Platform architecture · How it works
How CodeNOW takes a Git push to governed production.
A technical walkthrough for evaluators and developers: the control-plane and data-plane architecture, the push-to-production workflow that replaces a DevOps team, and the customer-controlled cluster your software runs on — ISO/IEC 27001 certified, multi-cloud, and operable by code and agents.
The architecture
CodeNOW runs the control plane. Your data plane runs your software.
Every block below is a real part of the platform. Follow the flow from the code you push, through the control plane CodeNOW operates, down to the cluster you control — and open any block for the detail.
Your software
The applications, components, and libraries you author and push.
- ApplicationA governed product boundary over the components that deliver one capability — releases, environments, and access managed per product, not per loose repo.
- ComponentThe deployable unit a developer pushes: one repo, one owner. The platform takes it from a laptop to a built, released, running workload — no hand-written deploy glue.
- LibraryReusable shared code as a governed, versioned artifact — resolved by the platform instead of copy-pasted folders or an unmanaged private-registry dependency.
- ContainerBring a plain container workload onto the same governed build-and-deploy rails without wrapping it in the full application and component model.
Control plane — CodeNOW-operated
Runs off your cluster: the API and MCP surface, CI, GitOps reconciliation, and release orchestration.
- Control plane vs data planesCodeNOW operates the control plane off your cluster — the API and MCP surface, CI env-generation, and orchestration — while you own the data plane your software runs on.
- Pipeline / CIA managed CI pipeline per tech stack, installed at provisioning and enforced identically on every trigger — no CI system to stand up or maintain.
- BuildEvery pushed commit becomes reproducible artifacts — release builds for production, fast preview builds for feedback — replacing hand-rolled build and registry-push scripts.
- Quality gateStatic analysis and security scanning run inside the enforced pipeline, not as a bolt-on someone remembers to wire.
- Application PackageA versioned release bundling specific component build versions — the promotable unit that ends “which version is in prod?” drift.
- GitOps reconciliationDeclared state is the running state: the platform reconciles deployments continuously and drift self-heals — no manual kubectl apply or Helm-by-hand.
Data Plane 1 — Production Cluster (GKE / AKS / OpenShift / RKE2)
You control this — the codenow.nyc tenant — operated via the CodeNOW self-service portal (nycmesh.codenow.com). Provided to you now; your own tenant on purchase.
- ClusterThe platform provisions the whole multi-cloud Kubernetes substrate (AWS, GCP, Azure, DigitalOcean, or private — no lock-in); isolation and capacity are a platform concern, not yours to architect.
- EnvironmentsDev, staging, and production are first-class, registered, access-controlled targets — promotion and rollback go through one controlled path, not ad-hoc kubectl.
- DeploymentA released instance running in an environment, continuously reconciled — with per-environment configuration for overrides, connected-service assignments, and runtime resources.
- Managed ServicesPlatform-provisioned stateful backing — PostgreSQL (CloudNativePG), Kafka (Strimzi), caches — provisioned, run, and credential-injected for you, with no database-ops backlog.
- External ServicesA governed, per-environment secret and connection store with an assign-vs-read permission split — replacing committed dotenvs and kubectl secret-patching. Values never live in git.
Data Plane 2 — a second registered cluster
You control this too. One control plane registers as many data planes as you run — for example an air-gapped or private-cloud cluster running the same governed stack, with fully isolated workloads.
Across every layer
Security, observability, and agent access that span the whole platform.
- Service mesh / zero-trustmTLS everywhere via an auto-provisioned Istio service mesh — zero-trust networking on by default, ISO/IEC 27001 certified.
- Observability + DORAGrafana, Loki, and Jaeger provisioned by default, plus industry-standard DORA metrics — every workload observable without building a monitoring stack.
- Vibe CodingAn AI coding session in a dedicated container on your data plane, with all component repos cloned; its commits trigger the same governed build-and-deploy flow as a human's.
