Knowledge Base¶
What this is
A public, evergreen technical knowledge base: product and stack research, internals, operational recipes, and neutral comparisons across cloud-native infrastructure, data systems, observability, and AI. It covers 14 domains and 60 topics, plus a curated tools catalogue. Every page is organized by reader need (the Diataxis framework) and carries a last_checked date. The most recent full audit was on 2026-09-25.
Verify before production use
AI generated or assisted much of this content. Each topic links its primary sources. Check versions, commands, and prices against official documentation before you rely on them. See the AI Disclaimer.
Domain Map¶
The diagram shows how the domains stack up. Delivery tooling provisions and deploys the platform. Cluster services and data systems run on it. Observability watches every layer. The AI domains sit on top.
flowchart TB
subgraph Delivery["Delivery"]
IAC["IaC<br/>OpenTofu · Terraform · Pulumi"]
CICD["CI/CD (GitOps)<br/>Argo CD · Flux"]
end
subgraph Compute["Compute platform"]
VIRT["Virtualization and private cloud<br/>Proxmox VE · OpenNebula · OpenStack"]
CLOUD["Public cloud and governance<br/>AWS · GCP · Alibaba Cloud · Tencent Cloud"]
K8S["Containers<br/>Docker · Kubernetes"]
end
subgraph Services["Cluster services"]
NET["Networking (CNI)<br/>Cilium · Calico · Flannel"]
MESH["Service mesh and gateways<br/>Istio · Linkerd · Envoy Gateway"]
STOR["Storage<br/>Ceph · Longhorn · MinIO"]
SEC["Secrets and identity<br/>Vault · ESO · SOPS · Zitadel"]
end
subgraph Data["Data and integration"]
DB["Databases<br/>PostgreSQL · MySQL · CockroachDB"]
MSG["Messaging<br/>Kafka · Redpanda · Pulsar · NATS · RabbitMQ"]
API["APIs<br/>REST · GraphQL · gRPC · AsyncAPI"]
end
subgraph AI["AI"]
AIP["AI platform engineering<br/>GPU scheduling · model serving"]
INF["LLM inference<br/>speculative decoding"]
AGT["AI agents<br/>agent runtimes · AI-PDLC · LLM fundamentals"]
end
OBS["Observability<br/>OpenTelemetry · Grafana LGTM · VictoriaMetrics · eBPF"]
IAC -->|provisions| VIRT
IAC -->|provisions| CLOUD
VIRT --> K8S
CLOUD --> K8S
CICD -->|reconciles manifests into| K8S
K8S --> Services
Services --> Data
K8S --> AIP
AIP --> INF
INF --> AGT
OBS -.->|telemetry from every layer| Compute
OBS -.-> Services
OBS -.-> Data
Domains¶
| Domain | Topics | Scope |
|---|---|---|
| AI Agents | OpenClaw, Hermes Agent, Jev, AI-PDLC, LLM Fundamentals, LLM Wiki, Zero Data Retention | Agent runtimes, AI-native delivery process, LLM internals, provider data retention |
| APIs | Web Services | REST, GraphQL, gRPC, WebSocket, AsyncAPI, BFF patterns, gateways |
| CI/CD | Argo CD, Flux | GitOps continuous delivery for Kubernetes |
| Coffee | Brewing | Extraction fundamentals, brew methods, recipes |
| Databases | PostgreSQL, MySQL, CockroachDB | Relational engines, replication, distributed SQL |
| IaC | OpenTofu, Terraform, Pulumi | Infrastructure as Code provisioning and state |
| Infrastructure | Kubernetes, Docker, Proxmox VE, OpenStack, OpenNebula, AWS, GCP, Alibaba Cloud, Tencent Cloud, Multi-Cloud Governance, AI Platform Engineering | Virtualization, containers, public clouds, landing zones, GPU platforms |
| LLM Inference | DFlash 2 | Speculative decoding and serving-side acceleration |
| Messaging | Kafka, Redpanda, Pulsar, NATS, RabbitMQ | Event streaming, message queues, pub/sub |
| Networking | Cilium, Calico, Flannel | Kubernetes CNI plugins, network policy, eBPF datapaths |
| Observability | OpenTelemetry, OpenTelemetry Collector, Grafana, LGTM, VictoriaMetrics, Coroot, SigNoz, SkyWalking, OpenObserve, Monoscope, Observability 2.0, bpftrace, eBPF Developer Tutorial | Telemetry pipelines, TSDBs, log and trace stores, APM, eBPF tracing |
| Secrets | HashiCorp Vault, External Secrets Operator, SOPS, Zitadel | Secrets management, encryption at rest in Git, identity |
| Service Mesh | Istio, Linkerd, Envoy Gateway | mTLS, traffic management, Gateway API |
| Storage | Ceph, Longhorn, MinIO | Distributed block, object, and file storage |
| Tools Catalogue | One curated catalogue | 625 tools in 31 categories: AI, infrastructure, security, and developer tools |
All Topics¶
AI Agents¶
- OpenClaw — self-hosted personal agent gateway with skills, MCP servers, and multi-channel routing
- Hermes Agent — self-improving agent with reflection loops and persistent skills
- Jev — "system one" decision model that returns typed, calibrated decisions instead of prose
- AI-PDLC — AI-native product development lifecycle: governed agents in every phase, gated by evals
- LLM Fundamentals — architecture, training, inference, quantization, and tuning
- LLM Wiki — agent-maintained Markdown wikis as a stateful alternative to RAG
- Zero Data Retention — provider-side retention controls for regulated LLM use
APIs¶
- Web Services — REST, GraphQL, gRPC, WebSocket, and AsyncAPI design and operations
CI/CD¶
- Argo CD — GitOps controller with a web UI and ApplicationSet patterns
- Flux — composable GitOps toolkit of Kubernetes controllers
Coffee¶
- Brewing — extraction fundamentals, grind, ratio, and method recipes
Databases¶
- PostgreSQL — extensible open-source relational database
- MySQL — widely deployed relational database with InnoDB
- CockroachDB — distributed SQL for globally consistent transactions
IaC¶
- OpenTofu — open-source (MPL-2.0) Terraform fork, CNCF Sandbox, with native state encryption
- Terraform — HashiCorp IaC tool with the largest provider ecosystem
