Context
Every piece of data on the site is published deliberately through a reviewed pull request. Nothing is written at runtime: no comments, no forms, no accounts.
Options
- PostgreSQL or Redis. These need migrations, backups, access control and monitoring, and add a recovery procedure, all for data that never changes at runtime.
- An immutable snapshot baked into the release artifacts.
Decision
No database. Each release's images contain the snapshot, and the image tag is the git commit. Recovering from failure means redeploying a known image. There is no state to back up beyond the Git repository and the TLS certificates.
Consequences
- Rollback is exact: the previous image carries the previous evidence.
- If a runtime write path is ever justified, it gets its own ADR covering migrations, backups and access control.