Skip to content

Architecture Overview

The Local Developer Platform is built on GitOps principles, using ArgoCD to manage all platform components declaratively.

High-Level Architecture

graph TB
    subgraph "Developer Interaction"
        DEV[Developer]
        GIT[Git Repository]
    end

    subgraph "Platform Layer"
        ARGO[ArgoCD]
        BACK[Backstage]
    end

    subgraph "Core Infrastructure"
        TRAEFIK[Traefik Ingress]
        CERT[Cert-Manager]
        ESO[External Secrets]
    end

    subgraph "Authentication"
        AUTH[Authelia]
        LDAP[LLDAP]
    end

    subgraph "Storage"
        PG[CloudNativePG]
    end

    subgraph "Version Control"
        GITEA[Gitea]
    end

    DEV --> GIT
    GIT --> ARGO
    DEV --> BACK
    DEV --> GITEA

    ARGO --> TRAEFIK
    ARGO --> CERT
    ARGO --> ESO
    ARGO --> AUTH
    ARGO --> PG
    ARGO --> GITEA
    ARGO --> BACK

    AUTH --> LDAP
    TRAEFIK --> CERT
    GITEA --> PG
    BACK --> PG
    BACK --> GITEA

Component Categories

Core Infrastructure

Component Purpose
Traefik Ingress controller and reverse proxy
Cert-Manager Automatic TLS certificate management
External Secrets Secure secret management and synchronization
Trust Manager Certificate trust bundle distribution

Authentication

Component Purpose
Authelia Single Sign-On (SSO) and OIDC provider
LLDAP Lightweight LDAP directory service

Orchestration

Component Purpose
ArgoCD GitOps continuous delivery
Crossplane Infrastructure as Code
Kargo Progressive delivery and promotion

Developer Experience

Component Purpose
Backstage Developer portal and service catalog
Gitea Git repository hosting

Storage

Component Purpose
CloudNativePG PostgreSQL operator for high availability

GitOps Flow

sequenceDiagram
    participant Dev as Developer
    participant Git as Git Repository
    participant ArgoCD as ArgoCD
    participant K8s as Kubernetes

    Dev->>Git: Push changes
    Git->>ArgoCD: Webhook notification
    ArgoCD->>Git: Pull latest state
    ArgoCD->>ArgoCD: Compare desired vs actual
    ArgoCD->>K8s: Apply changes
    K8s->>ArgoCD: Report status
    ArgoCD->>Dev: Sync status (UI/CLI)

Namespace Organization

The platform organizes applications into namespaces by category:

Namespace Purpose Components
core Core infrastructure Traefik, Cert-Manager, External Secrets
auth Authentication services Authelia, LLDAP
orchestration GitOps and delivery ArgoCD, Crossplane, Kargo
portal Developer portal Backstage
storage Data persistence CloudNativePG
vcs Version control Gitea

Secret Management

Secrets flow through External Secrets Operator:

graph LR
    GEN[Password Generator] --> ESO[External Secrets]
    ESO --> CSS[ClusterSecretStore]
    CSS --> NS1[Namespace A Secret]
    CSS --> NS2[Namespace B Secret]
  • Secrets are generated or fetched by External Secrets
  • ClusterSecretStore enables cross-namespace secret sharing
  • Namespace-scoped RBAC ensures least-privilege access

Next Steps