Every source behind this page, graded and dated. The shape of this wall is
itself a finding: nineteen decision records, eleven repository artefacts, three advisories, one
price list, and no blog post, talk or paper, because the network policy in this session
resolved code hosts and registries only.
Advisory
Gardener2025-05-19
GHSA-3hw7-qj9h-r835: bypassing project secret validation
A tenant project administrator could obtain control over the host clusters running their
control planes, in every installation regardless of cloud provider. Fixed on four
maintenance lines simultaneously.
Carry forwardIn a shared-host fleet, the tenancy boundary is the validation code on the path from tenant input to host-side objects.
GitHub Advisory Database record
Advisory
Gardener2025-05-19
GHSA-9x73-87fh-54w9: metadata injection on a project secret
The same escalation through a second path, this time in the host-cluster agent and
scoped to installations using the GCP provider extension. Identical severity vector, with
a changed scope.
Carry forwardTwo independent paths to the same escalation in one month is a signal about the class of defect, not about the two bugs.
GitHub Advisory Database record
Advisory
Gardener2025-09-25
GHSA-227x-7mh8-3cf6: code injection through provider configuration
Where Terraform drives infrastructure provisioning, tenant-supplied configuration could
be injected, again ending in control over the host cluster. Four provider extensions each
needed their own fixed version.
Carry forwardOut-of-tree extensions multiply the places a shared defect class must be fixed; put the sanitisation in the contract.
GitHub Advisory Database record
Decision record
Gardenerin v1.0.0, 2020-02
GEP-1: extensibility and extraction of cloud-specific knowledge
The founding decision: provider and operating-system behaviour leaves the core for separate controllers behind a contract, explicitly modelled on Kubernetes extracting its own cloud, container, storage and network specifics.
Carry forwardThe trigger to extract is not code size; it is that a provider change forces a rebuild of the whole platform.
GEP-1
Decision record
Gardenerin v1.0.0, 2020-02
GEP-8: one load balancer for every tenant API server
Routes every tenant API server in a host cluster through one gateway using server name indication, with the tenant's API server still terminating TLS. Prices the rejected option and names the quota limit behind it.
Carry forwardPer-tenant infrastructure objects are a quota problem before they are a cost problem, and quotas are harder to raise than budgets.
GEP-8
Decision record
Gardenerin v1.4.0, 2020-05
GEP-11: invert host-to-tenant connectivity with the upstream proxy
Documents the pre-2020 design, a tunnel needing a load balancer in every tenant cluster, and proposes adopting the upstream proxy instead. The gate it added was removed sixteen months later.
Carry forwardRead an adopted upstream component's exit date, not only its entry date, before copying the decision.
GEP-11
Decision record
Gardenerin v1.21.0, 2021-04
GEP-14: the tunnel is opened from the tenant side
Supersedes both the old tunnel and the adopted upstream proxy, and states the intention to delete the upstream code once validated. The non-goals are unusually honest: not a low latency path, no availability promise.
Carry forwardWriting down what a connectivity path is explicitly not for is what stops the next team from loading it with traffic it cannot carry.
GEP-14
Decision record
Gardenerin v1.14.0, 2020-12
GEP-13: host clusters get capacity and allocatable
Makes placing tenants onto hosts a scheduling problem using the fields a node publishes, because "seeds have a practical limit of how many shoots they can accommodate".
Carry forwardGive your host a declared capacity early; an unbounded packing ratio is discovered during an incident.
GEP-13
Decision record
Gardenerin v1.0.0, 2020-02
GEP-6: etcd gets an operator instead of a webhook
Replaces a mutating webhook that rewrote the etcd StatefulSet to inject provider details, because that "restricts the operations on etcd, such as scale-up and upgrade".
Carry forwardA webhook that edits another controller's output is a lifecycle liability; model the thing you are managing as its own resource.
GEP-6
Decision record
Gardenerin v1.41.0, 2022-02
GEP-18: rotating a tenant's certificate authority as an API call
Turns the most dangerous manual operation in a cluster into a staged, declarative one, which is the only form that survives being multiplied by a fleet.
Carry forwardAt fleet scale, a credential rotation runbook is not an operation; it has to become an API with states.
GEP-18
Decision record
Gardenerin v1.53.0, 2022-08
GEP-20: failure-domain tolerance as a per-tenant choice
States plainly that critical components including etcd ran with a single replica, "making them susceptible to both node failure as well as zone failure", and makes isolation a per-tenant selection.
