--- name: platform-engineering description: Build internal developer platforms (IDPs) with self-service infrastructure, golden paths, and developer portals using Backstage, Crossplane, and score. category: devops risk: critical source: https://github.com/BagelHole/DevOps-Security-Agent-Skills source_repo: BagelHole/DevOps-Security-Agent-Skills source_type: community date_added: '2026-09-20' license: MIT license_source: https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE compatibility: Requires the relevant platform CLIs (kubectl, helm, terraform, git, CI runners) and authorized access to the target environment. Docs-only; helper scripts and templates not bundled. metadata: author: devops-skills version: '1.0' --- # Platform Engineering Platform engineering is the discipline of building and maintaining internal developer platforms (IDPs) that enable self-service capabilities for software engineering teams. The goal is to reduce cognitive load, standardize infrastructure provisioning, and accelerate delivery while maintaining governance and security guardrails. --- ## 2. Backstage Setup [Backstage](https://backstage.io) is the leading open-source developer portal framework, originally created at Spotify. ### Installation ```bash # Prerequisites: Node.js 18+, yarn 1.x npx @backstage/create-app@latest # Follow the prompts -- name your app, e.g., "internal-platform" cd internal-platform # Start the development server yarn dev ``` ### Production Docker Build ```dockerfile # Dockerfile for Backstage production image FROM node:18-bookworm-slim AS build WORKDIR /app COPY package.json yarn.lock ./ COPY packages/ packages/ COPY plugins/ plugins/ RUN yarn install --frozen-lockfile RUN yarn tsc RUN yarn build:backend FROM node:18-bookworm-slim WORKDIR /app COPY --from=build /app/packages/backend/dist/ ./ COPY --from=build /app/node_modules/ ./node_modules/ COPY app-config.yaml app-config.production.yaml ./ ENV NODE_ENV=production CMD ["node", "packages/backend", "--config", "app-config.production.yaml"] ``` ### Core app-config.yaml ```yaml # app-config.yaml app: title: Internal Developer Platform baseUrl: http://localhost:3000 organization: name: MyOrg backend: baseUrl: http://localhost:7007 listen: port: 7007 database: client: pg connection: host: ${POSTGRES_HOST} port: ${POSTGRES_PORT} user: ${POSTGRES_USER} password: ${POSTGRES_PASSWORD} integrations: github: - host: github.com token: ${GITHUB_TOKEN} catalog: import: entityFilename: catalog-info.yaml pullRequestBranchName: backstage-integration rules: - allow: [Component, System, API, Resource, Location, Template] locations: - type: url target: https://github.com/myorg/software-catalog/blob/main/catalog-info.yaml - type: url target: https://github.com/myorg/backstage-templates/blob/main/all-templates.yaml ``` --- ## 3. Crossplane for Self-Service Infrastructure Crossplane extends Kubernetes to provision and manage cloud infrastructure through declarative YAML. ### Install Crossplane ```bash # Add the Crossplane Helm repo helm repo add crossplane-stable https://charts.crossplane.io/stable helm repo update # Install Crossplane into its own namespace helm install crossplane crossplane-stable/crossplane \ --namespace crossplane-system \ --create-namespace \ --set args='{"--enable-composition-revisions"}' # Install the AWS provider kubectl apply -f - < Adapted from [BagelHole/DevOps-Security-Agent-Skills](https://github.com/BagelHole/DevOps-Security-Agent-Skills) (MIT); frontmatter, When to Use/Limitations, and safety boundaries added for upstream compliance. Docs-only import: helper scripts and templates not bundled.