Kubernetes Architecture and Deployment Model

This chapter provides a technical reference for the Kubernetes deployment model underlying the AppViewX platform.

Component Topology

Category Key Services Description
Core Platform config-server, platform-core, platform- gateway, platform-web, platform- queue Central business logic, REST API gateway, web UI, and async task processing.
Subsystems policy-engine, ssh-server, code-signing, kube-clm, subsystem-sync Module-specific logic for PKI, SSH, code signing, Kubernetes CLM.
Vendor Integrations ~50+ avx vendor * plugins Device-specific connectors for ADC vendors, CA systems, and cloud providers.
Python Sandboxes avx python sandbox* Isolated execution environments for custom workflow scripts.
Infrastructure MongoDB, Redis, OpenBao Primary data store, caching, and secret management.
Service Mesh Istio base, istiod, gateway mTLS, traffic management, circuit-breaking, and observability.
Maintenance Jobs avx-dbmigration, crypt-migration-job Database schema and cryptographic migration Jobs.

Kubernetes Resource Types

Resource Usage
Deployment Core platform microservices (~100+ workloads).
StatefulSet MongoDB replica set, Redis Sentinel, OpenBao HA.
DaemonSet NodeLocalDNS, log shipping agents.
Job DB migrations, crypto migrations.
HorizontalPodAutoscaler Auto-scaling for aggregator and sync services.
Service ClusterIP / Headless services for inter-pod communication.
Gateway / VirtualService Istio traffic routing with timeouts and retries.
DestinationRule Istio circuit-breaking and load balancing policies.
ConfigMap Platform properties, avx-common-config.
Secret TLS certificates, Vault secret IDs, credentials.
PersistentVolumeClaim Backup staging, stateful service storage.
ServiceAccount Per-plugin RBAC identity.
ClusterRole/Binding Cluster-level resource access for platform operations.
NetworkPolicy Zero-trust traffic segmentation (default-deny model).
PodDisruptionBudget Availability guarantees for Redis and OpenBao.
PriorityClass Scheduling priority for critical pods.

Service Mesh (Istio)

Feature Configuration Purpose
mTLS PeerAuthentication STRICT All pod-to-pod traffic requires mutual certificate auth.
VirtualService Per-plugin Helm template HTTP route rules, timeouts, and retry config per service.
DestinationRule Per-plugin Helm template Circuit-breaking, connection pool limits, load balancing.
Gateway istio-ingressgateway External traffic entry into the platform namespace.
Secret TTL ISTIO SECRET TTL in appviewx.conf Rotation interval for Istio mTLS certificates.

Stateful Services

Service HA Configuration Key CLI Operations
MongoDB Replica Set: 1 primary + secondaries + optional arbiter --db-backup, --db-restore, --set-db-cache-size, --mongo- replicaset-reconfiguration
Redis Sentinel mode with DC-aware failover --setup-redis-dc-priority priority
OpenBao HA mode (appviewx openbao ha chart) --vault-backup, --vault-restore, --vault-sync-status, --kek enable|disable