> One is more hypothetical: the microservices had gotten to the point that no one knew how to start the system if all services are down,
this is a good one and have been thinking about this myself. Even with smallish projects that might have 10s of container based applications / services. In my case I end up with what is essentially a 3 tier architecture with each tier being a group of containers/machines with their own rules for startup/shutdown.