Q: Developers need Redis clusters with encryption at rest, automatic failover, and VPC subnet placement. How do you design a Crossplane Composite Resource Definition (XRD) and Composition that abstracts 150 lines of Terraform into a simple 8-line Kubernetes Claim?
Designing an enterprise Composite Resource Definition (XRD) in Crossplane allowing developers to vend secure Redis replication groups across multiple environments.
Want to master this scenario in a live sandbox? KodeKloud's CKA & CKAD Hands-On Certification Track covers this exact problem with hands-on terminal drills.
🛠️ Production Runbook & Step-by-Step Resolution
Define the Custom XRD Schema
Create the `CompositeResourceDefinition` exposing only parameters developers care about: node size tier, multi-AZ toggle, and engine version.
apiVersion: apiextensions.crossplane.io/v1
kind: CompositeResourceDefinition
metadata:
name: xappcaches.platform.acme.com
spec:
group: platform.acme.com
names:
kind: XAppCache
plural: xappcaches
claimNames:
kind: AppCache
plural: appcaches
versions:
- name: v1alpha1
served: true
referenceable: true
schema:
openAPIV3Schema:
type: object
properties:
spec:
properties:
tier: { type: string, enum: ['small', 'medium', 'large'] }
highAvailability: { type: boolean }
Author Composition Enforcing Security Guardrails
The Composition maps `small` to `cache.t4g.micro` and `large` to `cache.r6g.large`. It hardcodes mandatory enterprise compliance: `transitEncryptionEnabled: true`, `atRestEncryptionEnabled: true`, and binds to private VPC subnet groups.
# Composition resource snippet
apiVersion: apiextensions.crossplane.io/v1
kind: Composition
metadata:
name: aws-elasticache-redis
spec:
compositeTypeRef:
apiVersion: platform.acme.com/v1alpha1
kind: XAppCache
resources:
- name: redis-replication-group
base:
apiVersion: elasticache.aws.upjet.crossplane.io/v1beta1
kind: ReplicationGroup
spec:
forProvider:
transitEncryptionEnabled: true
atRestEncryptionEnabled: true
automaticFailoverEnabled: true
Developer Consumes Simple Claim
The developer commits an 8-line manifest to their repository. Crossplane provisions the AWS ElastiCache cluster and exports credentials to a local Secret.
apiVersion: platform.acme.com/v1alpha1
kind: AppCache
metadata:
name: session-cache
namespace: team-auth
spec:
tier: medium
highAvailability: true
writeConnectionSecretToRef:
name: session-cache-credentials
- Design Crossplane XRDs exposing minimal, business-aligned attributes (tier, highAvailability).
- Enforce enterprise compliance rules (encryption, private subnets) invisibly inside Compositions.
- Automatically write database endpoints and authentication secrets directly to developer namespaces.