Skip to content

Lesson 3: Universal Control Planes with Crossplane

🧠 The Concept (Explain Like I'm 5)

In standard cloud architectures, developers need two completely separate tools to launch an app: 1. Terraform: To provision an AWS PostgreSQL database or S3 bucket. 2. Kubernetes (kubectl / Helm): To deploy the application containers.

Crossplane turns your Kubernetes cluster into a Universal Cloud Control Plane. Developers define an AWS RDS Database using standard Kubernetes YAML. The cluster reaches out to AWS, provisions the database, grabs the credentials, and hands them to the application—all in the same GitOps workflow!


🏢 The Enterprise Context

  • XRDs (Composite Resource Definitions): Platform architects don't let developers write raw AWS RDS parameters (which have 100+ complex settings like VPC peering, KMS keys, multi-AZ, and backup retention). The platform team publishes an opinionated custom API: kind: PostgreSQLInstance.
  • Compositions: The behind-the-scenes template written by platform engineers that binds the simple PostgreSQLInstance into an enterprise-compliant, encrypted, multi-AZ AWS RDS cluster with monitoring enabled.

🗺️ Visual Architecture: Crossplane XRD & Composition Hierarchy

flowchart TD
    Dev["👨‍💻 App Developer"] -->|Applies clean abstraction| Claim["<b>Claim: SQLDatabase</b><br/>spec: storage: 50Gi, env: prod"]

    subgraph PlatformEngineers ["Platform Architecture Guardrails (Crossplane)"]
        XRD["<b>XRD: CompositeResourceDefinition</b><br/>(Validates OpenAPI Schema)"]
        Comp["<b>Composition</b><br/>(Templates AWS RDS, SubnetGroup, KMS Key)"]
    end

    Claim --> XRD
    XRD --> Comp
    Comp --> ProviderAWS["Crossplane AWS Provider"]
    ProviderAWS --> RealRDS[("☁️ AWS RDS Database<br/>(Encrypted, Multi-AZ)")]

💻 Production Code: Crossplane Composition Example

apiVersion: apiextensions.crossplane.io/v1
kind: Composition
metadata:
  name: enterprise-postgresql-aws
  labels:
    provider: aws
    db: postgresql
spec:
  compositeTypeRef:
    apiVersion: platform.enterprise.corp/v1alpha1
    kind: XPostgreSQLInstance
  resources:
    - name: rds-instance
      base:
        apiVersion: database.aws.upbound.io/v1beta1
        kind: RDSInstance
        spec:
          forProvider:
            engine: postgres
            engineVersion: "16.1"
            instanceClass: db.m6i.large
            allocatedStorage: 50
            storageEncrypted: true
            publiclyAccessible: false
            skipFinalSnapshot: false