Self-Hosted Infrastructure

Always On.
Always Secure.

A two-node Kubernetes cluster running every service here. Traffic arrives through a Cloudflare Tunnel, secrets come from a vault, deploys are GitOps, and the things that matter run one replica per machine — so losing a server costs capacity, not availability.

— Services Ready
— Nodes
Public view

The Nodes

Both machines, side by side: ready state, load, and disk. The ZAP holds the control plane and the small disk; the S4Y holds the data and the muscle.

Loading nodes...

What's Running

Every card below is read live from the cluster. The name, description and link come from the annotations on each workload's manifest — there is no list in this page to keep in sync.

Loading services...

Multi-Layer Defense

Every connection is encrypted, every secret has an owner, and every workload runs with the least it can get away with.

01

No Open Ports

Public traffic arrives through a Cloudflare Tunnel with two connectors, one per node. Nothing is exposed directly except the photo uploads, which are too large for the tunnel.

02

Namespace Isolation

One namespace per application, each with its own limits, quotas and secrets. Nothing shares a flat network with everything else any more.

03

Workload Hardening

All capabilities dropped, privilege escalation off, memory and CPU bounded, and images pinned to an immutable tag — never latest.

04

Secrets From a Vault

No passwords in git. OpenBao holds them, External Secrets syncs them into the cluster, and a rotation is one write away.

05

GitOps Deploys

The cluster reconciles itself against a git repository. A deploy is a commit, a rollback is a revert, and drift is corrected automatically.

06

Backups You Can Restore

Encrypted daily snapshots with continuous archiving for the databases, plus a dead-man's switch that shouts when a backup simply stops running.

Get in Touch

Have a question or want to collaborate? Send us a message.

We use your name and email only to answer you. Privacy