# Stribog > Engineering-sovereignty practice — infrastructure, Kubernetes, open-source tooling, sovereign AI, and audit-grade compliance for technical organizations. Operating since 2013. Stribog partners with CTOs, VPs of Engineering, and technology executives to build production infrastructure that teams own and operate after the engagement. The practice rests on five pillars: sovereignty (owning the systems you depend on), open source as method (a discipline of review and independence, not a license checkbox), audit-grade rigor (compliance built in as a byproduct of operations), optionality (anti-lock-in architecture with exit ramps designed in), and the long game (systems built to outlast the tools and vendors that will change around them). The practice has operated since 2013. Stribog does not sell SaaS. Every engagement ends with the client's team owning and operating what was built — runbooks, architecture decision records, and GitOps repositories are deliverables, not retention mechanisms. Contact: hello@stribog.com ## Pages - [Thesis](https://stribog.com/thesis) — The intellectual spine of the practice: why hyperscaler concentration, AI data liability, and intensifying audit regimes make owned infrastructure the rational choice. - [Data Sovereignty](https://stribog.com/sovereignty) — The pillar page: data residency vs data sovereignty vs digital sovereignty, one geo-agnostic engineering method, and regulation-by-region lenses for India (DPDP Act, RBI localization, CERT-In), the EU (AI Act, GDPR/Schrems II, NIS2, DORA), and the US (HIPAA, SOC 2, FedRAMP). - [Capabilities](https://stribog.com/capabilities) — Four practice domains: Infrastructure & Platform, Open-Source & Tooling Strategy, Sovereign AI, Audit & Compliance Engineering. - [Cloud Repatriation](https://stribog.com/capabilities/cloud-repatriation) — Service deep-dive: moving Kubernetes workloads off hyperscalers to owned bare-metal or colo infrastructure. - [Sovereign AI](https://stribog.com/capabilities/sovereign-ai) — Service deep-dive: private inference on owned GPUs with vLLM, RAG pipelines, and governed agents — data stays in your perimeter. - [Kubernetes Security Posture Management (KSPM)](https://stribog.com/capabilities/kspm) — Service deep-dive: continuous posture monitoring, policy-as-code, and audit-ready compliance evidence with KubeVigil and Kyverno. - [Selected Work](https://stribog.com/work) — Anonymized case studies across regulated fintech, healthcare SaaS, and logistics platforms. - [Open Source](https://stribog.com/open-source) — Open source as method: the practice of inspectability, supply-chain discipline, and earned independence. Featuring KubeVigil. - [Writing](https://stribog.com/blog) — Deeply technical articles on Kubernetes security, Talos Linux, cloud repatriation, self-hosted AI, OSS supply-chain integrity, and audit-grade infrastructure. RSS: https://stribog.com/blog/feed.xml - [Engagement](https://stribog.com/engagement) — How Stribog engages: executive briefing, sovereignty assessment, phased roadmap and execution. - [Book a briefing](https://stribog.com/book) — book a 30-minute executive briefing (self-hosted Cal.com scheduler; Mon–Fri 09:00–13:00 IST). - [Contact](https://stribog.com/contact) — hello@stribog.com - [Colophon](https://stribog.com/colophon) — How the site is built and why. - [Privacy](https://stribog.com/privacy) — No cookies, no trackers, no analytics. - [Accessibility](https://stribog.com/accessibility) — WCAG 2.2 AA commitment and contact for accessibility issues. ## Case Studies (anonymized — no real client names) - [A regulated payments platform](https://stribog.com/work/regulated-fintech-cloud-exit) — Cloud exit