An Open Source Data and Analytics Platform based on Stackable
  • Python 35.9%
  • Shell 19.8%
  • Astro 14.2%
  • MDX 7.6%
  • Jupyter Notebook 5.5%
  • Other 17%
Find a file
karel goense a7e52bf594 edit infra
2026-06-25 06:22:16 +02:00
.devcontainer feat(academy): add UDP Academy — certificeringstracks per platform-rol 2026-05-07 18:02:43 +02:00
.github add nanitics logic 2026-05-30 06:16:14 +02:00
ci style: apply pre-commit hooks repo-wide (ruff-format + EOF newlines) 2026-05-22 06:03:26 +02:00
data-generation style: apply pre-commit hooks repo-wide (ruff-format + EOF newlines) 2026-05-22 06:03:26 +02:00
dbt feat(openmetadata): CGM-glossary linker + intermediate dbt-meta 2026-05-22 06:34:08 +02:00
docs edit infra 2026-06-25 06:22:16 +02:00
infrastructure edit infra 2026-06-25 06:22:16 +02:00
logs feat: OpenMetadata Trino-ingest + OPA filter-ops + ShowSchemas 2026-05-05 11:55:13 +02:00
nifi-flows/templates docs: repair stale/broken repo links found in cleanup sweep 2026-05-30 08:12:40 +02:00
opa-policies-src add nanitics logic 2026-05-30 06:16:14 +02:00
platform edit infra 2026-06-25 06:22:16 +02:00
platform-overlays edit infra 2026-06-25 06:22:16 +02:00
portal add nanitics logic 2026-05-30 06:16:14 +02:00
scripts edit infra 2026-06-25 06:22:16 +02:00
spark-jobs docs: fix stale facts in hand-written docs 2026-05-29 18:12:32 +02:00
tests docs: repair stale/broken repo links found in cleanup sweep 2026-05-30 08:12:40 +02:00
.editorconfig fase 1 2026-05-01 05:54:10 +02:00
.gitignore feat(stackit): add SKE deployment as third mode (--mode=stackit) 2026-05-20 23:05:41 +02:00
.pre-commit-config.yaml feat(portal): add Dashboarding rail with Power BI embed 2026-05-24 17:35:06 +02:00
docker-compose.yml feat(academy): add UDP Academy — certificeringstracks per platform-rol 2026-05-07 18:02:43 +02:00
LICENSE fase 1 2026-05-01 05:54:10 +02:00
Makefile docs: fix stale facts in hand-written docs 2026-05-29 18:12:32 +02:00
mkdocs.yml docs: disentangle in-flight AI-agents feature from this docs pass 2026-05-29 18:58:39 +02:00
platform-config.yaml edit infra 2026-06-25 06:22:16 +02:00
README.md edit infra 2026-06-25 06:22:16 +02:00
referentiearchitectuur-uwv-data-analytics.md fase 1 2026-05-01 05:54:10 +02:00
requirements-compliant-data-analyseplatform.md fase 1 2026-05-01 05:54:10 +02:00
requirements-docs.txt chore(deps): bump pillow from 11.0.0 to 12.2.0 (#5) 2026-05-25 14:17:19 +02:00
SECURITY.md fases 2-11: complete platform + quick-wins 2026-05-02 06:59:15 +02:00
uwv-platform-adr-0002-iceberg-vs-delta.md fase 1 2026-05-01 05:54:10 +02:00
uwv-platform-mapping-research.md fase 1 2026-05-01 05:54:10 +02:00
uwv-platform-master-agent-prompt-v2.md chore: drop kind support, keep k3d (local) + aks (cloud) only 2026-05-17 19:20:07 +02:00
WORKLOG.md edit deployment config 2026-06-25 06:16:25 +02:00

UWV Reference Data & Analytics Platform

Een fictieve, illustratieve referentie-implementatie van een modern data- en analyticsplatform voor UWV, gebouwd op open source en gericht op compliance met NORA, AVG, BIO/BIO2, NIS2 en de AI Act.

Disclaimer. Geen echte UWV-data, geen echte BSN's, geen echte productiecode. Alle datasets zijn synthetisch en gemarkeerd met # SYNTHETIC DATA — UWV REFERENCE PLATFORM — NOT FOR REAL USE. Deze repo is geen UWV-product en geen aanbestedingsstuk.


Wat dit platform doet

Een Kubernetes-native lakehouse + analytics-stack:

  • Storage: S3-compatible object store — SeaweedFS in k3d-mode (zie ADR-0011), MinIO in aks/stackit (migratie naar SeaweedFS in follow-up).
  • Tabelformaat: Delta Lake (default voor deze implementatie — zie ADR-0006). Iceberg-pad blijft afgedekt via abstractie.
  • Catalog backend: Apache Hive Metastore (Postgres-backed).
  • Ingestion: file-source → Spark Structured Streaming → Delta op MinIO. NiFi/Kafka-flows zijn als template aanwezig (nifi-flows/templates/) maar de bijbehorende Stackable-operators staan in deze release uit — UC-11 leest direct uit de S3 raw-zone.
  • Query engine: Trino, met OPA-authorisatie (Rego: doelbinding, row filters, column masking).
  • Transformatie: dbt-trino, format-agnostisch via macro table_format().
  • Orchestratie: Apache Airflow 3 + astronomer-cosmos voor dbt-DAGs.
  • BI: Apache Superset.
  • Notebooks: JupyterHub + KubeSpawner (UWV Lab) — Python/SQL op alle data-lagen, Git-integratie. Zie platform/16-jupyter/.
  • Catalog/governance/lineage/DQ: OpenMetadata, met een self-service om-access-bridge (OM task-approval → Keycloak realm-role → OPA grant).
  • AuthN: Keycloak (OIDC).
  • Portal: Astro/React workspace-shell die alle service-UIs embed onder één URL (portal/, platform/15-portal/).
  • Agent-tooling: Multica server + Nanitics observatory (zie platform/17-multica/, platform/19-nanitics-observatory/, platform/20-multica-daemon/). Exploratory, niet aangesloten op de governance-flow.
  • Logs/metrics/tracing: Vector + Prometheus; OpenSearch single-node gedeeld voor logs en OM-search. OpenTelemetry-tracing is bekabeld voor support op Trino/Airflow maar nog niet aangesloten op een backend.

