GitOps overlays for the DramisInfo platform clusters, plus the NATS cross-cluster load-test stack and a few operator scripts that go with them.
Per-cluster configuration surface for the platform-core Argo CD Application. The repo pins the upstream Helm chart, splits a single base/ manifest into per-cluster Kustomize overlays, and ships the docker-compose stack used to drive cross-cluster NATS load tests. Argo CD is the only deployment path — nothing here is applied by hand.
platform-tools owns three things:
- The base
platform-coreArgo CDApplication(base/platform-core.yaml), pulling theplatform-corechart fromDramisInfo/platform-helmattargetRevision: HEAD, with automated prune + selfHeal andCreateNamespace=true. - One Kustomize overlay per target cluster under
overlays/. Each overlay inherits../../baseand applies a strategic-merge patch onspec.source.helm.valuesObjectto setclusterName, toggle monitoring / hermesSRE, and configure the NATS gateway. - A workstation-driven NATS load-test stack (
nats-load-test/+nats-cluster-test.sh) that publishes fromcace-1-devand subscribes oncace-2-devto verify cross-cluster message delivery and latency.
kube.sh and ansible/playbook.yml round it out as shortcuts for pulling a kubeconfig and refreshing every Argo CD Application across the four k3s masters.
flowchart LR
helm[DramisInfo/platform-helm<br/>chart: platform-core @ HEAD]
base[base/platform-core.yaml<br/>Argo CD Application]
ov1[overlay az-1]
ov2[overlay az-2]
ov3[overlay cace-1-dev]
ov4[overlay cace-2-dev]
argo[(Argo CD<br/>in each cluster)]
nodes[k3s masters<br/>192.168.20.10/20/30/90]
load[nats-load-test<br/>docker-compose]
pub[(NATS nats.cace-1-dev)]
sub[(NATS nats.cace-2-dev)]
helm --> base
base --> ov1
base --> ov2
base --> ov3
base --> ov4
ov1 --> argo
ov2 --> argo
ov3 --> argo
ov4 --> argo
argo --> nodes
load --> pub
load --> sub
Argo CD in each cluster reconciles the rendered Application against live state; the workstation-side load-test stack talks to the clusters over their public NATS hostnames and is intentionally outside the Argo CD control loop.
base/— single source of truth for theplatform-coreArgo CDApplication(chart pin, sync policy, finalizer,sync-wave: "-100").overlays/— one Kustomize overlay per cluster:az-1/,az-2/,cace-1-dev/,cace-2-dev/.cace-1-dev/also hoststeams/team-alpha/(AppProject + ApplicationSet + Namespace template) andcrossplane-identity.yaml.nats-load-test/— docker-compose stack: Fastifypublisher, NATSsubscriber, k6 load generator. Each subproject ships its ownpackage.jsonandDockerfile.nats-cluster-test.sh— wrapper around the compose file withbuild | test | status | interactive | downand env overrides (VUS,DURATION,PUBLISHER_REPLICAS,SUBSCRIBER_REPLICAS).kube.sh—scps the k3s kubeconfig from192.168.20.10and merges it as contextk3s-dev1into~/.kube/config.ansible/—inventory.inilists the four k3s masters;playbook.ymlrefreshes every Argo CDApplicationviakubectl patch..github/agents/,.github/prompts/— repo-local Copilot-style agent specs (component-manager,dashboard) and themanage-componentprompt, all scoped tocace-1-dev.AGENTS.md— agent-facing source of truth for layout, conventions, and "what NOT to do".
Prerequisites: kubectl, kustomize, docker (or docker compose v2), and optional ansible for the cluster refresh play. Argo CD must already be installed in the target cluster with a project named default.
Render an overlay to verify the patch lands cleanly:
kustomize build overlays/cace-1-dev | lessApply a refresh across all four k3s masters:
ansible-playbook -i ansible/inventory.ini ansible/playbook.ymlPull the dev1 kubeconfig into ~/.kube/config as context k3s-dev1:
./kube.shThe most common task is the cross-cluster NATS load test. The wrapper auto-builds images on first run, then drives the publisher / subscriber / k6 stack end-to-end:
./nats-cluster-test.sh test
# 10 VUs for 60s, 10 publisher + 10 subscriber replicas by default
VUS=50 DURATION=120s \
PUBLISHER_REPLICAS=3 SUBSCRIBER_REPLICAS=2 \
./nats-cluster-test.sh testFor manual probing, interactive brings the publisher and subscriber up in the background, tails subscriber logs, and prints the in-container wget command for a one-off publish.
