Secrets & DNS
Two things are deliberately managed by hand rather than through automated tooling: secret material and DNS. Both share the same reasoning — a single-operator setup with infrequent, low-volume changes doesn’t justify standing up new machinery just to automate something that rarely happens.
Secrets
Nothing here uses a secrets-management operator. Credentials are kept in one local, never-committed file and applied to the cluster directly when needed. A pre-commit safety check backstops this, scanning for anything that looks like a secret before it can ever be committed by accident.
DNS
DNS changes are made directly against the domain provider, not through infrastructure-as-code. There’s no wildcard record — every subdomain is added individually, which means DNS has to exist before a new app’s route can get a valid certificate; adding a new app is a two-step sequence, DNS first, then the route.