Developer enablement platforms provide a safe, reproducible, and automated infrastructure foundation. By utilizing a GitOps-driven approach, your platform engineering team can enforce strict governance while empowering rapid provisioning for developers.
Service distribution: centralized vs. application-specific
To address the architecture correctly, it is crucial to understand that some services are offered by centralized platform instances, while others are provisioned individually per application environment:
Centralized Platform Services: Centralized Platform Services are hosted within the Platform Landing Zone and act as the backbone for the entire organization. Centralized Platform Services include shared toolchains such as a central Git instance, a centralized STACKIT Kubernetes Engine (SKE) cluster for CI/CD runners, and a central STACKIT Secrets Manager.
Application-Specific Services: Application-Specific Services are part of every individual Application Landing Zone (Developer Landing Zone). Application-Specific Services include the specific application workloads, dedicated STACKIT databases, and dedicated STACKIT Kubernetes Engine (SKE) clusters provisioned exclusively for the specific developer team.
To get such a developer platform running at STACKIT from scratch, the platform engineering team follows this end-to-end process:
Platform Landing Zone Setup: The platform engineering team provisions the central Platform Landing Zone on STACKIT. The Platform Landing Zone setup establishes the core network, identity management (IAM), and central observability routing for the organization. Central networking topics like load balancers and VPN gateways can also be included here.
Tooling Deployment: The platform engineering team deploys centralized platform services into the Platform Landing Zone. Centralized platform services include the Git repository (STACKIT Git), GitOps runners (e.g. ArgoCD), and the internal developer portal (e.g., Backstage).
Golden Path Creation: Platform engineers define Infrastructure as Code (Terraform) modules for STACKIT services. Platform engineers store these modules as standardized Golden Path templates in the central Git repository to ensure compliance.
Application Landing Zone Vending: Developers request a new application environment via the developer portal. The developer portal triggers the automated provisioning of a completely isolated Application Landing Zone on STACKIT.
Workload Deployment: Developers utilize the Golden Paths to deploy application code and required STACKIT services into the newly created Application Landing Zone. The central GitOps runner automatically synchronizes and manages the Workload Deployment.
Landing Zone Provisioning: Deploy one Platform Landing Zone and multiple Application Landing Zones using a highly automated approach.
Configuration-Driven Generation: Define infrastructure needs in a defined code-based structure in the Git repository. Configuration-Driven Generation uses tools like Terraform Modules, Terragrunt, or cookiecutter.
GitOps Deployment Runner: Utilize a GitOps Runner (running on a STACKIT Server, STACKIT Kubernetes Engine, or STACKIT Functions) that regularly pulls the Git repository and deploys the STACKIT infrastructure using Terraform.
Read-Only Developer Access: Ensure developers can view the current state in the STACKIT Portal or via the CLI. Read-Only Developer Access ensures developers lack the permissions to make manual configuration changes.
To reduce cognitive load and accelerate time-to-market, the platform provides Golden Paths: opinionated, pre-configured templates for common workloads.
Embedded Best Practices: Embedded Best Practices ensure that security, backup configurations, and high availability are included in the Golden Path templates by default.
Self-Service Generation: Self-Service Generation allows developers to use tools like Cookiecutter, Backstage Software Templates, or Terraform modules to scaffold new microservices that are instantly compliant with the STACKIT architecture framework.
Developer Permissions: Developer Permissions restrict direct write access on the STACKIT environment, ensuring a tamper-proof infrastructure state.
Granular Policies: Granular Policies allow fine-grained authorization and permissions to be securely maintained directly within the GitOps Runner.
Service Account Security: Service Account Security guarantees that the GitOps Runner operates using a dedicated Service Account with write permissions, authenticated by short-lived tokens.
Automated Credential Storage: Automated Credential Storage ensures that credentials must be automatically deposited into the STACKIT Secrets Manager during the deployment phase.
Defined User Access: Defined User Access guarantees that specifically defined users receive read-only access to the secrets within the STACKIT Secrets Manager.
Application Service Accounts: Application Service Accounts are granted read-only access to fetch the necessary credentials from the STACKIT Secrets Manager at runtime.
Secret Distribution: Secret Distribution allows developers the permission to create read-only users on the STACKIT Secrets Manager for the developers’ own operational use.
Building a Developer Enablement Platform requires stringing together the right tools. Depending on the build versus buy strategy, engineering teams can assemble individual components or use the advantages of a comprehensive platform. Here is the recommended ecosystem for STACKIT:
TMTobias M.Head of STACKIT Cloud Framework · STACKITOwnerActive 12 of the last 12 weeks · 168 updatesSTACKITwww.linkedin.com/in/tobias-müller-011304172LWLukas WeberrußHead of STACKIT Cloud Migration Framework · STACKITOwnerActive 10 of the last 12 weeks · 47 updatesSTACKITwww.linkedin.com/in/lukas-weberruß-a360b081??Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site.Contributed in STACKIT
If the organization prefers to buy rather than build, a comprehensive Cloud Foundation Platform can abstract away the complexity of gluing tools together.
Instant Self-Service: Instant Self-Service empowers developers to request STACKIT resources directly from a unified service catalog without waiting on IT tickets.
Built-in Governance: Built-in Governance automatically injects central security policies and landing zone configurations into every newly provisioned STACKIT tenant.
Unified Billing & FinOps: Unified Billing provides immediate cost allocation and visibility, mapping STACKIT usage directly back to specific teams, projects, or cost centers.
Centralized Logging: Centralized Logging ensures that all Application Landing Zones automatically forward logs to a central STACKIT Logging Service managed by the Platform Landing Zone.
Pre-configured Dashboards: Pre-configured Dashboards within Golden Path templates include out-of-the-box STACKIT Observability dashboards so developers instantly see the application’s health.
Mandatory Tagging: Mandatory Tagging relies on the GitOps Runner enforcing policies requiring team, environment, and cost-center tags on all STACKIT resources.
Visibility: Visibility grants developers read-only access to STACKIT billing dashboards filtered by the team’s tags to foster cost awareness without needing administrative billing rights.
Workload Isolation: Workload Isolation means Application Landing Zones provide dedicated, isolated environments for individual applications to operate securely on STACKIT.
Resource Autonomy: Resource Autonomy allows each Application Landing Zone to manage specific STACKIT resources while strictly adhering to central governance policies.
Governance: Governance for Application Landing Zones defines policies to restrict developers’ agency to create random resources and provides infrastructure compliance.
Centralized Governance: Centralized Governance establishes the Platform Landing Zone as the core management hub, providing centralized networking, identity, and security services.
Shared Infrastructure: Shared Infrastructure means the Platform Landing Zone hosts shared resources such as the central STACKIT Telemetry Router, Unified Firewall instances, and the central STACKIT Secrets Manager.
Global Policies: Global Policies enforce baseline security within the Platform Landing Zone, such as restricting public IP creation, enforcing compliance tags, and managing global IAM roles.
Networking: Networking rules mandate that applications provisioned within a Platform Landing Zone must automatically be added to the landing zone’s Secure Network Architecture.