§25 Clever Cloud's Open-Source Stack and the GitOps Deployment

Inventory and verdicts for every relevant Clever Cloud project (licenses, activity); Sōzu vs Envoy vs Pingora; Biscuit vs OpenFGA + OIDC and JWTs; the forked operator and `ObjectStoreProvider`; Argo CD, the umbrella chart and sync waves over RustFS, TiKV (TiDB Operator v2), Resonate, the edge, Loam and the runtime tiers

Status: Proposed · 2026-09-29. This is the companion to §24. The owner's direction (2026-09-29): "use rustfs and clever cloud opensource stack to gitops, evaluate all the tools that are we adopt from clever cloud". This document does four things: it inventories every relevant open-source project from Clever Cloud (§2), compares Sōzu with Loam's planned edge (§3), compares Biscuit with the planned auth (§4), and designs the GitOps layout (§5–§6). Its decisions are D185–D188 in §24's table, and its questions are Q-RT-8 … Q-RT-14.

Amended 2026-10-02 by §38 (proposed): "GitOps from Clever Cloud" means Clever's open-source operator and infrastructure tooling (D185, the CKE Terraform and Karpenter providers); Clever publishes no GitOps engine, so Argo CD stays (D186, D453), with a Flux layout for the smallest profile (D454). §6.3 gains waves for CloudNativePG, the Knative Operator, Authentik and Knative (D455); the operator also reconciles Knative tenancy per namespace (D443). Plan MT3.

Markers are the same as in §24. Every license was read from the repository's LICENSE file (or, where there is none, from the crate manifest, as noted). Activity dates come from the GitHub API on 2026-09-29.

License rule applied throughout. A linked dependency must not be AGPL, BSL, SSPL or ELv2. An AGPL service may run only unmodified, as a separate process, and the risk is flagged even then. LGPL linked into a Rust binary is not banned by the rule, but static linking brings relinking obligations. It is flagged wherever it appears.


1. Summary

  • Adopt as linked dependencies: biscuit-auth (Apache-2.0) for sandbox tokens (D188), and clevercloud-sdk (MIT) behind an optional Cellar provider feature.
  • Fork: clever-kubernetes-operator (MIT), as the skeleton of loam-operator (D185). What carries over is small, a kube-rs controller registry, finalizers, event recording, metrics and a hardened Helm chart, because its CRDs provision Clever Cloud add-ons through Clever's API rather than running workloads in the cluster.
  • Adopt as unmodified tools or services, only when deploying on Clever Cloud: terraform-provider-clevercloud and karpenter-provider-clever-cloud (Apache-2.0), plus biscuit-cli (BSD-3-Clause) as a developer tool.
  • Reject as the edge: Sōzu (AGPL-3.0) and sozu-gateway. Envoy stays the edge, and Pingora is the library if a Rust L7 component is ever needed.
  • Reference only: clever-tools (CLI UX), clever-components (UI), kawa, nlrs, poule, simple-vmm, cellar-migration, kaniop (AGPL-3.0, not Clever's).
  • Not published: Clever Cloud's hypervisor, deployer, log pipeline and Materia KV engine. No open repository was found in CleverCloud, sozu-proxy or eclipse-biscuit; only simple-vmm, a 2021 example VMM, touches virtualization.
  • GitOps: Argo CD (D186), with an app-of-apps and sync waves over one umbrella chart. RustFS is the object store (D178), TiDB Operator v2 deploys PD and TiKV (D179), and the forked operator reconciles Loam and Function resources.

2. Inventory (D187)

Searched on 2026-09-29: every public, non-archived, non-fork repository of github.com/CleverCloud (about 250), github.com/sozu-proxy and github.com/eclipse-biscuit (where Biscuit moved from Clever Cloud), and biscuit-auth. About 150 of Clever's repositories are *-example deployment samples, most with no license. They are grouped as one row. Everything with a plausible place in Loam's GitOps, runtime, edge or auth stack is listed individually.

