---
title: Developer enablement platform for STACKIT
description: Establish a scalable Internal Developer Platform for STACKIT using standardized Terraform modules, Golden Paths, and tiered abstractions for rapid cloud.
sidebar:
  label: Developer Enablement Platform
  order: 3
source_url: "https://framework.stackit.cloud/migration/design-and-mobilize/landing-zones/developer-enablement/"
source_file: "docs/migration/design-and-mobilize/landing-zones/developer-enablement.mdx"
---

## General

Developer enablement platforms provide a safe, reproducible, and automated infrastructure foundation. By utilizing a GitOps-driven approach, your platform engineering team can enforce strict governance while empowering rapid provisioning for developers.

### Service distribution: centralized vs. application-specific

To address the architecture correctly, it is crucial to understand that some services are offered by centralized platform instances, while others are provisioned individually per application environment:

- **Centralized Platform Services**: Centralized Platform Services are hosted within the Platform Landing Zone and act as the backbone for the entire organization. Centralized Platform Services include shared toolchains such as a central Git instance, a centralized STACKIT Kubernetes Engine (SKE) cluster for CI/CD runners, and a central STACKIT Secrets Manager.
- **Application-Specific Services**: Application-Specific Services are part of every individual Application Landing Zone (Developer Landing Zone). Application-Specific Services include the specific application workloads, dedicated STACKIT databases, and dedicated STACKIT Kubernetes Engine (SKE) clusters provisioned exclusively for the specific developer team.

### End-to-end process: establishing the platform

To get such a developer platform running at STACKIT from scratch, the platform engineering team follows this end-to-end process:

<Steps>

1. **Platform Landing Zone Setup**: The platform engineering team provisions the central Platform Landing Zone on STACKIT. The Platform Landing Zone setup establishes the core network, identity management (IAM), and central observability routing for the organization. Central networking topics like load balancers and VPN gateways can also be included here.

2. **Tooling Deployment**: The platform engineering team deploys centralized platform services into the Platform Landing Zone. Centralized platform services include the Git repository (STACKIT Git), GitOps runners (e.g. ArgoCD), and the internal developer portal (e.g., Backstage).

3. **Golden Path Creation**: Platform engineers define Infrastructure as Code (Terraform) modules for STACKIT services. Platform engineers store these modules as standardized Golden Path templates in the central Git repository to ensure compliance.

4. **Application Landing Zone Vending**: Developers request a new application environment via the developer portal. The developer portal triggers the automated provisioning of a completely isolated Application Landing Zone on STACKIT.

5. **Workload Deployment**: Developers utilize the Golden Paths to deploy application code and required STACKIT services into the newly created Application Landing Zone. The central GitOps runner automatically synchronizes and manages the Workload Deployment.

</Steps>

### Main process (day-to-day operations)

<Steps>

1. **Landing Zone Provisioning**: Deploy one Platform Landing Zone and multiple Application Landing Zones using a highly automated approach.

2. **Configuration-Driven Generation**: Define infrastructure needs in a defined code-based structure in the Git repository. Configuration-Driven Generation uses tools like Terraform Modules, Terragrunt, or cookiecutter.

3. **GitOps Deployment Runner**: Utilize a GitOps Runner (running on a STACKIT Server, STACKIT Kubernetes Engine, or STACKIT Functions) that regularly pulls the Git repository and deploys the STACKIT infrastructure using Terraform.

4. **Read-Only Developer Access**: Ensure developers can view the current state in the STACKIT Portal or via the CLI. Read-Only Developer Access ensures developers lack the permissions to make manual configuration changes.

</Steps>

```d2
direction: down

# Define Nodes
Developer: Developer
GitRepo: Git Repository
CI: CI Pipeline
Registry: Artifact Registry
GitOpsRunner: GitOps Runner
STACKIT_API: STACKIT Cloud API
AppLZ: Application Landing Zone
PlatLZ: Platform Landing Zone

# Define Connections and Labels
Developer -> GitRepo: Commits Code/Config
GitRepo -> CI: Triggers
CI -> Registry: Pushes Artifact
GitOpsRunner -> GitRepo: Pulls State
GitOpsRunner -> STACKIT_API: Deploys Infrastructure (TF, SDK, direct API)
STACKIT_API -> AppLZ
STACKIT_API -> PlatLZ

```

### Golden paths & templates

To reduce cognitive load and accelerate time-to-market, the platform provides Golden Paths: opinionated, pre-configured templates for common workloads.

