---
title: "STACKIT Professional Service Repository"
description: "Access the STACKIT Professional Service repository with verified Terraform modules, helper scripts, and reference blueprints to accelerate platform onboarding."
scfAsset:
  maintainers:
    - user: "tobias.mueller"
  managed: false
  category: "guide"
  external: false
  partnerLogo: "scf-core"
  tags: ["IaC", "Terraform", "Blueprints", "Automation"]
source_url: "https://framework.stackit.cloud/architecture/assetcontainer/stackit/prof-service-repo/"
source_file: "docs/architecture/assetcontainer/stackit/prof-service-repo.mdx"
---

Building cloud infrastructure on STACKIT does not mean reinventing the wheel every time. To maximize customer enablement, the STACKIT Professional Service team provides public access to production-ready architecture blueprints, verified Terraform modules, and operational helper scripts.

The STACKIT Professional Service repository serves as a standardized resource library that accelerates platform onboarding and simplifies sovereign cloud deployments.

---

### Featured blueprints and examples

The STACKIT Professional Service repository includes a comprehensive `examples/` directory covering many STACKIT products and complex use cases. The following templates are representative of what the repository provides.

#### STACKIT Kubernetes Engine (SKE)

- **SKE with Azure Arc**: Integrate STACKIT Kubernetes Engine clusters into Azure Arc for unified multi-cloud cluster management.
- **SKE observability and alerting**: Deploy Kube-State-Metrics and configure log alerts with STACKIT Observability.
- **SKE external secrets sync**: Synchronize secrets securely using the External Secrets Operator.
- **SKE GPU operator**: Provision and configure GPU-enabled STACKIT Kubernetes Engine nodes.

#### Infrastructure as a Service (IaaS)

- **High-availability VRRP**: Set up a highly available architecture using VRRP on STACKIT IaaS.
- **Cross-AZ load balancing**: Configure Layer 4 and Layer 7 (WAF) load balancers across multiple availability zones.
- **Windows BYOL migration**: Migrate and run Windows Bring-Your-Own-License instances efficiently.

#### Networking and security

- **OPNsense hub-and-spoke**: Establish a scalable hub-and-spoke network topology using OPNsense.
- **VPN use cases**: Implement site-to-site and client-to-site VPN scenarios securely.
- **IAM SCIM integration**: Automate identity management using STACKIT IAM and SCIM.

#### Data and operations

- **DBaaS OpenTelemetry metrics**: Collect and ship database metrics using OpenTelemetry.
- **Telemetry router hub-spoke**: Set up centralized telemetry routing with compliance locking.
- **STACKIT Landing Zone**: Deploy the core foundation setup that links to the official STACKIT landing zone repository.

---

### Repository philosophy

To maintain agility, the STACKIT Professional Service repository operates under a specific lifecycle philosophy. Keep the following operational principles in mind before integration.

- **Best-effort delivery**: All examples, modules, and scripts are provided on a flexible, best-effort basis by the STACKIT Professional Service team.
- **No freshness guarantees**: Cloud APIs change rapidly, so some components might require manual adjustments over time.
- **Review before deployment**: Never copy code directly into production environments without a prior security review.

---

### How to use the repository

Follow these procedural steps to safely integrate the STACKIT Professional Service blueprints into your project environments.

<Steps>

1. **Understand the code**: Analyze the resource definitions thoroughly to comprehend which STACKIT infrastructure assets a blueprint will provision.

2. **Adapt the configuration**: Tweak deployment variables, regional settings, and security guardrails to match your internal landing zone policies.

3. **Test in a sandbox**: Run, plan, and validate the customized configuration inside an isolated staging or development environment first.

</Steps>

---

### Contributions and upstream sync

The STACKIT Professional Service repository is mirrored automatically from an internal STACKIT Git instance to public GitHub, and external contributions are highly encouraged.

If you fix a broken script or develop a new architectural blueprint, open a pull request directly on GitHub. The STACKIT Professional Service team reviews incoming community contributions regularly and aims to provide feedback within **7 business days**.

<LinkCard
  title="Access the Professional Service Repository"
  description="Explore the codebase, clone blueprints, or open a pull request on the primary STACKIT Professional Service repository mirror."
  href="https://professional-service.git.onstackit.cloud/professional-service-best-practices/professional-service"
/>
