Skip to content

0002: Keeper is generic; no deployment-specific values in code

Date: 2026-10-07 · Status: accepted

Context

Keeper is first deployed for Republic, but it must be usable by other projects and organizations, and possibly be published as open source. The design's examples use Republic values (domains, zone id, bucket, registry, org labels).

Decision

  • No organization-specific value is compiled in or used as a default: console hostname, sandbox hostname pattern, DNS zone and zone id, Cloudflare account and Access team domain/audience, S3 endpoint/region/bucket/prefix, registry, image repository, org/project/env label values, time zones, role mappings. They come only from CRDs, Helm values, flags or env, and are required where no neutral default exists.
  • Neutral defaults are allowed when they are not tied to anyone (e.g. watchdog 60 s, 8 x 16 MiB parts, sandbox TTL 24 h, retention presets shipped as optional example policies).
  • Chart values.yaml, README and examples use example.com-style placeholders; Republic's real values live only in republic-gitops.
  • The API group keeper.republic.global and the Go module path github.com/republic-global/keeper stay as decided: they are the project's identity (like cert-manager.io), not deployment configuration.
  • The sandbox exposure provider (Cloudflare Tunnel today) and the console auth provider (Cloudflare Access today) sit behind small interfaces so another provider, or none (in-cluster only), can be configured.

Consequences

A unit test greps the non-test Go sources and chart templates for known deployment values (republic.global, the-republic.net, telnyxcloudstorage.com, azurecr.io, the zone id) and fails if any appear.