Technology Stack
Every component this platform runs, and what it is responsible for — not
which version. There is no version column below, on purpose: Renovate opens a
pull request for every upstream release, and CI renders the whole repository
against it before that pull request can merge. A version number copied into
this page would be stale the moment that job runs next, and nothing would
fail to tell us — a hand-maintained version table rots silently, a role does
not. Where the version actually lives — mise.toml, opentofu/config.tm.hcl,
a HelmRelease, an OCIRepository — is still worth knowing, so the “Pinned
in” column stays. For the why behind a choice, see
Decisions.
The table is generated from website/data/stack.yaml, which is also what
renders the strip on the landing page — one source, so the two cannot
disagree.
CLI tools
All pinned in mise.toml. Run mise install to get exactly these.
Decisions: ADR-0014 (OpenTofu over Terraform)
| Component | Role | |
|---|---|---|
| OpenTofu | Provisions every infrastructure stack — network, OpenBao, EKS, LLM platform | |
| Terramate | Orchestrates OpenTofu stacks — deploy order, drift detection, opt-in gating | |
| Flux CLI (+ schema plugin) | Validates the rendered manifest tree in CI; drives Flux day to day | |
| Helm | Templates every HelmRelease chart for the manifest-validation render bundle | |
| Kustomize | Builds each overlay for validation; the only Flux postRenderer kind used here | |
| Trivy | Scans OpenTofu config, the filesystem, and built images for vulnerabilities | |
Google Cloud SDKgcloud components install gke-gcloud-auth-plugin is a separate required step — kubectl cannot talk to GKE without it (see the comment in mise.toml). | Cluster credentials and teardown verification for the GCP stacks | |
| Go | Fetches the Hextra theme via Hugo Modules; no app code lives here | |
| Node.js | Runtime pin for markdownlint-cli, currently disabled in pre-commit | |
| golangci-lint | Pinned for Go linting; no Go source remains in this repository | |
| pre-commit | Runs formatting, Terraform, and secret-scanning hooks locally and in CI | |
| Hugo (extended)Required for this site — Hextra targets the extended build. | Builds this documentation site — Hextra needs the extended build | |
EKS bootstrap
What the cluster is built from, before Flux takes over.
Decisions: ADR-0008 (Flux), ADR-0009 (Cilium), ADR-0015 (Gateway API)
| Component | Role | Pinned in | |
|---|---|---|---|
| Kubernetes (EKS control plane) | The managed control plane Stage 1 creates before Cilium and Flux land | opentofu/aws/eks/init/variables.tf — kubernetes_version default, not overridden in variables.tfvars | |
| Cilium | eBPF datapath, kube-proxy replacement, NetworkPolicy and GatewayClass in one | opentofu/config.tm.hcl — cilium_version | |
| Flux Operator | Installs and manages the Flux Instance's controllers and their upgrades | opentofu/config.tm.hcl — flux_operator_version | |
| Flux Instance | The CR pointing Flux at each cluster's clusters/<cluster> path | opentofu/config.tm.hcl — flux_instance_version | |
| Gateway API CRDs | The Gateway/HTTPRoute schema Cilium and Envoy Gateway both implement | opentofu/aws/eks/configure/variables.tf — gateway_api_version default | |
GKE bootstrap
Same shape on GCP — the versions Cilium and Flux run are shared with EKS,
pinned once in opentofu/config.tm.hcl.
Decisions: ADR-0005 (GKE Standard, self-managed Cilium)
| Component | Role | Pinned in | |
|---|---|---|---|
| Kubernetes (GKE control plane) | GKE Standard with a private-only endpoint, created by Stage 1 before Cilium and Flux land | opentofu/gcp/gke/init/variables.tf — kubernetes_version default (latest tracks the release channel) | |
| Cilium | Same eBPF datapath as aws-0 — `cni.exclusive` displaces GKE's own CNI config | opentofu/config.tm.hcl — cilium_version, shared with EKS | |
| Flux Operator + Instance | Same Flux install as aws-0 — the Instance points at clusters/gcp-0 | opentofu/config.tm.hcl — flux_operator_version / flux_instance_version, shared with EKS | |
Infrastructure
Decisions: ADR-0001 (KCL for compositions), ADR-0012 (Crossplane/OpenTofu boundary)
| Component | Role | Pinned in | |
|---|---|---|---|
| Crossplane (controller) | Runs the XRDs and Compositions that back every xplane-* resource | infrastructure/base/crossplane/controller/helmrelease.yaml | |
Crossplane Configuration packageThe compositions themselves are built and released from Smana/crossplane-configuration, not from this repository. | Ships the App, SQLInstance, KVStore and InferenceService compositions as a package | infrastructure/base/crossplane/configuration-aws/configuration-packages.yaml | |
| Karpenter | Provisions spot nodes on demand — the general pool and the GPU pool | flux/sources/ocirepo-karpenter.yaml | |
| KEDA | Scales vLLM replicas on saturation, KV-cache, and queue-depth metrics | infrastructure/base/keda/helmrelease.yaml | |
| CloudNativePG (operator) | Provisions the managed Postgres every App's sqlInstance claim requests | infrastructure/base/cloudnative-pg/helmrelease.yaml | |
