Kubernetes Architecture and Deployment Model
This chapter provides a technical reference for the Kubernetes deployment model underlying the AppViewX platform.
Component Topology
| Category | Key Services | Description |
|---|---|---|
| Core Platform | config-server, platform-core, platform- gateway, platform-web, platform- queue | Central business logic, REST API gateway, web UI, and async task processing. |
| Subsystems | policy-engine, ssh-server, code-signing, kube-clm, subsystem-sync | Module-specific logic for PKI, SSH, code signing, Kubernetes CLM. |
| Vendor Integrations | ~50+ avx vendor * plugins | Device-specific connectors for ADC vendors, CA systems, and cloud providers. |
| Python Sandboxes | avx python sandbox* | Isolated execution environments for custom workflow scripts. |
| Infrastructure | MongoDB, Redis, OpenBao | Primary data store, caching, and secret management. |
| Service Mesh | Istio base, istiod, gateway | mTLS, traffic management, circuit-breaking, and observability. |
| Maintenance Jobs | avx-dbmigration, crypt-migration-job | Database schema and cryptographic migration Jobs. |
Kubernetes Resource Types
| Resource | Usage |
|---|---|
| Deployment | Core platform microservices (~100+ workloads). |
| StatefulSet | MongoDB replica set, Redis Sentinel, OpenBao HA. |
| DaemonSet | NodeLocalDNS, log shipping agents. |
| Job | DB migrations, crypto migrations. |
| HorizontalPodAutoscaler | Auto-scaling for aggregator and sync services. |
| Service | ClusterIP / Headless services for inter-pod communication. |
| Gateway / VirtualService | Istio traffic routing with timeouts and retries. |
| DestinationRule | Istio circuit-breaking and load balancing policies. |
| ConfigMap | Platform properties, avx-common-config. |
| Secret | TLS certificates, Vault secret IDs, credentials. |
| PersistentVolumeClaim | Backup staging, stateful service storage. |
| ServiceAccount | Per-plugin RBAC identity. |
| ClusterRole/Binding | Cluster-level resource access for platform operations. |
| NetworkPolicy | Zero-trust traffic segmentation (default-deny model). |
| PodDisruptionBudget | Availability guarantees for Redis and OpenBao. |
| PriorityClass | Scheduling priority for critical pods. |
Service Mesh (Istio)
| Feature | Configuration | Purpose |
|---|---|---|
| mTLS | PeerAuthentication STRICT | All pod-to-pod traffic requires mutual certificate auth. |
| VirtualService | Per-plugin Helm template | HTTP route rules, timeouts, and retry config per service. |
| DestinationRule | Per-plugin Helm template | Circuit-breaking, connection pool limits, load balancing. |
| Gateway | istio-ingressgateway | External traffic entry into the platform namespace. |
| Secret TTL | ISTIO SECRET TTL in appviewx.conf | Rotation interval for Istio mTLS certificates. |
Stateful Services
| Service | HA Configuration | Key CLI Operations |
|---|---|---|
| MongoDB | Replica Set: 1 primary + secondaries + optional arbiter | --db-backup, --db-restore, --set-db-cache-size, --mongo- replicaset-reconfiguration |
| Redis | Sentinel mode with DC-aware failover | --setup-redis-dc-priority priority |
| OpenBao | HA mode (appviewx openbao ha chart) | --vault-backup, --vault-restore, --vault-sync-status, --kek enable|disable |
