# Stribog > Engineering-sovereignty practice — infrastructure, Kubernetes, open-source tooling, sovereign AI, and audit-grade compliance for technical organizations. Operating since 2013. Stribog partners with CTOs, VPs of Engineering, and technology executives to build production infrastructure that teams own and operate after the engagement. The practice rests on five pillars: sovereignty (owning the systems you depend on), open source as method (a discipline of review and independence, not a license checkbox), audit-grade rigor (compliance built in as a byproduct of operations), optionality (anti-lock-in architecture with exit ramps designed in), and the long game (systems built to outlast the tools and vendors that will change around them). The practice has operated since 2013. Stribog does not sell SaaS. Every engagement ends with the client's team owning and operating what was built — runbooks, architecture decision records, and GitOps repositories are deliverables, not retention mechanisms. Contact: hello@stribog.com ## Pages - [Thesis](https://stribog.com/thesis) — The intellectual spine of the practice: why hyperscaler concentration, AI data liability, and intensifying audit regimes make owned infrastructure the rational choice. - [Data Sovereignty](https://stribog.com/sovereignty) — The pillar page: data residency vs data sovereignty vs digital sovereignty, one geo-agnostic engineering method, and regulation-by-region lenses for India (DPDP Act, RBI localization, CERT-In), the EU (AI Act, GDPR/Schrems II, NIS2, DORA), and the US (HIPAA, SOC 2, FedRAMP). - [Capabilities](https://stribog.com/capabilities) — Four practice domains: Infrastructure & Platform, Open-Source & Tooling Strategy, Sovereign AI, Audit & Compliance Engineering. - [Cloud Repatriation](https://stribog.com/capabilities/cloud-repatriation) — Service deep-dive: moving Kubernetes workloads off hyperscalers to owned bare-metal or colo infrastructure. - [Sovereign AI](https://stribog.com/capabilities/sovereign-ai) — Service deep-dive: private inference on owned GPUs with vLLM, RAG pipelines, and governed agents — data stays in your perimeter. - [Kubernetes Security Posture Management (KSPM)](https://stribog.com/capabilities/kspm) — Service deep-dive: continuous posture monitoring, policy-as-code, and audit-ready compliance evidence with KubeVigil and Kyverno. - [How We Work](https://stribog.com/work) — Constructed scenarios, not client work: how we approach cloud exit, sovereign AI, and self-operated Kubernetes. Real client work is under NDA and is not described. - [Open Source](https://stribog.com/open-source) — Open source as method: the practice of inspectability, supply-chain discipline, and earned independence. Featuring KubeVigil. - [Writing](https://stribog.com/blog) — Deeply technical articles on Kubernetes security, Talos Linux, cloud repatriation, self-hosted AI, OSS supply-chain integrity, and audit-grade infrastructure. RSS: https://stribog.com/blog/feed.xml - [Engagement](https://stribog.com/engagement) — How Stribog engages: executive briefing, sovereignty assessment, phased roadmap and execution. - [Book a briefing](https://stribog.com/book) — book a 30-minute executive briefing (self-hosted Cal.com scheduler; Mon–Fri 09:00–13:00 IST). - [Contact](https://stribog.com/contact) — hello@stribog.com - [Colophon](https://stribog.com/colophon) — How the site is built and why. - [Privacy](https://stribog.com/privacy) — No cookies, no trackers, no analytics. - [Accessibility](https://stribog.com/accessibility) — WCAG 2.2 AA commitment and contact for accessibility issues. ## Worked Scenarios (constructed illustrations — not client engagements) - [A regulated payments platform](https://stribog.com/work/regulated-fintech-cloud-exit) — Cloud exit to owned Kubernetes on Talos: eliminated single-hyperscaler concentration, addressed data-residency requirements, produced audit-ready compliance evidence. - [A regulated healthcare SaaS](https://stribog.com/work/healthcare-saas-sovereign-ai) — Sovereign AI inference: deployed vLLM on owned GPUs with private