ArchitectureΒΆ
| Area | How it works | Details |
|---|---|---|
| GitOps | One shared base per component, one overlay per cluster | GitOps |
| Networking | Outbound-only ingress through Cloudflare Tunnel | Networking |
| Identity | Dashboards log in with GitHub through Dex | Identity |
| Secrets | Encrypted in Git, decrypted inside the cluster | Secrets |
| Delivery | CI on ephemeral runners, promotion generated from each application's contract | Delivery |
| Observability | Metrics, logs, and traces in Grafana | Observability |
| Recovery | Velero for resources and volumes, StackGres for PostgreSQL | Recovery |
What each cluster runs
| Component group | Local | Production |
|---|---|---|
| Argo CD, cert-manager, networking, secrets operator | ||
| Kargo, Argo Rollouts, ARC runners | ||
| Observability | ||
| Velero, StackGres | ||
| Reloader |
A component runs in a cluster when it has a directory under live/<cluster>/kubernetes/.
