Chuyển đến nội dung chính

Lesson 22: Infrastructure & DevOps — Kubernetes, CI/CD & Multi-region

Production infrastructure for Fashion POD — Kubernetes cluster design, CI/CD GitOps, multi-region deployment, secrets management, IaC and cost optimization.

🏗️ Architecture — Lesson 22 Lesson 22: Infrastructure & DevOps — Kubernetes, CI/CD & Multi-region

Fashion Design & Print-on-Demand System Architecture — From Domain Analysis to Production

Part 7: Operations, Security & Scale

xdev.asia

1. Kubernetes Cluster Design

Cluster
  ├─ Node Pool: General apps (API, web)
  ├─ Node Pool: Workers (rendering, queues)
  ├─ Node Pool: GPU (AI inference)
  └─ Node Pool: Data plane add-ons
  • Namespace separated by domain: `core`, `ai`, `ops`, `data`
  • HPA according to CPU/RAM/queue depth
  • PodDisruptionBudget for services critical

2. CI/CD + GitOps

Git push
  -> CI (test/lint/build/security scan)
  -> Build image + SBOM
  -> Push registry
  -> Update manifest repo
  -> ArgoCD sync to cluster
  -> Progressive rollout (canary)
// Example deployment strategy
strategy:
  type: RollingUpdate
  rollingUpdate:
    maxSurge: 25%
    maxUnavailable: 0

3. Secrets & IaC

  • Secrets: Vault/External Secrets Operator
  • IaC: Terraform modules for network, cluster, DB, CDN
  • Policy as code: OPA/Gatekeeper

4. Multi-region Deployment

RegionRole
USPrimary traffic + AI inference
EUData residency + low latency EU
APACRegional storefront + async workers
Routing: Geo DNS + health checks
Data: primary region + read replicas + async replication
Failover: RTO < 30 min, RPO < 5 min

5. Cost Optimization

  • Spot instances for batch workers
  • Scale-to-zero with intermittent jobs
  • Reserved capacity for stable workload
  • Image optimization + CDN offload to reduce egress

6. Summary

  • Hierarchical cluster helps optimize performance and costs

  • GitOps Increase control and rollback ability

  • Multi-region is an important requirement when expanding globally

  • Cost optimization need to design from the beginning