Skip to content

Knowledge Base

What this is

A public, evergreen technical knowledge base: product and stack research, internals, operational recipes, and neutral comparisons across cloud-native infrastructure, data systems, observability, and AI. It covers 14 domains and 60 topics, plus a curated tools catalogue. Every page is organized by reader need (the Diataxis framework) and carries a last_checked date. The most recent full audit was on 2026-09-25.

Verify before production use

AI generated or assisted much of this content. Each topic links its primary sources. Check versions, commands, and prices against official documentation before you rely on them. See the AI Disclaimer.

Domain Map

The diagram shows how the domains stack up. Delivery tooling provisions and deploys the platform. Cluster services and data systems run on it. Observability watches every layer. The AI domains sit on top.

flowchart TB
    subgraph Delivery["Delivery"]
        IAC["IaC<br/>OpenTofu · Terraform · Pulumi"]
        CICD["CI/CD (GitOps)<br/>Argo CD · Flux"]
    end
    subgraph Compute["Compute platform"]
        VIRT["Virtualization and private cloud<br/>Proxmox VE · OpenNebula · OpenStack"]
        CLOUD["Public cloud and governance<br/>AWS · GCP · Alibaba Cloud · Tencent Cloud"]
        K8S["Containers<br/>Docker · Kubernetes"]
    end
    subgraph Services["Cluster services"]
        NET["Networking (CNI)<br/>Cilium · Calico · Flannel"]
        MESH["Service mesh and gateways<br/>Istio · Linkerd · Envoy Gateway"]
        STOR["Storage<br/>Ceph · Longhorn · MinIO"]
        SEC["Secrets and identity<br/>Vault · ESO · SOPS · Zitadel"]
    end
    subgraph Data["Data and integration"]
        DB["Databases<br/>PostgreSQL · MySQL · CockroachDB"]
        MSG["Messaging<br/>Kafka · Redpanda · Pulsar · NATS · RabbitMQ"]
        API["APIs<br/>REST · GraphQL · gRPC · AsyncAPI"]
    end
    subgraph AI["AI"]
        AIP["AI platform engineering<br/>GPU scheduling · model serving"]
        INF["LLM inference<br/>speculative decoding"]
        AGT["AI agents<br/>agent runtimes · AI-PDLC · LLM fundamentals"]
    end
    OBS["Observability<br/>OpenTelemetry · Grafana LGTM · VictoriaMetrics · eBPF"]

    IAC -->|provisions| VIRT
    IAC -->|provisions| CLOUD
    VIRT --> K8S
    CLOUD --> K8S
    CICD -->|reconciles manifests into| K8S
    K8S --> Services
    Services --> Data
    K8S --> AIP
    AIP --> INF
    INF --> AGT
    OBS -.->|telemetry from every layer| Compute
    OBS -.-> Services
    OBS -.-> Data

Domains

Domain Topics Scope
AI Agents OpenClaw, Hermes Agent, Jev, AI-PDLC, LLM Fundamentals, LLM Wiki, Zero Data Retention Agent runtimes, AI-native delivery process, LLM internals, provider data retention
APIs Web Services REST, GraphQL, gRPC, WebSocket, AsyncAPI, BFF patterns, gateways
CI/CD Argo CD, Flux GitOps continuous delivery for Kubernetes
Coffee Brewing Extraction fundamentals, brew methods, recipes
Databases PostgreSQL, MySQL, CockroachDB Relational engines, replication, distributed SQL
IaC OpenTofu, Terraform, Pulumi Infrastructure as Code provisioning and state
Infrastructure Kubernetes, Docker, Proxmox VE, OpenStack, OpenNebula, AWS, GCP, Alibaba Cloud, Tencent Cloud, Multi-Cloud Governance, AI Platform Engineering Virtualization, containers, public clouds, landing zones, GPU platforms
LLM Inference DFlash 2 Speculative decoding and serving-side acceleration
Messaging Kafka, Redpanda, Pulsar, NATS, RabbitMQ Event streaming, message queues, pub/sub
Networking Cilium, Calico, Flannel Kubernetes CNI plugins, network policy, eBPF datapaths
Observability OpenTelemetry, OpenTelemetry Collector, Grafana, LGTM, VictoriaMetrics, Coroot, SigNoz, SkyWalking, OpenObserve, Monoscope, Observability 2.0, bpftrace, eBPF Developer Tutorial Telemetry pipelines, TSDBs, log and trace stores, APM, eBPF tracing
Secrets HashiCorp Vault, External Secrets Operator, SOPS, Zitadel Secrets management, encryption at rest in Git, identity
Service Mesh Istio, Linkerd, Envoy Gateway mTLS, traffic management, Gateway API
Storage Ceph, Longhorn, MinIO Distributed block, object, and file storage
Tools Catalogue One curated catalogue 625 tools in 31 categories: AI, infrastructure, security, and developer tools

