Platform & Infrastructure
The plumbing. Most of these exist so everything else can exist.
Every service in this group has its own page documenting how it runs: the values it is deployed with, and the trade-offs behind those choices.
| Service | What it does |
|---|---|
| Cert-manager | Issues and renews the wildcard TLS certificate using Cloudflare DNS-01 |
| Cloudflared | Publishes services to the internet through an outbound-only tunnel: zero open inbound ports |
| External Secrets Operator | Pulls secrets out of Vault and lays them down as native Kubernetes secrets |
| Istio | The front door and the mesh: Gateway API edge plus ambient mTLS between workloads |
| Longhorn | Replicates block storage across nodes, so a lost disk is not a lost volume |
| MetalLB | Hands out real LAN addresses to services in L2 mode, no cloud load balancer required |
| Reflector | Copies secrets and config maps into the namespaces that need them |
| Vault | Keeps every credential the cluster uses in one audited place |
| Velero | Whole-cluster backups: nightly manifests and PVC data (Kopia) to RustFS running on backup-raspi3, kept 30 days |
| Zot | Private container registry that scans images for known vulnerabilities |