Platform & Infrastructure

The plumbing. Most of these exist so everything else can exist.

Every service in this group has its own page documenting how it runs: the values it is deployed with, and the trade-offs behind those choices.

Service What it does
Cert-manager Issues and renews the wildcard TLS certificate using Cloudflare DNS-01
Cloudflared Publishes services to the internet through an outbound-only tunnel: zero open inbound ports
External Secrets Operator Pulls secrets out of Vault and lays them down as native Kubernetes secrets
Istio The front door and the mesh: Gateway API edge plus ambient mTLS between workloads
Longhorn Replicates block storage across nodes, so a lost disk is not a lost volume
MetalLB Hands out real LAN addresses to services in L2 mode, no cloud load balancer required
Reflector Copies secrets and config maps into the namespaces that need them
Vault Keeps every credential the cluster uses in one audited place
Velero Whole-cluster backups: nightly manifests and PVC data (Kopia) to RustFS running on backup-raspi3, kept 30 days
Zot Private container registry that scans images for known vulnerabilities

← All service groups