In my previous role I wanted to try Crossplane on one small, well-understood resource: a secret store. That proof of concept never happened. In Hangar the same idea became Airframe's first real cross-cluster API.
Planned, never built
One claim, two outputs: an Azure Key Vault and an External Secrets SecretStore pointing at it. Small enough to learn on, useful enough to matter.
Built
First live on 2026-08-17 behind a small operator of my own.
Since September, provider-infisical (my own Upjet provider) does the provisioning, and the operator is retired.
A per-environment store narrows a secret to exactly one namespace.
What it taught me
A namespaced XR can't compose a cluster-scoped resource in Crossplane v2, so the ClusterSecretStore rides inside a provider-kubernetes Object. And a secret store must never be deleted just because its request was.