Skip to content

Commit b24e1b5

Browse files
inafevclaude
andcommitted
docs(readme): full architecture diagram (delivery+runtime) with legend
Match the OpenShift sibling: the §3 diagram now covers GitOps delivery, all four LB backends, ESO/Vault secrets and the air-gap mirror, with a colour legend mapping each group. Part of v0.1.0. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
1 parent 046ca02 commit b24e1b5

2 files changed

Lines changed: 74 additions & 18 deletions

File tree

‎CHANGELOG.md‎

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -40,7 +40,9 @@ Initial release — the multi-distribution sibling of
4040
and `docs/` (`tls-secret.md`, `air-gapped.md`, `external-secrets.md`,
4141
`network-policies.md`), including 8 collapsible, parser-validated Mermaid
4242
diagrams. Answers the CNI/CSI question (CSI N/A — stateless; CNI only via
43-
NetworkPolicy).
43+
NetworkPolicy). The architecture diagram is a **full delivery + runtime view**
44+
(all components, all LB backends, ESO/Vault, air-gap mirror, GitOps) with a
45+
colour **legend**.
4446
- **CI** (`.github/workflows/ci.yml`): `helm lint` + `helm template`/`kubeconform`
4547
for every preset, optional-feature render, validation-rule checks, `yamllint`,
4648
`shellcheck`, and mermaid parsing (`scripts/validate-mermaid.mjs`).

‎README.md‎

Lines changed: 71 additions & 17 deletions
Original file line numberDiff line numberDiff line change
@@ -153,61 +153,115 @@ rows describing the same core).
153153

154154
## 3. Deployment topology
155155

156+
Full picture — **delivery (GitOps) + runtime**, all components and the optional
157+
pieces (External Secrets/Vault, air-gap mirror, the four LB backends). Node
158+
colours map to the **legend** below.
159+
156160
<details>
157-
<summary><b>Diagram — deployment topology (any distribution)</b> (click to expand)</summary>
161+
<summary><b>Diagram — full architecture (delivery + runtime, all components)</b> (click to expand)</summary>
158162

