This lesson focuses on Kubernetes-native patterns and trade-offs between Crossplane, Terraform/OpenTofu, and Cluster API. Understanding when to use each will help you design self-service, GitOps-driven platforms.


Crossplane — Kubernetes-native infrastructure control
Crossplane is a CNCF project that treats cloud resources as Kubernetes custom resources (CRDs). It runs controllers in-cluster to reconcile those CRs against cloud provider APIs, enabling a Kubernetes-native control plane for external resources. You can compose reusable infrastructure patterns (Compositions) and expose developer-friendly claim APIs (CompositeResourceDefinitions, XRDs). Benefits:- Cloud resources become first-class Kubernetes objects with continuous reconciliation.
- Compositions let you package complex infrastructure patterns as templates.
- GitOps-friendly and integrates with Kubernetes RBAC, admission controllers, and observability.

- Define a CompositeResourceDefinition (XRD) that models what developers can request.
- Create a Composition template that maps the XRD to concrete cloud resources (e.g., RDS instance, network, secrets).
- Developers submit a claim (instance of the XRD) and Crossplane reconciles the Composition to provision resources.


Terraform / OpenTofu — mature IaC with operator integrations
Terraform (HashiCorp) is the long-standing infrastructure-as-code tool using HCL and a large provider ecosystem. Terraform’s license change led to community forks such as OpenTofu (a community-driven fork of Terraform); OpenTofu aims to preserve an open-source path while maintaining compatibility with Terraform modules and HCL. Terraform/OpenTofu characteristics:- Mature ecosystem and provider coverage.
- HCL language and state management (remote state backends).
- Often used outside the cluster (CI/CD pipelines) or integrated into-cluster via operators.

- Terraform/OpenTofu have broad provider coverage and module ecosystems.
- They are not inherently Kubernetes-native; you integrate them into GitOps workflows or run them from CI/CD.
- Crossplane provides tighter Kubernetes-native reconciliation, but Terraform has a lower initial learning curve for many teams and more mature provider modules.
Cluster API — declarative cluster lifecycle management
Cluster API (CAPI) is a CNCF project that focuses on Kubernetes cluster lifecycle management (provisioning, scaling, upgrades, machine lifecycle) using Kubernetes-style declarative APIs. It’s effectively “Kubernetes managing Kubernetes” — controllers in a management cluster reconcile Cluster and Machine CRs to provision and operate workload clusters.
- Cluster lifecycle: creating, upgrading, and scaling Kubernetes clusters.
- Multi-cloud/hybrid/edge consistent cluster management.
- Use-cases where you want cluster standardization and automation of node and control-plane lifecycle.


Comparing the three approaches
- Crossplane: Kubernetes-native, manages a wide range of cloud resources via CRDs and Compositions; excellent for GitOps-driven, self-service platforms. Requires deeper Kubernetes expertise to design compositions effectively.
- Terraform/OpenTofu: Mature IaC, extensive provider ecosystem and modules, generally managed outside the cluster (or integrated via operators). Familiar, approachable HCL workflow and broad community adoption.
- Cluster API: Specialized for Kubernetes cluster lifecycle management. Narrow scope but deep capability for cluster provisioning, scaling, and upgrades.


- Crossplane: deep Kubernetes skills, composition design, and provider wiring.
- Terraform/OpenTofu: HCL proficiency, state and module management; easier ramp for many teams.
- Cluster API: Kubernetes and cluster operations experience — focused but narrower in scope.
Patterns and best practices (2025)
Aim for layered abstractions and GitOps-first workflows. Reusable compositions and modules reduce one-off “unicorns.” Policy-as-code and built-in observability ensure compliance and operational visibility across teams.
- Start experimenting with Cluster API to standardize and manage cluster lifecycles.
- Add Crossplane to model application infrastructure as Kubernetes resources and provide self-service compositions.
- Keep Terraform/OpenTofu for complex foundational networking, or for teams that already rely on a large Terraform module ecosystem.
- Expose multiple abstraction levels (platform operators, SREs, and developers) according to persona.


Key takeaways
- Crossplane (CNCF): represents Kubernetes-native infrastructure control using CRDs and composition patterns; ideal when you want infrastructure as Kubernetes objects and tight GitOps integration.
- Terraform / OpenTofu: mature IaC ecosystem using HCL and modules; often the quickest way to adopt IaC at scale and has the largest provider coverage.
- Cluster API (CNCF): specialized for Kubernetes cluster lifecycle management — provisioning, upgrading, scaling — and not a general cloud resource orchestrator.
- Design your platform with layered abstractions, GitOps, policy-as-code, and observability to enable self-service while preserving security and compliance.