RAG, so PHI never transited a third-party API. Legal and security signed off in under six weeks. - [A Series-B logistics platform](https://stribog.com/work/logistics-platform-onprem-k8s) — On-premises Kubernetes on Talos and bare metal; replaced SaaS tooling sprawl (CI/CD, registry, identity, monitoring) with self-hosted OSS stack. Team independently operating within six months of handoff. - [A mid-market European insurance SaaS](https://stribog.com/work/insurance-saas-continuous-compliance) — Continuous compliance: KubeVigil + Kyverno posture management, CIS-benchmarked Talos, hash-chained audit logs; recurring ISO 27001 findings closed, evidence produced in hours not weeks. ## Tools (free, interactive, privacy-preserving) Interactive instruments that run entirely in the visitor's browser — no sign-up, no data transmitted. - [Cloud Repatriation TCO Calculator](https://stribog.com/tools/tco-calculator) — A directional three-year cost model comparing hyperscaler run-rate against self-operated infrastructure, with break-even, net-savings range, and every assumption exposed. Explicitly a thinking tool, not a quote. - [Sovereignty Readiness Assessment](https://stribog.com/tools/sovereignty-assessment) — A ten-question self-assessment scoring engineering sovereignty across five pillars (ownership, open source, audit rigor, optionality, the long game), with a per-pillar profile and where to focus. Scored locally; nothing is sent. ## Writing (all 93 articles, newest first) - [ISO/IEC 42001: Stage 1, Stage 2 and the Recognition Gap](https://stribog.com/blog/iso-iec-42001-certification-audit-self-hosted-inference) — ISO/IEC 42001 certification is a multi-year audit programme, not an event — and the global accreditation MRA scope table still has no 42001 row. (2026-09-05, Compliance) - [Secure by Design Is Now a Procurement Question](https://stribog.com/blog/secure-by-design-cisa-pledge-what-it-asks-of-operators) — Secure by Design is a voluntary pledge CISA never verifies — yet its goals reach you as buyer questions. What each one demands, and the evidence answering it. (2026-09-04, Supply Chain) - [The Data Processing Agreement Is an Architecture Decision](https://stribog.com/blog/data-processing-agreement-article-28-self-hosted-subprocessor) — A data processing agreement allocates obligations your stack must then meet: AWS and Google resolve the right to object into leaving, not refusing. (2026-09-03, Compliance) - [OpenSearch vs Elasticsearch: Benchmarks, Drift, Licence](https://stribog.com/blog/opensearch-elasticsearch-licence-fork-migration-self-hosted) — OpenSearch vs Elasticsearch: both ship Lucene 10.5, the vendor benchmarks disagree, and Elastic's AGPL covers the source, not the releases you actually run. (2026-09-02, Data) - [PCI DSS Audit Scope: An Evidence Problem, Not a Network One](https://stribog.com/blog/pci-dss-4-0-1-audit-scope-cardholder-data-environment-evidence) — A PCI DSS compliance audit validates a scope you documented yourself. What the ROC template asks for, who picks SAQ D, and where tokenisation truly helps. (2026-09-01, Compliance) - [Air-Gapped Patching with Katello: Mirrors and Evidence](https://stribog.com/blog/air-gapped-patching-os-package-mirrors-pulp-katello-sovereign-updates) — Katello mirrors move packages across the air gap. Proving the patch SLA is the harder half, and Debian and Ubuntu hosts need their own OVAL feeds. (2026-08-31, Operations) - [On-Premise AI: The Decision Order for the Whole Stack](https://stribog.com/blog/on-premise-ai-infrastructure-decision-guide-sovereign-stack) — On premise AI fails on sequencing, not technology. The decision order for the whole stack: workload contract, silicon, serving, partitioning, gateway. (2026-08-30, Sovereign AI) - [Third-Party Risk When One Vendor Runs Your Whole Platform](https://stribog.com/blog/third-party-risk-management-concentration-cloud-exit-evidence) — Third party risk management scores control maturity, and the vendor running everything wins on it. DORA template B_07.01 scores substitutability instead. (2026-08-29, Sovereignty) - [TISAX