⚡ ~/naveed Interview Prep
⚡ Portfolio Home ✍️ Engineering Blog Deep Dives 🎯 Interview Hub 1,000+ Scenarios ☸️ Kubernetes Mastery Hub 24 Modules 🎮 DevOps Arcade & Quizzes Subnet Blitz ⚡ 🗺️ DevOps Roadmaps PDFs & Guides 🤖 Morpheus Analysis AI Quant ↗ 🛠️ Developer Tools Utilities 🧪 Labs & Experiments 📄 Interactive CV & Certs 🔗 All Links & Socials ⚡ Join The Dispatch (Weekly SRE Newsletter) →
← Back to All Platform Engineering & IDP Interview Questions Scenario 13 of 50 in Platform Engineering & IDP
Senior Platform Engineer Platform Engineering Control Planes & Crossplane Cloud Vending
🎯 Target Role / Context: Senior Platform Engineer Interview · Cloud Infrastructure Abstraction

Q: Developers need Redis clusters with encryption at rest, automatic failover, and VPC subnet placement. How do you design a Crossplane Composite Resource Definition (XRD) and Composition that abstracts 150 lines of Terraform into a simple 8-line Kubernetes Claim?

Designing an enterprise Composite Resource Definition (XRD) in Crossplane allowing developers to vend secure Redis replication groups across multiple environments.

#Crossplane #Redis #AWS ElastiCache #Platform Engineering #Kubernetes #Self-Service
🎙️ Candidate Opening & Architectural Context
"Platform engineering builds high-leverage abstractions. By defining an `XRD` for an `AppCache` and authoring environment-specific `Compositions`, the platform team enforces enterprise networking and security defaults while developers simply declare their cache size and environment."
Advertisement
⚡ Recommended Practice Lab

Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.

🛠️ Production Runbook & Step-by-Step Resolution

1

Define the Custom XRD Schema

Create the `CompositeResourceDefinition` exposing only parameters developers care about: node size tier, multi-AZ toggle, and engine version.

apiVersion: apiextensions.crossplane.io/v1
kind: CompositeResourceDefinition
metadata:
  name: xappcaches.platform.acme.com
spec:
  group: platform.acme.com
  names:
    kind: XAppCache
    plural: xappcaches
  claimNames:
    kind: AppCache
    plural: appcaches
  versions:
    - name: v1alpha1
      served: true
      referenceable: true
      schema:
        openAPIV3Schema:
          type: object
          properties:
            spec:
              properties:
                tier: { type: string, enum: ['small', 'medium', 'large'] }
                highAvailability: { type: boolean }
2

Author Composition Enforcing Security Guardrails

The Composition maps `small` to `cache.t4g.micro` and `large` to `cache.r6g.large`. It hardcodes mandatory enterprise compliance: `transitEncryptionEnabled: true`, `atRestEncryptionEnabled: true`, and binds to private VPC subnet groups.

# Composition resource snippet
apiVersion: apiextensions.crossplane.io/v1
kind: Composition
metadata:
  name: aws-elasticache-redis
spec:
  compositeTypeRef:
    apiVersion: platform.acme.com/v1alpha1
    kind: XAppCache
  resources:
    - name: redis-replication-group
      base:
        apiVersion: elasticache.aws.upjet.crossplane.io/v1beta1
        kind: ReplicationGroup
        spec:
          forProvider:
            transitEncryptionEnabled: true
            atRestEncryptionEnabled: true
            automaticFailoverEnabled: true
Advertisement
3

Developer Consumes Simple Claim

The developer commits an 8-line manifest to their repository. Crossplane provisions the AWS ElastiCache cluster and exports credentials to a local Secret.

apiVersion: platform.acme.com/v1alpha1
kind: AppCache
metadata:
  name: session-cache
  namespace: team-auth
spec:
  tier: medium
  highAvailability: true
  writeConnectionSecretToRef:
    name: session-cache-credentials
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Abstract complex cloud infrastructure using Crossplane XRDs and Compositions. Developers specify tier and HA; the platform guarantees encryption and VPC isolation."
⚡ 60-Second Elevator Pitch Talking Points
  • Design Crossplane XRDs exposing minimal, business-aligned attributes (tier, highAvailability).
  • Enforce enterprise compliance rules (encryption, private subnets) invisibly inside Compositions.
  • Automatically write database endpoints and authentication secrets directly to developer namespaces.
Advertisement
Want more Platform Engineering & IDP scenarios?
Explore our complete collection of scenario-based Platform Engineering & IDP interview runbooks.
Browse All Platform Engineering & IDP Questions →