159163
```mermaid
160164
flowchart TB
161-
subgraph EXT["🌐 On-prem systems (may be air-gapped)"]
165+
subgraph EXT["⬜ Client · on-prem (may be air-gapped)"]
162166
direction TB
163167
BROWSER["Browser"]
164168
DNS["DNS · A record → LB IP"]
165-
KC["Keycloak · OIDC IdP"]
166-
MIRROR["Internal registry mirror<br>(air-gap: images + vendored chart)"]
167169
end
168-
subgraph LBG["⚖️ LoadBalancer (pick one per cluster)"]
170+
subgraph GIT["🔁 GitOps · ArgoCD (optional delivery)"]
171+
direction TB
172+
REPO[("Git repo")]
173+
APP["Application: traefik-keycloak<br>vendored chart + $values preset"]
174+
PROJ["AppProject: traefik"]
175+
REPO --> APP
176+
PROJ -. scopes .-> APP
177+
end
178+
subgraph LBG["🟦 LoadBalancer · pick one (loadBalancer.backend)"]
169179
direction TB
170180
METAL["MetalLB"]
171181
NSX["NSX ALB (Avi)"]
172182
KVIP["kube-vip"]
183+
CIL["Cilium LB-IPAM"]
173184
end
174-
subgraph NS["🟦 Namespace: traefik (any distro)"]
185+
subgraph NS["Namespace: traefik (any distribution)"]
175186
direction TB
176187
TRAEFIK["Traefik<br>web :80→443 · websecure :443 TLS"]
177-
subgraph RT["Traefik CRDs · routing"]
188+
subgraph RT["🟪 Traefik CRDs · routing"]
178189
direction TB
179-
IRD["IngressRoute<br>/dashboard · /api"]
180-
MERR["Middleware<br>oauth-errors"]
181-
MAUTH["Middleware<br>oauth-auth"]
182-
IRO["IngressRoute<br>/oauth2/*"]
190+
IRD["IngressRoute · /dashboard · /api"]
191+
MERR["Middleware · oauth-errors"]
192+
MAUTH["Middleware · oauth-auth"]
193+
IRO["IngressRoute · /oauth2/*"]
183194
end
184195
API["api@internal · Dashboard"]
185196
O2P["oauth2-proxy · :4180"]
186-
SECRET["oauth2-proxy-secret"]
187-
TLS["traefik-dashboard-tls"]
197+
subgraph ESOG["🟩 External Secrets Operator · optional"]
198+
direction TB
199+
SS["SecretStore → Vault"]
200+
ES["ExternalSecret"]
201+
end
202+
subgraph SEC["🩷 Secrets · in-cluster"]
203+
direction TB
204+
SECRET["oauth2-proxy-secret"]
205+
TLS["traefik-dashboard-tls"]
206+
end
188207
TRAEFIK --> IRD --> MERR --> MAUTH --> API
189208
TRAEFIK --> IRO --> O2P
190209
MAUTH -. forwardAuth .-> O2P
191210
O2P -. reads .-> SECRET
192211
TRAEFIK -. TLS .-> TLS
212+
SS --> ES
213+
ES -->|creates| SECRET
193214
end
215+
KC["Keycloak · OIDC IdP"]
216+
VAULT[("HashiCorp Vault · KV v2")]
217+
MIRROR["Internal registry mirror<br>images + vendored chart"]
194218
BROWSER --> DNS --> LBG
195219
LBG --> TRAEFIK
196220
O2P -->|OIDC| KC
221+
VAULT -->|"Kubernetes auth"| ES
197222
MIRROR -. "images + chart (no internet)" .-> TRAEFIK
198223
MIRROR -. image .-> O2P
224+
APP -. helm .-> TRAEFIK
225+
EXT ~~~ GIT
199226
classDef ext fill:#ECEFF1,stroke:#607D8B,color:#111;
227+
classDef idp fill:#F8D7DA,stroke:#C0392B,color:#111;
228+
classDef vault fill:#FFF3CD,stroke:#E0A800,color:#111;
229+
classDef mirror fill:#E0F2F1,stroke:#00695C,color:#111;
230+
classDef gitops fill:#DDE8FF,stroke:#3B6FD4,color:#111;
200231
classDef lb fill:#B2DFDB,stroke:#00897B,color:#111;
201-
classDef proxy fill:#CDEDF6,stroke:#1E8AA8,color:#111;
232+
classDef app fill:#FFE0B2,stroke:#EF7B4D,color:#111;
202233
classDef crd fill:#E8E0FF,stroke:#7C4DFF,color:#111;
203-
class BROWSER,DNS,KC,MIRROR ext;
204-
class METAL,NSX,KVIP lb;
205-
class O2P,API proxy;
234+
classDef eso fill:#D7F5DD,stroke:#2E9E5B,color:#111;
235+
classDef secret fill:#FCE1F0,stroke:#C2185B,color:#111;
236+
class BROWSER,DNS ext;
237+
class KC idp;
238+
class VAULT vault;
239+
class MIRROR mirror;
240+
class REPO,APP,PROJ gitops;
241+
class METAL,NSX,KVIP,CIL,TRAEFIK lb;
206242
class IRD,MERR,MAUTH,IRO crd;
243+
class API,O2P app;
244+
class SS,ES eso;
245+
class SECRET,TLS secret;
207246
```
208247

209248
</details>
210249

250+
**Legend**
251+
252+
| | Group | What it covers |
253+
|---|---|---|
254+
| 🟦 | Ingress / LB | MetalLB · NSX ALB · kube-vip · Cilium · Traefik |
255+
| 🟪 | Traefik CRDs | IngressRoutes · middlewares (oauth-auth / oauth-errors) |
256+
| 🟧 | Apps | oauth2-proxy · api@internal dashboard |
257+
| 🟩 | External Secrets Operator | SecretStore · ExternalSecret (`secret.mode=external-secrets`) |
258+
| 🩷 | Secrets | oauth2-proxy-secret · traefik-dashboard-tls |
259+
| 🔁 | GitOps | git repo · ArgoCD Application · AppProject |
260+
| 🟨 | Vault | HashiCorp Vault · KV v2 (backend for ESO) |
261+
| 🟥 | Keycloak | OIDC IdP |
262+
| 🟢 | Internal mirror | image registry + vendored chart (air-gap) |
263+
| ⬜ | Client / DNS | browser · DNS record |
264+
211265
## 4. Supported platforms & presets
212266

213267
### Platform × LoadBalancer backend

0 commit comments

Comments
 (0)