Service Mesh Platform · View 22 of 31 · 6 · Operations
Decisions
- A room is the on-premise availability zone: separate power, cooling and top-of-rack switching. istiod, SPIRE server, OpenBao voters and gateway pods spread across three rooms with pod anti-affinity.
- Every site runs its own Argo CD, OpenBao and telemetry stores. A site cut off from the other two still changes, issues and observes for itself.
- Forgejo has one writable primary. The other sites hold read-only mirrors, so Argo CD in any site keeps applying the last merged intent during a site partition.
Targets
- Loss of one room: no loss of mesh function. Control plane ≥ 99.9% monthly; mesh-attributable data path ≥ 99.99%.
Risks
- If site A is lost, intent changes pause until a mirror is promoted to primary. That is a runbook step with an RTO of 15 minutes, not an automatic failover, because two writable Git primaries are worse than a short pause.