Agentic DevOps with Claude Code Build governed AI platforms on Kubernetes with GitOps, observability, and self-service… (Michael Forrester) (z-library.sk, 1lib.sk, z-lib.sk)
Build and validate a governed AI-native developer platform with Claude, Kubernetes, GitOps, policy controls, observability, and reproducible workflows
Key Features
• Control Claude with specifications, permissions, tests, and auditable workflows
• Build governed agent and model infrastructure on Kubernetes with GitOps
• Create a Backstage self-service path from developer request to traced agent
Build agentic DevOps workflows without bypassing the controls your Kubernetes platform already depends on. This book shows you how to use Claude as a controlled platform-engineering worker while introducing agents, model serving, and developer self-service through reproducible GitOps workflows, explicit trust boundaries, policy checks, and testable completion gates.
You’ll establish a cloud-native foundation with Argo CD, cert-manager, OpenBao, External Secrets Operator, Kyverno, Prometheus, Grafana, Loki, Tempo, and OpenTelemetry. You’ll then add governed AI traffic using Gateway API, kgateway, agentgateway, kagent, MCP tools, and LLM Guard before serving an OpenAI-compatible model with KServe and vLLM.
The hands-on approach shows you how to constrain Claude with specifications, permissions, audit hooks, tests, and Git checkpoints. You’ll trace agent and model activity, diagnose failures from evidence, and turn operational fixes into reusable tests. You’ll also build a Backstage template and Argo CD ApplicationSet that provide a governed path from developer request to running agent.
By the end, you’ll be able to build and validate an AI-native internal developer platform in phases, route agent and model activity through existing platform controls, and prepare the architecture for production use.
For:
Platform engineers, DevOps engineers, SREs, cloud engineers, and platform architects who want to use Claude to build and operate governed AI capabilities on Kubernetes. Engineering and technical leads can also use the architecture and production guidance to assess scope and
AI Reading Assistant
Whole-book reading guide from stratified index samples; jump to passages in the text
Tip the Site
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat Pay
Alipay
Open WeChat or Alipay and scan. No login required.
AI guide
【One-Line Pitch】
A hands-on guide to building a governed, AI-native internal developer platform on Kubernetes, where Claude Code acts as a controlled build-time worker and agents, models, and MCP tools run as first-class platform resources. Best for platform engineers, DevOps/SREs, and architects who already know Kubernetes and want to add AI capabilities without abandoning GitOps, policy, and observability discipline.
【Book Arc】
- **Opening (~0%–9%)**: Frames the core problem — a 30-component platform becomes unmanageable if each tool is installed in isolation. Introduces the three-plane architecture (foundation, AI, self-service), separates Claude Code as builder from runtime agents and served models, and maps trust boundaries from developer intent to operational evidence.
- **Early (~9%–28%)**: Establishes the controlled cloud-native foundation: governing Claude Code with written specifications, narrow permissions, audit hooks, and test gates; bootstrapping Argo CD and the GitOps dependency chain; and building the observability plane with OpenTelemetry, Prometheus, Grafana, Loki, and Tempo.
- **Early–Middle (~28%–47%)**: Turns architecture into executable contracts. Covers phased specifications, pinned dependency inventories (components.yaml, versions.lock.md), chart vs. application versioning, CRD upgrade hazards, and the GitOps bootstrap with sync waves, health vs. sync status, and App-of-Apps refresh behavior.
- **Middle (~47%–60%)**: Hardens the foundation with storage classes, EKS Pod Identity, secret materialization, and Kyverno policies in Audit mode — measuring violations before blocking workloads.
- **Late (~60%–85%)**: Adds the AI plane: declaring agents, models, and MCP tools as Kubernetes resources (kagent CRDs, ModelConfig, agentgateway), prompt-injection protection, tracing, and serving OpenAI-compatible models with KServe and vLLM while measuring latency and resource use.
- **Ending (~85%–100%)**: Ships the governed self-service golden path — a Backstage template and Argo CD ApplicationSet that take a developer request to a running, traced agent — then moves from demo to production by enforcing policy, attributing actions, turning defects into tests, and planning adoption.
【Key Takeaways】
- **The platform is defined by outcomes, not tool count** (Opening): foundation, AI, and self-service planes each have distinct ownership, identity, and evidence requirements. This framing prevents the common failure of treating 30 tools as 30 independent installations.
- **Claude Code is a construction-time builder, not a runtime component** (Early): it is constrained by specifications, allow/ask/deny permissions, sandbox limits, audit hooks, and test gates. Separating builder identity from runtime agent and model identity is what makes attribution and investigation possible.
