← Back to Index

System Architecture

Overview

The proposed architecture is a holistic On-Premise Sovereign Cloud built on Ubuntu Server LTS. It is designed to replace the traditional Microsoft ecosystem (Windows Server/Hyper-V/Active Directory) with a modern, container-based open-source stack.

Physical Layer

The foundation consists of 3 Physical Servers configured as a High-Availability (HA) cluster:

Orchestration Layer: Kubernetes & Rancher

Instead of legacy virtualization, the system uses Kubernetes (RKE2) managed by Rancher.

Logical Architecture & Namespaces

Services are logically isolated into Kubernetes Namespaces for security and resource management:

Namespace Services Role & Configuration
infrastructure Samba 4 AD
Authentik
Core Identity: AD serves as the "Source of Truth". Authentik syncs via LDAP to provide SSO (SAML/OIDC) and MFA.
collaboration Zimbra Suite Business Apps: Email, Calendar, Contacts. Data persists on Longhorn volumes; secured by ClamAV/SpamAssassin.
security Wazuh Manager Defensive Ops: Central SIEM for log correlation.
monitoring Prometheus
Grafana
Observability: Scrapes metrics from nodes/pods and visualizes them via accessible dashboards (e.g., grafana.sovereign.lan).

Networking & Integration

Backup & Disaster Recovery