Always On.
Always Secure.
A two-node Kubernetes cluster running every service here. Traffic arrives through a Cloudflare Tunnel, secrets come from a vault, deploys are GitOps, and the things that matter run one replica per machine — so losing a server costs capacity, not availability.
The Nodes
Both machines, side by side: ready state, load, and disk. The ZAP holds the control plane and the small disk; the S4Y holds the data and the muscle.
What's Running
Every card below is read live from the cluster. The name, description and link come from the annotations on each workload's manifest — there is no list in this page to keep in sync.
Multi-Layer Defense
Every connection is encrypted, every secret has an owner, and every workload runs with the least it can get away with.
No Open Ports
Public traffic arrives through a Cloudflare Tunnel with two connectors, one per node. Nothing is exposed directly except the photo uploads, which are too large for the tunnel.
Namespace Isolation
One namespace per application, each with its own limits, quotas and secrets. Nothing shares a flat network with everything else any more.
Workload Hardening
All capabilities dropped, privilege escalation off, memory and CPU bounded, and images pinned to an immutable tag — never latest.
Secrets From a Vault
No passwords in git. OpenBao holds them, External Secrets syncs them into the cluster, and a rotation is one write away.
GitOps Deploys
The cluster reconciles itself against a git repository. A deploy is a commit, a rollback is a revert, and drift is corrected automatically.
Backups You Can Restore
Encrypted daily snapshots with continuous archiving for the databases, plus a dead-man's switch that shouts when a backup simply stops running.
Get in Touch
Have a question or want to collaborate? Send us a message.