Beyond Kubernetes: Building a Self-Service Platform with AWS Native Services
While Kubernetes is often seen as essential for platform engineering, many organizations can achieve faster and simpler developer experiences using AWS-native services like App Runner, Lambda, Fargate, CodePipeline, and Proton. By focusing on core platform principles such as self-service, security guardrails, observability, and scalability, teams can avoid the complexity of managing Kubernetes clusters.
Platform engineering has emerged as the backbone of modern software delivery, fundamentally transforming how organizations approach developer productivity. At its core, platform engineering aims to empower developers to ship code faster, safer, and with greater confidence through golden paths, robust automation, and intelligent guardrails.
Yet in discussions about platform engineering, one technology dominates the conversation: Kubernetes. While Kubernetes has become synonymous with modern platform architecture, this raises a critical question that many organizations fail to ask:
Is Kubernetes truly indispensable for every platform?
The unequivocal answer is: not necessarily
For many organizations, Kubernetes introduces more complexity than it solves, creating operational overhead that diverts engineering resources from their primary mission — delivering value to users. This post explores how to build a production-grade internal developer platform (IDP) using AWS-native services, bypassing Kubernetes entirely while delivering superior developer experience and operational simplicity.
The Kubernetes Complexity Trap
Before diving into alternatives, let’s address the elephant in the room: platform engineering is a discipline, not a technology stack.
The core mission of platform engineering centers on:
- Accelerating developer velocity through reduced friction
- Fostering innovation by removing operational barriers
- Minimizing cognitive load so developers focus on business logic
- Ensuring governance, security, and scalability without compromising speed
While Kubernetes can be a powerful tool for complex, containerized workloads, it’s not the only path to platform excellence. If your team spends more time managing clusters than enabling developers, it’s time to reconsider your approach.
The goal of platform engineering is to accelerate product delivery, not to become Kubernetes experts.
Core Principles of Effective Platform Engineering
Any modern platform — regardless of underlying technology — should embody these fundamental principles:
Self-Service Capabilities: Developers deploy and manage applications independently through intuitive interfaces and well-defined processes.
Golden Paths: Opinionated templates and curated toolchains ensure secure, efficient, and compliant deployments by default.
Embedded Security: Guardrails that enforce standards seamlessly without blocking delivery velocity.
Comprehensive Observability: Full visibility into application health, performance, and usage for rapid issue resolution.
Effortless Scalability: Both platform and workloads scale automatically with demand, requiring minimal manual intervention.
AWS provides a comprehensive suite of native services that fulfill all these principles — crucially, without the operational complexity of managing Kubernetes clusters.
Building Your AWS-Native Platform: The Complete Toolkit
Let’s explore how to architect a production-grade internal developer platform using AWS-native services:
Compute Abstractions: Managed Simplicity for Any Workload
AWS App Runner: Deploy web applications and APIs directly from GitHub or container registries. App Runner automatically handles autoscaling, HTTPS termination, load balancing, and observability — all without infrastructure management. While it may lack the fine-grained controls needed for complex applications with specific networking, security, or deployment requirements, App Runner has a clear place in the AWS ecosystem for teams wanting to focus on code rather than infrastructure, making it ideal for straightforward web applications, APIs, and microservices that benefit from rapid deployment and minimal operational overhead.
AWS Lambda: Perfect for event-driven architectures, background processing, and microservices. Scales to zero when idle and can instantly scale to handle thousands of concurrent executions, integrating natively with over 200 AWS services to eliminate integration complexity. Lambda excels at building loosely-coupled microservices that can be developed, deployed, and scaled independently, making it ideal for decomposing monolithic applications into manageable, function-based services. Lambda shines when you need rapid development cycles, automatic scaling that can handle massive traffic spikes without pre-provisioning, and pay-per-execution pricing for unpredictable or bursty workloads.
AWS Fargate: Run containers serverlessly through ECS or EKS without managing clusters or EC2 instances. Ideal for long-running tasks, batch processing, and sidecar patterns, with IAM-based task-level security that provides granular access control. Fargate bridges the gap between Lambda’s execution limits and full container orchestration, offering the flexibility of containerized applications with serverless operational simplicity. Perfect for teams wanting container portability and custom runtime environments while eliminating infrastructure management overhead.
CI/CD & Developer Automation: Streamlining Software Delivery
AWS CodePipeline and CodeBuild: Create automated build, test, and deployment pipelines that integrate seamlessly with Lambda, App Runner, or Fargate for end-to-end delivery.
Amazon Q Developer: A generative AI assistant that helps developers write and refactor code, generate infrastructure as code, and troubleshoot builds. It’s integrated into AWS services like Lambda console and available in various development environments.
