Skip to content

Latest commit

 

History

55 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

SentinelFlow

A secure, enterprise-grade Azure Kubernetes Service (AKS) infrastructure managed with Terraform and automated through GitOps workflows.

Architecture Overview

SentinelFlow implements a production-ready Kubernetes infrastructure on Azure with:

  • Private AKS Cluster with Azure CNI networking
  • GitOps Deployment using Flux for continuous delivery
  • Secure Networking with private endpoints and NSG protection
  • Azure Key Vault integration for secret management
  • Cloudflare Tunnel for secure ingress without exposing load balancers
  • Infrastructure as Code with Terraform
  • Automated CI/CD pipeline with security scanning

Infrastructure Components

Azure Resources

Resource Description Configuration
AKS Cluster Private Kubernetes cluster Standard tier, auto-scaling enabled
Virtual Network Isolated network (10.0.0.0/16) AKS subnet (10.0.1.0/24) + PE subnet (10.0.2.0/24)
Key Vault Premium vault with HSM keys Private endpoint, RBAC enabled
Network Security Groups Traffic filtering rules Applied to both subnets
Disk Encryption Set Customer-managed encryption RSA-HSM 2048-bit keys

Node Pools

  • Infrastructure Pool (infra): Critical system addons only, 2-3 nodes
  • Production Pool (prd): User workloads, auto-scaling 2-3 nodes
  • VM Size: Standard_D2s_v3 (2 vCPU, 8GB RAM)
  • Storage: Ephemeral OS disks with host encryption

Kubernetes Applications

  • Flux System: GitOps controller managing deployments
  • Cloudflared: Secure tunnel for ingress traffic
  • HTTPBin: Sample application for testing
  • Secret Store CSI: Key Vault secrets integration
  • Azure Policy: Governance and compliance enforcement

Cloudflare Tunnel Integration

Overview

SentinelFlow uses Cloudflare Tunnel (formerly Argo Tunnel) to provide secure ingress connectivity without exposing public load balancers or opening inbound firewall ports. This creates a secure, outbound-only connection from the AKS cluster to Cloudflare's edge network.

Architecture Benefits

  • Zero Trust Ingress: No public IPs or load balancers required
  • Outbound Only: All connections initiated from inside the cluster
  • Edge Security: DDoS protection and firewall at Cloudflare edge
  • SSL Termination: Automatic HTTPS with Cloudflare certificates
  • Global CDN: Content delivery and acceleration worldwide

Implementation Details

Tunnel Configuration:

  • Deployment: 2 replicas for high availability
  • Health Checks: Built-in liveness probes on port 2000
  • Tolerations: Can run on infrastructure nodes if needed

Secret Management:

  • Token Storage: Cloudflare tunnel token stored in Azure Key Vault
  • CSI Integration: Mounted securely via Secret Store CSI driver
  • Namespace Isolation: Runs in dedicated cloudflared namespace

Network Flow:

Internet → Cloudflare Edge → Encrypted Tunnel → AKS Pod → Application

Security Features

  • Encrypted Transport: All traffic encrypted end-to-end
  • Token-Based Auth: No username/password authentication required
  • Network Policies: Microsegmentation within Kubernetes
  • Pod Security: Runs with restricted security context
  • Audit Logging: All tunnel activity logged and monitored

Security Features

Network Security

  • Private AKS Cluster: No public API endpoint exposure
  • Network Security Groups: Traffic filtering on all subnets
  • Private Endpoints: Secure Key Vault access via private network
  • Azure CNI: Advanced networking with network policies
  • No Public IPs: All nodes use private IP addresses only

Identity & Access Management

  • Azure AD Integration: RBAC with managed identities
  • Local Accounts Disabled: Azure AD authentication required
  • Managed Identity: Pod-level authentication to Azure services
  • RBAC Authorization: Fine-grained Key Vault permissions
  • Service Principal: Dedicated identity for CI/CD operations

Data Protection & Encryption

  • Customer-Managed Keys: HSM-backed RSA-2048 encryption
  • Disk Encryption: Host-level and disk-level encryption
  • Secrets Rotation: Automatic 10-minute rotation interval
  • Key Vault Premium: Hardware Security Module protection
  • Purge Protection: Prevent accidental secret deletion

