π Capstone Project: The Self-Service Cloud Engine
Welcome to the definitive Capstone Portfolio Project: The Self-Service Cloud Engine.
This end-to-end project unifies all 8 phases of the curriculum into an enterprise-ready, multi-cloud platform that you can build, deploy, and showcase in staff-level architectural interviews.
π― Architectural Mission Statement
Build a zero-touch, developer-centric internal cloud platform where an engineer can request a production-ready, secure, and compliant microservice (including AWS RDS database, Redis cache, CI/CD pipeline, and DNS) via a self-service web portal, and have it fully operational in under 3 minutesβall governed by strict enterprise compliance, immutable Golden AMIs, GitOps, and Zero-Trust eBPF security.
πΊοΈ Master Architecture Diagram
flowchart TD
Dev["π¨βπ» Application Developer"] -->|1. Selects Golden Path Template| IDP["<b>Spotify Backstage (IDP)</b><br/>β’ Self-Service Scaffolder<br/>β’ Software Catalog & TechDocs"]
subgraph ControlPlanePipeline ["Orchestration & Governance Layer"]
IDP -->|2. Creates Repo & CI/CD| Git["π GitHub Enterprise Fleet Repo"]
Git -->|3. Pulls GitOps Commits| ArgoCD["<b>ArgoCD (App-of-Apps)</b><br/>β’ Continuous Reconciliation<br/>β’ Sync Waves & Self-Healing"]
ArgoCD -->|4. Provisions Cloud Resources| Crossplane["<b>Crossplane Control Plane</b><br/>β’ Custom XRDs & Compositions<br/>β’ AWS Provider"]
end
subgraph InfrastructureLayer ["Multi-Account AWS Infrastructure"]
Crossplane -->|5. Provisions Managed DB| RDS[("AWS RDS PostgreSQL<br/>(Private Subnet, Multi-AZ)")]
subgraph EKSCluster ["βΈοΈ AWS EKS Workload Fleet"]
Karpenter["<b>Karpenter JIT Autoscaler</b><br/>β’ Provisions Graviton Spot Instances<br/>β’ Bypasses ASGs"]
Cilium["<b>Cilium eBPF Service Mesh</b><br/>β’ Zero-Trust L7 Network Policies<br/>β’ mTLS & Hubble Observability"]
WorkloadPod["π Microservice Workload Pod<br/>β’ IRSA IAM Identity<br/>β’ Vault Agent Secrets"]
Karpenter --> WorkloadPod
Cilium --> WorkloadPod
end
ALB["βοΈ AWS Application Load Balancer<br/>(Direct Pod IP Routing via AWS VPC CNI)"] --> WorkloadPod
end
subgraph SecurityObservability ["Enterprise DevSecOps & Governance"]
TrivyCosign["Trivy Vulnerability Scan & Cosign Keyless Sign"]
Vault["HashiCorp Vault Dynamic Database Credentials"]
Prometheus["Prometheus, PromQL & Grafana Dashboards"]
ArgoRollouts["Argo Rollouts (Progressive Canary Releases)"]
end
WorkloadPod --> Vault
WorkloadPod --> RDS
Prometheus --> ArgoRollouts
π Comprehensive Phase-by-Phase Integration
| Phase | Technology | Role in Capstone Engine |
|---|---|---|
| Phase 0 | Linux, Bash, Docker, Networking | Containerizes services with minimal multi-stage base images, non-root users, and calculates VPC CIDR blocks without IP exhaustion. |
| Phase 1 | AWS Organizations, TGW, RAM | Isolates networking into a Central Hub VPC with centralized NAT Gateway egress shared across Workload accounts via AWS RAM. |
| Phase 2 | Terragrunt, Checkov, OPA | Provisions base landing zone infrastructure using DRY Terragrunt modules with pre-merge Checkov security gates. |
| Phase 3 & 3B | Trivy, Cosign, Packer, CIS | Enforces immutable Golden AMIs hardened to CIS Level 1, signs container images with Cosign, and enforces Kyverno admission controls. |
| Phase 4 | EKS, Karpenter, AWS ALB | Provisions JIT EC2 Spot compute in under 45 seconds using Karpenter, routing traffic via AWS Load Balancer Controller directly to Pod IPs. |
