EpochCloud

staging

Infrastructure Dashboard

Version 0.1.22
Commit 701f973
Built 9d ago
Uptime
Environment staging
Pod epochcloud-demo-7dbcd65854-cgfh4
Git Push
Argo Workflows
📦 Harbor
🚀 Kargo
🔄 ArgoCD

Platform Stack

76
Online 76
Proxmox VE + OpenTofuTalos OS + K8s 1.36KarpenterCilium + HubbleWireGuard EncryptionArgoCDOpenBaoExternal Secrets OperatorSOPS + agehelm-secretsTraefik + cert-manager + trust-managerCloudflare Zero TrustKeycloak SSOoauth2-proxyLonghorn StorageCloudNativePGHarbor RegistrySpegel (image mirror)Argo Workflows CIArgo EventsKyverno PoliciesCosign SigningKyverno verifyImagesFulcio (keyless signing CA)Rekor (signing transparency log)Tessera (Rekor v2 log storage)TUF (self-hosted trust root)TSA (RFC3161 timestamps)SLSA Build L3 ProvenanceSyft + GrypeSemgrep + TrivyPluto (deprecated APIs)OWASP ZAPHeadlampkubernetes-reflectorReloaderRenovateArgoCD Image UpdaterKargo PromotionsArgo RolloutsLinkerd mTLSPrometheus + AlertManagerGrafanaGatusAlloy CollectorLoki LogsTempo Tracesntfy NotificationsGoldilocks VPAHPA AutoscalingKEDA ScalingVPA Right-sizingKRR AnalysisVelero BackupsVelero UISeaweedFS S3RabbitMQValkey CacheCrowdSec Threat IntelBeelzebub (Honeypot)Maddy SMTPBetterAuth + HonoResend EmailKnative ServingRybbit AnalyticsGO Feature FlagGrafana Faro (Web Vitals)Falco RuntimeFalcosidekickDefectDojoLoki Ruler (LogQL)LitmusChaosfail2ban (brute-force)Kanister (data-recovery drills)Skaffold Inner LoopFastlane (iOS + Android)
Under Review 0

All components reviewed and promoted.

Pending 0

Current infrastructure stack fully implemented and online.

How a Deploy Flows

CI/CD
Application path
git push GitHub
Argo Events webhook sensor
Pre-build scans Semgrep, TruffleHog, OSV
Buildah build + push image
Post-build scans Trivy, Syft, Grype
Cosign sign key + keyless (Fulcio)
SLSA attest provenance v1.0
Harbor signed digest
Kargo Warehouse new freight
Promote stages dev -> staging -> prod
Argo Rollouts canary delivery
Serving live traffic
Infrastructure path
PR validation (no apply)
IaC pull request GitHub
Argo Workflows infra-validate
tofu validate syntax + config
IaC scans Checkov, Trivy, Pluto, TFLint
Operator apply
merge to main reviewed
bin/ deploy operator runs tofu apply
Proxmox + Talos VMs provisioned
Cluster platform updated
GitOps sync (manifests)
ArgoCD GitOps reconcile
Manifests applied desired state

Nothing reaches a cluster by hand. Application images are signed and provenance-attested before a deployable tag exists, and Kargo gates prod on manual approval. Argo Workflows only validates infrastructure on PRs; the actual tofu apply runs from the deploy script, and ArgoCD reconciles the rendered manifests separately.

How Security Layers

Defense in depth
Identity & Access
Keycloak SSO / OIDC
oauth2-proxy ForwardAuth
Cloudflare edge proxy + WAF
OpenBao secrets vault
External Secrets vault sync
SOPS + age encrypted at rest
Network & Mesh
Linkerd mTLS mesh
Cilium default-deny + Hubble
WireGuard pod encryption
cert-manager TLS + trust-manager
Traefik TLS edge termination
Supply Chain & Admission
Kyverno admission policy
Cosign key + keyless signing
SLSA L3 build provenance
Trivy / Syft / Grype image + SBOM scan
Semgrep SAST
TruffleHog secret scan
OSV dependency vulns
Pluto deprecated APIs
Runtime
Falco syscall detection
Falcosidekick alert routing
CrowdSec threat intel + bouncer
fail2ban edge brute-force ban
Beelzebub honeypot
OWASP ZAP DAST on promotion
Aggregation & Response
DefectDojo findings + SLA
Loki Ruler LogQL alerting
ntfy notifications

Five layers, each independent. Identity and secrets gate access, the mesh encrypts and segments every hop, supply-chain gates stop unsigned or unattested images at admission, runtime sensors watch live workloads, and every signal lands in DefectDojo for triage on an SLA.

How Data Is Protected

Backup + restore
Velero manifests + CSI snapshots daily / weekly
CloudNativePG base backup + continuous WAL daily base
Longhorn block-level snapshots every 30 min
Kanister recovery-drill verification weekly
SeaweedFS S3 object storage
Restore drill-verified recovery
Longhorn snapshots: 30 minTier-2 daily: 7 daysWeekly + secrets: 30 daysContinuous WAL: point-in-time
Verification monitors -> Prometheus alerts
cnpg-witnessvelero-watchersentinel-freshnessdrill-result-exporter

Four independent sources back up to one S3 store. A monitor layer writes per-backup sentinels and tracks freshness, and Kanister exercises the full restore path on a schedule, so recovery is tested, not assumed.

Dashboards

21

Live Demos

13

RabbitMQ

Message Queue
Not checked
Publish
Message
Count
Consume
EpochCloud Demo 2026-07-28T01:19:15.701Z