Deployment History Portal
Generated portal for browsing live applies, promotions, and mutation audit history.
Developer Portal
Generated public documentation site for services, ADRs, runbooks, release notes, and platform reference data.
Docker Build VM
Private build worker for image builds, heavy validation, and repository offload tasks.
Docker Runtime VM
Primary runtime for containerised control-plane and platform services.
Grafana
Metrics dashboards, platform overview, and service detail dashboards.
Keycloak
Shared SSO and OIDC broker for operator-facing and approved agent-facing applications.
Mail Platform
Managed SMTP, IMAP, and delivery automation surface for platform notifications.
Mattermost
Private operator and agent collaboration surface for ChatOps workflows.
NGINX Edge
Public ingress edge that terminates TLS and publishes selected services.
NetBox
Private topology, IPAM, and inventory system for the platform.
Open WebUI
Private operator and agent workbench for governed platform interactions.
OpenBao
Private secrets authority for controller automation and runtime credentials.
Platform API Gateway
Unified authenticated gateway for operator and automation access to platform HTTP APIs.
Platform Context API
Private retrieval-augmented query API for repository and platform context.
Platform Operations Portal
Interactive operator portal with live service actions, drift visibility, runbook launchers, and deployment streaming.
Portainer
Private read-mostly Docker runtime operations UI and API.
PostgreSQL
Managed high-availability PostgreSQL service for control-plane and future application state.
Proxmox Backup Server
Backup datastore and snapshot retention service for the Proxmox estate.
Proxmox UI
Private Proxmox management interface for host and guest administration.
Public Status Page
Public-facing platform status page backed by Uptime Kuma and independently checked by Uptime Robot.
Uptime Kuma
Synthetic monitoring surface used to track public and internal service reachability.
Windmill
Operator and agent workflow runtime exposed privately on the management tailnet.
ntopng
Private flow-visibility and traffic-inspection surface for the platform network.
step-ca
Private certificate authority for internal TLS and SSH certificates.