Global cluster infrastructure — deploys Vault, External Secrets, and shared security components.
- Vault — secrets management (dynamic DB credentials, KV secrets)
- External Secrets Operator — sync Vault secrets to Kubernetes
- Orchestration: Helm, ArgoCD
- Secrets: Vault, External Secrets
- Task Runner: Just
apps/ # one folder per ArgoCD Application (self-contained Helm charts)
manifests/ # raw K8s YAML (namespaces, RBAC, Jobs, SecretStores)
justfile # deploy / delete recipes
platform.env # platform-wide constants
- Docker — container runtime
See the core repository for complete setup instructions.
- Helm — Kubernetes package manager
- kubectl — Kubernetes command-line tool
- Just — task runner for common commands
just deploy # Deploy Vault + namespace + components
just delete # Remove everythingA DevContainer configuration is included. Inside the container: kubectl, Helm, Docker CLI, Just.
- Check cluster connectivity:
kubectl cluster-info - Verify Vault:
kubectl get pods -n vault - Verify namespace:
kubectl get ns mathtrail