2.1 GitOps, operators and infrastructure

ProjectWhat it doesLicense (file)Last commit · releaseLangFit in LoamVerdictRationale
CleverCloud/clever-kubernetes-operatorExposes Clever Cloud add-ons (PostgreSQL, MySQL, Redis, MongoDB, Pulsar, Cellar, Elasticsearch, Keycloak, Matomo, Metabase, Otoroshi, KV, Azimutt, ConfigProvider) as CRDs in group api.clever-cloud.com/v1, provisioned through Clever's APIMIT (LICENSE, © 2021 Clever Cloud)2026-09-04 · v0.8.0 (2026-06-09)Rust (kube 3.1, k8s-openapi 0.27, edition 2024)Skeleton of loam-operatorFork (D185)Its reusable part is crates/core (a Controller trait, a registry and sync strategies; 212 lines), svc/k8s (finalizer, event recorder, secret and resource helpers) and svc/http (metrics server), about 1,300 lines, plus a Helm chart with NetworkPolicy, PDB and CA bundle. The svc/clevercloud client and the 16 add-on CRDs are dropped. The README says "under development … may have bugs". The MIT notice is kept
CleverCloud/clevercloud-sdk-rustRust client and types for Clever Cloud's APIMIT2026-06-04 · v1.0.1RustProvisioning Cellar buckets and keys in the Cellar ObjectStoreProviderAdopt, linked, behind the optional feature provider-cellarLicense is fine. It is only needed to provision on Clever; reading and writing Cellar is plain S3
CleverCloud/terraform-provider-clevercloudTerraform provider for Clever resourcesApache-2.02026-09-28 · v2.3.0GoInfra layer below GitOps when the target is Clever Kubernetes Engine (CKE): cluster, Cellar, network groupsAdopt as a tool (unmodified), Clever targets onlyActive and Apache-2.0. Runs outside the cluster, before Argo CD
CleverCloud/karpenter-provider-clever-cloudKarpenter CloudProvider over CKE's nodegroups.api.clever-cloud.com/v1Apache-2.02026-08-12 · v0.12.0GoNode autoscaling for runtime tiers on CKEAdopt as an unmodified service, Clever targets onlyREADME says "under development", validated end to end on a live CKE cluster. It is irrelevant off Clever
CleverCloud/pulumi-clevercloudPulumi providerApache-2.02026-01-26 · v0.0.19GoAlternative to TerraformReference onlyPre-1.0, slower cadence
CleverCloud/clever-autoscaler-operator-exampleSample node autoscaler for CKEno LICENSE file2025-12-04 · noneTS—RejectUnlicensed; superseded by the Karpenter provider
CleverCloud/clever-cloud-review-appGitHub Action for per-PR review apps on Cleverno LICENSE file2025-08-07 · v2.0.2HTML/shellPreview environmentsRejectUnlicensed; previews are a non-goal (§24 §2.2)
pando85/kaniop (not Clever)Kanidm operator in RustAGPL-3.0 (LICENSE.md)2026-09-26 · v0.16.4RustOperator designReference onlyAGPL: no code copied (as the draft already says)

2.2 CLI, SDKs and UI

ProjectWhat it doesLicenseLast commit · releaseLangFitVerdictRationale
CleverCloud/clever-toolsOfficial Clever CLI: clever deploy, logs, add-ons (Node 22+)Apache-2.02026-09-28 · 5.0.2 (2026-09-16)JavaScriptThe loam deploy / loam functions UXReference onlyLoam's CLI is the Rust loam binary; clever-tools talks only to Clever's API
CleverCloud/clever-client.jsJS client for Clever's APIApache-2.02026-09-28 · v12.6.5TS—RejectClever-API specific
CleverCloud/clever-componentsWeb Components used in Clever's consoles, with StorybookApache-2.02026-09-23 · 26.5.0JavaScriptLoam consoleReference onlyThe console has its own stack (§19, loam-cloud). Useful for patterns (log viewer, metrics widgets)
CleverCloud/clevercloud-sdk-go, -python, clevercloud-client-goAPI SDKsApache-2.02026-09Go/Python—RejectClever-API specific
CleverCloud/mcp-simple-serverMCP server over Clever's APIApache-2.0 text (GitHub: NOASSERTION)2026-04-14 · noneTS—RejectClever-API specific
CleverCloud/oauth10a-rustOAuth 1.0a (Clever's API auth)MIT2025-05-28 · v3.0.0Rust—RejectOnly pulled in by clevercloud-sdk, transitively