Carry forwardUniform redundancy is the expensive default; make the failure domain a field on the tenant's resource.
GEP-20
Decision record
Gardenerin v1.76.0, 2023-07
GEP-23: delete the in-house autoscaler, use the upstream pair
The clearest cost document in the set: tenant API server compute is "a major part of Gardener's overall compute cost", requirements vary by two orders of magnitude, and the home-grown fused autoscaler had "severe algorithmic limitations".
Carry forwardFusing two upstream controllers into one is the invention most likely to be deleted; prefer composing them and measuring the fight.
GEP-23
Decision record
Gardenerin v1.93.0, 2024-04
GEP-26: federated tokens instead of tenant cloud keys
Replaces long-lived infrastructure credentials with short-lived tokens the cloud provider trusts through federation, naming the operational failure as well as the security one.
Carry forwardCredential expiry is an availability problem for a reconciler, which is the argument that gets rotation funded.
GEP-26
Decision record
Gardenerin v1.112.0, 2025-02
GEP-31: update nodes in place instead of replacing them
Rolling replacement assumes interchangeable machines; the proposal lists what breaks that, including long bare-metal boot, local disks, and machine types scarce during a capacity crunch, with GPUs named.
Carry forwardHardware scarcity is an architectural input: when you cannot get the replacement, immutable infrastructure stops being a free choice.
GEP-31
Decision record
Gardenerin v1.132.0, 2025-11
GEP-28: tenant clusters that host their own control plane
Adds the model the architecture was built to avoid, for air-gapped, edge and compliance cases, and so that Gardener can bootstrap the cluster it runs in, which the document calls "somewhat paradoxical" to have needed third-party tools for.
Carry forwardA platform that cannot create its own first instance has a bootstrap dependency it will eventually pay to remove.
GEP-28
Decision record
Gardenerin v1.132.0, 2025-11
GEP-35: replacing a forked log store
Records why the fleet sat on a fork of a relicensed log engine, what that cost, and why collection was standardised first so the storage engine became swappable.
Carry forwardStandardise the interface before the fork goes stale; the interface is what makes the second migration cheap.
GEP-35
Decision record
Gardenerin v1.41.0, 2022-02
GEP-17: recovering a tenant whose host cluster is unreachable
Ownership passes through a DNS text record that every participant checks, including the etcd backup sidecar, so the source host need not cooperate for split brain to be avoided. An earlier design using files in the backup bucket is recorded as no longer needed.
Carry forwardFor a stateful tenant, the recovery primitive is a forgery-resistant ownership record plus migration, not repair in place.
GEP-17
Decision record
Gardenerin v1.0.0, 2020-02
GEP-5: a version lifecycle with four classifications
Sets the policy for marking versions preview, supported, deprecated or expired, against an upstream that ships a minor roughly quarterly and maintains three.
Carry forwardPublish the lifecycle as data your tenants can query, or you will negotiate every upgrade individually.
GEP-5
Decision record
Gardenerin v1.137 era, 2026
GEP-32: the whole version lifecycle, scheduled in advance
Extends classifications with scheduled transitions, because moving versions through stages by hand "is cumbersome".
Carry forwardAn expiry date is the cheapest forcing function a platform has; make it declarative and let the calendar do the arguing.
GEP-32
Decision record
Gardenerchecked 2026-10-01
Why not the upstream Cluster API
A standing comparison: Cluster API harmonises getting to clusters, Gardener harmonises the clusters themselves. Lists the blockers, including provider-specific control plane resources and experimental managed-service providers.
Carry forwardDecide whether you are standardising the request or the result; the two need different APIs and only one gives you homogeneity.
Cluster API relation doc
Decision record
Gardenerchecked 2026-10-01
The enhancement process moved out of the code repository
Project-wide proposals now live in a dedicated repository under a technical steering committee, modelled on the upstream Kubernetes process. The pointer files left in the code repository date the move.
Carry forwardWhen decisions outlive the release they shipped in, move them out of the release artefact and give them their own lifecycle.
gardener/enhancements README
Source
Gardenerv1.152.0, 2026-09
README: kubeception, and the concept mapping
States the central decision (no dedicated master machines, control planes as workload, lower total cost of ownership) and publishes the concept mapping the rest of the architecture follows.
Carry forwardNaming your fleet concepts after the system you already operate is a design constraint, not documentation.
