Skip to content

Evidence and authority model

Volatile fact format

Every runtime fact must identify:

Field Meaning
Value Observed value, without secrets
Lifecycle Current, transitional, retired, or historical
Last verified UTC date
Evidence Read-only command, workflow, config path, or owner confirmation
Confidence Verified, user-confirmed, inferred, historical, or unverified
Canonical page The one page responsible for the fact

Authority order

  1. Read-only live state from the component that owns the value.
  2. Active deployment source and workflow.
  3. Current canonical handbook page.
  4. User-confirmed context.
  5. Redacted exports and dated recovery captures.
  6. Historical prose and generated site/.

A newer timestamp does not automatically make prose authoritative. Resolve conflicts against the owning system and record the observation date.

Canonical ownership

Fact family Canonical page
Hosts, VMs, LXCs, storage Current inventory
Networks, addresses, DNS, ingress, routes Network reference
Services, versions/images, ports, lifecycle, priority Service catalog
Runtime dependency and recovery order Dependency map
Documentation build and serve path Publishing architecture
Historical transitions History
Rationale ADRs

2026-07-17 evidence summary

  • Proxmox: pveversion, qm list/config, pct list/config, pvesm status.
  • CT 101: rootless Podman version, containers, user units, publication Quadlet, runner config allow-list, artifact metadata, HTTP backend.
  • CT 102: service state, listeners, selected DNS queries.
  • CT 103: Caddy version/state/listeners, selected route lines, backend and SNI checks.
  • VPS: Headscale version, node list, route list, rootless Podman containers.
  • OPNsense: SSH reached the host but authentication failed; QEMU guest agent reported not running. Runtime remains last verified 2026-07-02.

No live configuration was changed during this evidence capture.