2.3 Edge and proxy (Sōzu family)

ProjectWhat it doesLicenseLast commit · releaseLangFitVerdictRationale
sozu-proxy/sozuHot-reconfigurable reverse proxy: HTTP/1.1 (kawa), HTTP/2 mux, TLS (rustls, aws-lc-rs, FIPS), TCP, UDP, per-IP limits, zero-downtime upgradeAGPL-3.0 (LICENSE; sozu and sozu-lib crates AGPL-3.0; sozu-command-lib LGPL-3.0)2026-09-29 · 2.2.1 (2026-08-28)RustEdge / ingressReject (§3). If ever used, only unmodified as a separate process, with the AGPL risk flaggedNo HTTP/3 in its README or docs; no GRPCRoute, header or query matching or weighted splits (sozu-gateway docs/features.md lists these as "not supported by Sōzu"). Envoy covers all of them under Apache-2.0
CleverCloud/sozu-gatewayKubernetes Ingress + Gateway API controller driving Sōzu over its command socket; compiles to an IR and applies deltasApache-2.0, but statically links sozu-command-lib (LGPL-3.0)2026-09-23 · v0.5.0RustK8s edge controllerReject (with Sōzu). Reference for its IR-and-delta designTied to Sōzu. Pod-IP backends from EndpointSlices and idempotent global reconcile are good ideas to copy by design, not code
CleverCloud/kawaZero-copy HTTP/1 and HTTP/2 representation used by SōzuApache-2.02026-09-28 · v0.7.2Rustloam-gateway parsingReference onlyThe gateway uses hyper, the ecosystem default; kawa is optimized for Sōzu's buffer model
CleverCloud/sozu-client, sozu-prometheus-connectorAsync client for Sōzu's command socket; metrics exporterApache-2.0 (sozu-client links LGPL sozu-command-lib)2026-07-16 · v0.5.0 / v0.4.0Rust—RejectOnly useful with Sōzu
CleverCloud/sozu-pulsar-connector, sozu-pki-connectorPulsar → Sōzu config; certificates from a directoryApache-2.02023–2024 · tags v0.1.1Rust—RejectStale; Sōzu-only
sozu-proxy/poule, circularGrowable object pool; nom stream bufferMIT2026-05 / 2023-07RustBuffer poolsReference onlyLoam has bytes and its own pools

2.4 Authorization (Biscuit)

ProjectWhat it doesLicenseLast commit · releaseLangFitVerdictRationale
eclipse-biscuit/biscuitThe Biscuit specification: public-key-verified, offline-attenuable capability tokens with Datalog checksApache-2.02025-10-21 · v3.3 (2024-12-17)specSandbox token formatAdopt (spec)Moved from Clever Cloud to the Eclipse Foundation; stable v3 format
eclipse-biscuit/biscuit-rust (biscuit-auth)Reference Rust implementationApache-2.0: no root LICENSE; biscuit-auth/LICENSE and license = "Apache-2.0" in biscuit-auth/Cargo.toml2026-08-17 · biscuit-auth 6.0.0 (2025-07-16)RustMinting in the node supervisor; verifying in loam-dapr and the gatewayAdopt, linked (D188)Apache-2.0, maintained, Rust. §4 has the comparison. cargo deny check at adoption (Q-RT-10)
eclipse-biscuit/biscuit-wasm, biscuit-python, biscuit-java, biscuit-go, biscuit-swiftBindingsApache-2.02026-07 to 2026-09variousLetting functions attenuate their own token before calling a sub-functionReference; adopt later if functions need itF1 attenuates in the supervisor only
eclipse-biscuit/biscuit-cliGenerate and inspect tokensBSD-3-Clause2026-06-19 · 0.6.0RustDeveloper and debugging toolAdopt as a tool (unmodified)Permissive, not linked
CleverCloud/biscuit-pulsarBiscuit auth plugins for Apache PulsarApache-2.02026-09-19 · 4.0.1Java—RejectLoam has no Pulsar
CleverCloud/biscuit-wasm-shim, biscuit-wasm-goExperimental wasm shimsno LICENSE file2025-10 · noneRust/Go—RejectUnlicensed

