Skip to main content
Hemanth.
Back to Feed
2025Backend & Systems

AuraDeploy: Distributed Container Orchestration Engine

A high-availability container orchestration engine written natively in Go, leveraging embedded Raft consensus, custom CNI networking, and CRI-O/containerd OCI runtimes.

Rationale

Why AuraDeploy? Full Kubernetes stacks carry heavy operational overhead and memory footprints that are overkill for resource-constrained or edge environments. I challenged myself to engineer a single-binary control plane in Go that guarantees state consistency and self-healing.

The Hardest Challenge: Multi-host container networking without external plugins. I wrote a custom CNI that uses Linux netlink to create veth pairs, attaches them to a host bridge (aura0), and encapsulates traffic across nodes via a VXLAN overlay interface (vxlan0).

Tech Stack

GoHashiCorp Raftcontainerd / CRI-OCustom CNI (VXLAN)Custom CSIGitOpsJWT / RBACPrometheusOpenTelemetryReact
System Architecture

Core Engineering Challenge

The Bottleneck: High-frequency cluster status updates to the React dashboard could easily trigger heavy DOM re-renders and UI freezing.

The Backend Architecture

Go goroutines continuously poll Raft state and system metrics, broadcasting snapshot diffs over a high-throughput WebSocket hub.

The Frontend Solution

Directly intercepted WebSocket payloads into the React Query cache, bypassing traditional React state hooks to achieve polling-free, 60fps dashboard updates.

Key Highlights

  • ▹Architected an Active-Passive high-availability control plane in Go using embedded HashiCorp Raft for distributed consensus, log replication, and FSM snapshots with zero external DB dependency.
  • ▹Integrated native CRI-O / containerd runtime interfaces (`containerd/oci`) for staging OCI images, configuring cgroup limits, and managing network namespaces via `netlink`.
  • ▹Designed a custom scheduling loop with predicate filtering (`HasSufficientResources`, `VolumeNodeAffinity`) and `LeastAllocated` priority scoring for optimal cluster workload placement.
  • ▹Engineered a multi-host custom CNI overlay featuring VXLAN mesh networking, deterministic `/24` IPAM subnets, and an integrated dummy UDP DNS server for service discovery.
  • ▹Built a custom CSI local volume provisioner with 1:1 PVC host-path binding, JWT + RBAC authentication, admission-control webhooks, and a declarative GitOps drift reconciler.

Architecture Details

AuraDeploy is structured as a decoupled distributed control plane and container execution agent written entirely in Go.

1. Control Plane & Consensus (Subsystem A)

  • Embedded HashiCorp Raft manages state machine replication, leader election, and log snapshots.
  • An HTTP API server protected by JWT authentication and RBAC admission control redirects state mutations to the active Raft leader.
  • A GitOps reconciler periodically diffs remote Git manifest specs against current cluster state to heal drift.

2. Execution & Data Plane (Subsystem B)

  • Custom Scheduler: Runs a goroutine loop evaluating predicates and LeastAllocated priorities to bind pending pods to worker nodes.
  • CRI-O / containerd Client: Downloads OCI image layers, applies cgroup memory/CPU limits, and spawns container runtimes.
  • Custom CNI & CSI: Provisions VXLAN network interfaces, handles deterministic IPAM allocations, and binds local storage paths to PVC mounts.

Interactive System Design

Click nodes to inspect engineering flow

API & Admission Control

JWTRBACValidating Webhooks
Engineering Insight

Extracts Bearer tokens and authorizes subjects against internal FSM RoleBindings. Intercepts layouts to strip Privileged Containers mapping to PodSecurityStandards.

Platform Showcase

AuraDeploy: Distributed Container Orchestration Engine Interface Banner

Technical Walkthrough