Skip to content

ArchitectureΒΆ

Production architecture

Area How it works Details
GitOps One shared base per component, one overlay per cluster GitOps
Networking Outbound-only ingress through Cloudflare Tunnel Networking
Identity Dashboards log in with GitHub through Dex Identity
Secrets Encrypted in Git, decrypted inside the cluster Secrets
Delivery CI on ephemeral runners, promotion generated from each application's contract Delivery
Observability Metrics, logs, and traces in Grafana Observability
Recovery Velero for resources and volumes, StackGres for PostgreSQL Recovery

What each cluster runs

Component group Local Production
Argo CD, cert-manager, networking, secrets operator
Kargo, Argo Rollouts, ARC runners
Observability
Velero, StackGres
Reloader

A component runs in a cluster when it has a directory under live/<cluster>/kubernetes/.