Component Inventory Every deployed component, where it runs, and what it talks to
Every deployed component, where it runs, and what it talks to, with one row per box in the topology diagram.
# Edge
Component Kind Talks to Protocol agent-subdomain-proxyCloudflare Worker HTTP role via ALB HTTPS sandbox-preview-proxyCloudflare Worker Sandbox-proxy role via ALB HTTPS, WebSocket mscdn-rewriteCloudflare Worker Git role and HTTP role via ALB HTTPS api-host-rewriteCloudflare Worker HTTP role via ALB HTTPS ws-host-rewriteCloudflare Worker WS role via ALB WebSocket files-cdn-host-rewriteCloudflare Worker Public S3 buckets; HTTP role for waveforms HTTPS image-cdn-qs-rewritesCloudflare Worker Regional public S3 buckets HTTPS videos-cdnCloudflare Worker Public S3 buckets HTTPS Remy editor and console Cloudflare Workers HTTP and WS roles HTTPS, WebSocket Cloudflare for SaaS Managed agent-subdomain-proxy fallback originHTTPS
# Trusted VPC: ingress
Component Kind Talks to Protocol Application Load Balancer AWS ALB, internet-facing, TLS 1.3 FIPS HTTP, WS, git, sandbox-proxy roles by IP HTTP Network Load Balancer AWS NLB, internet-facing Mail-inbound pods by IP SMTP
The platform is one container image, started with a role flag and deployed as separate roles. Each role below is a Kubernetes Deployment on the trusted cluster.
Role Kind Talks to HTTP API Deployment Aurora, Valkey, S3, SQS, Firehose, orchestrator, app-db, git, providers WebSocket Deployment Aurora, Valkey, app-db Worker fleet, general pool Deployment SQS, Aurora, Valkey, S3, SES, providers, content inspection Worker fleet, bulk pool Deployment SQS bulk queue, S3, Qdrant, embedding providers Git Deployment S3, Valkey, Aurora, orchestrator App-database Deployment S3, Valkey, Aurora Mail-inbound Deployment and Service Aurora, execution path Sandbox-proxy Deployment Dev boxes over peering, Aurora Provisioner Deployment, one replica Trusted Kubernetes API, Aurora, SQS Sandbox-orchestrator Deployment Untrusted Kubernetes API over peering, Valkey Voice worker Deployment, own image LiveKit, model providers, HTTP role Platform migration Job Aurora
Every role reaches AWS through Pod Identity, which maps its Kubernetes identity to an IAM role. Most roles share one identity; the provisioner and the sandbox-orchestrator each run under their own, scoped to the one cluster each is allowed to reach.
Component Kind Talks to ClamAV Deployment and Service Worker pods Presidio analyzer and anonymizer Deployments and Services Worker and HTTP pods Shared Qdrant StatefulSet and Service, own node group HTTP and worker pods Dedicated Qdrant StatefulSet and Service per resource, isolated namespace HTTP and worker pods Tuned-model serving pool Deployment and Service, GPU node group HTTP role; S3 for weights and adapters Model trainer KEDA ScaledJob, GPU node group SQS training queue, S3, HTTP role callback External Secrets Operator Helm Parameter Store KEDA Helm SQS Cluster autoscaler Helm EC2 Auto Scaling AWS Load Balancer Controller Helm ALB and NLB External DNS Helm Route 53 OpenTelemetry collector Helm Trace and metric backends NVIDIA device plugin DaemonSet, GPU nodes
# Trusted VPC: data plane
Component Kind Aurora PostgreSQL 17 Cluster, writer and reader, Serverless v2 RDS Proxy Read-write and read-only endpoints Valkey ElastiCache replication group, Multi-AZ S3 private and public buckets One pair per region S3 access-log buckets One per region CloudFront private-file distributions One per region, signed URLs, OAC Kinesis Firehose and audit bucket Object Lock, COMPLIANCE, one year SQS queues Steps, ingest, bulk ingest, file scan, email send, training SNS file-scan topics One per region KMS keys Database, secrets, registry, backups AWS Backup vaults and plans Main and DR vault, restore testing Cognito user pool Platform users SES configuration set and identity Outbound email ECR repositories Images VPC endpoints S3 gateway, Bedrock interface Bastion SSM-managed, no public IP
# Untrusted VPC
Component Kind Untrusted EKS cluster Private API endpoint kata_apps node groupRelease sandboxes kata_jobs node groupJob runners kata_dev node groupDev boxes Sandbox namespace, Role, RoleBinding, access entry Orchestrator access Sandbox egress NetworkPolicy Internet only Kata node configuration DaemonSet Node-level defaults Prepull balloon Keeps the dev-box image warm VPC peering and security-group rules Three ports from trusted S3 gateway endpoint Container Insights Metrics only Bastion SSM-managed
# Sandbox images
Image Runs on Release worker kata_appsMethod compiler kata_jobsWeb interface compiler kata_jobsFrontend diagnostics kata_jobsDev box kata_dev
# Account-level
Component Purpose GuardDuty with EKS runtime monitoring Threat detection CloudTrail Control-plane API history VPC flow logs Network telemetry, both VPCs SNS notifications Alerts to email and Slack
← Previous 35 · Portability Next → Connection Matrix