Reconciliation, security, and intent delivery — as runtime services.
You declare behavior; Orkestra runs it.No boilerplate. No scaffolding. No ceremony.
Keep your existing Reconcile() — or point to an HTTP server in any language.
Informers, workqueues, workers, leader election, retries, finalizers, drift correction, status patching, panic recovery — provided unconditionally to every CRD in your Katalog. You own the declaration. Orkestra owns the loop.
Admission webhooks, validation rules, mutation rules, RBAC generation, TLS management, deletion protection, namespace isolation, pod security — derived from your declarations. The default posture is the safe one.
CR construction, caller interfaces, field routing, value translation, schema evolution — any caller submits flat intent in their own vocabulary. The gateway translates, validates, stamps provenance, and delivers. No caller sees a CRD schema.
Two binaries: ork is the operator CLI. orkcc is the Control Center.
Traditionally, your operator has whatever you built into it. If you forgot metrics, there are no metrics. In Orkestra, the runtime provides the full stack unconditionally to every CRD in your Katalog.
apiVersion: orkestra.orkspace.io/v1 kind: Katalog metadata: name: hello-website spec: crds: website: crdFile: my-website.yaml operatorBox: reconcile: onCreate: deployments: - image: "{{ .spec.image }}" replicas: "{{ .spec.replicas }}" reconcile: true
// Your Reconcile method: completely untouched. // Same signature. Same body. Same r.Get, r.Status().Update(). func (r *WebAppReconciler) Reconcile( ctx context.Context, req ctrl.Request, ) (ctrl.Result, error) { // ... your logic, unchanged ... return ctrl.Result{}, nil } // Two lines replace SetupWithManager, Scheme, and main.go. func NewWebAppReconciler(kube kubeclient.Interface) domain.Reconciler { return domain.ReconcilerFrom(&WebAppReconciler{ Client: orkadapter.ToClient(kube), }) }
# The reconciler is any HTTP server — bash, Python, Go, Rust. # It receives the CR as JSON and returns resources + status. # No kubeconfig. No SDK. No Kubernetes knowledge required. operatorBox: reconcile: default: false remote: endpoint: "http://my-service/reconcile" timeout: 15s auth: secretRef: name: reconciler-token key: token managedResources: - group: apps plural: deployments # Orkestra owns: queue · backoff · SSA apply · owner refs # RBAC · health · events · annotation stamping # The server owns: everything else.
The moment you run ork run, a live dashboard starts on :8081 — showing every CRD, worker, queue depth, and reconcile event. No extra setup.
ork CLI. Launch with ork control — no additional binary or Helm chart.Add serve: true to a CRD entry. Your operator instantly surfaces a token-scoped API. Callers submit flat intent in their own vocabulary. Orkestra translates, validates, stamps provenance, and applies.
When the CRD schema changes — a field moves, a structure deepens — update one line in the serve declaration. Callers notice nothing.
# What the caller submits (flat, no Kubernetes) target: app name: payments-api repository: myorg/payments-api environment: staging team: payments replicas: 2 # What Orkestra builds and applies apiVersion: platform.myco.io/v1 kind: App metadata: name: payments-api namespace: team-payments-staging annotations: orkestra.sh/target: app orkestra.sh/source: github-actions orkestra.sh/subject: repo:myorg/payments:ref:main spec: source.repository: myorg/payments-api environment: staging replicas: 2
The Orkestra Registry distributes operator patterns as OCI artifacts. A Katalog pulled at postgres:v14 behaves identically in every environment. Uses your existing docker login. See production deployment →
Every pattern ships with a declarative E2E test that gates publication. You do not push a pattern without proof it works.
ork pull postgres:v14
ork push my-operator:v1 .
ork patternsNo shared database. No shared cache. No direct in-process calls. Run them on the same pod or entirely separate deployments.
The reconciliation engine. Watches Kubernetes resources, runs operator logic, manages resource lifecycle, exposes the /katalog API.
Serves admission and conversion webhooks, handles notifications, validates and delivers intent. Stateless, multi-replica. No reconciliation logic.
Connects to one or more runtimes, reads their /katalog APIs, and renders a live view of every operator, CRD, worker, and CR in your fleet.
Why reconciliation is a data problem, not a programming problem — and how the Katalog completes the promise Kubernetes made in 2017.
A missed interview, a wall of boilerplate, and a pattern that kept repeating. The story behind the super-operator model and the music metaphor.
DevOps. GitOps. PlatformOps. Every shift absorbed complexity from callers. IntentOps absorbs the manifest itself.