Twelve-factor anti-patterns
Classic violations — snowflake servers, env-specific builds, and sticky state disguised as cloud-native.
Snowflake servers
Hand-configured VMs with unique packages. Instead: immutable artifacts and IaC.
Env-specific binaries
“Prod build” with different compile flags and untested paths. Instead: one artifact, config at release/run.
Config in code or images
API keys in source or layers. Instead: environment/secret stores; rotate.
Sticky sessions as architecture
In-memory user state required for correctness. Instead: external session/store; redesign affinities as optimization only.
SSH as the control plane
Untracked scripts on prod boxes. Instead: versioned Jobs/pipelines.
Silent log files
Disk fills; nobody tails. Instead: stream logs to the platform.
Fake parity
Totally different datastores and auth in dev. Instead: same types of backing services; testcontainers or shared ephemeral envs.
Twelve-factor is violated most often by teams who “already run on Kubernetes” and stopped checking the basics.