Multi-AZ Secure Kubernetes Cluster Deployment
Budget / Salary₹12,500–37,500
TypeFreelance project
LocationRemote
Posted2 hours ago
I need a production-grade Kubernetes cluster built on AWS that remains fully available even if an entire Availability Zone disappears. The control plane must run as three separate nodes, each placed in a different AZ, with matching worker groups spread the same way so that every component benefits from true zone redundancy.
Security is just as critical as uptime. Please configure Calico as the CNI (ebpf) and oracle 9 and activate fine-grained Network Policies so I can isolate teams and services. Role-Based Access Control must gate every API action, and Pod Security Policies should lock containers to the least privilege they need.
The cluster will host a mixed workload of web applications, data-processing jobs, and microservices, so I’m looking for sensible defaults that balance latency with throughput while keeping the platform generic enough for future workloads. Automated node provisioning, in-place upgrades with minimal disruption, and detailed logging/metrics routed to native AWS services are all expected.
Deliverables
• Terraform (or equivalent IaC) that stands up the VPC, subnets, three control-plane nodes, auto-scaling worker groups, and supporting AWS resources
• Calico configuration with sample Network Policies and documentation on extending them
• RBAC roles and Pod Security Policies committed to version control
• A concise runbook that explains day-two operations—backups, upgrades, disaster recovery, and security patching
• An architecture diagram (draw.io, Visio, or similar) illustrating traffic flow, AZ placement, and security boundaries
Acceptance criteria: cluster survives loss of any single AZ without manual intervention; kubectl auth tests confirm RBAC boundaries; test pods validate Network Policies; CIS benchmark scan shows no high-severity findings; sample app deploys successfully across AZs.
If you have recent experience building multi-AZ clusters on AWS with Calico and hardened security, I’d love to review your approach and timeline.
Security is just as critical as uptime. Please configure Calico as the CNI (ebpf) and oracle 9 and activate fine-grained Network Policies so I can isolate teams and services. Role-Based Access Control must gate every API action, and Pod Security Policies should lock containers to the least privilege they need.
The cluster will host a mixed workload of web applications, data-processing jobs, and microservices, so I’m looking for sensible defaults that balance latency with throughput while keeping the platform generic enough for future workloads. Automated node provisioning, in-place upgrades with minimal disruption, and detailed logging/metrics routed to native AWS services are all expected.
Deliverables
• Terraform (or equivalent IaC) that stands up the VPC, subnets, three control-plane nodes, auto-scaling worker groups, and supporting AWS resources
• Calico configuration with sample Network Policies and documentation on extending them
• RBAC roles and Pod Security Policies committed to version control
• A concise runbook that explains day-two operations—backups, upgrades, disaster recovery, and security patching
• An architecture diagram (draw.io, Visio, or similar) illustrating traffic flow, AZ placement, and security boundaries
Acceptance criteria: cluster survives loss of any single AZ without manual intervention; kubectl auth tests confirm RBAC boundaries; test pods validate Network Policies; CIS benchmark scan shows no high-severity findings; sample app deploys successfully across AZs.
If you have recent experience building multi-AZ clusters on AWS with Calico and hardened security, I’d love to review your approach and timeline.
Apply on Freelancer →
Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.