Skip to content

Architecture

graal installs into two namespaces of your Kubernetes cluster:

  • an application namespace (console, API, platform services);
  • a workload execution namespace (graal-run in the reference deployment), where user jobs and workspaces run.

The installation creates no CRDs, requires no cluster-admin rights, and creates no namespace, ServiceAccount or RoleBinding itself: those objects are provided by your platform team (an execution ServiceAccount, a namespaced Role).

Every pod — including user workloads — follows the PSA restricted profile:

  • runAsNonRoot: true;
  • all Linux capabilities dropped (drop: ["ALL"]);
  • seccomp profile RuntimeDefault.

Images (Python, Spark, Jupyter, VS Code…) come from a registry you control; no arbitrary user-supplied image is ever run.

Component Role
Keycloak One realm per tenant, directory federation possible
PostgreSQL Dedicated application database, and the Iceberg catalog (one schema per tenant)
S3 storage Buckets, files and Apache Iceberg tables
Trino SQL engine on Iceberg tables and your existing databases
MLflow (facade) Experiment tracking and model registry

Project secrets (credentials to your systems) are encrypted at rest (AES-256-GCM) in the database, with a key derived per tenant from a root key you generate at installation (see installation).

See also: Security and governance · the site’s Architecture page.