Architecture
Namespaced installation
Section titled “Namespaced installation”graal installs into two namespaces of your Kubernetes cluster:
- an application namespace (console, API, platform services);
- a workload execution namespace (
graal-runin the reference deployment), where user jobs and workspaces run.
The installation creates no CRDs, requires no cluster-admin rights, and creates no
namespace, ServiceAccount or RoleBinding itself: those objects are provided by your platform
team (an execution ServiceAccount, a namespaced Role).
Every pod — including user workloads — follows the PSA restricted profile:
runAsNonRoot: true;- all Linux capabilities dropped (
drop: ["ALL"]); - seccomp profile
RuntimeDefault.
Images (Python, Spark, Jupyter, VS Code…) come from a registry you control; no arbitrary user-supplied image is ever run.
Components
Section titled “Components”| Component | Role |
|---|---|
| Keycloak | One realm per tenant, directory federation possible |
| PostgreSQL | Dedicated application database, and the Iceberg catalog (one schema per tenant) |
| S3 storage | Buckets, files and Apache Iceberg tables |
| Trino | SQL engine on Iceberg tables and your existing databases |
| MLflow (facade) | Experiment tracking and model registry |
Secrets
Section titled “Secrets”Project secrets (credentials to your systems) are encrypted at rest (AES-256-GCM) in the database, with a key derived per tenant from a root key you generate at installation (see installation).
See also: Security and governance · the site’s Architecture page.