to owned Kubernetes on Talos: eliminated single-hyperscaler concentration, addressed data-residency requirements, produced audit-ready compliance evidence. - [A regulated healthcare SaaS](https://stribog.com/work/healthcare-saas-sovereign-ai) — Sovereign AI inference: deployed vLLM on owned GPUs with private RAG, so PHI never transited a third-party API. Legal and security signed off in under six weeks. - [A Series-B logistics platform](https://stribog.com/work/logistics-platform-onprem-k8s) — On-premises Kubernetes on Talos and bare metal; replaced SaaS tooling sprawl (CI/CD, registry, identity, monitoring) with self-hosted OSS stack. Team independently operating within six months of handoff. - [A mid-market European insurance SaaS](https://stribog.com/work/insurance-saas-continuous-compliance) — Continuous compliance: KubeVigil + Kyverno posture management, CIS-benchmarked Talos, hash-chained audit logs; recurring ISO 27001 findings closed, evidence produced in hours not weeks. ## Tools (free, interactive, privacy-preserving) Interactive instruments that run entirely in the visitor's browser — no sign-up, no data transmitted. - [Cloud Repatriation TCO Calculator](https://stribog.com/tools/tco-calculator) — A directional three-year cost model comparing hyperscaler run-rate against self-operated infrastructure, with break-even, net-savings range, and every assumption exposed. Explicitly a thinking tool, not a quote. - [Sovereignty Readiness Assessment](https://stribog.com/tools/sovereignty-assessment) — A ten-question self-assessment scoring engineering sovereignty across five pillars (ownership, open source, audit rigor, optionality, the long game), with a per-pillar profile and where to focus. Scored locally; nothing is sent. ## Writing (all 49 articles, newest first) - [DORA Compliance Without Concentrating Your Risk: The Self-Hosted Case](https://stribog.com/blog/dora-compliance-operational-resilience-self-hosted-ict-third-party-risk) — DORA's five pillars mapped to self-hosted controls — ICT third-party risk, the 4h/72h incident clock, resilience testing, and exits you have rehearsed. (2026-07-29, Compliance) - [WebAssembly on Kubernetes: SpinKube, runwasi and the Portable Runtime](https://stribog.com/blog/spinkube-runwasi-wasmcloud-webassembly-sovereign-runtime-kubernetes) — Running WebAssembly on Kubernetes: the runwasi shim, SpinKube and wasmCloud, the honest limits, and why Wasm is the exit ramp from proprietary serverless. (2026-07-28, Runtime) - [Self-Hosting the Mesh: Headscale and NetBird as a Tailscale Exit](https://stribog.com/blog/headscale-netbird-self-hosted-tailscale-alternative-mesh-vpn) — Replacing the Tailscale coordination plane with self-hosted Headscale or NetBird: Kubernetes subnet routers, owned exit nodes, failure modes and the exit ramp. (2026-07-27, Networking) - [Kubernetes Block Storage You Control: Rook/Ceph, Longhorn, OpenEBS](https://stribog.com/blog/rook-ceph-longhorn-openebs-sovereign-block-storage-kubernetes) — Choosing a self-hosted block storage layer for Kubernetes CSI: Rook/Ceph RBD vs Longhorn vs OpenEBS Mayastor, with hardware numbers and the exit ramp. (2026-07-26, Storage) - [On-Prem RAG: Qdrant vs pgvector for a Sovereign Retrieval Tier](https://stribog.com/blog/qdrant-pgvector-self-hosted-vector-database-on-prem-rag) — Choosing and operating a self-hosted vector database for on-premises RAG: Qdrant vs pgvector vs Weaviate, HNSW tuning, quantization, and the exit ramp. (2026-07-25, Sovereign AI) - [Managing a Disconnected Fleet: K3s and Rancher Fleet at the Far Edge](https://stribog.com/blog/k3s-rancher-fleet-edge-kubernetes-disconnected-air-gapped) — Operate K3s edge clusters over intermittent