2.5 Messaging, metrics, logs and storage tooling

ProjectWhat it doesLicenseLast commit · releaseLangFitVerdictRationale
CleverCloud/magnetarSans-io Apache Pulsar clientApache-2.02026-09-21 · v1.7.2Rust—RejectLoam's streams are native and Kafka-compatible (D72, D74); no Pulsar
CleverCloud/pulsar4s, logstash-output-pulsar, pulsar-addon-migration-tool, node-pulsar-rust-backed, warp10-ext-pulsarwriterPulsar clients and toolsApache-2.0 / MITmixed, most staleScala/Ruby/JS/Java—RejectNo Pulsar
CleverCloud/fdbexporterFoundationDB → Prometheus exporterApache-2.02026-09-24 · v2.5.0Rust—RejectFoundationDB was dropped (D71)
CleverCloud/warp10.rs, telegraf-output-warp10, clevercloud-warp10-datasource, warp10-*Warp 10 time-series clients and pluginsBSD-3-Clause / Apache-2.0mixedRust/Go/TS/Java—RejectLoam's telemetry is OTLP (D73) and Iceberg
CleverCloud/cellar-migrationCopies an S3-compatible store into CellarApache-2.02025-09-23 · v2.1.0 (2023-12-13)RustMigrating a tenant's bucket to CellarReference onlyOne direction, no release since 2023; rclone or Loam's own bulk import (§21 §7) covers this
CleverCloud/testcontainers-cephCeph testcontainer (Cellar is Ceph-based (verify))MIT2026-05-10JavaCellar-compatibility CIRejectCI uses RustFS (D61); a Rust Ceph harness would be written separately if Q-RT-9 needs it
CleverCloud/stream-dnsDNS server updated from KafkaMIT2020-01-22Go—RejectStale
CleverCloud/nlrsMinimal Netlink requestsMIT2026-08-20 · v0.2.0RustSupervisor network namespaces (veth, routes, egress allowlist)Reference; candidate linked dependency in F1 against rtnetlinkSmall and permissive; the choice is made on API fit
CleverCloud/simple-vmmExample VMM on rust-vmmMIT2021-03-01 · noneRustT3 (later)Reference onlyStale teaching example
CleverCloud/CleverCloud-exheresExherbo packages for Clever's imagesno LICENSE file2026-09-28——RejectUnlicensed; distribution-specific
CleverCloud/rust-guidelines, guidelinesClever's Rust guidelinesno license2018——Reference onlyLoam has its own lints
~150 CleverCloud/*-example reposDeployment samples per framework (Astro, SvelteKit, Bun, FrankenPHP, Django, n8n, GlitchTip, …)mostly no license2026-03 to 2026-09variousFramework support matrix (§24 §4.3)Reference onlyRead to learn build commands and ports; nothing copied

Not open source. Clever Cloud's hypervisor and VM images, its deployer, its log and metrics pipeline and the Materia KV engine are not published. Only clients and demos for Materia exist (mkv-*, MIT). Nothing from those systems can be adopted.

3. The edge: Sōzu vs Envoy vs Pingora or River

Envoy (planned edge)SōzuPingoraRiver
LicenseApache-2.0AGPL-3.0 (command lib LGPL-3.0)Apache-2.0Apache-2.0 / MIT
FormProxy binaryProxy binaryLibrary (framework)Proxy binary on Pingora
Activity2026-09-29 · v1.39.12026-09-29 · 2.2.12026-09-11 · 0.9.02024-09-06 · v0.5.0 (stalled)
HTTP/3 (QUIC)Yes (verify maturity label)Not found in README or docsNot in Pingora 0.9 (verify)No
gRPC routing / gRPC-WebYes (GRPCRoute via Envoy Gateway (verify), gRPC-Web filter)No GRPCRouteYou build itNo
Header/query match, weighted split, mirroringYesNoYou build itPartial
WebSocket / SSEYesWebSocket upgrade (verify); SSE passes as HTTPYesYes
Hot reconfigurationxDSCommand socket, no restartIn codeConfig reload
Rate limits, ext_authzBuilt-in filters and ext_authz (useful for Biscuit/OIDC checks at the edge)Per-IP connection capsYou build itBasic
KubernetesEnvoy Gateway (Gateway API) (verify version)sozu-gateway (Apache-2.0, v0.5.0)——

