Operational runbooks
Use the narrowest runbook that matches the task.
| Task | Runbook |
|---|---|
| Validate hosts, guests, services, DNS, ingress, and Headscale | Infrastructure validation |
| Add or update pages, navigation, diagrams, and screenshots | Documentation maintenance |
| Diagnose a build, runner, stale artifact, or static backend | Documentation publishing |
Diagnose Caddy 403, 404, 502, TLS, DNS, or backend failures |
Caddy and ingress |
| Publish a static website through the standard backend pattern | Static website publishing |
| Back up or restore source and publishing artifacts | Backup and recovery |
| Handle exports, credentials, and safe evidence | Security and secrets |
| Review Git changes or retire a system | Change and retirement |
| Operate a specific service | Service catalog |
Every live change requires separate authorization, a current backup, a defined impact window, validation, and rollback. These pages default to read-only diagnosis.