Sari la conținut

Kubernetes Platform — Tender Response Library (World-Bank-grade)

Acest conținut nu este încă disponibil în limba selectată.

Reusable across tenders. The methodology, component catalogue, DevSecOps model, SSO/management design, standards references and measurable non-functional requirements for a production Kubernetes platform, written to the evidentiary bar a World Bank “Information Systems” procurement expects. No commands — this is the approach document. The engineering “how” lives in [[Kubernetes-Platform-Production-Install-Guide]].

How to use. Lift the relevant section into a bid; adapt every target to what the tender demands and what the awarded architecture actually supports. We win on traceable evidence, not adjectives — the Requirement Traceability Matrix (§7) is the spine.

Sibling libraries: [[Database-Tender-NFR-Responses]] · [[PostgreSQL-HA-Production-Install-Guide]]. Last revised: 2026-07-25.

⚠️ Scope caveat (read first). A World Bank Information Systems SPD bid is roughly half non-technical: implementation methodology & timeline, staffing & CVs, past performance, SLA/support model, training & handover, warranty, and the financial envelope. This library covers the technical component only. Assemble the rest of the bid around it.

⚠️ Version & license currency. Component versions and licences change. Re-validate each at bid submission (support window, EOL, licence). Three current flags carried through this document: HashiCorp Vault is BSL (evaluate OpenBao, OSI-licensed), MinIO CE is effectively EOL (SeaweedFS / Garage / Rook-Ceph RGW), Redis 8 is AGPLv3 (Valkey, BSD).


1. Reference architecture (one paragraph for the evaluator)

Section titled “1. Reference architecture (one paragraph for the evaluator)”

A self-managed, CNCF-conformant Kubernetes platform: 3 control-plane nodes with stacked etcd behind a highly-available API virtual IP, and 6–9 worker nodes, on the latest supported Kubernetes minor. Networking is Cilium (eBPF, kube-proxy-free, identity-based and L7 network policy, Hubble observability); storage is Longhorn replicated block storage on dedicated disks with off-cluster backups; north-south traffic uses Gateway API with cert-manager (internal CA + public ACME); delivery is GitOps with ArgoCD; secrets are centralised in Vault/OpenBao with dynamic credentials and an internal PKI; security and multi-tenancy are enforced by Kyverno + Pod Security Admission + default-deny network policy; observability is the VictoriaMetrics stack with SLO alerting and a dead-man’s-switch; and all authentication — the Kubernetes API and every management console — federates to Keycloak (OIDC/SAML, groups→RBAC, MFA). Everything is open-source and standards-based, deployed as Infrastructure-as-Code, and independently verifiable (CNCF conformance, CIS benchmark, SBOM, signed images).


Each platform component, its technology, purpose, HA approach, governing standard, and licence (the open-standards / anti-lock-in column a World Bank evaluator scores).