WAN with pull-based Rancher Fleet GitOps, air-gapped image delivery, per-site overlays, and offline reconciliation. (2026-07-25, Edge) - [Self-Hosted Chaos Engineering as an Audit-Grade Compliance Control](https://stribog.com/blog/litmuschaos-chaos-mesh-resilience-verification-audit-evidence) — Structure LitmusChaos and Chaos Mesh fault injection as signed, ID-tagged artifacts that satisfy scenario-based operational resilience testing mandates. (2026-07-24, Resilience) - [Two-Tier Autoscaling on Bare Metal: KEDA Pods, Descheduler Bin-Packing](https://stribog.com/blog/keda-descheduler-bare-metal-event-driven-autoscaling-scale-to-zero) — KEDA event-driven autoscaling on Kubernetes scales pods to zero on queue depth; the descheduler bin-packs survivors to reclaim bare-metal nodes — no Karpenter. (2026-07-23, Scaling) - [Bare-Metal Ingress, Owned: MetalLB, kube-vip, and Gateway API](https://stribog.com/blog/metallb-kube-vip-gateway-api-bare-metal-ingress-cloudflare-exit) — Run a Kubernetes bare-metal load balancer without a cloud provider — MetalLB BGP, kube-vip control-plane VIP, and Envoy Gateway API, exiting Cloudflare's proxy. (2026-07-22, Networking) - [Kubernetes Cost Allocation: OpenCost Namespace Showback to Chargeback](https://stribog.com/blog/opencost-namespace-showback-chargeback-kubernetes-finops) — Namespace-level Kubernetes cost allocation with OpenCost: run showback and graduate to chargeback on bare-metal clusters where no cloud billing API exists. (2026-07-21, FinOps) - [Your Own ACME: Sovereign Internal PKI with step-ca and cert-manager](https://stribog.com/blog/step-ca-cert-manager-sovereign-internal-pki-private-acme) — Run a self-hosted certificate authority for internal Kubernetes names: step-ca as a private ACME server, cert-manager as the client, no CT-log leakage. (2026-07-20, Security) - [Self-Managed Kafka: Strimzi, Redpanda, NATS Off Confluent Cloud](https://stribog.com/blog/strimzi-redpanda-nats-self-managed-event-backbone-confluent-exit) — A production ops playbook for a self-owned event backbone: Strimzi's Kafka lifecycle on Kubernetes, Redpanda's single binary, and NATS — off Confluent Cloud. (2026-07-19, Streaming) - [Sharing the GPU: MIG vs Time-Slicing for Mixed Inference on Kubernetes](https://stribog.com/blog/nvidia-gpu-operator-mig-time-slicing-kubernetes-sharing) — MIG gives hard, isolated GPU partitions; time-slicing shares one context with none; DRA makes fractional GPU scheduling a first-class Kubernetes primitive. (2026-07-18, Sovereign AI) - [The Sovereign AI Gateway: LiteLLM, MCP, and Agent Data Residency](https://stribog.com/blog/litellm-self-hosted-mcp-model-gateway-ai-data-residency) — Model residency is not agent residency. A self-hosted MCP gateway and LiteLLM proxy keep tool-calls, keys, and PII inside your own network boundary. (2026-07-17, Sovereign AI) - [Schrems II, Six Years On: EU Data on US Clouds Is Still Unsafe](https://stribog.com/blog/schrems-ii-data-transfer-eu-data-us-cloud-self-hosted) — Schrems II turns six today. The EU-US Data Privacy Framework is under fresh challenge, and CLOUD Act reach means US-parent clouds remain a live transfer risk. (2026-07-16, Compliance) - [European Sovereign Cloud: Build, Buy, or Self-Host Framework](https://stribog.com/blog/european-sovereign-cloud-build-vs-buy-self-hosted) — European sovereign cloud is three options, not one: hyperscaler region, EU-incorporated provider, or self-host — scored on control, jurisdiction, lock-in, cost. (2026-07-15, Sovereignty) - [Digital Sovereignty: From Policy Slogan to Testable Architecture](https://stribog.com/blog/digital-sovereignty-engineering-architecture-cornerstone) — Digital sovereignty is not a