Service Mesh Platform  ·  View 22 of 31  ·  6 · Operations

Deployment Architecture

Three sites, three rooms per site, 20 clusters, and the site services each site runs for itself.

Editable source SVG draw.io All views
Site A · three rooms Seven workload clusters, each spread across rooms Room 1 istiod replica 1 SPIRE server replica 1 Workers sidecars · agents Room 2 istiod replica 2 SPIRE server replica 2 Workers sidecars · agents Room 3 istiod replica 3 SPIRE server replica 3 East-west gateways BGP VIP · ECMP Site services Argo CD site A clusters only OpenBao PKI 5 voters · 3 rooms Forgejo primary Harbor images · bundles Thanos · Tempo · ClickHouse site stores Sites B and C · same shape Thirteen clusters own istiod · SPIRE Site services Argo CD · OpenBao Forgejo mirror read-only Root CA vault room offline HSM · two keyholders Global views Thanos query · Grafana mTLS · SNI Deployment — Three Sites, Twenty Clusters, No Cross-Site Dependency In-Site Application we own Security / platform Interface / broker Data store synchronous A site cut off from the other two still changes, issues and serves for itself. Mirrors, global views and the yearly root ceremony pause. v 1.0 · owner Platform Networking Architecture · date 2026-09

Decisions

  • A room is the on-premise availability zone: separate power, cooling and top-of-rack switching. istiod, SPIRE server, OpenBao voters and gateway pods spread across three rooms with pod anti-affinity.
  • Every site runs its own Argo CD, OpenBao and telemetry stores. A site cut off from the other two still changes, issues and observes for itself.
  • Forgejo has one writable primary. The other sites hold read-only mirrors, so Argo CD in any site keeps applying the last merged intent during a site partition.

Targets

  • Loss of one room: no loss of mesh function. Control plane ≥ 99.9% monthly; mesh-attributable data path ≥ 99.99%.

Risks

  • If site A is lost, intent changes pause until a mirror is promoted to primary. That is a runbook step with an RTO of 15 minutes, not an automatic failover, because two writable Git primaries are worse than a short pause.