Infrastructure and authority map
The deployable Terraform root is infrastructure/environments/prod/. Its local modules describe cloud networking, GKE, optional workload add-ons, and runtime observation. Admission policy and Argo desired state are separate configuration paths. Counting files is not a reliable way to count active controls.
Foundation modules
Section titled “Foundation modules”| Path | Responsibility | Important fields and limits |
|---|---|---|
environments/prod/main.tf |
Join network, cluster, and add-ons | Enables flow logs/IAP SSH; passes root node-pool and endpoint-network inputs |
vpc/main.tf |
Custom VPC, private subnets, Pod/Service secondary ranges, Router/NAT, firewalls | Internal TCP/UDP ranges are broad within supplied subnets; NAT is egress plumbing, not an application trust check |
gke/main.tf |
Regional VPC-native cluster, distinct node pools, Workload Identity | Private nodes; optional private endpoint; logging; managed node auto-repair/upgrade; node-pool service accounts |
kubernetes-addons/main.tf |
Optional metrics-server and ExternalDNS | Production defaults disable both; GKE supplies its own metrics-server |
environments/prod/versions.tf |
Providers and remote state interface | GCS backend supplied during init; Kubernetes/Helm depend on GKE endpoint and CA |
The module’s enable_private_endpoint default is false, and the production root does not override it. Do not infer a private API from private nodes. The GKE node-pool account includes project-level roles/artifactregistry.reader, together with logging and monitoring roles; it is broader than the repository-scoped Kyverno reader grants. deletion_protection is false. These are source facts that a reproduction plan should inspect explicitly.
Delivery and verifier identities
Section titled “Delivery and verifier identities”supply-chain.tf creates required APIs, application/metadata registries, GitHub CI identity, repository writer grants, a dedicated federation pool/provider, Kyverno verifier identity, repository reader grants, and its KSA impersonation binding. Application tags are immutable; metadata tags are mutable so Cosign v2 can append legacy statement indexes. Immutability does not remove registry deletion authority.
The provider checks assertion.repository against the canonical repository. It maps the ref but does not enforce main in its condition. Workflow job conditions provide the main-only release restriction. The verifier’s GSA can read the two repositories, but has no configured application-write role. Its KSA binding names kyverno/kyverno-admission-controller exactly.
Argo CD and Kyverno are installed separately with Helm. The active policy is policy/kyverno/block-unsigned-images.yaml; its reader annotation and 8 MiB context setting are in policy/kyverno/values.yaml. The application source is defined under argocd/, not by the add-ons module.
Runtime detection and optional routing
Section titled “Runtime detection and optional routing”The production falco.tf selects chart 9.1.0, overriding the reusable module’s older default 4.7.4. The module uses the modern_ebpf driver by default, Kubernetes collection, rule_matching: all, custom rules passed as chart values, Falcosidekick, and resource limits. The custom shell condition checks process activity and namespace exclusions; it does not verify image signatures despite its rule name.
enable_runtime_alerting defaults to false. When explicitly enabled, falco-alerting.tf creates Pub/Sub → Cloud Function routing and a dedicated Falcosidekick Workload Identity publisher. The module stores the Discord webhook in Secret Manager; the function retrieves it, filters priorities, formats an embed, and posts it. The prod root sets min_priority: notice, while the function’s environment fallback is warning. Follow the configured value when documenting an enabled environment.
No recorded external alert delivery is established for the disabled baseline route. The webhook is secret input; the function’s presence is configuration evidence, not delivery evidence.
Inactive and retained components
Section titled “Inactive and retained components”ratify-gar-auth.tf uses count guarded by enable_legacy_ratify, which defaults false. Its dedicated account, reader grant, key, outputs, and secret-creation helper are compatibility material. policy/gatekeeper/ and the older Ratify ADR document an earlier admission design; they are not the final active enforcement engine.
terraform/main.tf defines GitHub branch rules separately from the GCP prod root. A defined active ruleset does not establish that it was applied; the historical handoff marks activation pending. The required-review rule is intentionally omitted for a single maintainer. Nested infrastructure workflows remain inactive under GitHub’s discovery path. Standalone k8s/manifests/ files are not the Argo chart path.
Source anchors
Section titled “Source anchors”Production root, GKE configuration, module defaults, and GitHub ruleset definition.