#ComponentTechnology (re-validate version)PurposeHA approachStandardLicence
1Orchestration / control planeKubernetes (RKE2 / Talos / kubeadm); containerd + runcConformant orchestration substrate3 control-plane, odd etcd quorum, API VIP, CP taintCNCF Certified Kubernetes; CIS K8s Benchmark; NSA/CISA Hardening GuideApache-2.0 ✅
2API-server VIPkube-vip (ARP/BGP) / HAProxy+KeepalivedStable HA API endpoint, in cert SANsLeader-elected/advertised VIP, /readyz probekubeadm HA topologyApache-2.0 ✅
3CNI / dataplaneCilium (eBPF) + HubblePod networking, in-eBPF service LB, identity/L7 policy, flow visibilityDaemonSet + operator, kube-proxy-freeCNCF Graduated; NIST 800-207 ZT; NetworkPolicy/Gateway APIApache-2.0 ✅
4Service LoadBalancerCilium LB-IPAM + BGP (ECMP/BFD); MetalLB fallbackOn-prem LoadBalancer VIPs, true multi-node spreadBGP/ECMP + BFD sub-second failover; one announcer/poolBGP host routesApache-2.0 ✅
5Ingress / API gatewayGateway API via Cilium/Envoy Gateway (ingress-nginx legacy)North-south HTTP/gRPC routing, role separation≥2 replicas, anti-affinity, PDB, externalTrafficPolicy:LocalK8s Gateway API; NIST 800-204Apache-2.0 ✅
6TLS / certificatescert-manager + Vault PKI + ACME DNS-01Automated internal/public cert issuance + renewalController + webhook; short-lived leafs; expiry alertingRFC 5280; ACME RFC 8555Apache-2.0 ✅
7Persistent storageLonghorn (V1 engine), dedicated disksReplicated block storage without external SAN3-way sync replication, node anti-affinity, S3/NFS backups, DR volumesCNCF Incubating; CSI; PV RetainApache-2.0 ✅
8GitOps deliveryArgoCD (HA) + ApplicationSets + Argo RolloutsDeclarative, auditable delivery; drift heal; progressive deliveryredis-ha 3+3, ≥2 server/repo, sharded controllerOpenGitOps 1.0; NIST SSDF PO.3/PS.1Apache-2.0 ✅
9Secrets managementVault → evaluate OpenBao + VSOCentral secrets, dynamic DB creds, internal PKI, audit3/5-node Raft quorum, auto-unseal, snapshotsNIST 800-57; FIPS 140-2/3 (HSM); OWASP ASVS V6Vault BSL ⚠️ / OpenBao MPL-2.0 ✅
10Policy / admissionKyverno + Pod Security Admission + cosign verifyImagesAdmission enforcement, tenant guardrails, signature verificationHA 3 admission replicas + separate controllersK8s Pod Security Standards; CIS; SLSA v1; NIST 800-190Apache-2.0 ✅
11Multi-tenant isolationNamespace-per-tenant (Kyverno generate) → Capsule → vClusterGraduated project isolationPer-tenant quota/RBAC/NetworkPolicy; vCluster for strong isolationK8s multi-tenancy; NIST 800-190 segmentation; ISO 27001 A.9Apache-2.0 ✅
12ObservabilityVictoriaMetrics stack + VictoriaLogs + OTel/Traces + GrafanaMetrics/logs/traces/dashboards/SLO alertingVMCluster RF≥2, HA Alertmanager, Watchdog + heartbeatOpenMetrics; OpenTelemetry OTLP; Google SRE SLOApache-2.0 ✅ (Grafana AGPLv3)
13Identity / SSOKeycloak (Operator + external PG) + kubelogin + oauth2-proxyOne IdP for the API and every UI, groups→RBAC2–3 clustered replicas, external HA PostgreSQLOIDC Core 1.0; SAML 2.0; NIST 800-63B AAL2Apache-2.0 ✅
14Private registryHarbor (+ mirror for air-gap)Signed images, SBOMs, cosign attestations, air-gap mirrorHA deployment + replicationOCI Distribution; SLSA provenanceApache-2.0 ✅
15Runtime threat detectionTetragon (or Falco)eBPF runtime security observability/enforcementDaemonSetNIST 800-190 runtime countermeasuresApache-2.0 ✅
16In-cluster PostgreSQLCloudNativePG (or CrunchyData PGO)Stage backing DB with failover + PITR1 primary + 2 replicas, WAL to object storageCNCF; PostgreSQL; RPO≤5m/RTO<30sApache-2.0 ✅
17In-cluster cacheredis-operator, Sentinel (Valkey)Cache/session store, HA1+2 replicas + 3 sentinelsRedis Sentinel quorumRedis 8 AGPLv3 ⚠️ / Valkey BSD ✅
18In-cluster brokerRabbitMQ Cluster Operator, RabbitMQ 4.xDurable messaging, quorum queues3-node cluster, Raft quorum queuesQuorum queuesMPL-2.0 ✅
19Object storageMinIO EOL ⚠️ → SeaweedFS / Garage / Rook-Ceph RGWS3-compatible storeErasure coding ≥4 drives, bucket replicationAWS S3 API compatMinIO AGPLv3+EOL ⚠️ / alternatives Apache/AGPL
20Platform backup / DRVelero (+ etcd snapshots + operator-native backups)k8s-native namespace/PVC backup + full-cluster DRCSI snapshots, off-site immutable reposISO 27031 continuityApache-2.0 ✅

(Every ⚠️ has a stated open-licence swap — this is the differentiator for an anti-lock-in bid.)


3. Management-plane access — SSO via Keycloak (a dedicated section)

Section titled “3. Management-plane access — SSO via Keycloak (a dedicated section)”

Every administrative console authenticates through a single identity provider (Keycloak), so access is centrally granted, revoked, MFA-enforced and audited — no per-tool local passwords in daily use. One reusable groups claim drives authorization everywhere; each tool is deny-by-default.

