ac02c69612928faf06a63e87e02be2fa30da87b2
Add docs/troubleshooting.md covering the common failure modes the spec implies, grounded in the actual control-plane code paths: - Stuck Starting (PodNotReady / RconSecretUnavailable / RconNotReachable) and the deliberate absence of a Starting->Failed timeout. - Failed reachable only via InvalidSpec on a malformed spec.storage.size, plus the stale status.endpoint=direct caveat after a failure. - Routing via status.endpoint direct/fallback and the empty fallbackServer pitfall; wake 403/429/503 gate order. - online-mode coupling and Velocity's offline-mode routing refusal. - Cloudflare Access 401/403, nil-Keyfunc fail-closed, audience checks, the absence of an issuer check, and local-session gating. - Internal service-token (FELIS_SERVICE_TOKEN) rejection path. - link/claim error codes, Kaniko build denials (SA-by-absence RBAC, default-deny egress, internal-registry push gate), and the registry DNS contract. - Reaper backup-before-delete invariant and false-delete vectors. - Unimplemented idle auto-stop, permanently-zero players.online, the inert CRD fields, and the always-survives world PVC behaviour. Each item is labelled with its evidence grade (GO-TESTED / CODE-ONLY / INTEGRATION-ONLY / INERT) so operators know what is verified versus asserted.
Languages
Go
62.7%
TypeScript
22.5%
Shell
7.4%
Java
7.1%
Dockerfile
0.2%
Other
0.1%