Verdict. Envoy stays the edge (D184). Sōzu is well engineered and fast, and its hot reconfiguration is appealing. But D176 puts HTTP/3 and gRPC in phase 1, and Sōzu has neither HTTP/3 nor gRPC routes. It would also bring an AGPL-3.0 binary into Loam's default install. As an unmodified separate process that is allowed by the rule, but every distributor of the self-hosted bundle would then carry the AGPL source-offer duty for it. Pingora is the right tool if Loam ever needs a Rust L7 component of its own (for example, a gateway that terminates HTTP/3 next to the supervisor). River is not an option while it is stalled.

4. Biscuit vs OpenFGA + OIDC vs the sandbox tokens (D182, D188)

These mechanisms answer different questions, so the comparison is about which job each one does.

OpenFGA + OIDC (D66, D67, §19)JWT access tokens (§19 §5.3)Biscuit
AnswersWho may do what (the relationship graph); OIDC says who you areThis bearer is principal X with scopes S until TThis bearer holds these capabilities, narrowed by every holder along the way
VerificationA network check (OpenFGA)Local, Ed25519 signatureLocal, Ed25519 (or P-256) signature chain
Attenuation (narrowing)Write new tuplesOnly by asking the token endpoint again (vending, §19 §5.2 item 3)Offline: any holder appends a block that can only restrict
Delegation chainsVia relationsThe act claim, set by the issuerNative: each block is a hop; third-party blocks carry attestations from another key
RevocationImmediate (delete tuples)Short TTL plus jti deny listShort TTL plus revocation ids checked against a list (the spec leaves revocation to external state)
Policy languageOpenFGA DSLNone (claims)Datalog checks inside the token
Size—Hundreds of bytesHundreds of bytes to a few KB, growing per block (estimate)
EcosystemCNCF, OIDC everywhereUniversalSmaller; Rust, Go, Java, Python, Wasm, Swift implementations

Recommendation.

  1. OpenFGA stays the authority for every decision on Loam data (the Authorizer, D66). Biscuit Datalog is not allowed to become a second policy store. Tokens carry only narrowing facts: tenant, namespace, function, invocation, operations and expiry.
  2. JWTs stay for external clients (§19 §5.3). They are universal, and MCP clients and OIDC federation expect them.
  3. Biscuit is used inside the runtime (D188), where offline attenuation pays off:
    • The control plane issues each node supervisor a Biscuit whose authority allows minting for the tenants scheduled on that node, with a short TTL and regular renewal.
    • For each invocation, the supervisor appends a block that narrows the token to one tenant, function, version and invocation id and an expiry of at most the invocation's wall limit. It adds a further block per call with the allowed operations (state:get, pubsub:publish, retrieval:query, …). No round trip is needed per invocation.
    • loam-dapr and the gateway verify the chain locally with the control plane's public key, take the namespace from the token, then ask OpenFGA.
    • A function that calls a sub-function passes an attenuated copy. This is §19 §5.2's "vended tokens can only attenuate", enforced cryptographically rather than by the token endpoint.
    • Suspension of an agent (§19 §5.4) adds its revocation ids to a TiKV-backed deny list that verifiers cache.
  4. Risk: two token formats. The gateway accepts JWTs from outside and Biscuits from sandboxes, and never the reverse (a Biscuit is not valid on public routes). Q-RT-10 asks whether §19's vending flow should also switch to Biscuit, so that there is one attenuation mechanism.

