Harmonized ecosystem.
Proven interoperability.
Every component exposes structured CRDs, emits unified OTel telemetry, and is designed to be managed by Specter. This is not a collection of tools. It is an integrated, AI-manageable ecosystem.
One tool from bootstrap to day-2
Bootstrap, operate, evolve
Catalyst handles the full platform lifecycle. It provisions your initial cluster, manages day-2 operations, provides an Internal Developer Platform for your teams, and gives operators a Workflow Explorer for visibility into every reconciliation.
Bootstrap
- Provisions infrastructure and K3s cluster
- Deploys all platform components via GitOps
- Exits cleanly — safe to remove
Day-2 operations
- Cloud resources managed as Kubernetes CRDs
- Continuous drift detection and reconciliation
- Self-service via IDP templates
Functional layers of the platform
All components
Bootstrap IaC (MPL 2.0)
InfrastructureDay-2 cloud resource provisioning
InfrastructureCNI + Service Mesh (eBPF, mTLS, L7)
Networking & Service MeshL7 proxy (embedded in Cilium)
Networking & Service MeshWAF (OWASP CRS)
Networking & Service MeshDNS sync to provider
Networking & Service MeshGSLB (authoritative DNS)
Networking & Service MeshGitOps engine
GitOps & GitInternal Git + CI/CD
GitOps & GitTLS certificates
SecuritySecrets operator
SecuritySecrets backend (per cluster, MPL 2.0)
SecuritySecurity scanning
SecurityRuntime security (eBPF)
SecurityContainer image signing + verification
Supply ChainSBOM generation + vulnerability matching
Supply ChainPolicy engine (validation, mutation, generation)
PolicyVertical autoscaling
ScalingEvent-driven horizontal autoscaling
ScalingAuto-restart on ConfigMap/Secret changes
OperationsAlloy, Loki, Mimir, Tempo, Grafana
ObservabilityApplication tracing (auto-instrumentation)
ObservabilityHot SIEM backend
ObservabilityContainer/artifact registry
RegistryObject storage
StorageBackup/restore
StorageContinuous availability orchestration
FailoverPostgreSQL operator
Data ServicesMongoDB wire protocol on PostgreSQL
Data ServicesApache Kafka streaming
Data ServicesRedis-compatible cache
Data ServicesOLAP analytics
Data ServicesEmail server (JMAP/IMAP/SMTP)
CommunicationK8s-native TURN/STUN (WebRTC)
CommunicationVideo/audio (WebRTC SFU)
CommunicationTeam chat (federation)
CommunicationPush notifications (HTTP/SSE/WebSocket)
CommunicationSaga orchestration
Workflow & ProcessingStream + batch processing
Workflow & ProcessingChange data capture (CDC)
Workflow & ProcessingOpen table format (data lakehouse)
AnalyticsBI dashboards and data exploration
AnalyticsModel serving
AI / MLServerless platform
AI / MLLLM inference
AI / MLVector database
AI / MLGraph database
AI / MLChat UI
AI / MLEmbeddings + reranking
AI / MLSubscription proxy for Claude Code
AI / MLOpenAI-to-Anthropic translation
AI / MLAI safety firewall
AI Safety & ObservabilityLLM observability (traces, cost, eval)
AI Safety & ObservabilityFAPI Authorization Server
Identity & MonetizationUsage metering
Identity & MonetizationChaos engineering experiments
OperationsThe AI brain of the platform
Specter has pre-built semantic knowledge of every CRD schema, integration dependency, failure mode, health check, upgrade path, and compliance mapping across every component. It doesn’t dump logs into an LLM. It sends surgical, structured context.
DevOps Agent
Drift detection, resource optimization, scaling recommendations, deployment validation
DevSecOps Agent
CVE scanning, policy compliance, security posture assessment, vulnerability remediation
SRE Agent
Incident correlation, root cause analysis, auto-remediation, runbook execution
FinOps Agent
Cost anomaly detection, right-sizing, waste elimination, capacity forecasting
Compliance Agent
Continuous audit, evidence collection, report generation, regulatory mapping
AI Ops Agent
LLM inference monitoring, model drift detection, GPU utilization, AI safety policy enforcement
Built for disaster recovery
Independent clusters
- 2 regions recommended (1 allowed)
- NOT stretched clusters — independent and resilient
- k8gb authoritative DNS for GSLB
- Split-brain protection via external DNS witnesses