Building a network with no trusted inside
3 min
Zero trust, from bare metal up, for a company that had none.
Kravos runs its own infrastructure. Not a managed cluster with a monthly bill attached, but actual machines that I set up and that I am responsible for when they stop.
From bare metal up
Ten or more services run in containers, orchestrated with Docker Compose and managed through Portainer. None of that is exotic, and the tooling was never the decision that mattered. Choosing to own the layer underneath it was.
No trusted inside
The network has no soft centre. Remote access goes through Tailscale and WireGuard, every host runs ufw, and AdGuard Home handles internal DNS so name resolution never leaves the network.
The term for this is zero trust. In practice it mostly means refusing to accept “it is behind the firewall” as a justification for anything, because there is no behind. Services authenticate their callers whether or not those callers are running on the same machine.
Configuring it was not the hard part. The hard part was that people had been working a particular way for years, and this made several of those ways stop working. Convenience you have had for a long time stops registering as convenience and starts feeling like something you are owed.
Grounding the models
A retrieval pipeline runs on the same infrastructure: Ollama serving models locally, Qdrant holding the vectors, n8n wiring the ingestion together. It exists so internal questions get answered from internal documents instead of from whatever the model happens to remember.
Running it locally was not a performance decision. Company knowledge does not leave the network, which is the same rule everything else here follows.
Knowing before somebody tells you
SonarQube runs static analysis against every pull request through the GitHub integration. Uptime Kuma watches the services and shouts into Discord and Slack when one stops answering.
Both are self-hosted, which means both are things I now have to keep running. Monitoring that needs its own monitoring is a real cost, and I would rather say so than pretend the setup is free.
More updates coming soon...