5. The forked operator and the ObjectStoreProvider trait (D178, D185)

Fork plan. Fork CleverCloud/clever-kubernetes-operator to dina-kar/loam-operator and keep the MIT LICENSE with Clever Cloud's copyright plus a NOTICE. Rename the API group from api.clever-cloud.com to Loam's (placeholder loam.<domain>/v1alpha1, Q-RT-8). Keep crates/core, svc/k8s, svc/http and the Helm chart. Delete svc/clevercloud and the add-on CRDs. Add:

CRDReconcilesNotes
LoamA Loam cluster: roles (meta, log, query, worker, gateway) as StatefulSets or Deployments, the metastore connection (TiKV PD endpoints, D179), the bucket (via an ObjectStore reference), the Resonate endpointReplaces §10's planned operon-operator (M2)
ObjectStoreA bucket and credentials from a providerStatus carries the endpoint, bucket and a Secret reference
FunctionA function version: contract, tier, bundle digest, routes, limitsWritten by loam deploy; the operator programs the gateway and warms nodes
RuntimePoolPer-node tier capacity (T0, T1, T2) and RuntimeClassMaps to the supervisor DaemonSet's config
/// Implemented by `rustfs` (default), `s3` (AWS, R2, GCS interop, any S3) and `cellar` (feature `provider-cellar`).
#[async_trait::async_trait]
pub trait ObjectStoreProvider: Send + Sync {
    fn kind(&self) -> &'static str;
    /// What the backend supports; Loam refuses a provider that lacks conditional writes (D1's WAL needs them).
    fn capabilities(&self) -> ProviderCapabilities; // if_none_match_put, if_match_put, max_object, ...
    async fn ensure_bucket(&self, spec: &BucketSpec) -> Result<BucketRef, ProviderError>;
    async fn issue_credentials(&self, bucket: &BucketRef, scope: &CredentialScope) -> Result<S3Credentials, ProviderError>;
    async fn revoke_credentials(&self, bucket: &BucketRef, key_id: &str) -> Result<(), ProviderError>;
    /// The `object_store` configuration Loam's roles receive (endpoint, region, path-style, TLS).
    fn store_config(&self, bucket: &BucketRef) -> ObjectStoreConfig;
}
  • rustfs: RustFS is deployed by its upstream Helm chart (rustfs/rustfs, helm/rustfs, Apache-2.0, 1.0.0 on 2026-09-16), and the provider creates buckets and access keys through RustFS's S3 and admin APIs (verify admin API shape).
  • s3: static credentials or IRSA / workload identity; no bucket creation unless allowed.
  • cellar: buckets and keys through clevercloud-sdk; data over S3. Whether Cellar honours If-None-Match and If-Match on PUT is unverified, and it decides whether Cellar can hold Loam's WAL or only static assets (Q-RT-9).

6. GitOps layout (D186)

6.1 Argo CD or Flux

Both are Apache-2.0 and CNCF-graduated. The latest releases are Argo CD v3.5.3 (2026-09-14; v3.6.0-rc1 on 2026-09-16) and Flux v2.9.5 (2026-08-31). Argo CD is chosen, for these reasons:

  1. The draft and this design are written in sync waves. Argo CD's argocd.argoproj.io/sync-wave orders resources inside an Application and, in an app-of-apps, orders the child Applications. Flux expresses the same thing with dependsOn between Kustomizations and HelmReleases. That works, but it is a different model from the one the owner wrote.
  2. Custom health checks for CRDs. Waves only wait for healthy resources. Argo CD's Lua resource.customizations.health lets the TiDB Operator v2 groups (PDGroup, TiKVGroup), RustFS, Loam and Function report real readiness.
  3. Hub and spoke for Loam cloud and BYOC. One Argo CD with ApplicationSets (cluster generator) can manage many clusters, and it has a UI for operators.

Costs, stated plainly. Argo CD is heavier than Flux: application controller, repo server, Redis, server and optional Dex (verify RSS on k3d). That matters on the dev machine and in small BYOC clusters. And since Argo CD 1.8, an Application's own health is not assessed by default. Without adding the documented argoproj.io/Application health customization, a parent's waves do not wait for child Applications to become healthy (verify against the v3.5 docs). The umbrella chart has no Argo-specific templates, so Flux can consume it unchanged if a BYOC customer requires Flux (Q-RT-11).