The values you'll actually touch live in overlay patches, not Helm values files:
overlays/<env>/patches/platform-core.yaml— strategic-merge patch onspec.source.helm.valuesObject. Setsglobal.clusterName, togglesbootstrap.hermesSre.enabled/bootstrap.monitoring.enabled, and thebootstrap.nats.gatewayblock (advertise URL, peer gateways, enabled flag).overlays/cace-1-dev/patches/crossplane-identity.yaml— public Azure UMIclientIdfor the Crossplane identity. Safe to commit; rotated via PR by an automated job.nats-load-test/docker-compose.yml—NATS_URL,SUBJECT,STATS_INTERVAL_MS,NATS_QUEUE(empty = fan-out, set = competing consumers), and k6VUS/DURATIONdefaults.ansible/inventory.ini— list of k3s master IPs that the refresh play targets.
base/platform-core.yaml pins targetRevision: HEAD on DramisInfo/platform-helm deliberately; see AGENTS.md before changing it.
- home-lab — Foundational infra and bootstrap orchestration for self-hosted k3s clusters on Proxmox + Azure.
- platform-tools — GitOps overlays for the DramisInfo platform clusters.
- platform-helm — Meta Helm chart (
platform-core) for Argo CD-driven platform bootstrap. - platform-crossplane-compositions — Crossplane Compositions (XRDs, compositions, RBAC) for the platform.
- crossplane-providers-and-functions — Helm chart that installs the Crossplane providers, composition functions, and ProviderConfigs.
- platform-project-workspaces — Bootstrap manifests for the product-workspaces App-of-Apps pattern and the preview/QAS GitHub repository_dispatch pipeline.
- platform-standards — Canonical schemas and conventions for product workspaces and app repositories.
- platform-workflows — Reusable GitHub Actions workflows for the DramisInfo org.
kustomize buildfails on an overlay after a base change. Re-renderkustomize build basefirst; every overlay inherits it, so a chart-pinned diff inbase/platform-core.yamlwill surface in all four.- Argo CD shows the
platform-coreApplication asOutOfSyncwith no diff. Force a refresh viaansible/playbook.yml— the play patches everyApplicationwith a normal refresh operation. - NATS load test never reaches the healthy publisher count. Check
./nats-cluster-test.sh statusand container logs; usually a stale image — run./nats-cluster-test.sh buildand retry. - JetStream warnings about "no metadata leader". Confirm the cace-2-dev gateway is not re-enabled in
overlays/cace-1-dev/patches/platform-core.yaml(bootstrap.nats.gateway.enabled: false); that cluster was decommissioned on 2026-06-23 and the gateway was blocking RAFT leader election. kube.shfails onscp. The script is hard-coded toubuntu@192.168.20.10; ensure your SSH agent has the matching key and the host is reachable before re-running.
- Do not commit kubeconfigs, kubeconfig certificates, Argo CD admin passwords, or registry credentials. The
clientIdinoverlays/cace-1-dev/patches/crossplane-identity.yamlis a public Azure UMI Application (client) ID, not a secret — do not paste the matching secret value here. - Do not bypass Argo CD with
kubectl applyfrom a workstation; useansible/playbook.ymlor the Argo CD UI/API. - Do not move
nats-load-test/under Argo CD; it is a workstation-driven docker-compose stack talking to clusters over the public NATS hostnames. - The full guardrail list (chart-version bumps, overlay scope,
targetRevision: HEAD, repo-rootpackage.json, etc.) lives in the "What NOT to do" section of AGENTS.md.
- Branch from
mainusing Conventional Commits names, e.g.feat/cace-1-dev/<slug>orfix/nats/<slug>. - Commits follow Conventional Commits — e.g.
feat(cace-1-dev): enable hermes-sre read-only ServiceAccount,fix(nats): disable gateway to defunct cace-2-dev cluster. Automated client-ID rotation commits use theUpdate Crossplane UMI client ID ...prefix and merge via PR. - Changes land through PRs into
main. There is noCONTRIBUTING.md,CODE_OF_CONDUCT.md, or CI workflow in this repo; agent specs in.github/agents/are scoped tocace-1-devonly.
No license — internal/private project. Do not redistribute without permission from the DramisInfo platform team.
Recent git log --oneline main highlights: feat(cace-1-dev): enable hermes-sre read-only ServiceAccount (PR #3); fix(nats): disable gateway to defunct cace-2-dev cluster on 2026-06-23; Gatekeeper non-root policy exclusion for it-gitops-enterprise-prd; and the steady stream of automated Crossplane UMI client-ID rotations for cace-1-dev (most recently 2026-08-01).
Part of the DramisInfo platform org. Built on Argo CD, Kustomize, k3s, NATS (with JetStream), and the platform-core Helm chart in DramisInfo/platform-helm. The cross-cluster load-test stack uses Fastify and k6.