Source & software factory
Workshop and loading dock
Agents may build in disposable workers. GitLab runners independently rebuild, test and sign before promotion.
This is a deliberately opinionated Greenfield stack: AWS and EKS, an integrated Microsoft workplace, open delivery and data protocols, managed stateful substrates, and no autonomous production write path.
Workshop and loading dock
Agents may build in disposable workers. GitLab runners independently rebuild, test and sign before promotion.
PostgreSQL is the default system of record because transactions, SQL, extensions and exportability are excellent. S3 holds large immutable objects. Telemetry stores absorb high-volume time series. Search indexes are disposable projections. Each choice has an explicit exit and recovery path.
The existing EKS/Copier target and managed service depth outweigh theoretical multicloud portability.
Cloudflare for workforce edge; open protocols for exit.A standardized runtime makes templates, policy, telemetry and recovery repeatable.
Do not put mail, IdP, source control or every database inside it.Explicit cloud plans plus continuous cluster reconciliation, with no field overlap.
Defer Crossplane until self-service demand repays another controller estate.Under 300 users it bundles Entra P1, Intune, Defender, mail, documents and Teams for $22/user/month.
Intune does manage macOS; add Jamf only for measured depth gaps.Managed transactional truth, cheap durable objects and one selected data orchestrator.
OpenMetadata supplies context; OpenLineage supplies portable runtime events.Factories change faster than the control contracts around them.
No agent directly approves, signs or deploys its own output.