- MCP server / APIThe whole platform is operable by agents and code — an MCP server and a versioned REST API that mirror each other and enforce the same RBAC as the authenticated user.
The complete reference architecture — every data plane, workload, and control-plane service, with the customer-managed and CodeNOW-managed zones marked. SVG, opens in a new tab.
The moving parts
Every part, and the work it takes off your plate.
Grouped the way the architecture above is: your software, the CodeNOW-operated control plane, the data plane you control, and the capabilities that span every layer. Each part is a drill-down from the diagram.
Your software
The applications, components, and libraries you author and push.
Application
A virtual envelope over the components that together deliver one end-user experience or business capability — the unit you reason about at the product level, deployed to environments within a cluster.
What CodeNOW runs for you
You get a first-class product boundary. Releases, environments, and access are governed per business capability, instead of scattered across loose repositories.
Component
An independently developed, generally stateless deployable unit with one owner and its own Git repository, connected to managed and external services. It is the thing a developer pushes.
What CodeNOW runs for you
The platform takes the repository from code on a laptop to a governed, built, running workload. You write no Dockerfile-to-production glue, no Kubernetes manifests, and no per-service release process.
Library
A reusable package of cohesive functionality used by components but not independently deployable — a first-class object in the model rather than an afterthought.
What CodeNOW runs for you
Shared code is versioned and resolved as a governed artifact, not a copy-pasted folder or an unmanaged private-registry dependency.
Container
A first-class, top-level build-and-deploy unit — a separate object domain from Applications and Components.
What CodeNOW runs for you
A plain container workload runs on the same governed build-and-deploy rails, without being wrapped in the full application-and-component model.
Control plane — CodeNOW-operated
Runs off your cluster: the API and MCP surface, CI, GitOps reconciliation, and release orchestration.
Control plane vs data planes
CodeNOW separates into a control plane and one or more data planes. The control plane runs off your cluster: the REST and MCP API, the CI environment-generation service, the account GitOps, and release orchestration. The data planes are your own Kubernetes clusters, where your workloads, managed services, service mesh, and observability run.
What CodeNOW runs for you
CodeNOW operates the control plane and the platform components; you own and control the data plane your software runs on. Data Plane 1 is the customer-controlled production cluster.
Pipeline / CI
The build-and-result automation for a component. CodeNOW CI, built on Tekton, is the default provider — installed and configured at provisioning, with no CI key to manage. Default pipelines per tech stack compile, test, package, and publish, declared in .codenow.yaml. GitHub Actions and custom CI are also supported.
What CodeNOW runs for you
You do not stand up or maintain a CI system, or author a pipeline per service. The managed pipeline is enforced and runs identically on every trigger.
Build
A pushed commit turned into deployable artifacts. A release build runs the full test suite for production; a preview build runs fast with minimal tests for developer feedback. The same source and inputs produce the same artifact, by construction.
What CodeNOW runs for you
Reproducible builds produce the container image and Helm chart as registered results — replacing hand-rolled build scripts, registry-push glue, and “works on my machine.”
Quality gate
Static analysis and security checks — via SonarQube — run as part of every CI run.
What CodeNOW runs for you
Code-quality and security scanning is built into the enforced path, not left to a bolt-on someone remembers to wire.
Application Package
A versioned release that bundles specific component build versions. It is the unit of promotion — a known set of versions moved together, not a floating “latest.”
What CodeNOW runs for you
CodeNOW freezes the exact component versions into one promotable unit and moves that same unit along the ladder — preview → staging → release → production — so you never track environment drift or ask “which version is in prod?”
GitOps reconciliation
The control-plane reconciliation engine — Argo CD — that keeps each running deployment equal to its declared state. The declared state is the running state.
What CodeNOW runs for you
Continuous reconciliation replaces manual kubectl apply and Helm-by-hand: drift self-heals rather than accumulating.
Data Plane 1 — Production Cluster (GKE / AKS / OpenShift / RKE2)
You control this — the codenow.nyc tenant — operated via the CodeNOW self-service portal (nycmesh.codenow.com). Provided to you now; your own tenant on purchase.