slogan but five engineering control layers — compute, data, keys, identity, supply chain — each mapped to a testable control. (2026-07-14, Sovereignty) - [Gaia-X in Practice: Federation, Labels, and the Sovereignty Gap](https://stribog.com/blog/gaia-x-sovereign-cloud-europe-self-hosted-reality) — Gaia-X gives European cloud services a machine-verifiable trust layer — but not control-plane custody, key ownership, or immunity from foreign jurisdiction. (2026-07-09, Sovereignty) - [DPDP Compliance in Practice: Consent, Erasure, and Breach Workflows](https://stribog.com/blog/dpdp-compliance-consent-data-principal-rights-breach-workflow) — Operationalizing the DPDPA: a consent flow, data-principal access and verifiable erasure across your stores, and a breach workflow on the DPB's clock. (2026-07-08, Compliance) - [CERT-In's 6-Hour Rule: On-Prem Logging for India's Reporting Mandate](https://stribog.com/blog/cert-in-directions-6-hour-incident-reporting-180-day-log-retention) — CERT-In's 2022 Directions as engineering constraints: six-hour incident reporting, 180 days of logs held inside India, and a synchronized NIC/NPL time source. (2026-07-07, Compliance) - [The DPDP Act for Engineers: Data Residency Architecture, Not Policy](https://stribog.com/blog/dpdp-act-2023-data-residency-self-hosted-architecture-india) — The engineering read of India's DPDP Act 2023: data fiduciary duties, cross-border transfer, and the Significant Data Fiduciary tier as infrastructure. (2026-07-06, Compliance) - [The EU AI Act for High-Risk AI Systems: An On-Prem Compliance Path](https://stribog.com/blog/eu-ai-act-high-risk-ai-systems-onprem-inference-compliance) — The EU AI Act's high-risk obligations — Article 12 logging, conformity assessment, post-market monitoring — mapped onto on-prem inference infrastructure. (2026-07-05, Compliance) - [Provisioning Bare Metal: Metal3, Tinkerbell, and Sidero Omni Compared](https://stribog.com/blog/metal3-tinkerbell-sidero-omni-bare-metal-kubernetes-provisioning) — Bare metal Kubernetes provisioning compared: Tinkerbell's workflow engine, Metal3's Cluster API/Ironic path, and Sidero Omni's post-CAPI machine model. (2026-07-04, Bare Metal) - [Hard Multi-Tenancy with vCluster: Retire 30 Clusters, Keep Isolation](https://stribog.com/blog/vcluster-hard-multi-tenancy-kubernetes-cluster-consolidation) — Kubernetes hard multi-tenancy without cluster sprawl: when namespaces suffice, where Capsule and vCluster fit, and how node isolation makes tenancy real. (2026-07-03, Multi-Tenancy) - [Sovereign Lakehouse: ClickHouse, Iceberg, and DuckLake Past Snowflake](https://stribog.com/blog/clickhouse-iceberg-ducklake-sovereign-analytics-snowflake-exit) — Self-hosted ClickHouse vs Snowflake: build a sovereign lakehouse with ClickHouse, Apache Iceberg, and DuckLake for teams past the warehouse cost ceiling. (2026-07-02, Data) - [Sizing the Iron: GPU and VRAM Planning for Self-Hosted LLM Inference](https://stribog.com/blog/self-hosted-llm-hardware-gpu-vram-sizing-sovereign-inference-capacity) — Self-hosted LLM hardware sizing: VRAM math per model size and quantization, consumer vs datacenter GPU economics, and throughput-versus-latency planning. (2026-07-01, Sovereign AI) - [GitHub Self-Hosted Runners on Kubernetes: Owning CI Compute with ARC](https://stribog.com/blog/self-hosted-github-actions-runners-kubernetes-arc-sovereign-ci-compute) — GitHub self-hosted runners on Kubernetes with actions-runner-controller: ephemeral, autoscaling, network-isolated CI compute you own, without leaving GitHub. (2026-06-30, CI/CD) - [Self-Hosted Coding Assistants: Continue, Tabby, and vLLM On-Prem](https://stribog.com/blog/self-hosted-coding-llm-continue-tabby-vllm-sovereign-developer-assistant) — Run