README at v1.152.0
Source
Gardenerv1.152.0, 2026-09
Architecture concept: one host cluster per infrastructure and region
The sizing statement ("hundreds or even thousands of clusters"), the placement rule, and the claim that single replicas are acceptable because the host cluster watches them.
Carry forwardIf the host restarts your component, availability becomes a scheduling property; write that assumption down so you notice when it stops holding.
architecture.md
Source
Gardenerv1.152.0, 2026-09
The feature gate table, which dates every mechanism
Sixty-nine documented features with the release each entered and left, including the adopted upstream tunnel (alpha in 1.6, removed in 1.27) and the in-house fused autoscaler (alpha since 0.31, removed in 1.109).
Carry forwardA dated gate table is an audit trail for architecture; keep one and your deprecations stop being folklore.
feature_gates.md
Source
Gardenerv1.152.0, 2026-09
Shipped agent configuration: capacity of 200 tenants
The default packing ratio is a line of YAML in the example component configuration, and the scheduler treats it as the Kubernetes scheduler treats a node's capacity.
Carry forwardThe most important number in a multi-tenant platform is usually a default in a config file; find it before you model cost.
20-componentconfig-gardenlet.yaml
Source
Gardenerv1.152.0, 2026-09
etcd concept: two stores per tenant, and a corruption check on start
Events are split away from the critical store so neither the hot path nor the backup bucket is flooded by low-value data; a sidecar handles snapshots, defragmentation and validation.
Carry forwardSplit a shared datastore by the value of the data, not only by size; the cheap half is what fills your backups.
etcd.md
Source
Gardenerv1.152.0, 2026-09
Istio, installed for exactly one job
Lists everything deliberately not deployed from the upstream default profile: telemetry, the egress gateway, the sidecar injector, the addons.
Carry forwardAdopting a large dependency is survivable if you write down the subset you use and refuse the rest in configuration.
istio.md
Source
Gardenerv1.152.0, 2026-09
Release process: every other week, three lines patchable, a named rota
Carries the cadence target, the hotfix window, and a rota naming a responsible engineer for each version through late 2026. Fourteen names rotate.
Carry forwardA fleet platform's release cadence has to be a rota with names in it, because the upstream it tracks will not slow down.
process.md
Source
Gardenerchecked 2026-10-01
dependency-watchdog: the prober and the weeder
A component built to stop cascading failure by "conservatively scaling down dependent configured resources", documenting the scenario, the two probes, the threshold and the meltdown-protection annotation.
Carry forwardShip the brake with the engine: automated recovery needs a documented, annotated way to be switched off while a fault lasts.
prober.md
Source
Gardenerv1.152.0, 2026-09
The notice file that dates the origin
"Copyright 2017-2019 SAP SE or an SAP affiliate company" still ships in the current release, alongside the record that the project was seeded from Kubernetes' sample API server.
Carry forwardCopyright and notice files are the cheapest provenance evidence in a repository, and they outlive the blog posts.
NOTICE.md
Source
Go module proxychecked 2026-10-01
759 released versions, each with a timestamp
The proxy lists every published version with its tag time, which dates this guide's timeline, and serves the full source archive of any version, which is how the 2020 and 2026 trees were compared.
Carry forwardFor any Go project, the module proxy is a dated archive of every release; it answers "when did this appear" without repository access.
proxy.golang.org version list
Source
pkg.go.devchecked 2026-10-01
Release dates, per year
The versions tab dates every release: 49 in 2020, then 70, 77, 79, 75, 92 and 79 so far in 2026.
Carry forwardRelease cadence over years is the most honest public signal of whether a platform is staffed.
Version history
Decision record
Gardenerin v1.132.0, 2025-11
GEP-34: standardise observability collection before swapping the store
Puts an OpenTelemetry collector in every tenant control plane because the stack "still relies on vendor specific format and protocols", and refuses a flag day: the migration is phased and the old components are not decommissioned immediately.
Carry forwardReplace the protocol first and the storage second; doing it in that order turns the next migration into a configuration change.
GEP-34
Vendor
Google Cloudchecked 2026-10-01
What a managed control plane costs per hour
"A flat cluster management fee of $0.10 per cluster per hour ... applies to all GKE clusters irrespective of the mode of operation, cluster size, or topology", plus $0.50 per hour more for clusters left on a version in extended support.
Carry forwardThe build-or-buy line for a fleet platform is a price per cluster hour; and note that the market charges for falling behind on versions.
GKE pricing