← All projects

Developer platform lab

Backstage on Kubernetes

An opinionated Helm chart for deploying Backstage through Argo CD with external secrets, managed PostgreSQL, and Gateway API.

RolePlatform Engineer
Year2026
StatusActive lab

Context

Backstage is often introduced as a simple application, but a production-oriented deployment has to fit an organization’s identity, secrets, database, networking, storage, and delivery standards.

Approach

I built an opinionated Helm chart designed for Argo CD. It consumes externally managed secrets, uses PostgreSQL provided by Crunchy PGO, supports the Kubernetes Gateway API, and leaves image creation to a dedicated CI workflow.

Platform fit

  • AWS Secrets Manager remains the source for sensitive configuration.
  • External Secrets synchronizes only the values Backstage needs.
  • The chart consumes PostgreSQL rather than owning its lifecycle.
  • Gateway API expresses routing without relying on legacy Ingress resources.
  • Environment-specific values remain declarative and reviewable.

Learning

The lab exposed a difference between GitLab.com and self-hosted GitLab user discovery. Capturing that limitation alongside the implementation makes the repository useful as an engineering record, not just a collection of templates.