All Topics

AI Agents

  • OpenClaw — self-hosted personal agent gateway with skills, MCP servers, and multi-channel routing
  • Hermes Agent — self-improving agent with reflection loops and persistent skills
  • Jev — "system one" decision model that returns typed, calibrated decisions instead of prose
  • AI-PDLC — AI-native product development lifecycle: governed agents in every phase, gated by evals
  • LLM Fundamentals — architecture, training, inference, quantization, and tuning
  • LLM Wiki — agent-maintained Markdown wikis as a stateful alternative to RAG
  • Zero Data Retention — provider-side retention controls for regulated LLM use

APIs

  • Web Services — REST, GraphQL, gRPC, WebSocket, and AsyncAPI design and operations

CI/CD

  • Argo CD — GitOps controller with a web UI and ApplicationSet patterns
  • Flux — composable GitOps toolkit of Kubernetes controllers

Coffee

  • Brewing — extraction fundamentals, grind, ratio, and method recipes

Databases

  • PostgreSQL — extensible open-source relational database
  • MySQL — widely deployed relational database with InnoDB
  • CockroachDB — distributed SQL for globally consistent transactions

IaC

  • OpenTofu — open-source (MPL-2.0) Terraform fork, CNCF Sandbox, with native state encryption
  • Terraform — HashiCorp IaC tool with the largest provider ecosystem
  • Pulumi — IaC in general-purpose programming languages

Infrastructure

  • Kubernetes — the standard container orchestrator
  • Docker — container engine, images, and Compose
  • Proxmox VE — Debian-based KVM and LXC virtualization with clustering, HA, ZFS, and Ceph
  • OpenStack — modular open-source cloud operating system
  • OpenNebula — lightweight cloud manager for private, hybrid, and edge clouds
  • AWS — multi-account landing zones, networking, and core services
  • GCP — resource hierarchy, Shared VPC, and landing-zone patterns
  • Alibaba Cloud — international regions, Resource Directory, and CEN networking
  • Tencent Cloud — international regions, organizations, and CCN networking
  • Multi-Cloud Governance — policy, cost, and identity across providers
  • AI Platform Engineering — GPU scheduling, distributed compute, and inference infrastructure

LLM Inference

  • DFlash 2 — block-diffusion speculative-decoding drafter with lossless output

Messaging

  • Apache Kafka — the standard distributed event-streaming log
  • Redpanda — Kafka-API-compatible C++ broker without the JVM
  • Apache Pulsar — separated compute and storage with built-in geo-replication
  • NATS — lightweight pub/sub with JetStream persistence
  • RabbitMQ — AMQP broker with quorum queues and streams

Networking

  • Cilium — eBPF-based CNI with network policy, observability, and service mesh features
  • Calico — CNI with BGP routing and network policy enforcement
  • Flannel — simple overlay CNI

Observability

  • OpenTelemetry — vendor-neutral telemetry APIs, SDKs, and managed-platform guidance
  • OpenTelemetry Collector — agent and gateway pipeline for traces, metrics, and logs
  • Grafana — visualization, alerting, and the Grafana ecosystem
  • LGTM Stack — Loki, Grafana, Tempo, Mimir, and Pyroscope as one stack
  • VictoriaMetrics — resource-efficient metrics, logs, and traces stores
  • Coroot — eBPF-based APM with automatic service maps
  • SigNoz — OpenTelemetry-native observability on ClickHouse
  • SkyWalking — Apache APM with agents, BanyanDB, and eBPF profiling
  • OpenObserve — logs, metrics, and traces on object storage
  • Monoscope — unified observability for self-hosted stacks
  • Observability 2.0 — wide events instead of three separate pillars
  • bpftrace — awk-like tracing language for Linux eBPF
  • eBPF Developer Tutorial — example-driven CO-RE eBPF course from eunomia-bpf