Atlas Operatorv0.7.11 does not support dir.remote for Git repositories; migrations use the GitOps/ConfigMap pattern instead. | Applies SQL migrations declaratively from Git via GitOps, not app code | flux/sources/ocirepo-atlas-operator.yaml | |
| AWS Load Balancer Controller | Provisions the NLBs behind this platform's internet-facing Gateways | infrastructure/base/aws-load-balancer-controller/helmrelease.yaml | |
| AWS EFS CSI driverChart 4.x ships driver v3.x, needed for S3 Files access points. | Mounts S3 Files (POSIX-over-S3) for shared LLM model weights | infrastructure/base/aws-efs-csi-driver/helmrelease.yaml | |
| External DNS | Watches HTTPRoutes and writes the matching Route 53 records | infrastructure/base/external-dns/helmrelease.yaml | |
| Envoy GatewayLLM platform, opt-in. | LLM platform's Gateway API implementation, delegating AI routing to its extension | flux/sources/ocirepo-envoy-gateway.yaml | |
| Envoy AI GatewayLLM platform, opt-in. | Authenticates and routes LLM requests directly to each model's vLLM Service | flux/sources/ocirepo-envoy-ai-gateway.yaml | |
| vLLM Semantic RouterLLM platform, opt-in. | Classifies prompts sent as model: MoM onto the right vLLM model | flux/sources/ocirepo-vllm-semantic-router.yaml | |
Security
Decisions: ADR-0002 (EKS Pod Identity), ADR-0011 (OpenBao), ADR-0013 (Tailscale), ADR-0016 (Kyverno)
| Component | Role | Pinned in | |
|---|---|---|---|
| OpenBao | Private PKI and secrets store — root of the platform's trust chain | opentofu/aws/openbao/cluster/variables.tf — openbao_version default, not overridden in variables.tfvars | |
| cert-manager | Issues and rotates leaf certificates from OpenBao's PKI and Let's Encrypt | security/base/cert-manager/helmrelease.yaml | |
| External Secrets Operator | Syncs every credential from AWS Secrets Manager — nothing hardcoded | security/base/external-secrets/helmrelease.yaml | |
| Kyverno | Enforces the Pod Security Standards as admission ClusterPolicies | security/base/kyverno/helmrelease-controller.yaml | |
| Tailscale Operator | Tags devices into the general and admin private-access gateways | security/base/tailscale-operator/helmrelease.yaml | |
| ZITADEL | SSO for the platform — EKS API auth and application OIDC login | security/base/zitadel/helmrelease.yaml | |
Observability
Decisions: ADR-0010 (VictoriaMetrics)
| Component | Role | Pinned in | |
|---|---|---|---|
| VictoriaMetrics k8s stackThe single-node variant pins the same 0.91.0 and is the one actually running. | Metrics storage, scraping, and alerting — the kube-prometheus-stack equivalent | observability/base/victoria-metrics-k8s-stack/helmrelease-vmcluster.yaml | |
| VictoriaLogs (cluster mode) | Dormant clustered variant — the single-mode release below is what runs | observability/base/victoria-logs/helmrelease-vlcluster.yaml | |
| VictoriaLogs (single mode) | Active log storage for the cluster — Vector ships every log here | observability/base/victoria-logs/helmrelease-vlsingle.yaml | |
| VictoriaTraces | Distributed-trace storage, pivoting from a span to its matching logs | observability/base/victoria-traces/helmrelease-vtsingle.yaml | |
| Grafana Operator | Manages dashboards and folders against the metrics stack's bundled Grafana | observability/base/grafana-operator/helmrelease.yaml | |
| metrics-server | Backs kubectl top and HPA resource metrics cluster-wide | observability/base/metrics-server/helmrelease.yaml | |
Data and tooling
| Component | Role | Pinned in | |
|---|---|---|---|
| Harbor | Self-hosted OCI/Helm registry, S3-backed; no in-repo pipeline publishes to it yet | tooling/base/harbor/helmrelease-harbor.yaml | |
| Headlamp | Kubernetes web UI for every tailnet member, via the general gateway | tooling/base/headlamp/helmrelease.yaml | |
| Homepage | Landing-page dashboard linking every service this platform runs | tooling/base/homepage/helmrelease.yaml | |
| GitHub Actions Runner ControllerOff by default. | Reconciles self-hosted GitHub Actions runners — off by default | tooling/base/gha-runners/controller-helmrelease.yaml | |
| GHA runner scale setOff by default. | Runner pool for plain Kubernetes jobs | tooling/base/gha-runners/default-scale-set-helmrelease.yaml | |
ValkeyProvisioned per tenant by the KVStore Crossplane composition in Smana/crossplane-configuration; the chart version tracks that repository’s release, not a pin here. | Per-tenant cache — kvStore claims for Harbor and this platform's demo apps | — | |
Managed cloud services
Not in the table above because there is nothing to install or upgrade: Route 53 (DNS), Elastic Load Balancing, IAM (via EKS Pod Identity), KMS, and S3 are AWS APIs this platform calls, not software this repository deploys and Renovate bumps. On GCP the same applies to Cloud DNS, GCS, Secret Manager, Workload Identity, and Cloud KMS.
A handful of components render a lettered tile rather than a logo. That is
deliberate: website/static/images/logos/LICENSES.md records every mark’s
source and terms, and explains why borrowing a neighbouring project’s logo —
Terraform’s for Terramate, the Kubernetes wheel for four different SIG
projects — was rejected as misleading rather than merely imperfect.