Cloud Dependencies¶
Most of the platform is self-hosted, but a few key pieces deliberately live in the cloud:
| Service | Used for |
|---|---|
| 1Password | Password management, and the source of every secret (External Secrets, doco-cd, op inject) |
| Cloudflare | Public DNS, the Zero Trust tunnel, DNS-01 for certificates, and hosting the CRD schemas |
| GitHub | This repository, Actions CI, and GitHub Pages for these docs |
| Fastmail | |
| Pushover | Alert and app notifications |
| Backblaze B2 | Off-site S3 object storage for apps and backups, including the nightly copy of the Kopia repository |
These stay external to avoid three problems:
- Chicken-and-egg: dependencies that would prevent bootstrapping, for example secrets for the thing that serves secrets.
- Critical availability: services that are needed whether or not the cluster is up.
- The "hit by a bus" factor: email, passwords and photos must stay accessible to family and friends without anyone keeping a cluster alive.