Secrets

  • HashiCorp Vault — secrets engine with dynamic credentials and leasing
  • External Secrets Operator — syncs external secret stores into Kubernetes
  • SOPS — encrypts files in place with KMS, age, and PGP
  • Zitadel — self-hosted identity with OIDC, SAML, and multi-tenancy

Service Mesh

  • Istio — Envoy-based mesh with sidecar and ambient modes
  • Linkerd — lightweight mesh with a Rust micro-proxy
  • Envoy Gateway — Kubernetes Gateway API implementation built on Envoy

Storage

  • Ceph — unified distributed block, object, and file storage
  • Longhorn — cloud-native distributed block storage for Kubernetes
  • MinIO — S3-compatible object storage; community edition archived in 2026, continued as commercial AIStor

Comparisons

Neutral, side-by-side evaluations. Each one links back to the topics it compares and ends with a decision guide.

Domain Comparison
AI Agents OpenClaw vs Hermes Agent vs Claude Code
AI Agents Jev vs AnyJev vs LLM structured outputs
APIs REST vs GraphQL vs gRPC
CI/CD GitOps: Argo CD vs Flux
Coffee Pour-over vs immersion vs espresso
Databases PostgreSQL vs MySQL vs CockroachDB
IaC Terraform vs OpenTofu vs Pulumi
Infrastructure Infrastructure platforms: Docker, Kubernetes, OpenStack, OpenNebula
Infrastructure Proxmox VE vs OpenNebula vs OpenStack
Infrastructure Public cloud landing zones: AWS vs GCP vs Alibaba Cloud vs Tencent Cloud
LLM Inference DFlash 2 vs EAGLE-3 vs MTP
Messaging Streaming brokers: Kafka vs Redpanda vs Pulsar
Messaging Messaging patterns: log stream vs queue vs pub/sub
Networking CNI: Cilium vs Calico vs Flannel
Observability Observability stacks
Observability LGTM stack vs Victoria stack
Observability eBPF Developer Tutorial vs libbpf-bootstrap vs bpftrace
Secrets Vault vs ESO vs SOPS
Secrets Identity providers: Zitadel vs Keycloak vs authentik vs Ory
Service Mesh Istio vs Linkerd vs Envoy Gateway
Storage Ceph vs MinIO vs Longhorn
Storage MinIO alternatives: Silo vs RustFS vs SeaweedFS vs Garage vs Ceph RGW

How a Topic Is Organized

Each topic follows the Diataxis framework, which groups pages by what the reader needs rather than by subject. A topic has an index.md hub and up to four mode-pure pages:

Page Reader question Contents
Index (hub) "What is it, and should I use it?" Summary, key facts and latest version, evaluation, map of the topic, sources, open questions
Tutorials "Teach me from zero." A tested path to a first success (only when real, tested steps exist)
How-to guides "How do I do this task?" Deployment, configuration, troubleshooting, commands and recipes
Reference "What is the exact fact?" Flags, data models, limits, pricing, benchmarks, checklists
Explanation "Why does it work this way?" Internals, design decisions, threat models, trade-offs

A topic can have fewer pages. No page exists without real content.

How to Navigate

  • By domain: start from the Domains table or the top navigation tabs.
  • Inside a topic: start at the hub. Newcomers read tutorials, then how-to guides, then reference, then explanation.
  • By decision: the Comparisons table above collects every neutral comparison.
  • By tool: the Tools Catalogue lists tools that do not warrant a full topic.
  • Across domains: landing zones, GitOps, eBPF, and multi-cloud governance span several domains. Follow the related-topic links at the end of each hub.

Trust and Freshness

  • Sources on every hub: each topic hub ends with a Sources section that links official documentation, repositories, and release notes. Specific numbers (benchmarks, prices, limits) cite their source inline.
  • Dated pages: every page carries last_checked. Version and pricing facts are stated with an "as of" date because they change faster than the prose around them.
  • Distilled, not copied: the pages hold distilled operational insight. Official documentation stays the source of truth.
  • Neutral comparisons: comparison pages contrast architectural trade-offs and do not pick a universal winner.
  • Honest unknowns: when a fact is not published or no source could be reached, the page says so with a reason and a date (for example "Not published: priced by quote (checked 2026-09-28)") rather than guessing. Unsupported figures are removed.