Management UIIntegrationAuthorization modelOperational note
Kubernetes API (kubectl)OIDC via apiserver Structured Auth Config + kubelogin (PKCE)RBAC bound to kind: Group (oidc: prefix)Short-lived tokens; no static kubeconfig certs in daily use
ArgoCD (GitOps)Native OIDCargocd-rbac-cm: default readonly, group→roleRequires a Keycloak group mapper
Grafana (dashboards)Native OAuthrole_attribute_strict, default ViewerStrict mapping mandatory
Vault / OpenBao (secrets)Native OIDCExternal groups → Vault policiesRecovery-key break-glass kept outside OIDC
pgAdmin (DB admin)Native OAuth2OIDC logs into pgAdmin; DB creds separateNo in-app roles; internal auth retained as sealed break-glass
Longhorn (storage)oauth2-proxy (no native auth)Gated on a Keycloak group; all-or-nothingA bare Ingress = full storage console — must be gated
RabbitMQ (broker)Native oauth2 pluginScopes → vhost/permission tagsaud must equal resource_server_id, not client id
MinIO Console (object store)Native OIDCpolicy JWT claim → accessNo claim = zero access
Hubble UI (network)oauth2-proxyGated on a Keycloak groupNo native auth
Kubernetes DashboardBearer token / oauth2-proxyInherits the user’s RBACReconsider deploying; HA oauth2-proxy mandatory

Resilience of the identity layer (state it — evaluators probe it). Because the Kubernetes API and the consoles depend on Keycloak, and Keycloak runs inside the platform, we design for its outage:

  • a sealed, offline break-glass cluster-admin certificate (expiry monitored) for API access when Keycloak is unavailable;
  • a documented, MFA-protected local-admin fallback per console (ArgoCD admin, Grafana admin, Vault recovery keys, pgAdmin internal);
  • Keycloak realm-as-code + its database in the platform DR plan (lose the realm = lose every client config);
  • oauth2-proxy in HA (≥2 replicas, shared session store) so the fronting layer is not itself a SPOF.

Security is built into every stage, not bolted on — a continuous, everything-as-code pipeline with blocking (not advisory) gates, mapped to recognised frameworks (NIST SSDF, CIS, OWASP, SLSA).

PhasePracticesTooling (representative)Framework
Plan & threat-modelSecurity-by-design reviews; security champions; requirements traced to standards; change management is the reviewed PR trailThreat-model templates, OWASP DSOMM maturity, ADRs, the RTM (§7)NIST SSDF PO; OWASP ASVS
Code & commitBlocking SAST + secret scanning in pre-commit and CI; peer review as the approval record; no plaintext secrets everSemgrep/CodeQL/Sonar; gitleaks/trufflehogSSDF PW; OWASP Top 10
Build & packageDistroless bases pinned by digest; SBOM (CycloneDX/SPDX); keyless-sign images + SBOMs; SLSA build-L3 provenance; hardened runnersSyft; cosign (Sigstore); TrivySLSA v1.0; SSDF PS
Test & scanSCA fail-on fixable CRITICAL/HIGH; IaC + manifest policy scan; CIS checks; fail the build to block promotionTrivy/Grype; Checkov + kube-linter; kube-bench; Trivy OperatorCIS K8s; NIST 800-190
Release & deployPull-based GitOps as the only path — Git is the sole source of truth, no kubectl/helm from pipelines or laptops; CI holds no cluster admin; drift auto-healedArgoCD (App-of-Apps/ApplicationSets, waves)OpenGitOps 1.0; SOC 2 CC8.1
Admission backstopAdmission-time guarantee that only signed, policy-compliant workloads run even if a gate is bypassed; policies unit-tested; Audit→Enforce; PSA restricted floorKyverno verifyImages + PSAPod Security Standards; SLSA
Progressive deliveryCanary/blue-green with automated SLI analysis that aborts on SLO breach; rollback = git revertArgo Rollouts (VictoriaMetrics AnalysisTemplate)Google SRE
Operate & respondFull-stack observability from day 0 with a dead-man’s-switch; probe real SLIs not L4; scheduled CIS + CVE scans; runbooks for low MTTRVictoriaMetrics + VictoriaLogs + OTel; kube-bench CronJobSSDF RV; SRE
Measure & improveTrack the four DORA keys against elite benchmarks; blameless post-mortems feeding pipeline + policyFour Keys / DORA dashboardsDORA / Accelerate

Supply chain & operations additions (from the completeness review): a private registry (Harbor) with an air-gap mirror and self-hosted Sigstore or key-pair signing where public Fulcio/Rekor is unreachable; runtime threat detection (Tetragon/Falco) to realise the NIST 800-190 runtime controls; a vulnerability-remediation SLA with a VEX process for triage (not just “we scan”); a golden-image / OS-patch pipeline (unattended-upgrades, kernel-CVE cadence, LTS EOL tracking); and Git repository HA/backup/mirror, because pull-GitOps makes the repo production-critical.


