Documentation is operating evidence.
Architecture, getting started and Day-2 knowledge stay attached to the systems they describe.
Documentation Overview
OSS Project Blueprint, reusable engineering standards, templates, and reference practices.
Core Concepts
Core concepts, three-tier architecture, trust models, and governance principles in OpenForge.
Getting Started
Step-by-step roadmap for adopting OpenForge standards and templates in new or existing OSS projects.
Standards
OpenForge standards grouped by engineering concern and lifecycle.
Templates Catalog
Catalog of reusable, production-tested implementation templates provided in OpenForge.
Architecture Blueprints
Recommended platform and service architecture patterns combining OpenForge standards and templates.
Operations Guide
Post-deployment lifecycle, observability, backup/recovery, and operational standards.
Reference & Source Map
Authoritative source mapping across OpenForge standards, templates, reference implementations, and evidence.
Troubleshooting Guide
Evidence-first symptom-cause-action debugging methodology and lessons-learned codification.
Architecture Decision Records (ADR)
Key architectural decisions, design rationale, and trade-offs behind OpenForge.
Repository Standard
OSS repository structure, required root files, and maintainability baseline.
Documentation Standard
Dual-language documentation model, source-of-truth invariants, and structure.
GitHub Standard
Issue, PR, branch protection, and collaborative maintainer workflow baseline.
Development Standard
Language-specific tooling baseline, deterministic formatting, and task automation.
Engineering Tooling Standard
Toolchain selection, configuration management, and developer workflow consistency.
Engineering Tooling Matrix
Recommended linters, formatters, and build tools per programming language.
CI/CD Standard
Continuous integration, delivery pipelines, and validation quality gates.
CI/CD Security Standard
CI trust boundaries, permissions, runners, caches, and release isolation.
CI/CD Resilience Standard
Safe fallback strategies and failure mitigation during CI platform outages.
Reproducible Build Standard
Deterministic build artifacts, pinned environments, and verification discipline.
Change Management & Impact Analysis
Full workflow impact analysis before dependency, runtime, or toolchain changes.
Upgrade & Compatibility Engineering
Support windows, backward-compatibility testing, and drift prevention.
Security Standard
OpenForge baseline for secure development and operational boundaries.
Supply Chain Security Standard
Dependency governance, package identity verification, and registry defense.
Package & Artifact Identity
Immutable package provenance, checksum, signature, and metadata verification.
Plugin Supply-Chain Intake Standard
Integrity verification, runtime capability constraints, and plugin intake pipelines.
Developer Environment Security
Local workstation boundaries, credential isolation, and secure tool execution.
AI-Assisted Engineering Security
Trust boundaries for AI agents, prompt injection defense, and sandbox isolation.
Container, Kubernetes & IaC Security
Hardened container images, non-root execution, NetworkPolicies, and policy-as-code.
Reference Implementation Metrics
Repository maturity scorecard and evidence model for OpenForge standards compliance.
Secrets & Machine Identity
Short-lived tokens, OIDC federation, secret scanning, and zero hardcoded credentials.
Vulnerability Management
CVE triage procedures, risk prioritization, patching workflows, and SLA.
Security & Incident Response
Incident triage, mitigation, communication, and lessons-learned codification.
Release Standard
Semantic Versioning, automated changelog, and tag-triggered distribution.
Release Security
Cryptographic signing, SBOM generation, provenance attestations, and distribution trust.
Security Exceptions & Waivers
Time-bounded exception handling, risk ownership, and expiration auditing.
Maintainer Governance
Risk-based governance and approval workflows for 1-person and multi-maintainer OSS.
Internationalization Standard
Multilingual UI resource structures, translation keys, and locale consistency.
OSS Compliance Standard
Apache 2.0 licensing, SPDX headers, dependency compatibility, and attribution.
Reference Practices Audit
Extracting, codifying, and validating repeatable patterns from real OSS projects.
ClusterDeck Overview
A macOS workstation access layer that keeps frequently recreated VM and Kubernetes environments reachable through stable Profiles.
ClusterDeck Architecture
Local systems architecture across Tauri UI, Rust core, OpenSSH, and kubeconfig boundaries.
ClusterDeck Getting Started
macOS development setup and the Profile-oriented SSH/kubeconfig connection flow.
Platform Overview
Narwhal IDP architectural philosophy, three-tier integration model, and 35 components.
Cluster Architecture
Narwhal 3M+3W node topology, HA control plane, and integration seams.
GitOps Workflow
Argo CD + Gitea App-of-Apps declarative delivery and Sync Waves ordering.
Networking & Ingress
Cilium eBPF CNI, MetalLB L2 load balancing, APISIX API Gateway, and DNS.
Security & SSO
Keycloak OIDC, Istio Ambient ztunnel mTLS, OpenBao, and Kyverno governance.
Observability Stack
Prometheus, Grafana, Loki, Tempo, Alloy, and Hubble eBPF telemetry.
Storage & Databases
NFS CSI + nfs-quota-agent, SeaweedFS S3 object storage, and CloudNativePG.
Day-2 Operations & DR
Velero backup automation, air-gap offline bundles, and maintenance runbooks.
Regression & Chaos Testing
263 incident lessons codified into 51 CI regression checks and Chaos Mesh.
