Architecture
How it works
- Edge. Cloudflare holds the maxmccann.us zone and delegates
retool.maxmccann.usto Azure DNS (DNS only, not proxied). Traffic goes straight to an Azure Application Gateway; certificates are Let's Encrypt via DNS-01 against Azure DNS. - Compute. AKS runs Retool prod, a Retool nonprod upgrade lane, this read-only dashboard, and one CronJob per public source. Every namespace runs at Pod Security "restricted"; containers are non-root with read-only root filesystems.
- Data. Loaders write only rows that pass the publication filters into
jobs_ingest. One analytics transaction rebuildsjobs_analytics, the only layer apps can read, as a read-only role with no access to the raw database. - Secrets. Key Vault is the root of trust; Infisical (private, no public route) gives each consumer its own identity, bound to one Kubernetes service account and readable only from its own folder.
- Sourcing rules. One honest User-Agent with a contact; robots.txt read per host; a 401/403/429 is final and never worked around.
- Everything is Terraform, built on Retool's official Azure modules.
Vendor findings
Reviewing every plan before applying it caught three defects in Retool's own Terraform modules, each patched in a vendored copy with the proof written down:
- Key Vault access silently removed on the second apply: inline access policies would have stripped Retool's access to its encryption key and database password.
- The nonprod lane was never routed: the ingress controller was hard-wired to one namespace, which assumes one App Gateway per deployment.
- Every request returned 502 with nothing in the logs: the ingress class and the controller name disagreed, and the controller overwrites one with the other at startup, so it claimed no ingress. Traced in the controller's source, proved live, then patched.