- **Standardized Tech Stacks**: Standardized Tech Stacks provide pre-approved combinations of STACKIT services (e.g., STACKIT Kubernetes Engine + STACKIT PostgreSQL + STACKIT Redis).
- **Embedded Best Practices**: Embedded Best Practices ensure that security, backup configurations, and high availability are included in the Golden Path templates by default.
- **Self-Service Generation**: Self-Service Generation allows developers to use tools like Cookiecutter, Backstage Software Templates, or Terraform modules to scaffold new microservices that are instantly compliant with the STACKIT architecture framework.

### Access management & security

- **Developer Permissions**: Developer Permissions restrict direct write access on the STACKIT environment, ensuring a tamper-proof infrastructure state.
- **Granular Policies**: Granular Policies allow fine-grained authorization and permissions to be securely maintained directly within the GitOps Runner.
- **Service Account Security**: Service Account Security guarantees that the GitOps Runner operates using a dedicated Service Account with write permissions, authenticated by short-lived tokens.

### Secret management

- **Automated Credential Storage**: Automated Credential Storage ensures that credentials must be automatically deposited into the STACKIT Secrets Manager during the deployment phase.
- **Defined User Access**: Defined User Access guarantees that specifically defined users receive read-only access to the secrets within the STACKIT Secrets Manager.
- **Application Service Accounts**: Application Service Accounts are granted read-only access to fetch the necessary credentials from the STACKIT Secrets Manager at runtime.
- **Secret Distribution**: Secret Distribution allows developers the permission to create read-only users on the STACKIT Secrets Manager for the developers' own operational use.

### Tooling landscape

Building a Developer Enablement Platform requires stringing together the right tools. Depending on the build versus buy strategy, engineering teams can assemble individual components or use the advantages of a comprehensive platform. Here is the recommended ecosystem for STACKIT:

<ScfAssetLoader
  showFilter={false}
  showSearch={false}
  frameworkSlug="migration"
  filterByTag="dev-platform"
/>

#### Why utilize a full IDP?

If the organization prefers to buy rather than build, a comprehensive Cloud Foundation Platform can abstract away the complexity of gluing tools together.

- **Instant Self-Service:** Instant Self-Service empowers developers to request STACKIT resources directly from a unified service catalog without waiting on IT tickets.
- **Built-in Governance:** Built-in Governance automatically injects central security policies and landing zone configurations into every newly provisioned STACKIT tenant.
- **Unified Billing & FinOps:** Unified Billing provides immediate cost allocation and visibility, mapping STACKIT usage directly back to specific teams, projects, or cost centers.

## Observability & FinOps

A mature developer platform does not only provision resources; the platform makes the resources transparent and measurable.

### Telemetry & monitoring

- **Centralized Logging**: Centralized Logging ensures that all Application Landing Zones automatically forward logs to a central STACKIT Logging Service managed by the Platform Landing Zone.
- **Pre-configured Dashboards**: Pre-configured Dashboards within Golden Path templates include out-of-the-box STACKIT Observability dashboards so developers instantly see the application's health.

### Cost attribution (FinOps)

- **Mandatory Tagging**: Mandatory Tagging relies on the GitOps Runner enforcing policies requiring `team`, `environment`, and `cost-center` tags on all STACKIT resources.
- **Visibility**: Visibility grants developers read-only access to STACKIT billing dashboards filtered by the team's tags to foster cost awareness without needing administrative billing rights.

## Application landing zone

- **Workload Isolation**: Workload Isolation means Application Landing Zones provide dedicated, isolated environments for individual applications to operate securely on STACKIT.
- **Resource Autonomy**: Resource Autonomy allows each Application Landing Zone to manage specific STACKIT resources while strictly adhering to central governance policies.
- **Governance**: Governance for Application Landing Zones defines policies to restrict developers' agency to create random resources and provides infrastructure compliance.

<LinkCard
  title="Application Landing Zone"
  description="Read more about the application landing zone."
  href="/migration/design-and-mobilize/landing-zones/application-landing-zone"
/>

## Platform landing zone

- **Centralized Governance**: Centralized Governance establishes the Platform Landing Zone as the core management hub, providing centralized networking, identity, and security services.
- **Shared Infrastructure**: Shared Infrastructure means the Platform Landing Zone hosts shared resources such as the central STACKIT Telemetry Router, Unified Firewall instances, and the central STACKIT Secrets Manager.
- **Global Policies**: Global Policies enforce baseline security within the Platform Landing Zone, such as restricting public IP creation, enforcing compliance tags, and managing global IAM roles.
- **Networking**: Networking rules mandate that applications provisioned within a Platform Landing Zone must automatically be added to the landing zone's Secure Network Architecture.

<LinkCard
  title="Platform landing zone"
  description="Read more about the platform landing zone."
  href="/migration/design-and-mobilize/landing-zones/platform-landing-zone"
/>
