Skip to Content
InfrastructureKubernetesCluster Overview

Kubernetes Cluster Overview

The HIC workload platform runs on AWS EKS. All Helm chart deployments are managed with Helmfile using .gotmpl templates for environment-aware rendering.

FieldValue
PlatformAWS EKS
Kube contextkubernetes-moh
Deployment toolHelmfile
Charts locationinfra/kube-cluster/charts/
Production valuesvalues.moh.prod.yaml per chart

Namespace topology

The namespaces chart is the source of truth for all Kubernetes namespaces. Namespaces are grouped by domain:

Namespace groupServices
analyticsdbt, Prefect, Spark
data-storeStackGres (PostgreSQL), MinIO, Valkey
monitoringPrometheus, Grafana, Alertmanager
infracert-manager, external-secrets, Istio, SSO, RBAC
appsGreenRiver, Superset, JupyterHub

Service mesh

Istio manages all internal service-to-service communication. It provides:

  • mTLS — all traffic between services is encrypted and mutually authenticated
  • Traffic policies — retries, circuit breaking, and timeouts configured per service
  • Ingress — Istio Gateway handles all external traffic entering the cluster

Explore further

Last updated on