OCI is implemented today

A Kubernetes foundation you can inspect first.

OCF combines Terraform, Helmfile and a small set of mise tasks. It creates an OKE foundation and installs the cluster services teams usually assemble by hand.

  • Plan before apply
  • Kubernetes 1.36.1 in CI
  • Pinned toolchain
ocf / first plan

Reach a reviewed plan without changing the target

$ mise trust
$ mise install
$ mise run doctor

$ mise run oci:cluster:plan
$ mise run k8s:base:check
Inspection complete

Review before any apply command

Cloud foundationOCI OKE

Implemented today.

Tested Kubernetes1.36.1

Installed by the end to end pipeline.

Change modelPlan first

Apply requires explicit confirmation.

Two clear boundaries

Own the cloud foundation. Choose the cluster services.

OCF separates infrastructure and Kubernetes concerns, so operators can see what Terraform owns, what Helmfile installs and where application configuration begins.

OCI foundation

Terraform creates the network, private OKE control plane, Bastion path, node pools and security boundaries.

  • Remote state with versioning
  • Private workers and API endpoint
  • Node labels and taints at startup
  • Reviewed plan before apply

Kubernetes foundation

Helmfile profiles install only the services selected for that cluster and preserve compatible upgrades.

  • Envoy Gateway and cert manager
  • Argo CD
  • Prometheus, Grafana, Loki and Tempo
  • Optional data service operators

The working loop

Inspect, plan and then apply.

The task names describe the action. Commands that inspect stay separate from commands that change infrastructure.

Explore the command surface
  1. 01
    Check the workstationmise run doctor
  2. 02
    Review the cloud planmise run oci:cluster:plan
  3. 03
    Inspect the cluster targetmise run k8s:base:check
  4. 04
    Render the selected profilemise run k8s:base:render

Profiles with a purpose

Start small. Add stateful services deliberately.

A profile chooses a coherent service set. It does not create application databases, topics, queues or capacity decisions.

starter

Edge, TLS, GitOps and observability for a first installation.

production

Adds database and messaging operators without creating application data.

production-ha

Adds failure tolerant services and durable observability. Capacity planning is required.

production-data

Adds Kafka, Kafka Connect and Valkey support for teams that need them.

Clear limits

Useful today and honest about what comes next.

OCI is the implemented cloud.

Magalu Cloud and DigitalOcean are plans, not support claims.

Examples need local decisions.

Capacity, credentials, retention and recovery objectives remain with the operator.

Tests are evidence, not a guarantee.

Every release still needs review against the target tenancy and workload.

Ready to evaluate it?

Reach a reviewed plan before changing anything.

The guide begins with a tested release, installs the pinned tools and stops at inspection before introducing apply commands.