Serguey Asael Shinder: A default is a decision somebody else made for you
Three unrelated pieces of news from the past week share a cause.
Trigger.dev's security advisories describe self-hosted installations running with secrets copied from the project's public example file, because the variables to override them were not documented. Caddy 2.11.6 introduced default idle timeouts that cut server-sent-event streams after exactly 60 seconds. And JDK 27 makes G1 the garbage collector everywhere, including small containers that used to get Serial.
The JDK change is deliberate and probably right for most workloads. The other two were mistakes. But they all work the same way: a value that nobody on your team chose starts deciding how your system behaves.
A default is not neutral. It is a guess, made by someone who has never seen your system, about what most systems need. Usually the guess is good, which is exactly why nobody checks it. When it is wrong for you, the failure does not look like a configuration problem. A stream that dies after a minute looks like a client bug. A container that pauses differently looks like a load problem. A deployment with example secrets looks fine until someone else reads the same example.

Defaults change under you. The settings you wrote down stay put. The ones you did not write down move with every upgrade, because the default belongs to the upstream project, and the release notes are the only place the change is announced. Caddy's timeouts and the JDK's collector both arrived as an upgrade, not as a change anyone on the application team made.
What to do about it. Three habits, all cheap:
- Write down the values that matter, even if they equal the default today. An explicit
-XX:+UseG1GCor an explicit timeout is a decision with a name and a date; the implicit one is not. - Read release notes for the word "default". It is the one change that reaches you without a code change on your side.
- Diff your secrets against the examples. Any value in your deployment that also appears in a public example file is not a secret.
None of this means distrusting defaults. It means knowing which of your settings are decisions and which are inheritance. You will keep most of the inheritance. You just want to have looked at it once.