a self-hosted LLM for coding: Continue and Tabby wired to an open-weight code model served on vLLM, so your proprietary source code never reaches a vendor. (2026-06-29, Sovereign AI) - [HIPAA-Compliant LLM: On-Prem PHI Inference Without the BAA Gap](https://stribog.com/blog/hipaa-compliant-self-hosted-llm-phi-on-prem-inference-baa) — How a covered entity runs a HIPAA-compliant LLM on-premises: PHI never leaves your perimeter, no third-party BAA to manage, every inference logged for audit. (2026-06-28, Sovereign AI) - [Catching the Breach in Kernel Time: Falco and Tetragon](https://stribog.com/blog/falco-tetragon-kubernetes-runtime-threat-detection-ebpf) — Kubernetes runtime threat detection with eBPF: Falco for broad MITRE ATT&CK detection, Tetragon for in-kernel enforcement, alerts piped to a self-hosted SIEM. (2026-06-27, Security) - [Self-Hosted SSO in 2026: Keycloak vs Authentik vs Zitadel After Okta](https://stribog.com/blog/keycloak-authentik-zitadel-self-hosted-identity-okta-exit) — Own your identity plane: a trust-model decision matrix comparing Keycloak, Authentik, and Zitadel as self-hosted SSO — the engineering exit from Okta. (2026-06-26, Identity) - [Own Your Pipeline: Forgejo, Woodpecker and Zot Off GitHub Actions](https://stribog.com/blog/forgejo-woodpecker-zot-sovereign-ci-cd-github-actions-exit) — A self-hosted CI/CD alternative to GitHub Actions: Forgejo for git, Woodpecker for pipelines, Zot for OCI artifacts — the delivery chain as owned infra. (2026-06-25, CI/CD) - [Zero-Trust Workload Identity on Kubernetes: SPIFFE/SPIRE and SVIDs](https://stribog.com/blog/spiffe-spire-zero-trust-workload-identity-kubernetes-mtls) — SPIFFE/SPIRE issues cryptographic, attested workload identity — X.509 and JWT SVIDs — so Kubernetes services get mutual TLS and zero long-lived static secrets. (2026-06-24, Security) - [PostgreSQL on Kubernetes with CloudNativePG: A Sovereign Data Layer](https://stribog.com/blog/postgres-on-kubernetes-cloudnativepg-sovereign-stateful-data) — Production PostgreSQL on Kubernetes with CloudNativePG: streaming-replication HA, WAL archiving and PITR to your own object store, and a clean exit from RDS. (2026-06-24, Kubernetes) - [Confidential Computing on Kubernetes: Hardware TEEs and Attestation](https://stribog.com/blog/confidential-computing-kubernetes-remote-attestation-tee) — Confidential computing on Kubernetes: AMD SEV-SNP, Intel TDX and Confidential Containers protect data-in-use, with remote attestation gating key release. (2026-06-24, Sovereignty) - [Audit-Grade Kubernetes Disaster Recovery: Velero, etcd, RPO/RTO](https://stribog.com/blog/kubernetes-disaster-recovery-backup-velero-etcd-rpo-rto) — Kubernetes disaster recovery you can evidence: Velero and CSI data-mover for volumes, etcd snapshots for cluster state, and restore drills that prove RPO/RTO. (2026-06-24, Resilience) - [After MinIO Goes Dark: Rook/Ceph, SeaweedFS or Garage for Sovereign S3](https://stribog.com/blog/minio-exit-rook-ceph-seaweedfs-garage-sovereign-object-storage) — After MinIO archived its open-source edition: a framework for choosing self-hosted S3-compatible object storage by tenancy, throughput, and jurisdiction. (2026-06-24, Storage) - [EU AI Act, NIS2 and DORA: Regulated Workloads Move Self-Hosted](https://stribog.com/blog/nis2-dora-eu-ai-act-self-hosted-kubernetes-compliance) — The EU AI Act, NIS2, and DORA are one architecture constraint, not three checklists — the technical evidence for why hyperscaler SaaS cannot satisfy them. (2026-06-23, Compliance) - [Talos Linux vs. the World: The Security Case for an Immutable OS](https://stribog.com/blog/talos-linux-immutable-kubernetes-os-security-case) — Talos