11. Risks and Technical Debts
| ID | Risk |
|---|---|
The team is too small |
|
The cluster is operated by a very small team ([CO-001 Small Team ], [MT02 Small Team Operability] . Operational knowledge (bootstrap procedure, Keycloak realm configuration, Bitwarden layout) is concentrated in very few people. Mitigation: keep as much as possible in this repository and in |
|
Hetzner Cloud Controller Manager was not GitOps-managed |
|
(erledigt) |
|
cnpg-system Application manifests reference a non-existent path |
|
(erledigt) |
|
Grafana ingress values requested the nginx ingress class |
|
(erledigt) |
|
Single infrastructure provider dependency |
|
The entire cluster — compute, network, load balancer, block storage, and (via Hetzner Robot/hidrive) part of the backup target — runs on Hetzner Cloud ([CT-001 Infrastructure Provider ]). An extended Hetzner outage or account issue affects availability ([RE01 24/7 Availability] with no fallback provider. |
|
Bitwarden Secrets Manager is the only secret backend |
|
Every runtime secret in the cluster (database credentials, TLS private keys stored via |