Cluster
An independent unit of infrastructure providing full isolation on dedicated compute; applications in different clusters share no resources.
What CodeNOW runs for you
CodeNOW provisions and operates the whole cluster for you and runs it on the infrastructure you choose — any public cloud or your own hardware: AWS, GCP, Azure, DigitalOcean, or private, with no lock-in. Isolation and capacity are a platform concern, not yours to architect.
Environments
A deployment target — dev, staging, or production — tied to a cluster. Deploying to a different environment routes the workload to a different cluster.
What CodeNOW runs for you
Each environment is first-class, registered, and access-controlled. Promotion and rollback follow one controlled path — preview → staging → release → production — not ad-hoc kubectl against whatever cluster someone has credentials for.
Deployment
A released instance of a component set running in an environment, continuously reconciled. Its per-environment Deployment Configuration carries the specifics: environment-variable overrides, configuration files, connected-service instance assignments, and runtime resources such as replicas and CPU or memory.
What CodeNOW runs for you
Structural defaults live in git; real values live per environment. You template no secrets into manifests and maintain no per-environment YAML forks, and every connection must have an instance assigned per environment before the deployment is valid.
Managed Services
A platform-provisioned stateful backing service — PostgreSQL via CloudNativePG, Kafka via Strimzi, caches — tied to a cluster, with connection details injected automatically into the components that connect to it.
What CodeNOW runs for you
The platform provisions, runs, backs up, secures, and injects credentials for your database or broker. There is no database-operations backlog to staff.
External Services
The platform’s typed secret and connection store. A template is the schema — named variables such as HOST, PORT, USERNAME, and PASSWORD, with no values. An instance holds the actual values, per environment. A connection is a binding slot on a component that declares it needs a service of a given template type at deploy time; the concrete instance is chosen per environment.
What CodeNOW runs for you
Values live in the governed store — never in git — with an assign-versus-read permission split, replacing committed dotenv files and kubectl secret-patching. The platform injects your connection secrets automatically at deploy time, and the component stays decoupled from any environment’s real values.
Across every layer
Security, observability, and agent access that span the whole platform.
Service mesh / zero-trust
An auto-provisioned Istio service mesh that enforces mTLS everywhere — zero-trust networking between your workloads, on by default.
What CodeNOW runs for you
You do not design or operate zero-trust networking. The mesh is provisioned and enforced by the platform, which is ISO/IEC 27001 certified.
Observability + DORA
The cloud-agnostic stack the platform provisions for every workload — Grafana for metrics, Loki for logs, Jaeger for tracing — alongside DORA metrics: deployment frequency, lead time for changes, and change failure rate.
What CodeNOW runs for you
You assemble no monitoring, logging, or tracing stack and build no delivery-metrics pipeline. Every workload is observable by default; this site’s own /status page reads those metrics live.
Vibe Coding
An AI-assisted coding session in a dedicated container on one of your data planes, provisioned per application with all component repositories cloned and accessed over SSH. The assistant edits and tests code; its commits and pushes per component trigger the normal build, merge-request, and deploy flow.
What CodeNOW runs for you
The AI teammate works inside the same governed SDLC as a human developer — one session per user, an ephemeral container whose git changes persist. It is distinct from the MCP server.
MCP server / API
The MCP server and REST API that make the whole platform operable by agents and code. The MCP server exposes platform operations as tools that mirror the versioned REST API — the same object surface — and both authenticate via OAuth 2.0 or a per-account API key.
What CodeNOW runs for you
Agents and automation act as non-human team members under the same identity, permissions, and audit model as a human: every operation enforces the same RBAC as the authenticated user.
The developer experience
Push a repo. Trace it to production.
One push starts a fixed sequence. At every step you can see what you did, what the platform did in your place, and the DevOps work it absorbs — the same governed, ISO/IEC 27001-certified rails regulated banks ship on. Follow any step to its place in the architecture.