GitHub Actions + OIDC: Implement secure CI/CD pipelines using federated identity. GitHub can assume IAM roles without managing AWS credentials, enabling scalable, secure GitOps workflows.
Governance & Infrastructure as Code: Consistency and Control at Scale
AWS Proton: Define, version, and distribute infrastructure and application templates. Developers self-serve standardized environments while platform teams ensure compliance and consistency.
AWS Service Catalog: Expose curated golden paths to developers, enforcing usage of approved configurations, budgets, and security controls.
AWS Control Tower: Manage multi-account environments with automated policy enforcement, account provisioning, and security guardrails.
CloudFormation / CDK: Define infrastructure as code using YAML/JSON (CloudFormation) or modern programming languages like TypeScript and Python (CDK), supporting version control and automation.
Observability: Deep Insights Built-In
Amazon CloudWatch & AWS X-Ray: Centralized logging, metrics, dashboards, alarms, and distributed tracing across all AWS services with no additional infrastructure.
AWS CloudTrail: Immutable audit logs of all AWS API activity, essential for security investigations and compliance requirements.
Integrated Telemetry: App Runner and Lambda provide built-in OpenTelemetry support for seamless instrumentation and vendor-agnostic observability.
Security & Access: Embedded, Granular Control
IAM Identity Center (formerly AWS SSO): Unified identity management with fine-grained, role-based access control across AWS accounts and services.
Service Control Policies (SCPs): Prevent unsafe operations across teams by enforcing policies at the account or organizational unit level.
AWS Config + Security Hub: Continuously monitor configurations, detect drift, and aggregate security findings for automated remediation.
A Day in the Life: Seamless Developer Experience
Here’s how a typical developer workflow looks with an AWS-native platform:
Morning: Project Setup A developer selects a “Node.js App with DynamoDB” template from AWS Proton. The template includes pre-configured infrastructure, security policies, and monitoring — all version-controlled and governed.
Development: Code and Deploy Code is pushed to GitHub. GitHub Actions authenticates using OIDC and triggers CodePipeline. CodeBuild handles testing and packaging, automatically deploying to App Runner with zero infrastructure concerns.
Monitoring: Real-time Insights Logs stream to CloudWatch, traces appear in X-Ray, and the developer accesses pre-configured dashboards to monitor application behavior and receive intelligent alerts.
Security: Built-in Protection IAM roles and AWS Secrets Manager handle runtime permissions and automatic secret rotation. Service Control Policies ensure no unauthorized actions can be taken.
Scaling: Automatic and Transparent App Runner scales in and out with traffic automatically. Lambda functions respond to demand spikes without manual intervention or cluster management.
This isn’t theoretical — this is a production-grade developer platform that eliminates the operational burden of Kubernetes while delivering superior developer experience.
When You Don’t Need Kubernetes
You likely don’t need Kubernetes if:
- Your workloads are primarily APIs, batch jobs, or background tasks
- You prefer managed services over building and maintaining control planes
- Your team is small or lacks extensive Kubernetes operational experience
- Your primary focus is developer velocity rather than infrastructure abstraction
- You value operational simplicity over configurability
Kubernetes can unlock powerful patterns, but often its complexity outweighs its benefits — especially when AWS-native alternatives already solve your core problems more elegantly.
When Kubernetes Still Makes Sense
To be fair, Kubernetes remains valuable in specific scenarios:
- Highly customized networking or scheduling requirements that managed services can’t accommodate
- Complex sidecar patterns or service mesh needs requiring fine-grained control
- Hybrid or multi-cloud portability requirements where vendor lock-in is a concern
- Large-scale container orchestration with thousands of services requiring shared runtimes
For these use cases, AWS offers Amazon EKS, EKS Blueprints, and EKS Auto Mode to reduce Kubernetes operational overhead while maintaining flexibility.
Conclusion: Platform Engineering Without the Complexity
Platform engineering is fundamentally about enabling developers, not managing infrastructure. The most successful platforms are those that become invisible to their users — providing powerful capabilities without operational burden.
AWS provides a rich ecosystem for building robust, scalable, and governed internal platforms without provisioning a single node or managing a single cluster. By leveraging services like App Runner, Proton, Lambda, and CodePipeline, you can accelerate innovation, reduce complexity, and focus on what matters most: delivering value to end users.
It’s time to look beyond Kubernetes and embrace the simplicity of AWS-native platform engineering. Your developers — and your delivery velocity — will thank you.
The future of platform engineering isn’t about managing more infrastructure — it’s about managing less while delivering more.
Enjoyed reading this content? Let the author know!
Your likes, comments, shares, and saves help creators reach more builders.
Loading recommendations
Loading article