Replace Microsoft Cloud Dependence with an Ubuntu-first Sovereign Stack

Kubernetes (RKE2) on Ubuntu LTS, Rancher for governance, Podman for rootless containers. Identity with Samba 4 + Authentik, collaboration via Zimbra, and observability with Wazuh, Prometheus, and Grafana. Client freedom: 10 Ubuntu-based desktops tuned to user personas.

Ubuntu Sovereign Stack
Server Architecture
🖥️

Compute & Orchestration

3× Ubuntu Server LTS; RKE2 Kubernetes with Rancher for lifecycle, RBAC, and multi-cluster governance.

🔒

Runtime & Security

Podman-only (daemonless/rootless); Longhorn for CSI storage; MetalLB for L2 LB; Cert-Manager for PKI.

🧭

Identity

Samba 4 AD as source of truth; Authentik for SSO/MFA and modern protocols.

✉️

Collaboration

Zimbra CE with ClamAV + SpamAssassin for secure mail and collaboration.

📈

Security & Observability

Wazuh SIEM/XDR; Prometheus + Grafana for metrics and dashboards.

💾

Backups

Velero with MinIO (S3-compatible) for cluster and PVC backups; snapshot-aware via CSI.

The 10-Distro Model

Ubuntu Desktop

Standard; broad hardware support.

Linux Mint

Office-friendly; Windows-like UX.

Zorin OS

Management-friendly polish.

Pop!_OS

Developer and engineering focus.

Kubuntu

Power users; KDE workflow.

Xubuntu

Legacy hardware (XFCE).

Lubuntu

Ultra-light, thin clients.

Ubuntu MATE

Traditional desktop paradigm.

elementary OS

Kiosk/public terminals.

KDE Neon

R&D, newest KDE.