Skip to Content
The HIC Learning Exchange begins July 13, 2026. View the agenda
InfrastructureKubernetesCluster Overview

Kubernetes Cluster Overview

The HIC workload platform runs on AWS EKS. All Helm chart deployments are managed with Helmfile using .gotmpl templates for environment-aware rendering.

FieldValue
PlatformAWS EKS
Kube contextkubernetes-moh
Deployment toolHelmfile
Charts locationinfra/kube-cluster/charts/
Production valuesvalues.moh.prod.yaml per chart

Namespace topology

The namespaces chart is the source of truth for all Kubernetes namespaces. Namespaces are grouped by domain:

Namespace groupServices
analyticsdbt, Prefect, Spark
data-storeStackGres (PostgreSQL), MinIO, Valkey
monitoringPrometheus, Grafana, Alertmanager
infracert-manager, external-secrets, Istio, SSO, RBAC
appsGreenRiver, Superset, JupyterHub

Service mesh

Istio manages all internal service-to-service communication. It provides:

  • mTLS — all traffic between services is encrypted and mutually authenticated
  • Traffic policies — retries, circuit breaking, and timeouts configured per service
  • Ingress — Istio Gateway handles all external traffic entering the cluster

Explore further

Last updated on