Crossplane: Infrastructure as Code, the Kubernetes Way
Crossplane extends Kubernetes to manage any infrastructure — cloud resources, databases, DNS records, even SaaS configurations — using the same Kubernetes API that your teams already know. For platform engineering teams building internal developer platforms, Crossplane provides the infrastructure provisioning layer with built-in compliance guardrails.
Why Crossplane for Regulated Enterprises
Compliance Through Composition
Crossplane's killer feature for regulated enterprises is Compositions — pre-defined infrastructure templates that encode compliance requirements:
- Example: A "compliant database" Composition that always creates an RDS instance with encryption at rest, in a private subnet, with automated backups, audit logging, and a specific retention period
- Developers request: "I need a PostgreSQL database" (Claim)
- Platform provides: A fully compliant database — encryption, networking, backups, monitoring — all invisible to the developer
- Result: Developers can't accidentally create a non-compliant database. Compliance is the default, not an afterthought.
GitOps-Native Infrastructure
- Kubernetes-native: Infrastructure state is in Kubernetes CRDs — managed by the same GitOps workflows (ArgoCD/Flux) as applications
- Continuous reconciliation: Crossplane continuously reconciles desired state with actual state — drift detection and correction is automatic
- Audit trail: Every infrastructure change is a Kubernetes event, logged in the API server audit log
- RBAC: Kubernetes RBAC controls who can create/modify infrastructure claims — no separate IAM system needed
Crossplane vs Terraform for Enterprise
| Dimension | Crossplane | Terraform |
|---|---|---|
| Model | Kubernetes CRDs (declarative, continuously reconciled) | HCL files + state (apply/plan workflow) |
| Self-service | Claims via kubectl or portal | Requires CI/CD pipeline per request |
| Drift detection | Continuous (Kubernetes controller loop) | On-demand (terraform plan) |
| Multi-tenancy | Kubernetes namespaces + RBAC | Separate state files + workspaces |
| Provider ecosystem | Growing (AWS, Azure, GCP, 100+ providers) | Massive (4,000+ providers) |
| Best for | Platform engineering, self-service infra | Infrastructure provisioning, one-off setups |
Enterprise pattern: Many teams use Crossplane for self-service developer infrastructure and Terraform for foundational platform infrastructure (VPCs, clusters, identity). They're complementary, not competitive.
Kubernetes Recipes
A practical guide for container orchestration and deployment by Grzegorz Stencel & Luca Berton (Apress).
Watch on Skillshare →Compliance Use Cases
- DORA Art. 9 (Change management): Every infrastructure change is a Git commit + Kubernetes event — full audit trail
- DORA Art. 28-44 (Third-party risk): Compositions can enforce cloud provider selection and region constraints
- NIS2 Art. 21(2)(e): Security in system development — Compositions encode security defaults into infrastructure provisioning
- GDPR: Compositions can enforce data residency by restricting resources to specific cloud regions
Getting Started
- Install Crossplane in your management cluster (Helm chart, 5 minutes)
- Install cloud provider (provider-aws, provider-azure, provider-gcp)
- Create your first Composition — Start with a "compliant S3 bucket" or "compliant RDS instance"
- Define a CompositeResourceDefinition (XRD) — The API your developers will use
- Test the developer workflow — Can a developer create a compliant database with one YAML file?
ServiceNow Basics: IT Automation & AI-Powered Workflows
Design AI-powered workflows in ServiceNow for IT operations. In collaboration with Starweaver.
Start on Coursera →
Luca Berton