| Phase 5 | ArgoCD, Argo Rollouts, Crossplane | Manages application lifecycles via GitOps App-of-Apps, executes progressive Canary releases, and provisions AWS RDS via Kubernetes YAML. |
| Phase 6 | Cilium & eBPF | Enforces Zero-Trust Layer 7 HTTP network policies, transparent mTLS encryption, and real-time flow tracing via Hubble. |
| Phase 7 | Backstage IDP | Provides developers with a single pane of glass to scaffold microservices and view ownership in the Software Catalog. |
| Phase 8 | LiteLLM & Milvus | Connects internal AI microservices through an enterprise AI Gateway with automated multi-model fallbacks and RAG semantic search. |
ποΈ Step-by-Step Implementation Guide
Step 1: Enterprise Account Hierarchy & Central Networking
- Create an AWS Organization with separate OUs:
Core-Infrastructure,Security, andWorkloads. - Deploy a centralized Egress VPC with public subnets, NAT Gateways, and an AWS Transit Gateway (TGW) in the Network Hub account.
- Share the TGW with the Workloads account using AWS Resource Access Manager (RAM).
- Verify routing: Route all private spoke subnet outbound traffic (
0.0.0.0/0) over the TGW attachment.
Step 2: The EKS Cluster & Karpenter Fleet
- Provision the EKS cluster using Terraform/Terragrunt with the AWS VPC CNI configured with secondary CIDRs (
100.64.0.0/16) to prevent IP exhaustion. - Deploy the Karpenter Controller using Helm with an IAM Role for Service Accounts (IRSA).
- Configure
NodePoolandEC2NodeClassresources with Graviton (arm64) Spot instances and disruption consolidation enabled. - Verify: Deploy a test workload with 50 replicas and confirm that Karpenter boots new EC2 instances in under 45 seconds.
Step 3: Zero-Trust Service Mesh with Cilium
- Install Cilium in
kubeProxyReplacement=truemode. - Enable transparent WireGuard encryption and Hubble network observability.
- Deploy a
CiliumNetworkPolicyenforcing default-deny ingress and egress, allowing only specific L7 HTTP routes and FQDN egress.
Step 4: Universal Cloud Control Plane (Crossplane)
- Install Crossplane and the AWS Upbound Provider using ArgoCD.
- Author an
XPostgreSQLInstanceComposite Resource Definition (XRD) and an enterprise-compliant Composition that creates an encrypted, multi-AZ RDS database. - Deploy a developer
Claimand verify that AWS RDS provisions and returns a connection secret directly into the application namespace.
Step 5: Self-Service Developer Portal (Backstage)
- Deploy Spotify Backstage using the community Helm chart.
- Author a
template.yamlfor a Production FastAPI service with GitHub repository creation, automated GitHub Actions CI/CD (Trivy + Cosign), and ArgoCD application registration. - Execute the template in the UI and verify that a full production app is running live in the cluster in under 3 minutes!
π€ Interview Presentation Strategy
When presenting this Capstone in an executive architectural interview: 1. Lead with the Business Value: "Before this engine, provisioning an app took 3 weeks of Jira tickets across 4 teams. With this engine, lead time dropped to 90 seconds while eliminating 100% of hardcoded credentials and cutting cloud compute costs by 70% using Karpenter Spot fleets." 2. Defend your Trade-offs: Be prepared to explain why you chose Cilium eBPF over Istio (sidecar-less memory savings), why you chose Karpenter over Cluster Autoscaler (speed and native Spot orchestration), and why you chose Crossplane over Terraform CI pipelines (declarative Kubernetes reconciliation).