Hanzo deploys all services via Kubernetes manifests stored in the universe repo (hanzoai/universe).
Category: Hanzo Ecosystem Related Skills: hanzo/hanzo-k8s.md, hanzo/hanzo-platform.md, hanzo/hanzo-kms.md
Hanzo deploys all services via Kubernetes manifests stored in the universe repo (hanzoai/universe). Universe is the single source of truth for all infrastructure. Branch main is production, branch dev is staging. All images are built by CI/CD on self-hosted runners and pushed to GHCR. Never build images locally unless explicitly requested.
~/work/hanzo/universe/infra/k8s/ghcr.io/hanzoai/<service>:<tag>, always --platform linux/amd64kubectl kustomize . | kubectl apply -f - for idempotent deploy| Item | Value | |------|-------| | Universe repo | github.com/hanzoai/universe (private) | | Local path | ~/work/hanzo/universe/infra/k8s/ | | Prod cluster | do-sfo3-hanzo-k8s (22 nodes) | | Staging cluster | do-sfo3-hanzo-dev-k8s | | Registry | ghcr.io/hanzoai/* | | DO registry | registry.digitalocean.com/hanzo (5/5 repo limit, avoid) | | Runner pool | 7x32GB nodes in hanzo-k8s | | KMS | kms.hanzo.ai |
# 1. Edit manifests in universe
cd ~/work/hanzo/universe/infra/k8s/<service>
# 2. Apply to production
kubectl --context do-sfo3-hanzo-k8s kustomize . | kubectl apply -f -
# 3. Verify
kubectl --context do-sfo3-hanzo-k8s -n hanzo get pods -l app=<service>
kubectl --context do-sfo3-hanzo-k8s -n hanzo logs -l app=<service> --tail=50
universe/infra/k8s/<service>/kustomization.yaml, deployment.yaml, service.yamlKMSSecret CRD in secrets.yaml for any secretsingressClassName: hanzo165.232.146.176 for hanzo-k8s)kubectl kustomize . | kubectl apply -f -All images are built in CI/CD pipelines, never locally.
# Typical .github/workflows/build.yml
name: Build and Push
on:
push:
branches: [main, develop]
jobs:
build:
runs-on: self-hosted # MUST use self-hosted runners
steps:
- uses: actions/checkout@v4
- name: Login to GHCR
run: echo "${{ secrets.GHCR_TOKEN }}" | docker login ghcr.io -u hanzoai --password-stdin
- name: Build and push
run: |
docker buildx build \
--platform linux/amd64 \
--push \
-t ghcr.io/hanzoai/<service>:latest \
-t ghcr.io/hanzoai/<service>:${{ github.sha }} \
.
# secrets.yaml -- KMSSecret CRD
apiVersion: kms.hanzo.ai/v1
kind: KMSSecret
metadata:
name: my-service-secrets
namespace: hanzo
spec:
project: my-service
environment: production
syncInterval: 5m
secretRef:
name: my-service-secrets
secrets:
- DATABASE_URL
- API_KEY
- JWT_SECRET
universe/infra/k8s/
namespace.yaml # hanzo namespace
cluster-issuer.yaml # Let's Encrypt issuer
platform-ingress.yaml # Platform-level ingress
rbac/ # RBAC for service accounts
base/ # Shared base manifests
# --- Services ---
app/ # hanzo.app
billing/ # billing.hanzo.ai
bot/ # bot gateway
chat/ # chat.hanzo.ai
cloud/ # cloud.hanzo.ai (Casibase)
commerce/ # commerce API
console/ # console.hanzo.ai (Langfuse)
dns/ # CoreDNS
flow/ # workflow builder
gateway/ # API gateway (KrakenD)
iam/ # hanzo.id (Hanzo IAM)
kms/ # kms.hanzo.ai (Hanzo KMS)
monitoring/ # Prometheus/Grafana
o11y/ # Hanzo o11y observability
paas/ # platform.hanzo.ai
registry/ # container registry
search/ # search service
sql/ # PostgreSQL + ZAP sidecar
s3/ # Hanzo S3 object storage
team/ # hanzo.team
vector/ # vector DB
zen/ # Zen model serving
zt/ # zero-trust (OpenZiti)
# ... 40+ service directories
do-sfo3-hanzo-k8s165.232.146.176do-sfo3-lux-k8s24.144.69.101registry.digitalocean.com/hanzo. Use GHCR exclusively.postgres.hanzo.svc -- no managed DB services.hanzo/hanzo-k8s.md -- K8s cluster detailshanzo/hanzo-kms.md -- Secret managementhanzo/hanzo-ingress.md -- Ingress routinghanzo/hanzo-platform.md -- PaaS for app deploymentLast Updated: 2026-03-23 Category: Hanzo Ecosystem Related: deployment, ci-cd, kubernetes, universe, ghcr Prerequisites: kubectl, K8s cluster access, GHCR credentials