← Back to Index

Tools & Components

Core Stack (Server)

CategoryComponentKey Features & Rationale
Operating SystemUbuntu Server LTS5y security updates; broad ecosystem; HWE kernel support.
OrchestrationKubernetes (RKE2) + RancherFIPS-capable K8s; Rancher UI/RBAC/upgrade pipeline.
Container RuntimePodmanDaemonless/rootless; Docker explicitly excluded to reduce attack surface.
IdentitySamba 4 ADAD-compatible source of truth; avoids CAL licensing.
SSO / MFAAuthentikOIDC/SAML; WebAuthn/TOTP; bridges LDAP/AD.
CollaborationZimbra CE + ClamAV + SpamAssassinExchange/O365 alternative with built-in AV/AS.
SIEM / XDRWazuhCentralized detection/response; OS + K8s + app telemetry.
Metrics / VizPrometheus + GrafanaDe facto metrics and dashboard stack.
Storage (CSI)LonghornDistributed block storage; CSI snapshots for PVCs.
Load BalancingMetalLB (L2)Bare-metal service publishing with ARP/NDP pools.
PKICert-ManagerAutomated cert issuance (self-signed or internal CA).
BackupVelero + MinIO (S3)Cluster + PVC backups with kopia/CSI to on-prem S3.

Client Stack: The "Flexible 10" Model

Philosophy

One-size-fits-all desktops create friction. A persona-based catalog of Ubuntu derivatives reduces resistance, speeds migration from Windows, and keeps support predictable.

The 10 Distributions

#DistributionTarget PersonaWhy This Choice
1Ubuntu DesktopStandard corporate userCanonical baseline; stable, broad hardware support.
2Linux Mint (Cinnamon)Office / AdminWindows-like workflow; minimal retraining.
3Zorin OSManagement / ExecPremium, polished UI akin to Win11/macOS.
4Pop!_OSEngineers / DevsTiling, good GPU support, dev tooling focus.
5KubuntuPower usersKDE customization for advanced users.
6XubuntuLegacy hardwareXFCE lightweight; extends life of old assets.
7LubuntuThin clientsUltra-light LXQt for low-resource endpoints.
8Ubuntu MATETraditionalistsClassic desktop metaphor; low learning curve.
9elementary OSKiosk / PublicOpinionated, focused UI; locked-down feel.
10KDE NeonR&D / ExplorersLatest KDE stack for experimentation.

Migration & Training Plan

Phase 1: Discover & Map

Phase 2: Pilot

Phase 3: Rollout & Support

Phase 4: Optimize

Note: This selection prioritizes open-source licensing, data sovereignty, and operational maturity over "cloud convenience."