Implemented today.
OCI is implemented today
A Kubernetes foundation you can inspect first.
OCF combines Terraform, Helmfile and a small set of mise tasks. It creates an OKE foundation and installs the cluster services teams usually assemble by hand.
- Plan before apply
- Kubernetes 1.36.1 in CI
- Pinned toolchain
Reach a reviewed plan without changing the target
$ mise trust
$ mise install
$ mise run doctor
$ mise run oci:cluster:plan
$ mise run k8s:base:checkReview before any apply command
Installed by the end to end pipeline.
Apply requires explicit confirmation.
Two clear boundaries
Own the cloud foundation. Choose the cluster services.
OCF separates infrastructure and Kubernetes concerns, so operators can see what Terraform owns, what Helmfile installs and where application configuration begins.
OCI foundation
Terraform creates the network, private OKE control plane, Bastion path, node pools and security boundaries.
- Remote state with versioning
- Private workers and API endpoint
- Node labels and taints at startup
- Reviewed plan before apply
Kubernetes foundation
Helmfile profiles install only the services selected for that cluster and preserve compatible upgrades.
- Envoy Gateway and cert manager
- Argo CD
- Prometheus, Grafana, Loki and Tempo
- Optional data service operators
The working loop
Inspect, plan and then apply.
The task names describe the action. Commands that inspect stay separate from commands that change infrastructure.
Explore the command surface- 01Check the workstation
mise run doctor - 02Review the cloud plan
mise run oci:cluster:plan - 03Inspect the cluster target
mise run k8s:base:check - 04Render the selected profile
mise run k8s:base:render
Profiles with a purpose
Start small. Add stateful services deliberately.
A profile chooses a coherent service set. It does not create application databases, topics, queues or capacity decisions.
starterEdge, TLS, GitOps and observability for a first installation.
productionAdds database and messaging operators without creating application data.
production-haAdds failure tolerant services and durable observability. Capacity planning is required.
production-dataAdds Kafka, Kafka Connect and Valkey support for teams that need them.
Clear limits
Useful today and honest about what comes next.
Magalu Cloud and DigitalOcean are plans, not support claims.
Capacity, credentials, retention and recovery objectives remain with the operator.
Every release still needs review against the target tenancy and workload.
Ready to evaluate it?
Reach a reviewed plan before changing anything.
The guide begins with a tested release, installs the pinned tools and stops at inspection before introducing apply commands.