Skip to content

πŸ† Capstone Project: The Self-Service Cloud Engine

Welcome to the definitive Capstone Portfolio Project: The Self-Service Cloud Engine.

This end-to-end project unifies all 8 phases of the curriculum into an enterprise-ready, multi-cloud platform that you can build, deploy, and showcase in staff-level architectural interviews.


🎯 Architectural Mission Statement

Build a zero-touch, developer-centric internal cloud platform where an engineer can request a production-ready, secure, and compliant microservice (including AWS RDS database, Redis cache, CI/CD pipeline, and DNS) via a self-service web portal, and have it fully operational in under 3 minutesβ€”all governed by strict enterprise compliance, immutable Golden AMIs, GitOps, and Zero-Trust eBPF security.


πŸ—ΊοΈ Master Architecture Diagram

flowchart TD
    Dev["πŸ‘¨β€πŸ’» Application Developer"] -->|1. Selects Golden Path Template| IDP["<b>Spotify Backstage (IDP)</b><br/>β€’ Self-Service Scaffolder<br/>β€’ Software Catalog & TechDocs"]

    subgraph ControlPlanePipeline ["Orchestration & Governance Layer"]
        IDP -->|2. Creates Repo & CI/CD| Git["πŸ™ GitHub Enterprise Fleet Repo"]
        Git -->|3. Pulls GitOps Commits| ArgoCD["<b>ArgoCD (App-of-Apps)</b><br/>β€’ Continuous Reconciliation<br/>β€’ Sync Waves & Self-Healing"]
        ArgoCD -->|4. Provisions Cloud Resources| Crossplane["<b>Crossplane Control Plane</b><br/>β€’ Custom XRDs & Compositions<br/>β€’ AWS Provider"]
    end

    subgraph InfrastructureLayer ["Multi-Account AWS Infrastructure"]
        Crossplane -->|5. Provisions Managed DB| RDS[("AWS RDS PostgreSQL<br/>(Private Subnet, Multi-AZ)")]

        subgraph EKSCluster ["☸️ AWS EKS Workload Fleet"]
            Karpenter["<b>Karpenter JIT Autoscaler</b><br/>β€’ Provisions Graviton Spot Instances<br/>β€’ Bypasses ASGs"]
            Cilium["<b>Cilium eBPF Service Mesh</b><br/>β€’ Zero-Trust L7 Network Policies<br/>β€’ mTLS & Hubble Observability"]
            WorkloadPod["πŸš€ Microservice Workload Pod<br/>β€’ IRSA IAM Identity<br/>β€’ Vault Agent Secrets"]

            Karpenter --> WorkloadPod
            Cilium --> WorkloadPod
        end

        ALB["βš–οΈ AWS Application Load Balancer<br/>(Direct Pod IP Routing via AWS VPC CNI)"] --> WorkloadPod
    end

    subgraph SecurityObservability ["Enterprise DevSecOps & Governance"]
        TrivyCosign["Trivy Vulnerability Scan & Cosign Keyless Sign"]
        Vault["HashiCorp Vault Dynamic Database Credentials"]
        Prometheus["Prometheus, PromQL & Grafana Dashboards"]
        ArgoRollouts["Argo Rollouts (Progressive Canary Releases)"]
    end

