AuraDeploy: Distributed Container Orchestration Engine
A high-availability container orchestration engine written natively in Go, leveraging embedded Raft consensus, custom CNI networking, and CRI-O/containerd OCI runtimes.
Rationale
Why AuraDeploy? Full Kubernetes stacks carry heavy operational overhead and memory footprints that are overkill for resource-constrained or edge environments. I challenged myself to engineer a single-binary control plane in Go that guarantees state consistency and self-healing.
The Hardest Challenge: Multi-host container networking without external plugins. I wrote a custom CNI that uses Linux netlink to create veth pairs, attaches them to a host bridge (aura0), and encapsulates traffic across nodes via a VXLAN overlay interface (vxlan0).
Tech Stack

Core Engineering Challenge
The Bottleneck: High-frequency cluster status updates to the React dashboard could easily trigger heavy DOM re-renders and UI freezing.
The Backend Architecture
Go goroutines continuously poll Raft state and system metrics, broadcasting snapshot diffs over a high-throughput WebSocket hub.
The Frontend Solution
Directly intercepted WebSocket payloads into the React Query cache, bypassing traditional React state hooks to achieve polling-free, 60fps dashboard updates.
Key Highlights
- ▹Architected an Active-Passive high-availability control plane in Go using embedded HashiCorp Raft for distributed consensus, log replication, and FSM snapshots with zero external DB dependency.
- ▹Integrated native CRI-O / containerd runtime interfaces (`containerd/oci`) for staging OCI images, configuring cgroup limits, and managing network namespaces via `netlink`.
- ▹Designed a custom scheduling loop with predicate filtering (`HasSufficientResources`, `VolumeNodeAffinity`) and `LeastAllocated` priority scoring for optimal cluster workload placement.
- ▹Engineered a multi-host custom CNI overlay featuring VXLAN mesh networking, deterministic `/24` IPAM subnets, and an integrated dummy UDP DNS server for service discovery.
- ▹Built a custom CSI local volume provisioner with 1:1 PVC host-path binding, JWT + RBAC authentication, admission-control webhooks, and a declarative GitOps drift reconciler.
Architecture Details
AuraDeploy is structured as a decoupled distributed control plane and container execution agent written entirely in Go.
1. Control Plane & Consensus (Subsystem A)
- Embedded HashiCorp Raft manages state machine replication, leader election, and log snapshots.
- An HTTP API server protected by JWT authentication and RBAC admission control redirects state mutations to the active Raft leader.
- A GitOps reconciler periodically diffs remote Git manifest specs against current cluster state to heal drift.
2. Execution & Data Plane (Subsystem B)
- Custom Scheduler: Runs a goroutine loop evaluating predicates and
LeastAllocatedpriorities to bind pending pods to worker nodes. - CRI-O / containerd Client: Downloads OCI image layers, applies cgroup memory/CPU limits, and spawns container runtimes.
- Custom CNI & CSI: Provisions VXLAN network interfaces, handles deterministic IPAM allocations, and binds local storage paths to PVC mounts.
Interactive System Design
API & Admission Control
Engineering Insight
Extracts Bearer tokens and authorizes subjects against internal FSM RoleBindings. Intercepts layouts to strip Privileged Containers mapping to PodSecurityStandards.
Platform Showcase
