Layer stack · 05 of 10 · Multi-cloud platform

One platform surface across AWS and OCI

Teams claim a capability once. Only the compositions layer knows whether that is AWS or OCI, so business lines converge on one surface and differ only where regulation or workload genuinely requires it.

One platform surface across AWS and OCI Layer stack from foundations at the bottom through GitOps delivery, cloud-specific Crossplane compositions, the golden-path API and business lines at the top, marking Terraform below and Crossplane plus ArgoCD above, with cloud differences confined to the compositions layer. L5Business linesMogo lending · Carta payments · Intelligent InvestingIntelligent InvestingCartaMogoL4Golden-path APIone typed abstraction per capabilitySecretsQueuePostgreSQLApplicationL3Compositionscloud specifics live here and nowhere elseOCIAWSL2GitOps deliveryper-cluster repos · lower/upper AppProject boundaryper-cluster repoKyvernoArgoCDL1Foundationsaccounts · networks · clusters · IAM rootsOKEEKSTerraformTERRAFORM BELOW · CROSSPLANE + ARGOCD ABOVEABSTRACTCONCRETELEGENDWhere clouds differShared across cloudsProvisioned onceTooling boundary

Requirement

Multi-cloud Kubernetes, IaC, GitOps. Serve every product line without a separate platform for each one; converge where they drifted for no reason.

Design choices

  • Terraform for foundations; Crossplane and Argo for everything above the cluster. State the boundary out loud.
  • PostgreSQL becomes RDS on AWS or OCI Database with the same claim.
  • Convergence is a queue: inventory drift, score justified vs accidental, converge the accidental.

Evidence and gap

Built in Hangar: the per-cluster repo decision, two ArgoCD instances per cluster, lower/upper AppProject boundary, generator-driven cluster bootstrap, a PostgreSQL component on CNPG. Gap: Hangar runs on kind and Apple container, not AWS or OCI.

Hangar · reference architecture