Linux vs Ubuntu for Kubernetes security: why an immutable, API-only node carries 40–50x fewer critical CVEs, and why hardening Ubuntu cannot close it. (2026-06-18, Infrastructure) - [Progressive Delivery with Argo Rollouts: Evidence-Gated Canary](https://stribog.com/blog/progressive-delivery-argo-rollouts-canary-blue-green-kubernetes) — Progressive delivery on Kubernetes with Argo Rollouts: metric-driven AnalysisRuns, automatic rollback, Gateway API traffic shaping, audit-grade promotion. (2026-06-18, Progressive Delivery) - [Own Your Telemetry: Self-Hosted Observability on Kubernetes](https://stribog.com/blog/self-hosted-observability-opentelemetry-prometheus-grafana-loki-kubernetes) — Self-hosted observability on Kubernetes: OpenTelemetry, Prometheus, Loki, Tempo and Grafana replacing Datadog — sovereign data, no per-GB ingestion bill. (2026-06-18, Observability) - [Cloud Repatriation Done Right: The Kubernetes Engineering Playbook](https://stribog.com/blog/cloud-repatriation-kubernetes-on-premises-engineering-playbook) — A no-hype cloud repatriation playbook for Kubernetes: dependency audit, stateful workload triage, a real TCO model, and why most attempts fail inside 18 months. (2026-06-09, Cloud Exit) - [Self-Hosted AI on Kubernetes: Production vLLM, Your Data Stays](https://stribog.com/blog/self-hosted-llm-kubernetes-vllm-production-deployment) — How to run self-hosted LLM inference on Kubernetes with vLLM at production grade: GPU sizing, cost crossover analysis, audit logging for EU AI Act compliance. (2026-06-02, Sovereign AI) - [OSS Supply Chain Security: SBOM, Sigstore, and Admission Control](https://stribog.com/blog/oss-supply-chain-security-sbom-sigstore-slsa-kubernetes) — Kubernetes supply chain security end to end: SBOMs with Syft, SLSA L3 provenance, Sigstore keyless signing, and Kyverno admission control that actually blocks. (2026-05-28, Supply Chain) - [Policy as Code at Cluster Scale: A Kyverno Governance Layer](https://stribog.com/blog/policy-as-code-kyverno-kubernetes-governance-scale) — Policy as code on Kubernetes: the Kyverno lifecycle — versioning, testing, exceptions, reporting — is 80% of the work. How to build governance that scales. (2026-05-19, Governance) - [Multi-Cluster GitOps at 100+ Clusters: Argo CD's Limits vs Flux](https://stribog.com/blog/multi-cluster-gitops-argocd-flux-scaling-100-clusters) — Multi-cluster GitOps past 20 clusters: where Argo CD's hub saturates, where Flux shifts that cost onto your Git origin, and the load model to find your ceiling. (2026-05-12, GitOps) - [Kubernetes Secrets Management Is Still Broken: ESO Over Vault](https://stribog.com/blog/kubernetes-secrets-management-external-secrets-operator-vault) — Vault is the right backend, not the right interface. ESO + dynamic credentials + etcd encryption eliminate long-lived secrets from Kubernetes clusters. (2026-05-05, Security) - [eBPF and Cilium Are Eating the Service Mesh: Zero Trust, No Sidecars](https://stribog.com/blog/cilium-ebpf-kubernetes-zero-trust-networking-service-mesh) — Cilium and eBPF for zero-trust Kubernetes networking: identity-based policy, WireGuard node encryption and Hubble visibility, without the sidecar tax. (2026-04-28, Networking) - [The Platform Engineering Trap: Golden Paths Need Enforcement](https://stribog.com/blog/platform-engineering-golden-paths-policy-enforcement-kubernetes) — Platform engineering on Kubernetes: golden paths without admission enforcement are only suggestions. How to make the golden path the only path that works. (2026-04-21, Platform Engineering) ## Full content The complete text of every article is available at https://stribog.com/llms-full.txt