platform-core is an open-source meta Helm chart that bootstraps shared platform components on Kubernetes clusters using a GitOps-first approach powered by Argo CD.
Rather than deploying workloads directly, every template renders an Argo CD Application CRD that points to an upstream Helm chart or Git repository. Argo CD then owns the full lifecycle of each component — upgrades, rollbacks, and drift detection — across one or more clusters.
Each component is controlled through a toggle in values.yaml. The table below lists all available components and their default activation state.
| Component | Description | Default |
|---|---|---|
| Gateway API | Kubernetes Gateway API CRDs (required by cert-manager and Envoy Gateway) | enabled |
| cert-manager | Automated TLS certificate management | enabled |
| Crossplane | Infrastructure provisioning via Kubernetes CRDs | enabled |
| Terraform Operator | Run Terraform workspaces from Kubernetes | enabled |
| External Secrets Operator | Sync secrets from Vault, AWS SM, GCP SM, and more | enabled |
| CNPG | CloudNativePG — production-grade PostgreSQL on Kubernetes | enabled |
| Atlas Operator | Database schema migrations as Kubernetes resources | disabled |
| Gatekeeper | Policy enforcement via OPA with community library support | enabled |
| Istio | Service mesh with mTLS, traffic management, and observability | enabled |
| Envoy Gateway | Kubernetes Gateway API-native ingress backed by Envoy | disabled |
| Prometheus | Metrics collection, alerting, and long-term storage | enabled |
| Grafana | Metrics dashboards with plugin and datasource provisioning | enabled |
| Loki | Log aggregation with Alloy collector | enabled |
| Tempo | Distributed tracing backend | enabled |
| Beyla | eBPF-based automatic application instrumentation | enabled |
| KEDA | Event-driven autoscaling for Kubernetes workloads | enabled |
| k6 Operator | Distributed load testing via Grafana k6 on Kubernetes | enabled |
| Argo Events | Event-driven workflow automation framework for Kubernetes | enabled |
| NATS | Cloud-native messaging with JetStream persistence | enabled |
| KubeVela | Application delivery platform based on Open Application Model | disabled |
Note: Loki, Tempo, Beyla, Prometheus, and Grafana are all gated by the single
bootstrap.monitoring.enabledtoggle.
helm install platform-core ./platform-core \
--namespace argocd \
--values your-values.yamlhelm upgrade platform-core ./platform-core \
--namespace argocd \
--values your-values.yamlglobal:
clusterName: "my-cluster" # used for resource naming and host templatesMost components are enabled by default. To opt out of a component, explicitly disable it:
bootstrap:
cnpg:
enabled: false
terraformOperator:
enabled: falseSee platform-core/values.yaml for the full list of available options and inline documentation.
# Lint the chart
helm lint platform-core
# Render all templates to stdout
helm template platform-core ./platform-core
# Render with a custom values override
helm template platform-core ./platform-core -f my-values.yamlplatform-helm/
└── platform-core/ # Main Helm chart
├── Chart.yaml
├── values.yaml # All component toggles and configuration
├── GATEKEEPER-POLICIES.md # Enforced OPA policies and exclusions
└── templates/
└── argo-applications/ # One Argo CD Application per component
├── argo-events/
├── atlas/
├── beyla/
├── cert-manager/
├── cnpg/
├── crossplane/
├── envoy-gateway/
├── external-secret-operator/
├── gatekeeper/
├── gateway-api/
├── grafana/
├── istio/
├── k6-operator/
├── keda/
├── kubevela/
├── loki/
├── nats/
├── prometheus/
├── tempo/
└── terraform-operator/
Refer to the inline comments in platform-core/values.yaml and the following component-specific guides:
- Gatekeeper Policies — enforced constraints, exclusions, and enforcement modes
- Grafana Configuration — plugin and datasource provisioning
Contributions are welcome! Please read CONTRIBUTING.md before opening a pull request. For security issues, see SECURITY.md.
When adding a new component:
- Create
platform-core/templates/argo-applications/<component>/<component>.yaml - Wrap the template with
{{- if .Values.bootstrap.<component>.enabled -}} - Add the corresponding
enabled: falsedefault invalues.yamlwith inline comments - Choose an appropriate
argocd.argoproj.io/sync-wavevalue based on dependency order
This project is licensed under the MIT License.