Stackable Data Platform-operators in deze release (zie infrastructure/stackablectl/release.yaml): airflow, commons, hive, listener, opa, secret, spark-k8s, superset, trino. NiFi/Kafka/ZooKeeper zijn in release.yaml uitgecommentarieerd — UC-11 vraagt ze niet en ze besparen ~2 vCPU + 4 GiB op k3d.


Snelstart

Het platform draait in drie deployment-modes; alle Make-targets accepteren MODE={k3d|aks|stackit} (default k3d). De mode bepaalt:

Aspect k3d (default) aks stackit
Cluster type k3d serverlb + local-path AKS managed-csi + LB SKE (Gardener) + yawol LB
Domain uwv-platform.local:8443 eu-sovereigndataplatform.com freshstackable.com
Storage class local-path managed-csi storage-class-ske-csi-cinder
Ingress controller DaemonSet + hostNetwork Deployment + LoadBalancer Deployment + yawol Floating-IP
Helm values …/values.yaml + values-k3d.yaml …/values-aks.yaml …/values-stackit.yaml
Platform overlays base (flat) platform-overlays/aks/<comp>/ platform-overlays/stackit/<comp>/

Mode 1 — k3d (developer laptop)

Voorvereisten:

  • Docker Desktop met ≥ 8 GB RAM en ≥ 4 CPU's beschikbaar voor containers.
  • k3d ≥ 5.6, kubectl ≥ 1.29, helm ≥ 3.14, stackablectl ≥ 25.x, make.
# 1. Doctor — controleert tooling + /etc/hosts + kubectl context
make doctor MODE=k3d

# 2. /etc/hosts injectie (vereist sudo, eenmalig)
echo "127.0.0.1 keycloak.uwv-platform.local \
  superset.uwv-platform.local airflow.uwv-platform.local \
  minio.uwv-platform.local openmetadata.uwv-platform.local \
  jupyter.uwv-platform.local platform.uwv-platform.local" | sudo tee -a /etc/hosts

# 3. End-to-end deploy (~15-30 min)
make deploy MODE=k3d   # cluster + bootstrap + platform + portal + smoke

# Of stap voor stap:
make cluster MODE=k3d
make bootstrap MODE=k3d
make deploy-platform MODE=k3d
make seed
make test

# 4. Cleanup
make clean

Mode 2 — aks (Azure productie)

# Vereist: az login, terraform, SP-secret in scripts/azure/env.sh
make doctor MODE=aks
make aks-up           # terraform: AKS + VNet + LB + DNS-zone
make aks-context      # kubeconfig
make aks-all          # bootstrap + deploy + smoke

# Of in CI: gebruik de aks-deploy.yml workflow (handmatige dispatch).

Mode 3 — stackit (StackIT SKE productie)

# Vereist: stackit CLI + STACKIT_SERVICE_ACCOUNT_TOKEN, terraform.
# Floating IP 188.34.84.39 + DNS-zone freshstackable.com worden door
# Terraform beheerd (zie infrastructure/stackit/terraform/).
make doctor MODE=stackit
make stackit-up                              # terraform: SKE + reserved Floating IP
eval "$(make stackit-context)"               # export KUBECONFIG=...
make stackit-all                             # bootstrap + deploy + portal + smoke (~40 min)

# Pauzeren (workers naar 0 — control plane sleeps, PVCs + IP behouden):
make stackit-hibernate
make stackit-wake                            # ~3-5 min terug
make stackit-status                          # HEALTHY / HIBERNATED / RECONCILING

# Of in CI: zie stackit-cd.yml + stackit-smoke.yml workflows.

Mode mismatch-bescherming

scripts/bootstrap.sh en scripts/deploy-platform.sh weigeren te draaien als de kubectl-context niet matcht met --mode. Een typische foutmelding:

FAIL mode=aks but kubectl context 'k3d-uwv-platform' is not an AKS cluster.
Run 'make aks-context'.

Repository-layout

Directory Inhoud
platform-config.yaml Centrale configuratie. Wijzig table_format hier, niet elders.
docs/ Architectuur, ADRs, use-case specs, compliance-mapping, runbook.
infrastructure/ k3d-config, externe Helm-values (cert-manager, Keycloak, SeaweedFS/MinIO, Postgres, OpenMetadata, oauth2-proxy), Stackable release-pinning.
platform/ Kubernetes-manifests per laag (00-namespaces … 13-openmetadata-config).
dbt/ dbt-project, models (staging/intermediate/marts/uc01..uc10), macros, tests.
data-generation/ Synthetische data-generators (Python).
nifi-flows/ NiFi-flow templates (iceberg/delta varianten).
spark-jobs/ PySpark-jobs (streaming + batch + ML demo).
opa-policies-src/ Rego-policies + tests.
scripts/ Bash-helpers voor make-targets.
tests/ Smoke / integration / e2e tests.
ci/ GitHub Actions workflows (in opzet).

Documentatie


Status

Werk-in-uitvoering. Zie WORKLOG.md voor laatste fase en openstaande items. De Definition of Done staat in docs/architecture.md.


Licentie

Apache License 2.0 — zie LICENSE.