- **Specifications and tests are the control surface for agentic work** (Early–Middle): phased specs, pinned dependencies, failing-test-first loops, and explicit stop conditions keep implementation under human direction. The book treats a green test that proved nothing as a real hazard.
- **GitOps is the control plane, not just a deployment mechanism** (Middle): Argo CD reconciles desired state, but sync waves, health customizations, App-of-Apps refresh order, and CRD upgrade gaps all require deliberate handling. Synced and Healthy are different signals and both matter.
- **Trust boundaries need authentication, authorization, data-handling, and failure stories** (Early): developer-to-portal, portal-to-Git, Git-to-Argo CD, agent-to-gateway, gateway-to-model/MCP, workload-to-secret-provider, and telemetry-producer-to-Collector are all crossings that must be explicitly designed.
- **Policy starts in Audit mode** (Middle): Kyverno policies measure violations before blocking workloads, letting teams understand drift and default behavior before enforcement. This is a practical adoption pattern, not a shortcut.
- **Agents, models, and MCP tools are Kubernetes resources** (Late): kagent CRDs, ModelConfig, and agentgateway bindings make AI capabilities declarative, reconcilable, and traceable through the same platform controls as any other workload.
- **Operational fixes should become reusable tests** (Ending): diagnosing failures from evidence and converting them into regression tests is the mechanism that moves the platform from demo to service.
【Reading Tips】
- **Work the labs in order on a non-production cluster.** The book explicitly warns against pointing labs at production; read-only first is a safety practice, not a slogan. Have kubectl, Helm, Git access, and a Claude Code subscription ready.
- **Deep-read Chapters 1–3 and 7–10; skim tool installation details.** The architecture, trust boundaries, Claude governance, GitOps bootstrap, agent resources, and production governance carry the durable ideas. Individual chart values and version pins will age quickly.
- **Treat the book repository as the technical source of truth.** Chart versions and APIs change; use the current manifests, work in a branch, read every diff, and run validation checks before moving on.
- **Pay special attention to the permission and audit sections.** The allow/ask/deny model, sandbox limits, and structured audit hooks are the practical core of controlling an agentic builder — these are the patterns most likely to transfer to your own environment.
- **Keep credentials out of the repository and use least-privilege access.** The book's governance posture depends on this discipline; without it, the audit and attribution story collapses.
【Coverage Limits】
This guide is synthesized from stratified excerpts covering the preface, table of contents, and selected chapters; detailed lab steps, exact manifests, and later-chapter production guidance are only partially represented. Specific version numbers and tool configurations should be verified against the book repository.
Excerpt 1
ols, and prepare the architecture for production use. For: Platform engineers, DevOps engineers, SREs, cloud engineers, and platform architects who want to u...
able at https://github.com/PacktPublishing. Check them out! Download the color images We also provide a PDF file that has color images of the screenshots/dia...
ill exits zero, which is a green result that proved nothing. Replace the EXPECTED_CONTEXT placeholder with a substring of your own context before you run the...
child spec in memory because the parent has not reread Git. Hard-refresh the App-of-Apps first, then inspect the child. Chapter 3 60 parameters: type: gp3 en...
ned values. If targets remain red for managed control-plane components, confirm the disable fields render correctly. If the Collector Service is absent, enab...
image, command, arguments, environment, mounts, and Secret references rendered? 3. Container: which UID runs, and can it traverse the working directory? 4. B...
schemas, model names, streaming responses, and token usage. The gateway may select a provider, map a model alias, protect credentials, enforce a budget, or a...
t asks the agent to use echo. The request format exposed by the chosen agent route must be pinned in the book repository because kagent and agentgateway APIs...
Support this siteYour recognition and a small knowledge-service contribution help keep this technical work open source.
Scan the WeChat Pay or Alipay code below. Logged-in and guest visitors can both tip.
WeChat PayAlipay
Open WeChat or Alipay and scan. No login required.
Add Tag
Enter tag name (max 50 characters)
Share E-Book
Agentic DevOps with Claude Code Build governed AI platforms on Kubernetes with GitOps, observability, and self-service… (Michael Forrester) (z-library.sk, 1lib.sk, z-lib.sk)
Scan QR code with your phone to access
Copy the link or scan the QR code to access this e-book on your phone
Share E-Book via Email
Please enter email address
Donation Statistics
¥.00
Total Donations
0
Donation Count
Agentic DevOps with Claude Code Build governed AI platforms on Kubernetes with GitOps, observability, and self-service… (Michael Forrester) (z-library.sk, 1lib.sk, z-lib.sk)
Find Your Favorite Books
Only registered users can comment after logging in. Comments need to be reviewed by administrators before being displayed
Loading comments...
Reply to Comment
Edit Comment