- Pulumi — IaC in general-purpose programming languages
Infrastructure¶
- Kubernetes — the standard container orchestrator
- Docker — container engine, images, and Compose
- Proxmox VE — Debian-based KVM and LXC virtualization with clustering, HA, ZFS, and Ceph
- OpenStack — modular open-source cloud operating system
- OpenNebula — lightweight cloud manager for private, hybrid, and edge clouds
- AWS — multi-account landing zones, networking, and core services
- GCP — resource hierarchy, Shared VPC, and landing-zone patterns
- Alibaba Cloud — international regions, Resource Directory, and CEN networking
- Tencent Cloud — international regions, organizations, and CCN networking
- Multi-Cloud Governance — policy, cost, and identity across providers
- AI Platform Engineering — GPU scheduling, distributed compute, and inference infrastructure
LLM Inference¶
- DFlash 2 — block-diffusion speculative-decoding drafter with lossless output
Messaging¶
- Apache Kafka — the standard distributed event-streaming log
- Redpanda — Kafka-API-compatible C++ broker without the JVM
- Apache Pulsar — separated compute and storage with built-in geo-replication
- NATS — lightweight pub/sub with JetStream persistence
- RabbitMQ — AMQP broker with quorum queues and streams
Networking¶
- Cilium — eBPF-based CNI with network policy, observability, and service mesh features
- Calico — CNI with BGP routing and network policy enforcement
- Flannel — simple overlay CNI
Observability¶
- OpenTelemetry — vendor-neutral telemetry APIs, SDKs, and managed-platform guidance
- OpenTelemetry Collector — agent and gateway pipeline for traces, metrics, and logs
- Grafana — visualization, alerting, and the Grafana ecosystem
- LGTM Stack — Loki, Grafana, Tempo, Mimir, and Pyroscope as one stack
- VictoriaMetrics — resource-efficient metrics, logs, and traces stores
- Coroot — eBPF-based APM with automatic service maps
- SigNoz — OpenTelemetry-native observability on ClickHouse
- SkyWalking — Apache APM with agents, BanyanDB, and eBPF profiling
- OpenObserve — logs, metrics, and traces on object storage
- Monoscope — unified observability for self-hosted stacks
- Observability 2.0 — wide events instead of three separate pillars
- bpftrace — awk-like tracing language for Linux eBPF
- eBPF Developer Tutorial — example-driven CO-RE eBPF course from eunomia-bpf
Secrets¶
- HashiCorp Vault — secrets engine with dynamic credentials and leasing
- External Secrets Operator — syncs external secret stores into Kubernetes
- SOPS — encrypts files in place with KMS, age, and PGP
- Zitadel — self-hosted identity with OIDC, SAML, and multi-tenancy
Service Mesh¶
- Istio — Envoy-based mesh with sidecar and ambient modes
- Linkerd — lightweight mesh with a Rust micro-proxy
- Envoy Gateway — Kubernetes Gateway API implementation built on Envoy
Storage¶
- Ceph — unified distributed block, object, and file storage
- Longhorn — cloud-native distributed block storage for Kubernetes
- MinIO — S3-compatible object storage; community edition archived in 2026, continued as commercial AIStor
Comparisons¶
Neutral, side-by-side evaluations. Each one links back to the topics it compares and ends with a decision guide.
How a Topic Is Organized¶
Each topic follows the Diataxis framework, which groups pages by what the reader needs rather than by subject. A topic has an index.md hub and up to four mode-pure pages:
| Page | Reader question | Contents |
|---|---|---|
| Index (hub) | "What is it, and should I use it?" | Summary, key facts and latest version, evaluation, map of the topic, sources, open questions |
| Tutorials | "Teach me from zero." | A tested path to a first success (only when real, tested steps exist) |
| How-to guides | "How do I do this task?" | Deployment, configuration, troubleshooting, commands and recipes |
| Reference | "What is the exact fact?" | Flags, data models, limits, pricing, benchmarks, checklists |
| Explanation | "Why does it work this way?" | Internals, design decisions, threat models, trade-offs |
A topic can have fewer pages. No page exists without real content.
How to Navigate¶
- By domain: start from the Domains table or the top navigation tabs.
- Inside a topic: start at the hub. Newcomers read tutorials, then how-to guides, then reference, then explanation.
- By decision: the Comparisons table above collects every neutral comparison.
- By tool: the Tools Catalogue lists tools that do not warrant a full topic.
- Across domains: landing zones, GitOps, eBPF, and multi-cloud governance span several domains. Follow the related-topic links at the end of each hub.
Trust and Freshness¶
- Sources on every hub: each topic hub ends with a Sources section that links official documentation, repositories, and release notes. Specific numbers (benchmarks, prices, limits) cite their source inline.
- Dated pages: every page carries
last_checked. Version and pricing facts are stated with an "as of" date because they change faster than the prose around them. - Distilled, not copied: the pages hold distilled operational insight. Official documentation stays the source of truth.
- Neutral comparisons: comparison pages contrast architectural trade-offs and do not pick a universal winner.
- Honest unknowns: when a fact is not published or no source could be reached, the page says so with a reason and a date (for example "Not published: priced by quote (checked 2026-09-28)") rather than guessing. Unsupported figures are removed.