Skip to content
Cloud architecture templates

Kubernetes — Workloads, Storage and Config

A cluster drawn in pure Kubernetes objects, with the distinction the notation exists to make visible: a Deployment is stateless and replicated, a StatefulSet has a volume claim behind it, and the two must not be drawn the same way. Reports clean.

Template previewCloud architecture
Platform clusterA Kubernetes architecture diagram: 14 resources in 6 scopes (0 networks, 0 availability zones), joined by 15 connections. Categories drawn: Compute, Containers, Storage, Networking, Security, Clients. No error or warning across 14 resources and 15 edges, every line read; 4 of the 10 checks could not run at all — so this is a clean result on the part that could be checked, not a clean bill of health.Platform clusterKubernetes · 14 resources · 6 scopes · 0 networks · 0 zones · 15 connectionsNo error or warning across 14 resources and 15 edges, every line read; 4 of the 10 checks could not run at all — so this is a clean result on the partthat could be checked, not a clean bill of health.Internetintern…8Clusterprod-cluster8Namespaceingress-nginx8Namespaceapplication8Namespacedata8Namespaceobservabil…8Users—5+nginx ingressk8s5+ingressservicek8s5+webk8s×45+web servicek8s5+workerk8s×36+app-configk8s5+db-credentialsk8s1+web autoscalerk8s6+postgresk8s×31+postgresservicek8s5+postgres-datak8s1+fast-ssdk8s6+prometheusk8s6+https 443http 80http 8080http 8080mountmountjob queuepostgres 5432postgres 5432volumeLegendComputeContainersStorageNetworkingSecurityClientsRequest trafficAsynchronousDepends onChecks — what ran, and what could notWhether the internet reaches something that ho…ran over 10 subjects, found nothingWhether anything holding data at rest sits in …could not run here — 1 reason givenWhether anything claiming redundancy is spread…could not run here — 1 reason givenEdges that leave one network for another, or c…could not run here — 1 reason givenResources that appear in no edge at all. A leg…ran over 14 subjects, found nothingEvery id an edge or a scope names is one that …ran over 14 subjects, found nothingEach id is declared once. Two declarations mak…ran over 20 subjects, found nothingType words that did not resolve. A hole in thi…ran over 14 subjects, found nothingDeclared ranges: that each parses, sits inside…could not run here — 1 reason givenWhether every line was read and no shape cap b…ran over 20 subjects, found nothingFindings1`creds`, `pg` and `pgdata` hold data at rest and sit inside no subnet at all, so nothing in this document says whether they are publicly routable and this check hadnothing to read.in the figure: creds, pg, pgdata2This document declares no availability zone, so the redundancy check DID NOT RUN AT ALL: nothing here claims redundancy either, so nothing was missed. Declare thezones (`zone az-a`, `zone az-b`) and put the resources inside them, and the claim becomes checkable.3This document declares no `network` scope, so there is no boundary for an edge to cross and this check DID NOT RUN over any of its 15 edges. Nothing here says thetraffic stays inside one network.4No network or subnet was declared, so there was no addressing to check.5The walk reached 10 resources from the internet; every one of the 3 that hold data at rest — `creds`, `pg` and `pgdata` — sits behind an ingress.in the figure: users, ing, ing-svc, web-svc, web +5 more6All 14 declared resources appear in at least one edge.in the figure: users (badge 5), ing (badge 5), ing-svc (badge 5), web (badge 5), web-svc (badge 5) +9 more7All 14 ids named by edges and scopes were declared somewhere in this document.in the figure: users (badge 5), ing (badge 5), ing-svc (badge 5), web-svc (badge 5), web (badge 5) +9 more8All 20 declared ids are distinct.in the figure: internet, prod, ingress-ns, app-ns, data-ns +15 more9All 14 resources resolved to a type this engine knows, so every check above had the full vocabulary to read.in the figure: users (badge 5), ing (badge 5), ing-svc (badge 5), web (badge 5), web-svc (badge 5) +9 more10Every line was read and no shape cap bit: the 20 declarations above are the whole document, so the counts are totals rather than floors.

Make it your own.

title "Platform cluster"
provider k8s

internet {
  user users "Users"
}

cluster prod "prod-cluster" {
  namespace ingress-ns "ingress-nginx" {
    ingress ing "nginx ingress"
    service ing-svc "ingress service"
  }

  namespace app-ns "application" {
    deployment web "web" count 4 tier web
    service web-svc "web service"
    deployment worker "worker" count 3 tier worker
    configmap cfg "app-config"
    secret creds "db-credentials"
    hpa auto "web autoscaler"
  }

  namespace data-ns "data" {
    statefulset pg "postgres" count 3
    service pg-svc "postgres service"
    pvc pgdata "postgres-data"
    storageclass fast "fast-ssd"
  }

  namespace obs-ns "observability" {
    deployment prom "prometheus"
  }
}

users -> ing : https 443
ing -> ing-svc : http 80
ing-svc -> web-svc : http 8080
web-svc -> web : http 8080
web -> cfg : mount
web -> creds : mount
web ~> worker : job queue
web -> pg-svc : postgres 5432
pg-svc -> pg : postgres 5432
pg -> pgdata : volume
pgdata ..> fast
auto ..> web
prom ..> web
prom ..> worker
prom ..> pg