Architecting your Internal Developer Platform
Situation
The Portal Trap
As organizations move beyond the initial hype of platform engineering, a common problem has emerged: many initiatives stall because teams build portals when they actually need platforms. Early Internal Developer Platforms (IDPs) improved service discovery, but developers still depend on manual approvals, ticket queues, and platform teams to provision infrastructure.
At the same time, infrastructure complexity continues to grow:
- Developers are expected to manage Kubernetes, CI/CD pipelines, cloud configurations, and security policies alongside application development.
- Platform teams struggle to provide secure multi-tenant environments and governance without increasing operational overhead.
- Self-service remains limited, and engineering teams spend too much time managing infrastructure instead of building software.
The result is a growing gap between the promise of developer self-service and the reality of day-to-day operations.
How we help
Kubermatic Developer Platform (KDP)
Kubermatic Developer Platform (KDP) is an industrialized IDP built from the infrastructure up, not the UI down. Built on the CNCF Sandbox project kcp, KDP provides a Kubernetes-native control plane that transforms internal IT into a service-oriented marketplace.
"Kubernetes-in-Kubernetes" Architecture
KDP leverages kcp workspaces — lightweight, logical clusters that operate as independent API servers. This provides hard multi-tenancy at the control plane level without the overhead of thousands of physical clusters.
A Service Catalog that Provisions
Unlike simple catalogs, KDP uses the api-syncagent to bidirectionally sync resource requests from the central control plane to distributed service clusters. Developers get running resources (databases, queues, AI models) in seconds, not days.
Standardized API Governance
KDP uses standard Kubernetes APIs all the way down. If a team knows kubectl, they know KDP. This eliminates the need for proprietary SDKs or complex TypeScript plugins.
Agentic-Ready Infrastructure
KDP is engineered for the era of AI. Its machine-readable APIs and AI Assistant allow both humans and autonomous agents to discover and provision resources via natural language.
Use Cases
Self-Service Database-as-a-Service (DBaaS)
- The Mission: Eliminate the 3-day wait for a PostgreSQL database.
- The Application: Service owners define a
PublishedResourcevia Crossplane. Developers select the service from the KDP dashboard, and KDP automatically provides the managed cloud instance (AWS RDS, GCP SQL) or on-prem database, delivering connection details directly to the developer’s workspace.
AI ModelOps and Governance
- The Mission: Control access to high-value AI models and GPU compute.
- The Application: Platform teams use KDP workspaces to isolate AI workloads. They publish LLM endpoints to specific teams through the catalog, managing GPU quotas and token rotation via Kubermatic SecureGuard to prevent cost overruns and hard-coded leaks.
Enterprise Multi-Tenancy at Scale
- The Mission: Supporting thousands of teams without cluster sprawl.
- The Application: Utilizing the hierarchical workspace model, platform owners manage the root, while individual departments manage their own branches. Each team operates in its own API space, completely invisible to others, drastically reducing the blast radius of misconfigurations.
Outcome
Speed, Simplicity, and Power
By implementing platform engineering with KDP, organizations replace manual toil with an automated software delivery engine.
Near-Zero Wait Times
Transition from ticket-based provisioning to one-click service creation, reducing delivery times from days to seconds.
70% Reduction in Operational Overhead
Shift the focus of DevOps teams from “putting out fires” to building “golden paths,” enabling a single engineer to manage hundreds of clusters.
Enhanced Developer Velocity
Reclaim up to 3 hours per week per developer by automating secret management and infrastructure tasks.
Future-Proof Scalability
A hardware-agnostic platform that supports any Kubernetes cluster across multi-cloud, on-prem, and edge environments.
Why Kubermatic?

Proven Leadership
Recognized by Gartner®, Forrester, GigaOM, SPARK Matrix™ and a top contributor to the CNCF.

Flexibility
Supports Bare Metal, vSphere, OpenStack, and all major public clouds (AWS, Azure, GCP).

Sovereignty
Germany-based company offering 100% sovereign infrastructure and secure, private cloud stacks.
Expert Support
Implementation, managed services, and 24×7 mission support from Kubernetes experts.
