Skip to content

Infrastructure

Hardware and software systems powering VIRDX work and R&D — cluster, CI/CD, data platform plumbing.

Hardware and software systems powering VIRDX work and R&D: the Kubernetes cluster (Argo Workflows, Tekton, Kyverno), image registry, CI/CD, and the plumbing behind the data platform.

SOPs (read first)

See sops/ — grouped by cluster operations, vxData, and apps/packaging. Highest-value entry points:

Access control

vxData access control (supersedes mono#90/#49) ships in two layers:

  • v1, shipped: static bearer tokens only (API_PRINCIPALS config), policy-scoped reads/writes in api/access.py / api/auth.py. Read scoping is baked into build_query_statement (parquet-safe); write gating declares payload_type on upload presigns. NULL license/access_level fails closed.
  • Keycloak/JWT hybrid, designed + built, deliberately parked (closed draft PRs, branches kept — reopening is “rebase”, not “redesign”). See vxData Keycloak/JWT extension (parked) for the full design and the exact PRs/order to reopen.

Notes

  • Agent skill argo-workflow-guide — low-level Argo/Kyverno mechanics.
Navigation

Type to search…

↑↓ navigate↵ selectEsc close