Skip to content
Technology Stack

Technology Stack

Every component this platform runs, and what it is responsible for — not which version. There is no version column below, on purpose: Renovate opens a pull request for every upstream release, and CI renders the whole repository against it before that pull request can merge. A version number copied into this page would be stale the moment that job runs next, and nothing would fail to tell us — a hand-maintained version table rots silently, a role does not. Where the version actually lives — mise.toml, opentofu/config.tm.hcl, a HelmRelease, an OCIRepository — is still worth knowing, so the “Pinned in” column stays. For the why behind a choice, see Decisions.

The table is generated from website/data/stack.yaml, which is also what renders the strip on the landing page — one source, so the two cannot disagree.

CLI tools

All pinned in mise.toml. Run mise install to get exactly these.

Decisions: ADR-0014 (OpenTofu over Terraform)

ComponentRole
OpenTofuProvisions every infrastructure stack — network, OpenBao, EKS, LLM platform
TerramateOrchestrates OpenTofu stacks — deploy order, drift detection, opt-in gating
Flux CLI (+ schema plugin)Validates the rendered manifest tree in CI; drives Flux day to day
HelmTemplates every HelmRelease chart for the manifest-validation render bundle
KustomizeBuilds each overlay for validation; the only Flux postRenderer kind used here
TrivyScans OpenTofu config, the filesystem, and built images for vulnerabilities
Google Cloud SDKgcloud components install gke-gcloud-auth-plugin is a separate required step — kubectl cannot talk to GKE without it (see the comment in mise.toml).Cluster credentials and teardown verification for the GCP stacks
GoFetches the Hextra theme via Hugo Modules; no app code lives here
Node.jsRuntime pin for markdownlint-cli, currently disabled in pre-commit
golangci-lintPinned for Go linting; no Go source remains in this repository
pre-commitRuns formatting, Terraform, and secret-scanning hooks locally and in CI
Hugo (extended)Required for this site — Hextra targets the extended build.Builds this documentation site — Hextra needs the extended build

EKS bootstrap

What the cluster is built from, before Flux takes over.

Decisions: ADR-0008 (Flux), ADR-0009 (Cilium), ADR-0015 (Gateway API)

ComponentRolePinned in
Kubernetes (EKS control plane)The managed control plane Stage 1 creates before Cilium and Flux landopentofu/aws/eks/init/variables.tf — kubernetes_version default, not overridden in variables.tfvars
CiliumeBPF datapath, kube-proxy replacement, NetworkPolicy and GatewayClass in oneopentofu/config.tm.hcl — cilium_version
Flux OperatorInstalls and manages the Flux Instance's controllers and their upgradesopentofu/config.tm.hcl — flux_operator_version
Flux InstanceThe CR pointing Flux at each cluster's clusters/<cluster> pathopentofu/config.tm.hcl — flux_instance_version
Gateway API CRDsThe Gateway/HTTPRoute schema Cilium and Envoy Gateway both implementopentofu/aws/eks/configure/variables.tf — gateway_api_version default

GKE bootstrap

Same shape on GCP — the versions Cilium and Flux run are shared with EKS, pinned once in opentofu/config.tm.hcl.

Decisions: ADR-0005 (GKE Standard, self-managed Cilium)

ComponentRolePinned in
Kubernetes (GKE control plane)GKE Standard with a private-only endpoint, created by Stage 1 before Cilium and Flux landopentofu/gcp/gke/init/variables.tf — kubernetes_version default (latest tracks the release channel)
CiliumSame eBPF datapath as aws-0 — `cni.exclusive` displaces GKE's own CNI configopentofu/config.tm.hcl — cilium_version, shared with EKS
Flux Operator + InstanceSame Flux install as aws-0 — the Instance points at clusters/gcp-0opentofu/config.tm.hcl — flux_operator_version / flux_instance_version, shared with EKS

Infrastructure

Decisions: ADR-0001 (KCL for compositions), ADR-0012 (Crossplane/OpenTofu boundary)

