1. Kubernetes Cluster Design
Cluster
├─ Node Pool: General apps (API, web)
├─ Node Pool: Workers (rendering, queues)
├─ Node Pool: GPU (AI inference)
└─ Node Pool: Data plane add-ons
- Namespace separated by domain: `core`, `ai`, `ops`, `data`
- HPA according to CPU/RAM/queue depth
- PodDisruptionBudget for services critical
2. CI/CD + GitOps
Git push
-> CI (test/lint/build/security scan)
-> Build image + SBOM
-> Push registry
-> Update manifest repo
-> ArgoCD sync to cluster
-> Progressive rollout (canary)
// Example deployment strategy
strategy:
type: RollingUpdate
rollingUpdate:
maxSurge: 25%
maxUnavailable: 0
3. Secrets & IaC
- Secrets: Vault/External Secrets Operator
- IaC: Terraform modules for network, cluster, DB, CDN
- Policy as code: OPA/Gatekeeper
4. Multi-region Deployment
| Region | Role |
|---|---|
| US | Primary traffic + AI inference |
| EU | Data residency + low latency EU |
| APAC | Regional storefront + async workers |
Routing: Geo DNS + health checks
Data: primary region + read replicas + async replication
Failover: RTO < 30 min, RPO < 5 min
5. Cost Optimization
- Spot instances for batch workers
- Scale-to-zero with intermittent jobs
- Reserved capacity for stable workload
- Image optimization + CDN offload to reduce egress
6. Summary
Hierarchical cluster helps optimize performance and costs
GitOps Increase control and rollback ability
Multi-region is an important requirement when expanding globally
Cost optimization need to design from the beginning