Engine Design
Architecture and design patterns of the CaD Engine.
The Engine (also called the CaD Engine - Configuration as Data Engine) is the central orchestration component in Porch that manages the complete lifecycle of package revisions and packages. It acts as the coordination layer between the API server, package cache, repository adapters, and task execution pipeline.
The Engine is responsible for:
exec_path, in-process pod evaluator)The Engine sits between the Porch API Server and the lower-level components:
Key architectural responsibilities:
Abstraction Layer: Provides a clean interface (CaDEngine) that hides the complexity of cache management, repository operations, and task execution from the API server
Workflow Orchestration: Implements the package revision workflow:
State Management: Enforces package lifecycle state machine rules, ensuring packages can only transition through valid states
Integration Point: Connects multiple subsystems:
Validation Gateway: Validates all package operations before execution, including workspace name uniqueness, lifecycle constraints, and task-specific validations
Function evaluation and pod lifecycle: The Engine hosts the function runtime chain (builtin → Function Runner exec → pod evaluator). The following diagram is the former Function Runner architecture drawing; those boxes now run in-process in porch-server. The PackageRevision controller is a gRPC client of that evaluator (POD_EVALUATOR_ADDRESS).
PackageRevision controller
(gRPC client, POD_EVALUATOR_ADDRESS)
│
│ EvaluateFunction
↓
┌─────────────────────────────────────────────────────────┐
│ Engine — pod evaluator (porch-server) │
│ │
│ ┌──────────────────┐ ┌──────────────────┐ │
│ │ gRPC Server │ │ Evaluators │ │
│ │ │ ───> │ │ │
│ │ • FunctionEval │ │ • Pod Evaluator │ │
│ │ Service │ │ • Exec Evaluator│ │
│ │ • Health Check │ │ • Multi-Eval │ │
│ └────────┬─────────┘ └────────┬─────────┘ │
│ │ │ │
│ └────────┬────────────────┘ │
│ ↓ │
│ ┌──────────────────┐ ┌──────────────────┐ │
│ │ Pod Lifecycle │ │ Image & Registry│ │
│ │ Management │ │ Management │ │
│ │ │ │ │ │
│ │ • Pod Cache │ │ • Metadata Cache│ │
│ │ • Pod Manager │ │ • Auth & TLS │ │
│ │ • GC & TTL │ │ • Pull Secrets │ │
│ └────────┬─────────┘ └────────┬─────────┘ │
│ │ │ │
│ └────────┬────────────────┘ │
│ ↓ │
│ ┌──────────────────────┐ │
│ │ Kubernetes API │ │
│ │ & Registries │ │
│ └──────────────────────┘ │
└─────────────────────────────────────────────────────────┘
↑
│
Task Handler / kpt Renderer
(in-process Engine path)
The Engine is instantiated once during Porch API server startup and configured with dependencies (cache, task handler, function runtimes, credential resolvers) through a functional options pattern. The PackageRevision controller uses the same builtin and Function Runner exec runtimes for v1alpha2 renders, and calls porch-server’s FunctionEvaluator gRPC for container functions.
Architecture and design patterns of the CaD Engine.
Overview of CaDEngine functionality and detailed documentation pages.
How the Engine interacts with other Porch components.