5. Building Block View

1. Level 1: Whitebox Overall System

The Pandur cluster’s GitOps layer (pandur/) is decomposed into seven top-level building blocks. Each is reconciled by its own parent Argo CD Application (pandur/apps/*.yml), which in turn points at that building block’s own apps/ directory — the app-of-apps pattern described in 4. Solution Strategy.

Overview of the Pandur cluster’s Level 1 building blocks and their dependencies.
Figure 1. Overview of the Pandur cluster’s Level 1 building blocks and their dependencies.
Building Block Responsibility

argocd

GitOps engine. Reconciles every other building block from this repository; hosts the app-of-apps root applications.

networking

Cluster networking (Cilium CNI) and ingress (Traefik), terminating all inbound HTTPS traffic behind the Hetzner Load Balancer.

security

Identity and secrets: Keycloak (OIDC provider), External Secrets Operator + Secrets Store CSI Driver (Bitwarden-backed secrets), cert-manager `ClusterIssuer`s.

storage

Persistent storage: Hetzner block storage (hcloud-csi) and CIFS-backed shares (csi-driver-smb) for Hetzner Robot/hidrive.

operators

Database operators for stateful workloads: MariaDB Operator, Redis Operator, and (as a nested app-of-apps) cnpg-system.

cnpg-system

CloudNativePG operator and Barman Cloud Plugin, providing managed PostgreSQL clusters with S3 backups. Reconciled as a child of operators.

observability

Monitoring, dashboards and the Kubernetes web UI: Prometheus, Grafana, Headlamp.

Cluster infrastructure itself — the Hetzner network, NAT gateway, and the Kubernetes nodes — is not one of these building blocks. It is created before any of them exist; see 7. Deployment View.