The #34 rename dropped the legacy chat/triage names from the certificate SANs, the hermes-sites Ingress, the CoreDNS overrides and the Keycloak ensure script at the same time, so nothing failed loudly: DNS and TLS still looked healthy while the legacy hosts served 404 and the renamed hosts could not finish a login. Pin the invariant that makes that silent: a public host is either served by all four layers or by none. The table of hosts is the contract, so retiring a name stays a deliberate edit rather than a side effect. Verified to catch the regression: against the pre-fix tree these fail for both legacy hosts on all four layers (9 failures); against this branch the suite is green. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
titan-iac
Flux-managed Kubernetes desired-state config for bstein.dev.
Canonical source URL:
ssh://git@scm.bstein.dev:2242/atlas/titan-iac.git
Scope
This repo contains cluster configuration consumed by Flux:
- platform/infrastructure manifests
- service manifests and kustomizations
- operational scripts for render/reconcile workflows
Apply model
I use Git + Flux as the source of truth and avoid manual in-cluster edits for durable changes.
Description
Languages
Python
74%
JavaScript
10.2%
Shell
6.2%
TypeScript
3.9%
Go
2.1%
Other
3.4%