    WorkloadPod --> Vault
    WorkloadPod --> RDS
    Prometheus --> ArgoRollouts

πŸ“‹ Comprehensive Phase-by-Phase Integration

Phase Technology Role in Capstone Engine
Phase 0 Linux, Bash, Docker, Networking Containerizes services with minimal multi-stage base images, non-root users, and calculates VPC CIDR blocks without IP exhaustion.
Phase 1 AWS Organizations, TGW, RAM Isolates networking into a Central Hub VPC with centralized NAT Gateway egress shared across Workload accounts via AWS RAM.
Phase 2 Terragrunt, Checkov, OPA Provisions base landing zone infrastructure using DRY Terragrunt modules with pre-merge Checkov security gates.
Phase 3 & 3B Trivy, Cosign, Packer, CIS Enforces immutable Golden AMIs hardened to CIS Level 1, signs container images with Cosign, and enforces Kyverno admission controls.
Phase 4 EKS, Karpenter, AWS ALB Provisions JIT EC2 Spot compute in under 45 seconds using Karpenter, routing traffic via AWS Load Balancer Controller directly to Pod IPs.
Phase 5 ArgoCD, Argo Rollouts, Crossplane Manages application lifecycles via GitOps App-of-Apps, executes progressive Canary releases, and provisions AWS RDS via Kubernetes YAML.
Phase 6 Cilium & eBPF Enforces Zero-Trust Layer 7 HTTP network policies, transparent mTLS encryption, and real-time flow tracing via Hubble.
Phase 7 Backstage IDP Provides developers with a single pane of glass to scaffold microservices and view ownership in the Software Catalog.
Phase 8 LiteLLM & Milvus Connects internal AI microservices through an enterprise AI Gateway with automated multi-model fallbacks and RAG semantic search.

πŸ—οΈ Step-by-Step Implementation Guide

Step 1: Enterprise Account Hierarchy & Central Networking

  1. Create an AWS Organization with separate OUs: Core-Infrastructure, Security, and Workloads.
  2. Deploy a centralized Egress VPC with public subnets, NAT Gateways, and an AWS Transit Gateway (TGW) in the Network Hub account.
  3. Share the TGW with the Workloads account using AWS Resource Access Manager (RAM).
  4. Verify routing: Route all private spoke subnet outbound traffic (0.0.0.0/0) over the TGW attachment.

Step 2: The EKS Cluster & Karpenter Fleet

  1. Provision the EKS cluster using Terraform/Terragrunt with the AWS VPC CNI configured with secondary CIDRs (100.64.0.0/16) to prevent IP exhaustion.
  2. Deploy the Karpenter Controller using Helm with an IAM Role for Service Accounts (IRSA).
  3. Configure NodePool and EC2NodeClass resources with Graviton (arm64) Spot instances and disruption consolidation enabled.
  4. Verify: Deploy a test workload with 50 replicas and confirm that Karpenter boots new EC2 instances in under 45 seconds.

Step 3: Zero-Trust Service Mesh with Cilium

  1. Install Cilium in kubeProxyReplacement=true mode.
  2. Enable transparent WireGuard encryption and Hubble network observability.
  3. Deploy a CiliumNetworkPolicy enforcing default-deny ingress and egress, allowing only specific L7 HTTP routes and FQDN egress.

Step 4: Universal Cloud Control Plane (Crossplane)

  1. Install Crossplane and the AWS Upbound Provider using ArgoCD.
  2. Author an XPostgreSQLInstance Composite Resource Definition (XRD) and an enterprise-compliant Composition that creates an encrypted, multi-AZ RDS database.
  3. Deploy a developer Claim and verify that AWS RDS provisions and returns a connection secret directly into the application namespace.

Step 5: Self-Service Developer Portal (Backstage)

  1. Deploy Spotify Backstage using the community Helm chart.
  2. Author a template.yaml for a Production FastAPI service with GitHub repository creation, automated GitHub Actions CI/CD (Trivy + Cosign), and ArgoCD application registration.
  3. Execute the template in the UI and verify that a full production app is running live in the cluster in under 3 minutes!

🎀 Interview Presentation Strategy

When presenting this Capstone in an executive architectural interview: 1. Lead with the Business Value: "Before this engine, provisioning an app took 3 weeks of Jira tickets across 4 teams. With this engine, lead time dropped to 90 seconds while eliminating 100% of hardcoded credentials and cutting cloud compute costs by 70% using Karpenter Spot fleets." 2. Defend your Trade-offs: Be prepared to explain why you chose Cilium eBPF over Istio (sidecar-less memory savings), why you chose Karpenter over Cluster Autoscaler (speed and native Spot orchestration), and why you chose Crossplane over Terraform CI pipelines (declarative Kubernetes reconciliation).