Skip to content

Setup operating model

Synced from lytebase-infra/setup/docs/OPERATING_MODEL.md. Run pnpm sync:docs to refresh this snapshot.

Use one runtime key everywhere:

  • k3s
  • swarm
  • lytebase-cli owns plan/apply/reconcile/destroy automation.
  • setup/ops/ is for human runbooks and break-glass procedures only.

Generated files belong outside committed setup/ content. Do not assume one fixed repo-local generated-state path as part of the supported operating model.

Examples include generated kubeconfig material, Terraform state, inventories, plans, and execution artifacts.

Use JSON Schema only (*.schema.json) for setup and environment tooling.

  • Encryption standard: sops + age
  • Commit only encrypted secret material (*.enc.yaml) when needed
  • Keep plaintext secrets out of git