Reference architecture

Five clusters, one sovereign platform

KubeSailor separates platform tooling, application workloads and storage into dedicated highly available clusters, each with its own control plane and a shared HA edge.

  • HA Kubernetes
  • GitOps with Argo CD
  • Prometheus Grafana Tempo
  • Rook-Ceph HA storage
Cluster topology

Inside each cluster

Control, compute and storage are separated by design — so governance, workloads and data each fail, scale and upgrade independently.

Management plane

Admin & governance control cluster

The platform's control center. Runs Argo CD, the Harbor container registry, and the centralized observability stack that aggregates metrics, logs, and traces from all clusters.

  • Native kubeadm installed HA Kubernetes cluster
  • Calico networking and Gateway API
  • GitOps ready with Argo CD projects
  • Istio Ambient Mode as a Service Mesh
  • Includes Prometheus, Grafana, Thanos, Harbor

Recommended hardware

Control nodes
3× nodes
Worker nodes
4× nodes
CPU per node
16 vCPU
RAM per node
32 GB RAM
Disk per node
120 GB
Network
Static IP
Platform services

Everything is wired together before handover

Each service is deployed through GitOps, exposed on internal DNS names and documented in the runbooks you receive.

Edge & availability

  • Bind9 primary/secondary DNS with a Keepalived virtual IP
  • HAProxy load balancer pair fronting every control plane and ingress
  • Keepalived VRRP failover for DNS, ingress and API server VIPs
  • Internal TLS certificate authority issued during build

Delivery & supply chain

  • GitLab CE on a dedicated server as the single source of truth
  • Argo CD controllers reconciling every cluster from Git
  • Harbor OCI registry with per-project robot accounts
  • Jenkins pipelines with Cosign image signing and verified deploys

Runtime & data

  • Istio Ambient mode — mTLS without sidecar overhead
  • Rook-Ceph OSD pools for block, file and object storage
  • Replicated persistent volumes for stateful workloads
  • Spring MVC reference application deployed as a demo

Observability

  • Prometheus per cluster with Thanos for long-term retention
  • Grafana Alloy collecting metrics, logs and traces
  • Loki for centralised, cluster-labelled log search
  • Tempo for distributed tracing across meshed services
Open standards

A battle-tested CNCF stack

No proprietary black boxes. Every component is an open, industry-standard tool chosen for performance, stability and long-term supportability.

kubeadm Kubernetes

Cluster orchestration

Argo CD projects

GitOps delivery

Istio Ambient

Sidecarless service mesh

Prometheus + Thanos

Metrics, long-term storage

Loki + Tempo

Logs, distributed tracing

Harbor + Cosign

Registry, image signing

Jenkins Pipelines

Dynamic agents

Rook-Ceph

HA distributed storage

HAProxy + Keepalived

Load balancing, VIPs

GitLab CE

Source control

Ready to run your own cloud?

Send us your server inventory and target workloads. We'll come back with a topology, a fixed quote and a start date — usually within one business day.

Review pricing