6.2 Repository layout

deploy/
  helm/loam-stack/                 # umbrella chart (Chart.yaml dependencies, all toggleable)
    charts/                        # rustfs (upstream), tidb-operator (upstream), loam-operator (fork),
                                   # resonate, loam-dapr, loam-gateway, envoy-gateway, dapr (long tail, off by default),
                                   # runtime (supervisor DaemonSet, RuntimeClasses)
    values.yaml
  gitops/
    bootstrap/argocd/              # Argo CD install + argocd-cm health customizations (Application, PDGroup, TiKVGroup, Loam, Function)
    root.yaml                      # the root Application (app-of-apps)
    apps/                          # one Application per wave, each rendering loam-stack with one component enabled
    envs/{dev-k3d,selfhosted,clever-cke,cloud}/values.yaml
  infra/clever-cke/                # Terraform (terraform-provider-clevercloud) — outside Argo CD

6.3 Sync waves

WaveApplicationContentsHealth gateClever piece
-2crdsCRDs: TiDB Operator v2 (core.pingcap.com), loam-operator, Gateway APICRDs establishedloam-operator CRDs (fork)
-1operatorsTiDB Operator v2; loam-operator; gVisor node setup (a DaemonSet installing runsc and the containerd shim, plus the gvisor RuntimeClass); Karpenter on CKEDeployments availablefork of clever-kubernetes-operator; karpenter-provider-clever-cloud (CKE only)
0object-storeRustFS (upstream chart) and ObjectStore resources for the system bucketsRustFS ready; ObjectStore Readycellar provider via clevercloud-sdk-rust when envs/clever-cke selects Cellar instead of RustFS
1tikvCluster + PDGroup + TiKVGroup (no TiDBGroup), TiKV with storage.api-version = 2 and enable-ttl = true (D122)Lua health on both groups—
2durableResonate server Deployment (the fork, TiKV store) + HPADeployment available—
3edgeloam-dapr (with biscuit-auth), loam-gateway, Envoy (Envoy Gateway), optional shared daprd for the long tailReady; Gateway Programmedbiscuit-auth (Eclipse, started at Clever)
4loamLoam resource → the engine rolesLoam Ready—
5runtimeSupervisor DaemonSet, RuntimePools, T0 workerd and T1 wasmtime, T2 when F2 landsDaemonSet rolled out—

envs/dev-k3d sets one replica everywhere and small TiKV memory (§20's playground peaked at 3.2 GB RSS for PD, TiKV and TiDB). It can use RustFS in single-node mode.

6.4 TiDB Operator v2 check (D179)

  • Status. main is v2 ("The main branch is now the default branch and hosts the v2 version", README). v2.0.0 was released on 2025-12-18 and v2.0.1 on 2026-03-26 (not pre-releases). v2.1.0-beta.6 and v2.2.0-alpha.11 (2026-09-16) are pre-releases. v1.6.6 (2026-08-12, release-1.x) is v1's latest. The v2 CRDs are still core.pingcap.com/v1alpha1 even in the GA line, which is an API-stability risk to pin against.
  • PD + TiKV only. v2 splits a cluster into a Cluster and one resource per component group. examples/pdms deploys Cluster, PDGroup, TSOGroup, SchedulingGroup and TiKVGroup with no TiDBGroup, and examples/basic puts TiDB in its own file (03-tidb.yaml). So a PD-and-TiKV cluster is a supported shape. In v1, TidbClusterSpec.TiDB is an optional pointer (json:"tidb,omitempty", release-1.6 types.go), but whether v1's controllers run cleanly without TiDB was not checked (verify).
  • Still to verify in F0: that storage.api-version = 2 passes through TiKVGroup.spec.template.spec.config; that PD keyspace pre-allocation (D122) can be set in PDGroup config; and Q33's question of whether keyspace is accepted for classic clusters.

