> Markdown version of [/videos/329-monoskope-developer-self-service-across-clusters?t=422](https://www.wearedevelopers.com/videos/329-monoskope-developer-self-service-across-clusters?t=422). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Monoskope: Developer Self-Service Across Clusters How do you safely delegate cross-cluster Kubernetes access in highly regulated environments? Discover how Monoskope leverages event sourcing to deliver compliant, fully auditable developer self-service. - **Speakers:** Jan Steffen - **Event:** WeAreDevelopers LIVE - **Published:** November 10, 2021 - **Duration:** 31:48 - **URL:** https://www.wearedevelopers.com/videos/329-monoskope-developer-self-service-across-clusters ## Summary The financial services sector demands rigorous compliance, continuously creating friction for agile DevOps workflows. To solve the persistent bottleneck of managing multiple Kubernetes clusters and manually executing routine developer requests, Finleap Connect open-sourced Monoskope. This platform acts as a secure developer self-service engine, allowing cross-cluster operations without compromising strict regulatory compliance across various hyperscaler and private cloud environments. By safely delegating operational control, DevOps operations can confidently shift away from manual interventions—like DNS allocations or IAM ticket processing—and return focus to high-impact platform engineering. Under the hood, Monoskope relies on a robust, cloud-native tech stack featuring Golang, RabbitMQ, CockroachDB, and Emissary Ingress. Its standout architectural choice is the heavy utilization of event sourcing and the CQRS (Command Query Responsibility Segregation) pattern. In this design, the current state of the system is entirely transient, built continuously from an immutable, append-only event log. This natively elevates auditability to a first-class feature, guaranteeing a flawless, undeletable record of every system action, role change, and access grant. For heavily regulated environments, this architecture provides unparalleled transparency and even permits "time travel" to accurately recreate the exact system state from any past moment. Designed around a granular tenant and role-based access model, Monoskope ensures scalable self-service remains inherently secure. Developers can autonomously orchestrate compliant secrets management, provision IP addresses, or request temporary elevated access using built-in guardrails like the 4-eyes approval principle. This principle safely auto-approves localized requests while enforcing multi-party sign-off for sensitive actions. Extensibility is additionally centralized via an event-driven "reactor" system, letting teams effortlessly trigger external notifications or custom workflows without disrupting core platform services. By coupling features like upcoming SCIM 2.0 synchronization with decentralized operational execution, the platform reinforces a crucial paradigm: robust security and high unblocked engineering velocity do not have to be mutually exclusive. **Keywords:** kubernetes self-service tools, multi-cluster management, compliant devops workflows, event sourcing architecture, CQRS pattern, financial tech compliance, tenant isolation models, automated DNS provisioning, 4-eyes approval principle, distributed microservices architecture, immutable audit logging, developer unblocking strategies, temporary elevated access, OIDC authentication integration, IAM synchronization API, cloud-agnostic platform architecture, infrastructure bottleneck resolution, compliant secrets management ## Chapters 1. **Introduction to the speaker and organization** (00:02) — Understanding the enterprise context helps explain why strict workload compliance drives platform development. 1. **FinLeap Cloud architecture and compliance guidelines** (02:35) — Navigating strict financial regulations requires leveraging Kubernetes abstraction layers for compliant infrastructure provisioning. 1. **Overcoming developer bottlenecks with Monoskope automation** (04:56) — Scaling development teams across multiple cloud providers necessitates automated permission management to eliminate operational blockers. 1. **Core features enabling secure developer self-service** (07:02) — Implementing role-based scopes and multi-tenancy empowers engineers to self-manage resources without compromising platform security. 1. **Core technology stack and cloud-native choices** (11:59) — Selecting a cloud-native technology stack provides the necessary messaging and database primitives for robust orchestration. 1. **Utilizing event sourcing for complete system auditability** (13:05) — Guaranteeing precise access records becomes possible by reconstructing system states from an append-only event log. 1. **Examining the Monoskope control plane architectural design** (18:29) — Separating commands from queries via message buses enables the control plane architecture to scale dynamically. 1. **Current project status and upcoming feature roadmap** (23:31) — Enhancing the open-source tooling requires upcoming integrations like SCIM 2 identity APIs and administration interfaces. 1. **Questions on open-source vision and developer autonomy** (27:02) — Removing daily infrastructure bottlenecks remains the primary motivation behind developing robust software self-service tools. ## Related Moments - [Refactoring a complex legacy monolith into microservices](https://www.wearedevelopers.com/videos/371-retooling-and-refactoring-an-investment-in-people) (from "Retooling and refactoring - an investment in people.") - [Speaker background and open source Kubernetes edge computing projects](https://www.wearedevelopers.com/videos/100094-from-bytes-to-execution-writing-a-webassembly-runtime-in-rust) (from "From Bytes to Execution: Writing a WebAssembly Runtime in Rust") - [Audience questions on security, limitations, and Kubernetes crossover](https://www.wearedevelopers.com/videos/732-kubernetes-dev-is-fun-but-setup-and-ops-isn-t-see-a-fun-paas-alternative-to-push-any-code-ipynbs-or-even-just-data) (from "Kubernetes dev is fun, but setup and ops isn't! See a fun PaaS alternative to push any code, ipynbs or even just data!") - [Transitioning from monolith architectures to microservices and Kubernetes](https://www.wearedevelopers.com/videos/108-get-ready-for-operations-by-pull-requests) (from "Get ready for operations by pull requests") - [Abstracting Kubernetes complexity with a self-service operator](https://www.wearedevelopers.com/videos/1181-startup-presentation-achieving-true-developer-self-service-in-kubernetes) (from "Startup Presentation: Achieving True Developer Self-Service in Kubernetes") - [Scaling monorepo tooling from prototypes to enterprise](https://www.wearedevelopers.com/videos/292-nx-the-easy-choice) (from "Nx - the easy choice") ## Related Articles - [MLops – Deploying, Maintaining And Evolving Machine Learning Models in Production](https://www.wearedevelopers.com/magazine/115-mlops-deploying-maintaining-and-evolving-machine-learning-models-in-production) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How we Build The Software of Tomorrow](https://www.wearedevelopers.com/magazine/120-how-we-build-the-software-of-tomorrow) ## Related Jobs - [Senior Engineer, Infrastructure Platform](https://www.wearedevelopers.com/jobs/ext/328836-senior-engineer-infrastructure-platform) at **Intercom, Inc.** - [Platform Engineer - Mercury Runtime Platform](https://www.wearedevelopers.com/jobs/ext/293235-platform-engineer-mercury-runtime-platform) at **Raiffeisen Bank International AG** - [Senior Backend Engineer (Java)](https://www.wearedevelopers.com/jobs/ext/19369-senior-backend-engineer-java) at **Bonial International GmbH** - [Platform Engineer (f/m/x) - Mercury Runtime Platform](https://www.wearedevelopers.com/jobs/48266-platform-engineer-f-m-x-mercury-runtime-platform) at **Raiffeisen Bank International AG** - [Senior Cloud Native Solution Architect (all genders welcome) - Kubernetes, CNCF, MlOps](https://www.wearedevelopers.com/jobs/ext/101488-senior-cloud-native-solution-architect-all-genders-welcome-kubernetes-cncf-mlops) at **Rosenxt Group** - [Staff Software Engineer](https://www.wearedevelopers.com/jobs/ext/1425755-staff-software-engineer) at **GitHub**