5. Building Block View
1. Level 1: Whitebox Overall System
The Pandur cluster’s GitOps layer (pandur/) is decomposed into seven top-level building blocks.
Each is reconciled by its own parent Argo CD Application (pandur/apps/*.yml), which in turn points at that building block’s own apps/ directory — the app-of-apps pattern described in 4. Solution Strategy.
| Building Block | Responsibility |
|---|---|
GitOps engine. Reconciles every other building block from this repository; hosts the app-of-apps root applications. |
|
Cluster networking (Cilium CNI) and ingress (Traefik), terminating all inbound HTTPS traffic behind the Hetzner Load Balancer. |
|
Identity and secrets: Keycloak (OIDC provider), External Secrets Operator + Secrets Store CSI Driver (Bitwarden-backed secrets), cert-manager `ClusterIssuer`s. |
|
Persistent storage: Hetzner block storage ( |
|
Database operators for stateful workloads: MariaDB Operator, Redis Operator, and (as a nested app-of-apps) |
|
CloudNativePG operator and Barman Cloud Plugin, providing managed PostgreSQL clusters with S3 backups. Reconciled as a child of |
|
Monitoring, dashboards and the Kubernetes web UI: Prometheus, Grafana, Headlamp. |
| Cluster infrastructure itself — the Hetzner network, NAT gateway, and the Kubernetes nodes — is not one of these building blocks. It is created before any of them exist; see 7. Deployment View. |