Skip to main content
← All posts·
Platform Engineering

Crossplane for Regulated Enterprises: Infrastructure Composition & Compliance Guardrails

Crossplane guide for regulated enterprises. Covers infrastructure composition with compliance built-in, multi-cloud provisioning from Kubernetes, policy enforcement via compositions, and comparison with Terraform for enterprise governance requirements.

Luca Berton11 min read

Crossplane: Infrastructure as Code, the Kubernetes Way

Crossplane extends Kubernetes to manage any infrastructure — cloud resources, databases, DNS records, even SaaS configurations — using the same Kubernetes API that your teams already know. For platform engineering teams building internal developer platforms, Crossplane provides the infrastructure provisioning layer with built-in compliance guardrails.

Why Crossplane for Regulated Enterprises

Compliance Through Composition

Crossplane's killer feature for regulated enterprises is Compositions — pre-defined infrastructure templates that encode compliance requirements:

  • Example: A "compliant database" Composition that always creates an RDS instance with encryption at rest, in a private subnet, with automated backups, audit logging, and a specific retention period
  • Developers request: "I need a PostgreSQL database" (Claim)
  • Platform provides: A fully compliant database — encryption, networking, backups, monitoring — all invisible to the developer
  • Result: Developers can't accidentally create a non-compliant database. Compliance is the default, not an afterthought.

GitOps-Native Infrastructure

  • Kubernetes-native: Infrastructure state is in Kubernetes CRDs — managed by the same GitOps workflows (ArgoCD/Flux) as applications
  • Continuous reconciliation: Crossplane continuously reconciles desired state with actual state — drift detection and correction is automatic
  • Audit trail: Every infrastructure change is a Kubernetes event, logged in the API server audit log
  • RBAC: Kubernetes RBAC controls who can create/modify infrastructure claims — no separate IAM system needed

Crossplane vs Terraform for Enterprise

DimensionCrossplaneTerraform
ModelKubernetes CRDs (declarative, continuously reconciled)HCL files + state (apply/plan workflow)
Self-serviceClaims via kubectl or portalRequires CI/CD pipeline per request
Drift detectionContinuous (Kubernetes controller loop)On-demand (terraform plan)
Multi-tenancyKubernetes namespaces + RBACSeparate state files + workspaces
Provider ecosystemGrowing (AWS, Azure, GCP, 100+ providers)Massive (4,000+ providers)
Best forPlatform engineering, self-service infraInfrastructure provisioning, one-off setups

Enterprise pattern: Many teams use Crossplane for self-service developer infrastructure and Terraform for foundational platform infrastructure (VPCs, clusters, identity). They're complementary, not competitive.

📘 Book

Kubernetes Recipes

A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).

Watch on Skillshare →

Compliance Use Cases

  • DORA Art. 9 (Change management): Every infrastructure change is a Git commit + Kubernetes event — full audit trail
  • DORA Art. 28-44 (Third-party risk): Compositions can enforce cloud provider selection and region constraints
  • NIS2 Art. 21(2)(e): Security in system development — Compositions encode security defaults into infrastructure provisioning
  • GDPR: Compositions can enforce data residency by restricting resources to specific cloud regions

Getting Started

  1. Install Crossplane in your management cluster (Helm chart, 5 minutes)
  2. Install cloud provider (provider-aws, provider-azure, provider-gcp)
  3. Create your first Composition — Start with a "compliant S3 bucket" or "compliant RDS instance"
  4. Define a CompositeResourceDefinition (XRD) — The API your developers will use
  5. Test the developer workflow — Can a developer create a compliant database with one YAML file?
🎓 Course with Starweaver

ServiceNow Basics: IT Automation & AI-Powered Workflows

Design AI-powered workflows in ServiceNow for IT operations. In collaboration with Starweaver.

Start on Coursera →
Crossplane
infrastructure composition
Kubernetes
compliance
regulated enterprises
multi-cloud
platform engineering

Need help applying this in your organization?

Get a free 30-minute assessment with actionable recommendations — whether we work together or not.

Book Your Free AI Platform Assessment

Or see AI readiness assessment scope & pricing

18+ years experience · Ex-Red Hat & Dell · Speaker at KubeCon EU 2026

Luca Berton

Written by

Luca Berton

CEO at Open Empower. 18+ years building enterprise infrastructure at JPMorgan Chase, Red Hat & Dell. Author of 9 technical books. Speaker at Red Hat Summit and KubeCon EU 2026. Instructor on Coursera, Pluralsight & Udemy.

Get more insights like this

Practical AI infrastructure and platform engineering guides — delivered to your inbox.

Subscribe to Newsletter →