Feature Guide
Guide to the automatic quota management, cleanup, trends, policies, and audit features provided by the NFS Quota Agent
Web UI
Guide to the built-in dashboard of the NFS Quota Agent, including its tab layout and API endpoints
Quota Agent Overview
Physical storage quota enforcement mechanisms and design principles for NFS PVs.
Storage Architecture
Linux XFS Project Quotas, gRPC daemon internals, and provisioning flows.
Features & CRD Guide
QuotaPolicy CRD, dynamic provisioning, Prometheus metrics, and REST APIs.
Installation & Setup
systemd service installation, binary compilation, and Helm deployment.
Operations & Monitoring
Web UI administration, Alertmanager rules, XFS diagnostics, and DR.
ldapium Overview
OpenLDAP 2.6 source compilation, web UI, and zero-default credential philosophy.
Directory Architecture
MDB backend storage engine, TLS/mTLS encryption, and Helm chart architecture.
Installation Guide
Docker Compose local execution and Kubernetes Helm production deployment.
Air-Gap Deployment
Air-gap bundle packaging, registry mirroring, and verification for disconnected networks.
Operations & Backup
TLS certificate rotation, slapcat/slapadd database backups, and disaster recovery.
Platform Overview
All-in-one modern data stack platform architecture (Kafka, Flink, Iceberg, Trino, Airflow).
Pipeline Architecture
Kafka → Flink → Iceberg → Trino → Airflow end-to-end data pipeline flow and integration.
Cluster Setup Guide
Vagrant + Helm + Argo CD local data platform 1-click bootstrap guide.
Data Operations Guide
Pipeline lifecycle, Iceberg table compaction, and metric monitoring runbooks.
Troubleshooting Guide
Root-cause analysis for Kafka lag, Flink checkpoint timeouts, and Trino OOMs.
Manager Overview
Target and current documentation/design boundary of the Beluga unified control plane.
Control Plane Architecture
Planned domain API, correlation, adapter structure, and authoritative-state boundaries.
Development Guide
Current repository verification and the boundary for selecting a future application stack.
Deployment & Operations
Operational and deployment-readiness criteria for an early control-plane design with no release artifact yet.
Siqoq Overview
Goals and current implementation boundary of simulation-to-edge Physical AI infrastructure.
Siqoq Architecture
Simulation-to-reality architecture centered on semantic event and action contracts.
Siqoq Development and Verification
Current executable Python foundation and principles for future adapters.
About K-PaaS Lite
Lightweight K-PaaS for easy development and testing
Container Platform Architecture
How K-PaaS Container Platform Works
Technology Stack
Technology Stack Used in K-PaaS Lite Installation
Components
K-PaaS Lite Components
Installation Process
K-PaaS Local Installation Process
Vagrant
Vagrant Configuration and Tips
Global Variable
K-PaaS Local Environment Variable Configuration
Account
K-PaaS Account Information
Tips & Tricks
Useful Tips for K-PaaS Local
Troubleshooting
K-PaaS Troubleshooting Guide
Release Note
K-PaaS Lite Release Notes
Usage
Vagrantfile configuration, provider selection, and K8s post-installation guide for Kube-Ready-Box
Release & Distribution
Vagrant Cloud upload pipeline, HCP credential mechanism, and deployment checklist
Box Overview
Kubernetes-optimized Ubuntu Vagrant base box architecture and design principles.
System Architecture
Build architecture and product boundary from Ubuntu cloud images to verified Kubernetes-ready Vagrant boxes.
Vagrantfile Guide
Multi-provider configuration, resource allocation, and provisioning guide.
Packer Builds & Releases
HashiCorp Packer build pipelines and Vagrant Cloud publishing automation.
Node Verification
Node Readiness Attestation and 30 kernel/storage integrity verification checks.
Usage
Installing and running KubeMetal, what each of the eight tabs does, the model-to-serving workflow, and measured performance
External Cluster Integration
The two tiers for attaching KubeMetal to an existing Kubernetes cluster — agent-only by default (L1) and opt-in full-stack deployment (L2), plus the GitOps path and air-gap support
KubeMetal Overview
Apple Silicon hybrid MLOps architecture and host-native MLX acceleration overview.
System Architecture
Tauri v2 IPC bridge, host MLX acceleration engine, and local K8s control plane.
MLOps Pipelines
Local LLM fine-tuning (LoRA/QLoRA), MLX quantization, and low-latency inference.
App Setup & Installation
Tauri v2 desktop compilation, dependency setup, and model initialization.
Performance & Operations
Unified Memory optimization, Apple Silicon chip matrix, and E2E validation.
Portal Development Workflow
Guide to the in-cluster portal development environment using Skaffold, Kaniko, and pnpm
Portal Deployment & Security
Deployment strategies for the Narwhal IDP Portal and secret hardening procedures for clean installs
Portal Overview
Narwhal Portal architecture, developer UX, and platform integration scope.
Portal Architecture
Next.js 16 App Router structure, gRPC communication, and OIDC session models.
Development Setup
pnpm local setup, environment variables, and Skaffold live reload workflows.
Deployment & Operations
Multi-stage production container packaging, health probes, and K8s deployment.
Architecture Decision Records
Architecture decision records on Skaffold workflows and cost-basis optimization.