docs/troubleshooting.md
0 → 100644
+544
−0
Loading
Add docs/troubleshooting.md covering the common failure modes the spec implies, grounded in the actual control-plane code paths: - Stuck Starting (PodNotReady / RconSecretUnavailable / RconNotReachable) and the deliberate absence of a Starting->Failed timeout. - Failed reachable only via InvalidSpec on a malformed spec.storage.size, plus the stale status.endpoint=direct caveat after a failure. - Routing via status.endpoint direct/fallback and the empty fallbackServer pitfall; wake 403/429/503 gate order. - online-mode coupling and Velocity's offline-mode routing refusal. - Cloudflare Access 401/403, nil-Keyfunc fail-closed, audience checks, the absence of an issuer check, and local-session gating. - Internal service-token (FELIS_SERVICE_TOKEN) rejection path. - link/claim error codes, Kaniko build denials (SA-by-absence RBAC, default-deny egress, internal-registry push gate), and the registry DNS contract. - Reaper backup-before-delete invariant and false-delete vectors. - Unimplemented idle auto-stop, permanently-zero players.online, the inert CRD fields, and the always-survives world PVC behaviour. Each item is labelled with its evidence grade (GO-TESTED / CODE-ONLY / INTEGRATION-ONLY / INERT) so operators know what is verified versus asserted.