Repeatable platforms
Blueprints and profiles replace environment-specific assembly.

PLATFORM ENGINEERING / PRIVATE CLOUD
Turns raw servers or existing Kubernetes environments into standardized RKE2, OKD or imported Kubernetes platforms with catalog, fleet, release, policy, disconnected delivery and Day‑2 operations.
4SO Platform Factory components: from raw infrastructure to target platforms
Product problem
Kubernetes, registry, identity, policy, monitoring, upgrades and recovery become another operations burden if they are assembled without one product lifecycle.
Blueprints and profiles replace environment-specific assembly.
RKE2, OKD and imported clusters share a product boundary without fake symmetry.
Health, drift, node lifecycle and upgrade stay under fleet operations.
Desired state and artifacts retain identity and provenance.
Capabilities
Factory owns platform lifecycle while target distributions keep their native capabilities.
Build a managed platform or enroll an existing cluster.
Versioned platform capabilities and templates.
Operate many targets through one product model.
Forgejo records intent; Argo CD reconciles it.
zot keeps canonical OCI identity; oc-mirror v2 + zot provide sealed acquisition.
Application release and environment binding on observed platform capabilities.
Policy, backup run, restore and drill for managed targets.
Drain, replace, maintenance and distribution-aware upgrade.
Deployment model
The Factory does not migrate itself into the target distribution. RKE2 management stays self-contained while RKE2, OKD and imported Kubernetes are distinct target identities.
| Target | Entry path | Ownership | Use |
|---|---|---|---|
| Managed RKE2 | Factory build | Platform lifecycle under Product Control Plane | Standard private application platform |
| Existing Kubernetes | Import + discovery | Existing runtime + 4SO lifecycle boundary | Bring existing clusters under management |
| Managed OKD | Distribution-aware build | OKD owns CVO/MCO/OVN/OLM/SCC behavior | OpenShift-compatible target |
| Existing OKD | Import + capability discovery | Native OKD + 4SO product workflows | Manage without duplicate platform stacks |
Architecture
The architecture avoids making Git, Argo or the target cluster an accidental second product source of truth.
| Boundary | Mechanism | Operational contract |
|---|---|---|
| Artifact plane | zot | Canonical OCI registry for connected and disconnected delivery. |
| Managed OKD install | openshift-install / oc + scoped Redfish boot media | Bare-metal bootstrap follows the distribution contract. |
| Disconnected OKD | oc-mirror v2 → zot | Acquisition, inventory and mirror identity are sealed before install. |
| Dapr | Optional application runtime trait | Never replaces 4SO state/workflow/lock/secret authority. |
| Domain | Component / Mechanism | Behavior |
|---|---|---|
| Product authority | PostgreSQL + Platform API | Org/Project, Catalog, Blueprint, Fleet, Release and Durable Operation remain product authority. |
| Desired state | Forgejo | Desired configuration and release inputs are versioned; Git does not become Runtime Truth. |
| Reconciliation | Argo CD | Applies desired state and observes drift without creating an independent state authority. |
Lifecycle
A target remains a managed product resource through capability discovery, releases, node change, upgrade and recovery.
Platform profiles
Each profile combines distribution identity, capability discovery, policy, supply chain and lifecycle. OKD and RKE2 are deliberately not forced into artificial implementation symmetry.
A lightweight, self-contained Kubernetes platform.
Uses OKD-native capabilities rather than duplicating them.
Adopt an existing cluster without rebuilding it.
Application delivery over a managed target.
Acquire, mirror and install without runtime Internet dependency.
Operate targets after creation.
State and flows
Risk, approval, retry policy and runtime verification belong to the operation model rather than an informal runbook.
High-risk actions never reach execution without an independent approval boundary.
Forgejo intent and Argo reconciliation do not create a second product authority.
Artifact identity is sealed before target installation.
Raw infrastructure to registered target.
Enrollment without rebuilding the cluster.
Release binds desired state to observed runtime.
Supply chain is sealed before install.
Day‑2 remains distribution-aware.
Drift and data protection deserve visible lifecycle paths too.
Resolve desired/observed differences without overwriting distribution-native ownership.
Data protection continues through isolated restore and workload verification.
| Action | Admission / Preconditions | Execution owner | Success criterion | Failure / recovery |
|---|---|---|---|---|
| Create Platform | Resolvable profile + provider/target inputs | Factory operation executor | Observed target matches desired profile | PLAN_FAILED / retry / recovery path |
| Import Cluster | Identity + access + capability discovery | Import workflow | Registered target with observed capabilities | Conflict requires operator resolution |
| Deploy Application | Immutable release + binding + policy | Forgejo/Argo + bounded executor | Observed deployment/service evidence | Unknown result is not blindly retried |
| Replace Node | Exact node identity + safety admission | Leased/fenced operation | Replacement ready; old node safely removed | Lease loss → retry wait or operator |
| Upgrade | Compatibility + health + evidence gate | Distribution-aware workflow | Observed version/capability health | Rollback only where real |
| Disconnected Delivery | Source lock + digest + inventory | acquire/mirror workflow | Target artifact identity matches sealed inventory | Mismatch fails closed |
Failure states: PLAN_FAILED / FAILED / ROLLBACK_FAILED / NEEDS_OPERATOR / CANCELLED. Retry applies only to allowed failure classes; rollback is claimed only where the workflow supports it.
Operator surface
The operator works with targets, fleet, releases and lifecycle actions rather than per-cluster tribal procedures.
Managed RKE2, OKD or existing Kubernetes.
Read distribution identity and native capabilities.
Version reusable platform capability.
Bind immutable release to an environment.
Change infrastructure membership safely.
Use distribution-aware admission and verification.
Seal acquisition through zot and oc-mirror v2.
Policy, run, drill and restore on the target.
Reconcile observed state and surface operator-required cases.
4SO owns the product lifecycle; the target keeps the native semantics that make it trustworthy.