Push the component
- You
- Pushed the component repo and declared its build once.
- Platform
- Registered the component and bound it to the managed build → test → release → deploy path — no per-service pipeline or deploy wiring to author.
- Replaces
- Per-service deploy glue and a bespoke release process.
Automatic CI build
- You
- Pushed a commit — the only trigger.
- Platform
- Ran the managed pipeline: resolved the branch's config, then compiled, tested, packaged, and published.
- Replaces
- Standing up and maintaining CI and a pipeline per service.
Containerize and register artifacts
- You
- Nothing; the build carried it.
- Platform
- Produced reproducible artifacts — the container image and Helm chart — registered as typed CI results.
- Replaces
- Dockerfile-to-registry glue and bespoke packaging.
Quality gate
- You
- Nothing; the gate is part of the pipeline.
- Platform
- Ran static-analysis and security checks inside the enforced pipeline before the release could bundle.
- Replaces
- Bolt-on scanning nobody owns.
Bundle a versioned release
- You
- Nothing; versions bundle automatically.
- Platform
- Bundled specific component build versions into a versioned application package — the promotable unit.
- Replaces
- “Which commit is in prod?” drift.
Deploy to a governed environment
- You
- Chose the target environment.
- Platform
- Deployed the package into an environment tied to a cluster and reconciled it continuously; per-environment configuration supplied overrides and connected-service assignments.
- Replaces
- Manual kubectl and Helm, and per-environment manifest forks.
Promote preview → staging → release → production
- You
- Approved promotion along the ladder.
- Platform
- Moved the same package along a controlled, logged path across registered environments — stoppable and reversible at any layer.
- Replaces
- Ad-hoc promotion and SSH-and-hope rollbacks.
Managed services and secret injection
- You
- Declared the connection once; the platform bound it per environment.
- Platform
- Assigned managed services and external-service instances per environment and injected their connection details automatically at deploy.
- Replaces
- Provisioning stateful backing services and hand-wiring credentials.
Observability and DORA, by default
- You
- Nothing; observability is on by default.
- Platform
- Made the workload observable immediately — metrics, logs, traces — and accrued DORA delivery metrics.
- Replaces
- Building a metrics, logging, and tracing stack.
That is one component, from a laptop push to governed production — the work a DevOps team would otherwise own, absorbed by the platform.
Proof, not pitch
The same platform regulated institutions run on.
The delivery system trusted by regulated EU banks and Deutsche Post DHL.
4 → 400+
Releases/year → releases/month, Komerční Banka on CodeNOW
~70%
Reduction in DevOps costs
ISO/IEC 27001
Information security management, certified
Komerční Banka went from four major release cycles a year to an agile organization capable of over four hundred independent monthly releases on CodeNOW — while cutting DevOps costs roughly 70% and overall delivery costs 20%, integrating 40+ open-source tools on Kubernetes without standing up a dedicated DevOps team.
Where the boundary sits
You control the data plane your software runs on.
CodeNOW operates the control plane for you — off your cluster: the API and MCP surface, CI, GitOps reconciliation, and release orchestration. Data Plane 1 is yours. The production cluster where your software actually runs is the layer you control — the CodeNOW tenant provided to you now, or your own tenant when you bring CodeNOW to your organization.
Right now, the tenant you’ll try is the one running this very site — codenow.nyc — operated from its CodeNOW self-service portal at nycmesh.codenow.com. Bring CodeNOW to your own organization and you get your own tenant and your own portal the same way. Either way, the self-service portal is the control surface for your data plane — not the address your software serves from.
You control this — the codenow.nyc tenant — operated via the CodeNOW self-service portal (nycmesh.codenow.com). Provided to you now; your own tenant on purchase.
Trace this on your own repository.
Developer access is arranged directly. You get a provisioned CodeNOW tenant, credentials set up by hand, and the full push-to-production rail running against a repository you choose — the same governed platform in this walkthrough, on your own code.