Glossary
The jargon, in plain words
Platform engineering comes with a lot of names. Here's what each one on this site means, and why it matters in Hangar. Across the site, the first mention of a term on a page has a dotted underline: hover or tap it for the short version.
- ApplicationSet
An ArgoCD feature that generates many applications from one template, for example one per folder in git.
Onboarding a service is adding a file, not running a command.
- AppProject
An ArgoCD boundary that limits which repos, clusters and namespaces an application may touch.
It is what keeps a lower environment from writing into an upper one.
- Argo Rollouts
A Kubernetes controller for canary and blue/green releases.
A new version gets a slice of traffic first, and moves on only when it looks healthy.
- ArgoCD
The tool that watches a git repo and applies what it describes to a Kubernetes cluster.
In Hangar it is the only thing that writes to a cluster, and each cluster runs its own.
- Backstage
Spotify's open-source framework for internal developer portals.
Tower is a Backstage plugin, so Hangar lives where developers already look.
- Canary
Releasing a new version to a small share of traffic before everyone gets it.
Problems show up on a few requests instead of all of them.
- CDEvents
A standard format for software-delivery events, such as "build finished" or "service deployed".
Hangar chains pipeline stages with them, and counts DORA metrics from the same stream.
- CEL
Common Expression Language: a small, safe language for writing rules.
Autopilot and Kyverno both write policy in it, so there is one policy idiom.
- Claim
A small request against a Crossplane API: "I want a PostgreSQL database, size small".
Developers ask for outcomes in a few lines; the platform fills in the rest and keeps it that way.
- Composition
The recipe that turns a claim into the actual resources behind it.
Changing a Composition changes every service built from it, which is powerful and needs care.
- Composition Function
A small program Crossplane runs while composing, for logic a template cannot express.
Hangar uses them for things like watching a rollout and dispatching an AI diagnosis.
- Crossplane
A Kubernetes add-on that lets you define your own APIs and turns requests against them into real resources.
It's Hangar's platform API: people, portals, pipelines and agents all ask for things the same way.
- DORA metrics
Four measures of delivery performance: how often you deploy, how long a change takes, how often it fails, and how fast you recover.
They say whether the platform is actually saving anyone time.
- External Secrets
An operator that copies secrets from a store like Infisical into Kubernetes, and keeps them in sync.
Nobody applies a raw Secret by hand, and nothing secret lives in git.
- Fulcio
Sigstore's certificate authority: it issues a short-lived signing certificate to a proven identity.
Hangar runs its own so in-cluster build identities can sign.
- GitOps
Running systems from a git repository: the repo says what should be deployed, and an agent makes the cluster match.
Every change is a reviewed commit, and rolling back is a revert.
- gitsign
A tool that signs git commits with Sigstore, using your normal login instead of a key.
Release gates can check that a real, allowed person authorized the code.
- Helm
A package manager for Kubernetes: a chart is a template, values fill it in.
Every Hangar service deploys through one chart, so good defaults live in one place.
- Infisical
An open-source secrets manager with an API.
It is Hangar's single source for secret values.
- Kaniko
A tool that builds container images without needing a privileged Docker daemon.
Builds run under Kubernetes' strictest pod security, on any cluster.
- Kyverno
A Kubernetes policy engine that can allow, reject or change resources as they are created.
Hangar uses it where plain RBAC cannot express a rule.
- MCP
The Model Context Protocol: a standard way for AI agents to call tools.
Any agent runtime can use Hangar through it without a custom client.
- Pipelines-as-Code
A Tekton add-on that starts pipelines from git events: pushes, pull requests, comments.
It handles webhook signatures and PR status checks, which are easy to get wrong by hand.
- Provenance
A signed record of how an artifact was built: from which source, by which pipeline, with which steps.
It is the evidence a release gate reads before anything reaches production.
- Reconciliation
A controller repeatedly comparing what exists with what was asked for, and fixing the difference.
Great for things that should stay a certain way; the wrong tool for things that should happen once.
- Rekor
Sigstore's transparency log: a tamper-evident public record of signatures.
A signature you can't look up later is a claim, not evidence.
- SBOM
A software bill of materials: the list of everything inside an image.
When a new vulnerability lands, you can tell in minutes which services contain it.
- Sigstore
An open-source project for signing software with short-lived certificates instead of long-lived keys.
Nothing secret to leak, and every signature can be looked up later.
- SLO
A service level objective: a target like "99.5% of requests succeed over 30 days".
It turns "is it healthy?" into a number you can alert and decide on.
- SLSA
Supply-chain Levels for Software Artifacts: a framework for proving how a piece of software was built.
A release gate can check what the build really did, not just that it finished.
- Tekton
A CI/CD engine that runs pipelines as Kubernetes resources.
It runs anywhere Kubernetes does, and developers never have to write its YAML.
- TokenReview
A Kubernetes API that confirms who a pod is from the token the cluster gave it.
Services can trust a caller without Hangar handing out any keys.
- XRD
A CompositeResourceDefinition: the schema for a new Crossplane API, such as "a Node.js application".
It is the contract for what a compliant service is, defined once and checked on every request.