DomainOur approachStandard / evidence
Cluster hardeningCIS Kubernetes Benchmark baseline, remediated in risk order, re-scanned for driftCIS K8s Benchmark (kube-bench PASS report, target score)
API auditkube-apiserver audit logging shipped to VictoriaLogs (who-did-what)NSA/CISA logging; retained + reviewable
Secrets at restetcd secret encryption-at-rest (aescbc/secretbox or KMS/HSM)NIST 800-57; no plaintext secrets in etcd
Workload securityPod Security Admission restricted floor + Kyverno policies (forbid privileged, :latest, untrusted registries; require limits, non-root, labels) — and a policy forbidding downgrade of the PSA labelsPod Security Standards; CIS
Network isolationCilium identity-based policy; default-deny per namespace (with explicit CoreDNS egress) + cluster-wide backstop; host-firewall for hostNetworkNIST 800-207 ZT; NetworkPolicy
Zero-trust transitCilium transparent encryption (WireGuard/IPsec) + L7 policy — implemented, not “optional”NIST 800-207; 800-204 mTLS
Supply chainSigned images (cosign) + SBOM + SLSA provenance, enforced at admissionSLSA v1.0; NIST SSDF
RuntimeTetragon/Falco runtime detection; Trivy Operator in-cluster CVENIST 800-190
EdgeWAF (Coraza/ModSecurity) + rate-limiting for internet-facing servicesOWASP Top 10; NIST 800-204
IdentityKeycloak OIDC/SAML, groups→RBAC, MFA (AAL2) on admin groupsOIDC Core; NIST 800-63B

Tenancy honesty (state it). A namespace is not a hard security boundary — a shared kernel/node means a container escape can reach other tenants. For hostile-tenant isolation we use vCluster or per-tenant node pools, and we document the escape surface (privileged, hostPath, hostPID/IPC/Network, nodes/proxy, DaemonSet node access) the guardrails close.


StandardWhat it covers in this bid
CNCF Certified KubernetesOpen, portable, vendor-neutral API conformance (Sonobuoy evidence) — anti-lock-in
CIS Kubernetes BenchmarkControl-plane/node/policy hardening, machine-verified (kube-bench), version-matched
NSA/CISA Kubernetes Hardening Guide v1.2Architectural hardening: network separation, authn/authz, logging, upgrades
Kubernetes Pod Security StandardsPrivileged/baseline/restricted profiles as the in-tree workload floor
NIST SP 800-190Container security: image, registry, orchestrator, container, host countermeasures
NIST SP 800-204 / 204A / 204BMicroservices, service-mesh, API security: mTLS ZT, gateway policy, segmentation
NIST SP 800-218 (SSDF v1.1)DevSecOps practice mapping (PO/PS/PW/RV)
NIST SP 800-207Zero-trust architecture (identity-based policy, mTLS)
SLSA v1.0 + in-totoSupply-chain integrity: signed artifacts, build provenance
Sigstore cosign / CycloneDX / SPDXKeyless image + SBOM signing + transparency (Rekor)
ISO/IEC 27001:2022 (+27017/27018)Certified ISMS; cloud-security controls; PII protection
ISO/IEC 25010:2023 (SQuaRE)Neutral vocabulary for measurable NFRs (§7)
OWASP Top 10 / ASVS / DSOMMApp-sec verification + DevSecOps maturity backing the pipeline gates
OpenGitOps v1.0Declarative, versioned, pulled, continuously-reconciled delivery
DORA / AccelerateDelivery-performance metrics committed in the bid
OIDC Core 1.0 / SAML 2.0 / NIST 800-63BFederated SSO, groups→RBAC, MFA across the API and every UI
World Bank Procurement Framework / SPD (Information Systems) + STEPThe procurement instrument, two-envelope structure, evaluation, STEP workflow
Data protection (GDPR / national law) + WCAG 2.2Data sovereignty/residency; accessibility for any citizen-facing UI

7. Requirement Traceability Matrix & measurable NFRs (the spine)

Section titled “7. Requirement Traceability Matrix & measurable NFRs (the spine)”

Every non-functional requirement → the component that meets it → the standard → the numeric target → the evidence artefact (automated where possible). This is where a World Bank technical evaluation is scored.

