System Architecture¶
Auto-generated
Rendered from docs/architecture/calm/architecture.json by the CALM
CLI (calm template). Do not edit this file by hand — edit the
architecture JSON or the Handlebars template at
docs/architecture/calm/templates/mermaid/system.md.hbs and regenerate
with make calm-diagrams.
A single Mermaid flowchart LR of every node in the CALM architecture
and the connections between them. connects and interacts
relationships become arrows (the protocol, when defined, labels the
arrow); deployed-in / composed-of containers become subgraphs.
flowchart LR
actor-cluster-operator["Cluster Operator"]
service-kube-apiserver["kube-apiserver (k0s)"]
service-sceau["sceau (KMS v2 plugin)"]
database-etcd["etcd (k0s)"]
system-tpm["TPM 2.0"]
data-asset-sealed-dek-envelope["Sealed DEK envelope"]
data-asset-encryption-config["EncryptionConfiguration"]
service-sceau-peer["sceau (peer fleet member, enroll mode)"]
subgraph sg_ecosystem-kairos-host [Ecosystem Kairos Host]
service-kube-apiserver
service-sceau
database-etcd
system-tpm
end
service-kube-apiserver --> service-sceau
service-sceau --> system-tpm
service-kube-apiserver -->|HTTPS| database-etcd
subgraph sg_database-etcd [Database Etcd]
data-asset-sealed-dek-envelope
end
actor-cluster-operator --> service-sceau
actor-cluster-operator --> data-asset-encryption-config
service-sceau -->|mTLS| service-sceau-peer
Source: nodes and relationships in architecture.json.