Hangar

Glossary

The jargon, in plain words

Platform engineering comes with a lot of names. Here's what each one on this site means, and why it matters in Hangar. Across the site, the first mention of a term on a page has a dotted underline: hover or tap it for the short version.

ApplicationSet

An ArgoCD feature that generates many applications from one template, for example one per folder in git.

Onboarding a service is adding a file, not running a command.

AppProject

An ArgoCD boundary that limits which repos, clusters and namespaces an application may touch.

It is what keeps a lower environment from writing into an upper one.

Argo Rollouts

A Kubernetes controller for canary and blue/green releases.

A new version gets a slice of traffic first, and moves on only when it looks healthy.

ArgoCD

The tool that watches a git repo and applies what it describes to a Kubernetes cluster.

In Hangar it is the only thing that writes to a cluster, and each cluster runs its own.

Backstage

Spotify's open-source framework for internal developer portals.

Tower is a Backstage plugin, so Hangar lives where developers already look.

Canary

Releasing a new version to a small share of traffic before everyone gets it.

Problems show up on a few requests instead of all of them.

CDEvents

A standard format for software-delivery events, such as "build finished" or "service deployed".

Hangar chains pipeline stages with them, and counts DORA metrics from the same stream.

CEL

Common Expression Language: a small, safe language for writing rules.

Autopilot and Kyverno both write policy in it, so there is one policy idiom.

Claim

A small request against a Crossplane API: "I want a PostgreSQL database, size small".

Developers ask for outcomes in a few lines; the platform fills in the rest and keeps it that way.

Composition

The recipe that turns a claim into the actual resources behind it.

Changing a Composition changes every service built from it, which is powerful and needs care.

Composition Function

A small program Crossplane runs while composing, for logic a template cannot express.

Hangar uses them for things like watching a rollout and dispatching an AI diagnosis.

Crossplane

A Kubernetes add-on that lets you define your own APIs and turns requests against them into real resources.

It's Hangar's platform API: people, portals, pipelines and agents all ask for things the same way.

DORA metrics

Four measures of delivery performance: how often you deploy, how long a change takes, how often it fails, and how fast you recover.

They say whether the platform is actually saving anyone time.

External Secrets

An operator that copies secrets from a store like Infisical into Kubernetes, and keeps them in sync.

Nobody applies a raw Secret by hand, and nothing secret lives in git.

Fulcio

Sigstore's certificate authority: it issues a short-lived signing certificate to a proven identity.

Hangar runs its own so in-cluster build identities can sign.

GitOps

Running systems from a git repository: the repo says what should be deployed, and an agent makes the cluster match.

Every change is a reviewed commit, and rolling back is a revert.

gitsign

A tool that signs git commits with Sigstore, using your normal login instead of a key.

Release gates can check that a real, allowed person authorized the code.

Helm

A package manager for Kubernetes: a chart is a template, values fill it in.

Every Hangar service deploys through one chart, so good defaults live in one place.

Infisical

An open-source secrets manager with an API.

It is Hangar's single source for secret values.

Kaniko

A tool that builds container images without needing a privileged Docker daemon.

Builds run under Kubernetes' strictest pod security, on any cluster.

Kyverno

A Kubernetes policy engine that can allow, reject or change resources as they are created.

Hangar uses it where plain RBAC cannot express a rule.

MCP

The Model Context Protocol: a standard way for AI agents to call tools.

Any agent runtime can use Hangar through it without a custom client.

Pipelines-as-Code

A Tekton add-on that starts pipelines from git events: pushes, pull requests, comments.

It handles webhook signatures and PR status checks, which are easy to get wrong by hand.

Provenance

A signed record of how an artifact was built: from which source, by which pipeline, with which steps.

It is the evidence a release gate reads before anything reaches production.

Reconciliation

A controller repeatedly comparing what exists with what was asked for, and fixing the difference.

Great for things that should stay a certain way; the wrong tool for things that should happen once.

Rekor

Sigstore's transparency log: a tamper-evident public record of signatures.

A signature you can't look up later is a claim, not evidence.

SBOM

A software bill of materials: the list of everything inside an image.

When a new vulnerability lands, you can tell in minutes which services contain it.

Sigstore

An open-source project for signing software with short-lived certificates instead of long-lived keys.

Nothing secret to leak, and every signature can be looked up later.

SLO

A service level objective: a target like "99.5% of requests succeed over 30 days".

It turns "is it healthy?" into a number you can alert and decide on.

SLSA

Supply-chain Levels for Software Artifacts: a framework for proving how a piece of software was built.

A release gate can check what the build really did, not just that it finished.

Tekton

A CI/CD engine that runs pipelines as Kubernetes resources.

It runs anywhere Kubernetes does, and developers never have to write its YAML.

TokenReview

A Kubernetes API that confirms who a pod is from the token the cluster gave it.

Services can trust a caller without Hangar handing out any keys.

XRD

A CompositeResourceDefinition: the schema for a new Crossplane API, such as "a Node.js application".

It is the contract for what a compliant service is, defined once and checked on every request.