Speaker
Description
Modern enterprise cloud-native architectures require a clean separation between bare-metal hardware management and developer-facing application abstractions. This optimized framework presents a multi-layer approach that decouples low-level core services and hardware management from application orchestration.
At the Core Infrastructure Layer, the platform provides a high-performance bare-metal foundation, managing core cluster services, networking topology, and hardware lifecycle operations.
Directly above this foundation, the Application Abstraction Layer delivers a modular, modern developer environment structured across three key pillars:
- Gateway API & Service Mesh: Ingress and east-west L7 routing are delivered via kgateway and agentgateway under the Kubernetes Gateway API standard. Integrated with Istio Ambient Mesh, this setup provides a lightweight, sidecarless mTLS overlay (HBONE) to seamlessly connect workloads across clusters or machines.
- Unified Object & RWX Storage: The Container Object Storage Interface (COSI) standardizes declarative bucket provisioning across external S3 providers. For in-cluster needs, SeaweedFS serves a dual role—delivering S3 object storage while simultaneously offering high-throughput ReadWriteMany (RWX) persistent volumes for multi-pod workloads.
- Modular Internal Developer Platform (IDP): Rather than relying on monolithic frameworks, workload management adopts a GitOps-driven, Client-Side IDP Stack:
- Developer Experience: Backstage provides a centralized software catalog and debugging portal, while Score (
score.yaml) allows developers to declare workload requirements in simple language without writing raw Kubernetes YAML or managing cluster credentials. - Platform Guardrails: Crossplane functions under the hood to provision infrastructure via pre-approved blueprints, while FluxCD acts as the continuous deployment engine syncing state to live clusters.
This layered architecture grants developers self-service autonomy while enabling platform engineers to maintain full operational control, security, and governance at scale.