Architecture & Zones
Three-zone security model for air-gapped deployments.
Three-zone security model for air-gapped deployments.
What openCenter blueprints are, how they compose, and how to choose the right one.
How users authenticate via Keycloak OIDC and receive Kubernetes RBAC permissions from group claims.
How kube-vip provides a virtual IP for Kubernetes API server high availability.
How Git commits become deployed Kubernetes resources through FluxCD reconciliation.
How operators access the Kubernetes cluster through Headlamp UI with OIDC authentication.
How external traffic reaches application pods through MetalLB, Gateway API, and HTTPRoutes.
Logical architecture of an openCenter cluster with Istio service mesh showing mTLS, traffic management, and observability integration.
How metrics, logs, and traces flow from pods through collection agents to Grafana dashboards.
How OLM installs and manages operators that provision stateful services like Kafka and Keycloak.
How Kyverno validates and mutates resources at admission time using ClusterPolicies.
How SOPS-encrypted secrets in Git are decrypted by FluxCD and delivered as Kubernetes Secrets.
How the openCenter repositories fit together to create the complete platform.
Hub-spoke architecture, management plane design, and agent-based cluster registration.
CRDs, topology options, platform dependencies, and lifecycle operations for openCenter Managed Kafka.
How platform teams and application teams collaborate through separated Git repositories and FluxCD reconciliation.
Logical architecture of a fully deployed openCenter Kubernetes cluster showing namespaces, services, and data flows.
Logical architecture of a fully deployed openCenter Kubernetes cluster on OpenStack showing namespaces, services, and data flows.
End-to-end system design from YAML config to running services.
Portal architecture — GitOps-backed request fulfillment, approval workflows, and integration with Keycloak RBAC.
Defense-in-depth security model across five layers.
Logical architecture of a fully deployed openCenter Kubernetes cluster on VMware vSphere showing namespaces, services, and data flows.