#NFR (ISO 25010 characteristic)Target (calibrate per tender)Delivered byStandardEvidence artefact
A1Availability (reliability)Platform control-plane 99.9–99.95 %/month at the API VIP; app-tier per SLA. Honest for single-site on-prem — not five-nines3 CP + API VIP; HA layersSRE SLOSLO dashboard + burn-rate; uptime report
A2API latency (performance)apiserver read p99 ≤ 1 s; scheduling latency p99 ≤ targetHA control plane, etcd on NVMeSREVictoriaMetrics SLO dashboard
A3Fault toleranceTolerate loss of 1 control-plane and 1 worker with no service lossodd etcd quorum, topology spread, PDBsK8s HA topologyNode-drain/failover drill report
R1Recoverability — data (RPO)In-cluster PG RPO ≤ 5 min; external system-of-record per its Patroni design (RPO=0 option)CloudNativePG WAL archiving / external Patroni—PITR drill log
R2Recoverability — time (RTO)Automatic DB failover < 30 s; platform DR-restore RTO stated per tier (etcd/Longhorn/Vault/Keycloak)operators + platform DR runbookISO 27031Timed DR game-day report
R3Backup integrityBackup success ≥ 99 %; restore tested monthly; off-site immutable copies (3-2-1-1-0)Velero + etcd snapshots + operator backupsISO 27031Restore-test reports; Object-Lock config
S1Authentication100 % SSO via Keycloak; MFA on admin; 0 shared local passwords in daily useKeycloak OIDC everywhereNIST 800-63B AAL2Auth config review; Keycloak event logs
S2HardeningCIS Kubernetes Benchmark ≥ target score; drift re-scan cadencekube-bench, PSA, KyvernoCISkube-bench PASS/FAIL report
S3Supply chain100 % of prod images signed + SBOM’d; admission blocks unsigned; fixable CRITICAL/HIGH = 0 at releasecosign + Kyverno verifyImages + TrivySLSA v1; SSDFSigned digests, SBOMs, provenance, scan gates
S4Secrets0 plaintext secrets in Git/config; etcd secrets encrypted; rotation interval definedVault/OpenBao + VSO; etcd encryptionNIST 800-57gitleaks-clean; EncryptionConfiguration; audit log
S5Network isolationDefault-deny in 100 % of tenant namespaces; only authorised east-west flowsCilium policy + Kyverno generateNIST 800-207Policy coverage report; Hubble flows
M1Maintainability100 % config as IaC/GitOps; zero undocumented drift; minor patch ≤ 30 days of releaseArgoCD, IaCOpenGitOps; SSDFGit history; drift = 0 dashboard
M2Patch SLACritical CVE remediated ≤ 14 days; VEX-triagedTrivy Operator + patch pipelineNIST 800-190CVE dashboard + VEX records
O1ObservabilityMTTD ≤ 2 min; dead-man’s-switch green; alert coverage of all critical signalsVictoriaMetrics stackSREAlert inventory; Watchdog heartbeat
C1CapacityStated pod/node/tenant limits; CPU/IOPS peak < 70 % with headroom; storage alert 75/85 %sizing model + monitoringISO 25010Capacity forecast + load-test results
P1Performance/throughputMeet stated req/s and p99 latency under representative loadtuned platform + poolingISO 25010k6/Locust load-test report with thresholds
PO1Portability / anti-lock-inCNCF-conformant; 100 % open-source (with the OpenBao/Valkey/SeaweedFS swaps); portable across substratesopen stackCNCF conformanceSonobuoy report; licence column (§2)
L1Licence complianceEvery component OSI-approved or with a stated compliant swap; no EOL on the critical path§2 licence columnopen-source policy§2 catalogue as evidence
G1Data sovereignty / privacyData residency per national law/GDPR; documented retention vs erasureon-prem + policyGDPR; national lawDPIA; residency statement
G2AccessibilityCitizen-facing UIs meet WCAG 2.2 AAapp layerWCAG 2.2Accessibility audit

Evidence is automated wherever possible: Sonobuoy (conformance), kube-bench (CIS score), Trivy + Syft + cosign (supply chain), k6/Locust (performance thresholds), SLO dashboards and timed drill reports (availability/DR). A claim without a named artefact is not a claim we make.


8. Non-technical envelope (checklist — assemble separately)

Section titled “8. Non-technical envelope (checklist — assemble separately)”

A World Bank IS bid is scored on more than technology. Ensure the full bid also includes: implementation methodology & work plan (with a realistic timeline and milestones), staffing plan & CVs (certified Kubernetes engineers), past performance / references, the SLA & support model (severity matrix, coverage, response/resolution), training & knowledge-transfer / handover, warranty & defect-liability, risk register & mitigation, and the financial proposal — kept in the correct envelope per the two-envelope evaluation.


Companion engineering guide (the “how”, with commands & scripts): [[Kubernetes-Platform-Production-Install-Guide]]. Grounded in the team’s real clusters (docs/K8S-U2/, docs/CG-Stage/) and a 2026-07 multi-agent best-practice research pass with an adversarial completeness review. Keep targets honest and evidence-backed — that is what wins technical evaluations. Last revised 2026-07-25.