ComponentRolePinned in
Crossplane (controller)Runs the XRDs and Compositions that back every xplane-* resourceinfrastructure/base/crossplane/controller/helmrelease.yaml
Crossplane Configuration packageThe compositions themselves are built and released from Smana/crossplane-configuration, not from this repository.Ships the App, SQLInstance, KVStore and InferenceService compositions as a packageinfrastructure/base/crossplane/configuration-aws/configuration-packages.yaml
KarpenterProvisions spot nodes on demand — the general pool and the GPU poolflux/sources/ocirepo-karpenter.yaml
KEDAScales vLLM replicas on saturation, KV-cache, and queue-depth metricsinfrastructure/base/keda/helmrelease.yaml
CloudNativePG (operator)Provisions the managed Postgres every App's sqlInstance claim requestsinfrastructure/base/cloudnative-pg/helmrelease.yaml
Atlas Operatorv0.7.11 does not support dir.remote for Git repositories; migrations use the GitOps/ConfigMap pattern instead.Applies SQL migrations declaratively from Git via GitOps, not app codeflux/sources/ocirepo-atlas-operator.yaml
AWS Load Balancer ControllerProvisions the NLBs behind this platform's internet-facing Gatewaysinfrastructure/base/aws-load-balancer-controller/helmrelease.yaml
AWS EFS CSI driverChart 4.x ships driver v3.x, needed for S3 Files access points.Mounts S3 Files (POSIX-over-S3) for shared LLM model weightsinfrastructure/base/aws-efs-csi-driver/helmrelease.yaml
External DNSWatches HTTPRoutes and writes the matching Route 53 recordsinfrastructure/base/external-dns/helmrelease.yaml
Envoy GatewayLLM platform, opt-in.LLM platform's Gateway API implementation, delegating AI routing to its extensionflux/sources/ocirepo-envoy-gateway.yaml
Envoy AI GatewayLLM platform, opt-in.Authenticates and routes LLM requests directly to each model's vLLM Serviceflux/sources/ocirepo-envoy-ai-gateway.yaml
vLLM Semantic RouterLLM platform, opt-in.Classifies prompts sent as model: MoM onto the right vLLM modelflux/sources/ocirepo-vllm-semantic-router.yaml

Security

Decisions: ADR-0002 (EKS Pod Identity), ADR-0011 (OpenBao), ADR-0013 (Tailscale), ADR-0016 (Kyverno)

ComponentRolePinned in
OpenBaoPrivate PKI and secrets store — root of the platform's trust chainopentofu/aws/openbao/cluster/variables.tf — openbao_version default, not overridden in variables.tfvars
cert-managerIssues and rotates leaf certificates from OpenBao's PKI and Let's Encryptsecurity/base/cert-manager/helmrelease.yaml
External Secrets OperatorSyncs every credential from AWS Secrets Manager — nothing hardcodedsecurity/base/external-secrets/helmrelease.yaml
KyvernoEnforces the Pod Security Standards as admission ClusterPoliciessecurity/base/kyverno/helmrelease-controller.yaml
Tailscale OperatorTags devices into the general and admin private-access gatewayssecurity/base/tailscale-operator/helmrelease.yaml
ZITADELSSO for the platform — EKS API auth and application OIDC loginsecurity/base/zitadel/helmrelease.yaml

Observability

Decisions: ADR-0010 (VictoriaMetrics)

ComponentRolePinned in
VictoriaMetrics k8s stackThe single-node variant pins the same 0.91.0 and is the one actually running.Metrics storage, scraping, and alerting — the kube-prometheus-stack equivalentobservability/base/victoria-metrics-k8s-stack/helmrelease-vmcluster.yaml
VictoriaLogs (cluster mode)Dormant clustered variant — the single-mode release below is what runsobservability/base/victoria-logs/helmrelease-vlcluster.yaml
VictoriaLogs (single mode)Active log storage for the cluster — Vector ships every log hereobservability/base/victoria-logs/helmrelease-vlsingle.yaml
VictoriaTracesDistributed-trace storage, pivoting from a span to its matching logsobservability/base/victoria-traces/helmrelease-vtsingle.yaml
Grafana OperatorManages dashboards and folders against the metrics stack's bundled Grafanaobservability/base/grafana-operator/helmrelease.yaml
metrics-serverBacks kubectl top and HPA resource metrics cluster-wideobservability/base/metrics-server/helmrelease.yaml

Data and tooling

ComponentRolePinned in
HarborSelf-hosted OCI/Helm registry, S3-backed; no in-repo pipeline publishes to it yettooling/base/harbor/helmrelease-harbor.yaml
HeadlampKubernetes web UI for every tailnet member, via the general gatewaytooling/base/headlamp/helmrelease.yaml
HomepageLanding-page dashboard linking every service this platform runstooling/base/homepage/helmrelease.yaml
GitHub Actions Runner ControllerOff by default.Reconciles self-hosted GitHub Actions runners — off by defaulttooling/base/gha-runners/controller-helmrelease.yaml
GHA runner scale setOff by default.Runner pool for plain Kubernetes jobstooling/base/gha-runners/default-scale-set-helmrelease.yaml
ValkeyProvisioned per tenant by the KVStore Crossplane composition in Smana/crossplane-configuration; the chart version tracks that repository’s release, not a pin here.Per-tenant cache — kvStore claims for Harbor and this platform's demo apps—

Managed cloud services

Not in the table above because there is nothing to install or upgrade: Route 53 (DNS), Elastic Load Balancing, IAM (via EKS Pod Identity), KMS, and S3 are AWS APIs this platform calls, not software this repository deploys and Renovate bumps. On GCP the same applies to Cloud DNS, GCS, Secret Manager, Workload Identity, and Cloud KMS.

A handful of components render a lettered tile rather than a logo. That is deliberate: website/static/images/logos/LICENSES.md records every mark’s source and terms, and explains why borrowing a neighbouring project’s logo — Terraform’s for Terramate, the Kubernetes wheel for four different SIG projects — was rejected as misleading rather than merely imperfect.