7. Risks

RiskMitigation
The forked operator's reusable core is small, so the fork buys less than it seemsAccepted: it saves the skeleton and the chart hardening; track upstream crates/core changes by hand
Argo CD's footprint on small clustersMeasure on k3d (Q-RT-11); the chart stays Flux-consumable
TiDB Operator v2 CRDs are v1alpha1Pin the operator version per Loam release; conversion tested in upgrade CI
RustFS 1.0 is newPin; S3 provider fallback (D178)
LGPL sozu-command-lib pulled in by accident (through sozu-client or sozu-gateway)cargo deny license policy lists LGPL-3.0 as needing review
Biscuit adds a second token format§4 item 4; Q-RT-10

8. Open questions

#QuestionOwnerNeeded by
Q-RT-8The operator's API group and domain (loam.<domain>), and whether the fork lives at dina-kar/loam-operator or in the engine workspaceFounderOperator fork
Q-RT-9Does Cellar honour If-None-Match / If-Match on PUT, so that it can hold the WAL, or is it only for static assets and bundlesEngCellar provider
Q-RT-10Biscuit for §19's vending flow too (one attenuation mechanism), or Biscuit only inside the runtime; cargo deny result for biscuit-auth 6.0FounderF1 plan
Q-RT-11Argo CD's RSS on k3d and in the smallest BYOC profile; whether BYOC-local-meta (§10 §1) needs a Flux optionEngF1
Q-RT-12Envoy Gateway or plain Envoy with a static xDS from loam-gatewayEngF1 plan
Q-RT-13Is Clever Kubernetes Engine a first-class target (CI on CKE, the clever-cke env), or only documentedFounderBefore cloud beta
Q-RT-14Should Loam contribute back to clever-kubernetes-operator's crates/core (for example, a generic Controller registry release on crates.io) rather than carry a diverging forkFounderAfter the fork

9. Sources

Read on 2026-09-29 through the GitHub API (repos/<owner>/<repo>, /license, /commits, /releases) and the files named.

  • CleverCloud org listing (all public, non-archived, non-fork repositories); sozu-proxy, eclipse-biscuit and biscuit-auth org listings.
  • CleverCloud/clever-kubernetes-operator: LICENSE (MIT), README.md, Cargo.toml (v0.8.0, workspace crates/core, crates/operator), crates/operator/Cargo.toml (kube 3.1, clevercloud-sdk 1.0.1), crates/core/src/{controller,registry,strategy}.rs, crates/operator/src/svc/crd/postgresql.rs (group = "api.clever-cloud.com"), deployments/kubernetes/helm/.
  • sozu-proxy/sozu: LICENSE (AGPL-3.0), README.md, lib/Cargo.toml (AGPL-3.0), command/Cargo.toml (LGPL-3.0), bin/Cargo.toml (AGPL-3.0), doc/. CleverCloud/sozu-gateway: README.md, docs/features.md, Cargo.toml (sozu-command-lib = "=2.2.1"). CleverCloud/sozu-client: Cargo.toml.
  • eclipse-biscuit/biscuit-rust: README.md, biscuit-auth/Cargo.toml (6.0.0, Apache-2.0), biscuit-auth/LICENSE. eclipse-biscuit/biscuit LICENSE. eclipse-biscuit/biscuit-cli LICENSE (BSD-3-Clause).
  • CleverCloud/karpenter-provider-clever-cloud README.md; CleverCloud/clever-tools README.md; CleverCloud/clever-components README.md; LICENSE files of every repository in §2.
  • pando85/kaniop LICENSE.md (AGPL-3.0).
  • pingcap/tidb-operator: README.md, examples/{basic,pdms}/, api/core/v1alpha1/, releases and tags (v2.0.0, v2.0.1, v2.1.0-beta.6, v2.2.0-alpha.11, v1.6.6), release-1.6:pkg/apis/pingcap/v1alpha1/types.go.
  • rustfs/rustfs: LICENSE (Apache-2.0), helm/, release 1.0.0. cloudflare/pingora (Apache-2.0, 0.9.0), memorysafety/river (Apache-2.0/MIT, v0.5.0, last commit 2024-09-06), envoyproxy/envoy (Apache-2.0, v1.39.1), argoproj/argo-cd (Apache-2.0, v3.5.3), fluxcd/flux2 (Apache-2.0, v2.9.5).
  • Loam: §10 §1, §18, §19 §5, §20 §9 and §15, §21, §22 §13b; D1, D61, D66, D67, D71, D72, D73, D74, D122, D-SC-16; Q33.

On this page