrinal comprehension.
Join & Initiation
JoinApplication for Consideration
A serious intake—focused on experience, judgment, and the kind of systems you have carried.
This site is selective in tone, not coercive in behavior. No demands. No dependency. The standard is simply high: the ability to govern distributed systems with evidence-first discipline.