L7 — Applications & workloads

What runs on top: demo apps + service mesh + tracing on wl, plus the middleware VM estate.

Demo apps (wl, GitOps spoke/base/demo-app)

App What
demo-app backend/frontend/postgres + Route + demo-db ExternalSecret + tracing
JBoss EAP demo EAP 8 JAX-RS, built on rhel-app-vm → Quay, deployed via Tekton. Live: eap-demo-eap-demo.apps.wl.airgap.lab/api/hello

Service mesh — OSSM3 ambient (wl)

Tracing — OpenTelemetry (wl)

CNV / OpenShift Virtualization (wl)

Middleware VMs (see Inventory)

Middleware VMs Notes
Postgres HA pg-0/1/2 (.47–.49) Patroni + PG16, etcd DCS, sync standby, VIP pg.airgap.lab, PgBouncer, pgBackRest→MinIO. 3 failover drills passed, zero-loss
Kafka kafka-ctrl/broker (.31–.36)
Redis redis-0..5 (.37–.42) failover (redis-failover-drill.sh)
Artemis artemis-0/1 (.50–.51) replication HA, TLS acceptors
APISIX .43–.44/.46 API gateway — see Identity
Wazuh .52 SIEM (alert + audit sink)

Build/staging host: rhel-app-vm (.30, Java/Maven/podman, has internet).

GitOps vs. out-of-band

wl in-cluster apps are GitOps (spoke/base/*). Middleware VMs are provisioned on the host (not GitOps); their secrets live in Vault apps/*.