Craft

Fieldcraft: own the escalation.

The drills show investigations; these guides teach the underlying craft: collecting evidence that survives scrutiny, turning "sometimes at one site" into a reproduction anyone can run, writing the handoff package that needs zero follow up questions, and running a live incident without losing the room.

The escalation pipeline these guides cover intake evidence repro resolved handoff package done to eng, zero Qs
Seven fields, seven round trips prevented summary prevents: what am I looking at? version matrix prevents: which build, which OS? reproduction prevents: can you make it happen again? log evidence prevents: send me the actual logs impact scope prevents: how urgent is this really? ruled out list prevents: did you check the obvious thing? proposed owner prevents: why is this in my queue? a missing field is not a formatting problem, it is a day of latency
  1. 01 Evidence collection How to gather logs, bug report markers, version facts, and point in time snapshots from a tailnet incident before you commit to any theory.
  2. 02 Reproduction construction How to turn a vague field report into a minimal, runnable reproduction using containers, iptables, and tc, with state discipline that keeps every run clean.
  3. 03 The handoff package The canonical template for escalating a confirmed product issue to engineering so that zero follow up questions are needed.
  4. 04 Live incident craft How to run a live high pressure incident call as the technical owner, from the first five minutes through the theory board, the async handoff, and the write up.