Compliance & Governance

  • Pod Security Standards: Restricted profile enforcement
  • Azure Policy: Automated compliance checking
  • Checkov Scanning: Infrastructure as Code security analysis
  • Security Baselines: CIS and Azure security recommendations
  • Audit Logging: Comprehensive activity monitoring

Application Security

  • Resource Limits: CPU and memory constraints on all pods
  • Security Contexts: Non-root containers with restricted privileges
  • Network Policies: Microsegmentation between namespaces
  • Admission Controllers: Policy enforcement at deployment time

GitOps Workflow

Flux Architecture

The cluster uses Flux v2 for GitOps with a three-stage deployment pipeline:

Git Repository → Flux Controller → Kubernetes Cluster
     ↓                ↓                    ↓
   Manifests    Detects Changes    Applies Resources

Deployment Stages

1. SecretProviderClass (./manifests/SecretProviderClass/)

  • Configures Azure Key Vault CSI driver integration
  • Substitutes Azure identity variables automatically:
    • ${AZURE_CLIENT_ID} - AKS managed identity client ID
    • ${AZURE_KEYVAULT_NAME} - Key Vault name
    • ${AZURE_TENANT_ID} - Azure AD tenant ID

2. Cloudflared Tunnel (./manifests/cloudflared/)

  • Deploys secure tunnel infrastructure
  • Mounts secrets from Key Vault via CSI driver
  • Depends on SecretProviderClass being ready
  • Creates cloudflared namespace with security policies

3. Applications (./manifests/httpbin/)

  • Sample workload deployment
  • Demonstrates resource limits and security contexts
  • Pod Security Standards enforcement
  • Depends on tunnel infrastructure being ready

Flux Configuration

# Key settings from gitops.tf
git_repository:
  url: "https://ozennouamine02@dev.azure.com/ozennouamine02/SentinelFlow/_git/SentinelFlow"
  branch: "main"
  sync_interval: "30s"

kustomizations:
  retry_interval: "30s"
  garbage_collection: enabled
  dependency_chain: secretproviderclass → cloudflared → httpbin

CI/CD Pipeline

Azure DevOps Integration

The project uses Azure DevOps Pipelines for automated infrastructure deployment with built-in security scanning and approval workflows.

Pipeline Stages

1. Infrastructure Validation

  • Terraform installation and initialization
  • Infrastructure validation and formatting checks
  • Generate and review Terraform execution plan
  • Environment variable injection for secrets

2. Security Scanning

  • Checkov Analysis: Static security analysis for Terraform code
  • Azure Pipelines Scanning: Pipeline configuration security review
  • Infrastructure Compliance: CIS and Azure security baseline validation
  • Dependency Scanning: Check for vulnerable Terraform providers

3. Manual Approval Gate

  • Human review of Terraform plan output
  • Email notification to designated approvers
  • Infrastructure change impact assessment
  • Security and compliance verification

4. Automated Deployment

  • Terraform apply with state file management
  • Azure resource provisioning and configuration
  • GitOps configuration sync with Flux
  • Post-deployment validation checks

Pipeline Configuration

# Key pipeline settings from azure-pipelines.yml
trigger: ["main"]
pool: "ubuntu-latest"

jobs:
  - Terraform (validate & plan)
  - Checkov (security scanning) 
  - WaitForApproval (manual gate)
  - TerraformApply (deployment)

# Required variables:
# - SERVICE_CONNECTION_NAME: Azure service connection
# - TF_VAR_tunnel_token (secret): Cloudflare tunnel token
# - TF_VAR_https_key_base64 (secret): Git access token

Security Features

  • Service Principal Authentication: Dedicated identity for pipeline execution
  • Variable Groups: Secure storage of sensitive configuration
  • Branch Protection: Deployment only from main branch
  • Approval Required: Human verification before infrastructure changes
  • Audit Trail: Complete deployment history and change tracking

About

SentinelFlow is a secure, production-ready Azure Kubernetes Service (AKS) platform built with Terraform and GitOps. It features a private AKS cluster, Flux-based continuous delivery, Azure Key Vault secret management, and Cloudflare Tunnel ingress for zero-trust access.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages