> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Infrastructure Provisioning with Kubernetes

> Overview of Kubernetes-centric infrastructure provisioning comparing Crossplane, Terraform/OpenTofu and Cluster API for GitOps driven self-service platform engineering and cluster lifecycle management

All right — welcome to another core topic in CNPA Domain 4: Infrastructure Provisioning with Kubernetes.

This is a foundational area for modern platform engineering. In this lesson we’ll cover three major approaches that platform teams use to manage cloud resources in a Kubernetes-centric environment: Crossplane, Terraform/OpenTofu, and Cluster API. These are important concepts for the CNPA exam and for real-world platform design.

<Callout icon="lightbulb" color="#1CB2FE">
  This lesson focuses on Kubernetes-native patterns and trade-offs between Crossplane, Terraform/OpenTofu, and Cluster API. Understanding when to use each will help you design self-service, GitOps-driven platforms.
</Callout>

Why re-think traditional provisioning? Consider this common scenario: your platform supports multiple development teams across AWS and Azure and needs to provide self-service provisioning for databases, storage, and networking — fast, without tickets — and integrated into the same GitOps workflow developers use for applications. You also want consistent behavior across clouds and Kubernetes-native integration.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/platform-2025-multicloud-gitops-kubernetes-selfservice.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=55ee1be874702f87cd1a90a481f32ad5" alt="A presentation slide titled &#x22;Platform Engineering Infrastructure Challenges in 2025&#x22; showing four modern platform requirements: Multi-Cloud Complexity, Developer Self-Service, GitOps Integration, and Kubernetes‑Native. Each requirement is shown in a colored card with a short explanatory line beneath." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/platform-2025-multicloud-gitops-kubernetes-selfservice.jpg" />
</Frame>

The core goal is a single source of truth and developer self-provisioning that is GitOps-friendly and, ideally, Kubernetes-native. Below we describe three common approaches and how they differ by native integration, resource scope, and operational model.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-opentofu-clusterapi-kubernetes-paths.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=f9df923077e93813cbf16886bfac4c99" alt="A slide titled &#x22;Three Paths to Kubernetes-Native Infrastructure&#x22; showing three options—Crossplane (CNCF), OpenTofu/Terraform, and Cluster API (CNCF)—each with a short description of their approach. Below are gray labels for &#x22;Native Integration&#x22;, &#x22;Resource Scope&#x22;, and &#x22;Operational Model&#x22; and a KodeKloud copyright." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-opentofu-clusterapi-kubernetes-paths.jpg" />
</Frame>

## Crossplane — Kubernetes-native infrastructure control

Crossplane is a CNCF project that treats cloud resources as Kubernetes custom resources (CRDs). It runs controllers in-cluster to reconcile those CRs against cloud provider APIs, enabling a Kubernetes-native control plane for external resources. You can compose reusable infrastructure patterns (Compositions) and expose developer-friendly claim APIs (CompositeResourceDefinitions, XRDs).

Benefits:

* Cloud resources become first-class Kubernetes objects with continuous reconciliation.
* Compositions let you package complex infrastructure patterns as templates.
* GitOps-friendly and integrates with Kubernetes RBAC, admission controllers, and observability.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-universal-cloud-api-features.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=19ec4d0fa4f6811115454a70d6b7b9b7" alt="A slide titled &#x22;Crossplane – CNCF's Universal Cloud API&#x22; showing four colored feature boxes: Custom Resources, Reconciliation, Composition, and Multi-Cloud. Each box has a brief description of that feature (e.g., cloud resources as Kubernetes objects, continuous reconciliation, reusable composition templates, and a single API for multiple cloud providers)." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-universal-cloud-api-features.jpg" />
</Frame>

Typical flow for a Database-as-a-Service with Crossplane:

1. Define a CompositeResourceDefinition (XRD) that models what developers can request.
2. Create a Composition template that maps the XRD to concrete cloud resources (e.g., RDS instance, network, secrets).
3. Developers submit a claim (instance of the XRD) and Crossplane reconciles the Composition to provision resources.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-database-provisioning-three-step.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=f9b070cb025095dfe5fd7b79cd52d33f" alt="A presentation slide titled &#x22;Crossplane in Action — Database-as-a-Service&#x22; showing a &#x22;Three-Step Provisioning Flow.&#x22; The three steps shown are: Define Composite Resource Definition (XRD), Create Composition Template, and Developers Submit Claims." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-database-provisioning-three-step.jpg" />
</Frame>

Example: install a Crossplane AWS provider using Kubernetes YAML.

```yaml theme={null}
# Provider: Connects to cloud APIs
apiVersion: pkg.crossplane.io/v1
kind: Provider
metadata:
  name: provider-aws
spec:
  package: xpkg.upbound.io/crossplane-contrib/provider-aws:v0.44.0
```

Example XRD (schema that defines what developers can request):

```yaml theme={null}
# XRD: Define what developers can request
apiVersion: apiextensions.crossplane.io/v1
kind: CompositeResourceDefinition
metadata:
  name: xpostgresqlinstances.database.spr.com
spec:
  group: database.spr.com
  versions:
    - name: v1alpha1
      schema:
        openAPIV3Schema:
          properties:
            spec:
              properties:
                storageGB:
                  type: integer
                  minimum: 20
                engineVersion:
                  type: string
                  enum: ["13.7", "14.6", "15.1"]
```

Platform teams like Crossplane because it enforces Kubernetes patterns (reconciliation, RBAC, GitOps) across infrastructure, enabling self-service claims, templated compositions, and standard monitoring.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-platform-benefits-kodekloud.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=d0abae5d74f243a276cd63f445853071" alt="A presentation slide titled &#x22;Why Platform Teams Choose Crossplane&#x22; listing four key benefits — Kubernetes-Native, GitOps Compatible, Self-Service, and Observability — each with a short explanatory note. The slide is branded © KodeKloud." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-platform-benefits-kodekloud.jpg" />
</Frame>

## Terraform / OpenTofu — mature IaC with operator integrations

Terraform (HashiCorp) is the long-standing infrastructure-as-code tool using HCL and a large provider ecosystem. Terraform’s license change led to community forks such as OpenTofu (a community-driven fork of Terraform); OpenTofu aims to preserve an open-source path while maintaining compatibility with Terraform modules and HCL.

Terraform/OpenTofu characteristics:

* Mature ecosystem and provider coverage.
* HCL language and state management (remote state backends).
* Often used outside the cluster (CI/CD pipelines) or integrated into-cluster via operators.

You can run Terraform from CI (recommended for many teams), or use an in-cluster Terraform Operator that exposes Terraform runs via CRs. A typical pattern is to keep Terraform modules as the canonical module source and trigger runs from a GitOps pipeline or operator.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-opentofu-clusterapi-kubernetes-paths.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=f9df923077e93813cbf16886bfac4c99" alt="A slide titled &#x22;Three Paths to Kubernetes-Native Infrastructure&#x22; showing three options—Crossplane (CNCF), OpenTofu/Terraform, and Cluster API (CNCF)—each with a short description of their approach. Below are gray labels for &#x22;Native Integration&#x22;, &#x22;Resource Scope&#x22;, and &#x22;Operational Model&#x22; and a KodeKloud copyright." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-opentofu-clusterapi-kubernetes-paths.jpg" />
</Frame>

Example of a Terraform custom resource that triggers an in-cluster Terraform operator:

```yaml theme={null}
# Terraform Operator in Kubernetes
apiVersion: tf.isaaguilar.com/v1alpha1
kind: Terraform
metadata:
  name: pony-database-infrastructure
spec:
  terraformModule:
    source: "git::https://github.com/spr/terraform-modules//rds-postgres"
  outputsToSecret:
    name: pony-db-connection
```

Notes on trade-offs:

* Terraform/OpenTofu have broad provider coverage and module ecosystems.
* They are not inherently Kubernetes-native; you integrate them into GitOps workflows or run them from CI/CD.
* Crossplane provides tighter Kubernetes-native reconciliation, but Terraform has a lower initial learning curve for many teams and more mature provider modules.

## Cluster API — declarative cluster lifecycle management

Cluster API (CAPI) is a CNCF project that focuses on Kubernetes cluster lifecycle management (provisioning, scaling, upgrades, machine lifecycle) using Kubernetes-style declarative APIs. It’s effectively “Kubernetes managing Kubernetes” — controllers in a management cluster reconcile Cluster and Machine CRs to provision and operate workload clusters.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/cluster-api-kubernetes-features.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=132541ea13eeacd2bdf005b1189f389b" alt="A presentation slide titled &#x22;Cluster API – Managing Kubernetes With Kubernetes.&#x22; It shows four colored feature boxes—Cluster Provisioning, Node Management, Cluster Upgrades, and Multi‑Cloud—with brief descriptions about creating clusters, scaling nodes, automated version upgrades, and multi‑cloud management." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/cluster-api-kubernetes-features.jpg" />
</Frame>

Cluster API is best suited for:

* Cluster lifecycle: creating, upgrading, and scaling Kubernetes clusters.
* Multi-cloud/hybrid/edge consistent cluster management.
* Use-cases where you want cluster standardization and automation of node and control-plane lifecycle.

Cluster API components include management cluster controllers, control plane controllers, machine controllers, and MachineHealthCheck controllers that automate node lifecycle and control plane operations.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/cluster-api-controllers-machines.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=d5ed4db42240cbb628e4a1a678daf989" alt="A slide titled “Cluster API Components – Controllers and Machines” showing four component types—Management Cluster, Workload Clusters, Machine Controllers, and Control Plane Controllers—each with a short description of its role." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/cluster-api-controllers-machines.jpg" />
</Frame>

Cluster API example: a Cluster resource that references an AWS infrastructure provider to declare a Kubernetes cluster.

```yaml theme={null}
# Cluster API Cluster resource
apiVersion: cluster.x-k8s.io/v1beta1
kind: Cluster
metadata:
  name: pony-production-cluster
spec:
  clusterNetwork:
    pods:
      cidrBlocks: ["192.168.0.0/16"]
  infrastructureRef:
    apiVersion: infrastructure.cluster.x-k8s.io/v1beta2
    kind: AWSCluster
    name: pony-production-cluster
```

Key point: Cluster API is focused on clusters themselves. It is not a general-purpose cloud resource orchestrator like Crossplane or Terraform. You’ll often combine Cluster API with Crossplane or Terraform for underlying networking and cloud resources.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/cluster-api-platform-engineering-callouts.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=7388063140efa18d5f28a99f865c5025" alt="A presentation slide titled &#x22;When to Use Cluster API for Platform Engineering&#x22; showing three colored callouts: &#x22;Multi‑Tenant Platforms&#x22; (provide dedicated clusters per team), &#x22;Edge and Hybrid&#x22; (manage clusters across on‑premises and cloud), and &#x22;Cluster Standardization&#x22; (ensure consistent cluster configurations)." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/cluster-api-platform-engineering-callouts.jpg" />
</Frame>

## Comparing the three approaches

* Crossplane: Kubernetes-native, manages a wide range of cloud resources via CRDs and Compositions; excellent for GitOps-driven, self-service platforms. Requires deeper Kubernetes expertise to design compositions effectively.
* Terraform/OpenTofu: Mature IaC, extensive provider ecosystem and modules, generally managed outside the cluster (or integrated via operators). Familiar, approachable HCL workflow and broad community adoption.
* Cluster API: Specialized for Kubernetes cluster lifecycle management. Narrow scope but deep capability for cluster provisioning, scaling, and upgrades.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/infrastructure-scope-crossplane-terraform-clusterapi.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=0e1c25fab5cc7d8358e7fbee34a32430" alt="A slide titled &#x22;Choosing the Right Tool — Crossplane vs Terraform vs Cluster API&#x22; showing an &#x22;Infrastructure Scope&#x22; comparison: Crossplane supports any cloud resource (databases, storage, networking, clusters), Terraform supports any cloud resource across providers, and Cluster API targets Kubernetes clusters exclusively." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/infrastructure-scope-crossplane-terraform-clusterapi.jpg" />
</Frame>

Team expertise considerations:

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-terraform-cluster-api-expertise.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=b1ff2ad58b37126fb77efe3bdb94d4d2" alt="A presentation slide titled &#x22;Choosing the Right Tool – Crossplane vs Terraform vs Cluster API&#x22; that summarizes required team expertise. It lists Crossplane (deep Kubernetes knowledge, composition design), Terraform (HCL proficiency, state management), and Cluster API (Kubernetes knowledge, cluster operations expertise)." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/crossplane-terraform-cluster-api-expertise.jpg" />
</Frame>

* Crossplane: deep Kubernetes skills, composition design, and provider wiring.
* Terraform/OpenTofu: HCL proficiency, state and module management; easier ramp for many teams.
* Cluster API: Kubernetes and cluster operations experience — focused but narrower in scope.

## Patterns and best practices (2025)

Aim for layered abstractions and GitOps-first workflows. Reusable compositions and modules reduce one-off “unicorns.” Policy-as-code and built-in observability ensure compliance and operational visibility across teams.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/2025-infra-provisioning-patterns.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=e96b53cfc8b8fd47044dda4dc6714f09" alt="A slide titled &#x22;2025 Best Practices – Infrastructure Provisioning Patterns.&#x22; It lists five numbered practices with brief explanations: Layered Abstractions, GitOps Everything, Composition Over Configuration, Policy as Code, and Observability Built‑In." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/2025-infra-provisioning-patterns.jpg" />
</Frame>

Implementation guidance (example timeline):

1. Start experimenting with Cluster API to standardize and manage cluster lifecycles.
2. Add Crossplane to model application infrastructure as Kubernetes resources and provide self-service compositions.
3. Keep Terraform/OpenTofu for complex foundational networking, or for teams that already rely on a large Terraform module ecosystem.
4. Expose multiple abstraction levels (platform operators, SREs, and developers) according to persona.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/2025-best-practices-infra-provisioning-patterns.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=e7ddc15614bc4f6cd1d079abd1f34428" alt="A slide titled &#x22;2025 Best Practices – Infrastructure Provisioning Patterns&#x22; showing an &#x22;Implementation Guidelines&#x22; timeline with four numbered steps. The recommendations are: start with Cluster API for cluster management, add Crossplane for application infrastructure, keep Terraform for complex networking and foundational resources, and provide multiple abstraction levels for different user personas." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/2025-best-practices-infra-provisioning-patterns.jpg" />
</Frame>

At SparklePonyRanch, the team roles reflect these choices: Swati (SRE) focuses on SLOs/SLA and Cluster API for cluster operations; Alan (Infrastructure) maintains Terraform/OpenTofu modules and Crossplane compositions for application infrastructure; Phuong (Developer) consumes the self-service APIs and GitOps workflows.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/spr-platform-team-infrastructure-strategy.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=5b449ed0cee186c8fadfdae5fbc675fe" alt="A presentation slide titled &#x22;SPR Platform Team Infrastructure Strategy&#x22; showing three colored avatar icons labeled Swati (SRE), Alan (Infrastructure), and Phuong (Developer) with brief bullet-point responsibilities under each. The slide also features a &#x22;Sparkle Pony Ranch&#x22; tag above the center avatar." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/spr-platform-team-infrastructure-strategy.jpg" />
</Frame>

## Key takeaways

* Crossplane (CNCF): represents Kubernetes-native infrastructure control using CRDs and composition patterns; ideal when you want infrastructure as Kubernetes objects and tight GitOps integration.
* Terraform / OpenTofu: mature IaC ecosystem using HCL and modules; often the quickest way to adopt IaC at scale and has the largest provider coverage.
* Cluster API (CNCF): specialized for Kubernetes cluster lifecycle management — provisioning, upgrading, scaling — and not a general cloud resource orchestrator.
* Design your platform with layered abstractions, GitOps, policy-as-code, and observability to enable self-service while preserving security and compliance.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/infrastructure-provisioning-crossplane-clusterapi-opentofu.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=918b4b47229952471230ab91fbd268ef" alt="A presentation slide titled &#x22;Key Takeaways – Infrastructure Provisioning&#x22; showing three boxed summaries for Crossplane, Cluster API, and OpenTofu/Terraform. Each box gives a short description of the project's role in Kubernetes or infrastructure-as-code (e.g., cloud resources as CRs, cluster lifecycle management, and mature IaC with Kubernetes integration)." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/infrastructure-provisioning-crossplane-clusterapi-opentofu.jpg" />
</Frame>

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/cnpa-infrastructure-provisioning-key-takeaways.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=de3403fab78bd9e24b74acb5a5dc2f96" alt="A slide titled &#x22;Key Takeaways – Infrastructure Provisioning&#x22; listing four essential concepts for CNPA certification: 01 GitOps Integration, 02 Self-Service Goal, 03 Observability, and 04 Composition Patterns, each shown in colored rounded boxes with brief explanations." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/cnpa-infrastructure-provisioning-key-takeaways.jpg" />
</Frame>

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/0r3GTobZImleUlJh/images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/infrastructure-provisioning-kubernetes-selfservice-excellence.jpg?fit=max&auto=format&n=0r3GTobZImleUlJh&q=85&s=4a317a9be4ff2a422ab30354c57cdc37" alt="A presentation slide titled &#x22;Key Takeaways – Infrastructure Provisioning&#x22; showing &#x22;Platform Value&#x22; bullets: Kubernetes-native provisioning, enables developer self-service, and ensures operational excellence. The slide includes a faint gear/server illustration and a © KodeKloud notice." width="1920" height="1080" data-path="images/Prep-Course-Certified-Cloud-Native-Platform-Engineering-Associate-CNPA/Domain-4-Platform-APIs-and-Provisioning-Infrastructure/Infrastructure-Provisioning-with-Kubernetes/infrastructure-provisioning-kubernetes-selfservice-excellence.jpg" />
</Frame>

Thanks for reading.

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/certified-cloud-native-platform-engineering-associate-cnpa/module/7b8d1069-510d-48c6-b656-7573a193aeff/lesson/baf9f07d-483b-444b-a87d-c3c8444779f0" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.