---
description: Platform Engineering Overview
alwaysApply: false
---

# Platform Engineering Overview

Guidelines for building and operating internal developer platforms, infrastructure automation, and reliability engineering.

## Scope

- Infrastructure as Code (Terraform, Pulumi, CDK, Crossplane)
- Kubernetes and container orchestration
- CI/CD pipelines and GitOps workflows
- Internal Developer Platforms (IDPs)
- Observability (metrics, logs, traces)
- Security and compliance automation
- Cost optimization and FinOps

## Core Principles

- **Platform as Product** — developers are your customers; measure adoption and satisfaction; iterate on real usage data
- **Self-Service First** — automate everything; provide golden paths with sensible defaults; build guardrails not gates; reduce time-to-first-deploy to minutes
- **Reliability Engineering** — define SLOs, measure SLIs, maintain error budgets; automate incident response; blameless postmortems
- **Security by Default** — shift-left scanning; policy as code; zero trust networking; secrets management; supply chain security (signed images, SBOMs)
- **Cost Consciousness** — tag all resources for attribution; provide per-team cost visibility; right-size automatically; clean up unused resources

## Definition of Done

### Infrastructure Change
- [ ] IaC passes lint/validate; plan reviewed and approved
- [ ] Tested in non-prod; rollback documented
- [ ] Monitoring, alerting, runbook updated; cost and security reviewed

### Platform Feature
- [ ] Self-service capable; documentation complete
- [ ] Integrated into golden path; metrics exposed for SLOs
- [ ] Tested with real workloads; support runbook created

## Anti-Patterns

- **Ticket queue platform** — build self-service automation; handle the platform, not tickets
- **Tribal knowledge** — golden paths with defaults, clear docs, quick feedback loops
- **Over-engineering** — right-size to actual needs; complexity has ongoing costs