ISA2027 for Suppliers Who Host Their Own Systems](https://stribog.com/blog/tisax-assessment-automotive-supply-chain-self-hosted-evidence) — TISAX and the VDA ISA2027 catalogue define an external IT service as processing outside the audit scope. What that boundary means when you self-host. (2026-08-28, Compliance) - [KubeEdge Device Twins and the Industrial Data Plane](https://stribog.com/blog/kubeedge-far-edge-industrial-iot-kubernetes-device-twin-sovereignty) — How KubeEdge models devices as Kubernetes CRDs, why DMI lets telemetry stay on site, and where the twin's offline guarantees actually stop. (2026-08-27, Edge) - [Workflow Orchestration You Host: Temporal vs Airflow 3](https://stribog.com/blog/self-hosted-workflow-orchestration-temporal-airflow-sovereign-scheduling) — Workflow orchestration you run yourself is a state question, not a geography one — what Temporal's Event History and Airflow 3's metadata database really hold. (2026-08-26, Delivery) - [NIST CSF 2.0 Govern: A Profile for Infrastructure You Own](https://stribog.com/blog/nist-csf-2-0-govern-function-self-hosted-infrastructure) — NIST CSF 2.0 moves supply chain into Govern as GV.SC — ten outcomes, up from five. Building a Current and Target Profile for an estate you run yourself. (2026-08-25, Compliance) - [Leaving VMware Without Kubernetes: Proxmox VE in Production](https://stribog.com/blog/proxmox-ve-vmware-exit-without-kubernetes-cluster-ha-backup) — Proxmox VE as a VMware exit that keeps the VM as the unit: corosync quorum, the one-minute self-fence, Ceph or ZFS replication, and PBS retention. (2026-08-24, Infrastructure) - [NIST SP 800-53 on Kubernetes You Own: AC, AU, CM, SC, SI](https://stribog.com/blog/nist-800-53-control-mapping-self-hosted-kubernetes-evidence) — NIST SP 800-53 Release 5.2.0 on self-hosted Kubernetes: which controls stop being inheritable, which get cheaper to evidence, and an error in NIST's OSCAL. (2026-08-23, Compliance) - [vLLM vs Ollama: Run Both, and Draw the Concurrency Line](https://stribog.com/blog/vllm-vs-ollama-self-hosted-llm-serving-production-choice) — vLLM vs Ollama is not a bake-off: Ollama's memory scales with parallel slots, vLLM pages the KV cache. Where the line falls, and how to measure it yourself. (2026-08-22, Sovereign AI) - [ISO 42001 for Self-Hosted Inference: Clause to Artefact](https://stribog.com/blog/iso-42001-ai-management-system-self-hosted-inference-evidence) — ISO/IEC 42001 clause titles that your inference stack can answer with artefacts — audit records, model signatures, telemetry — and where a certificate stops. (2026-08-21, Compliance) - [RBI and SEBI Cloud Rules: India's BFSI Data Boundary](https://stribog.com/blog/rbi-sebi-cloud-guidelines-bfsi-data-localisation-self-hosted-india) — RBI cloud guidelines demand supervisory access and a tested exit, not blanket residency. SEBI's residency duty splits by deployment model. Building for both. (2026-08-20, Compliance) - [OpenFeature Ports Your Code, Not Your Flag Data](https://stribog.com/blog/openfeature-flagsmith-unleash-self-hosted-feature-flags-runtime-control) — OpenFeature standardises the flag call, not the flag definitions. What actually moves when you swap self-hosted Flagsmith for Unleash, and what does not. (2026-08-19, Optionality) - [Kubernetes Audit Logs Into a SIEM You Operate: Wazuh](https://stribog.com/blog/kubernetes-audit-logs-siem-wazuh-pipeline-retention-jurisdiction) — An open source SIEM starts at the kube-apiserver audit log: write a policy that survives production volume, ship it to Wazuh, retain it in jurisdiction. (2026-08-18, Security) - [ElectricSQL, PowerSync, Automerge: Picking a Sync Engine](https://stribog.com/blog/electricsql-powersync-automerge-local-first-sync-engine-sovereign) — ElectricSQL syncs reads only, PowerSync owns the offline write queue, Automerge merges with no server authority. Pick the boundary, then self-host it. (2026-08-17, Local-First) - [Clusters as Cattle: Cluster API for Fleets on Owned Infra](https://stribog.com/blog/cluster-api-capi-declarative-cluster-lifecycle-fleet-self-hosted) — Cluster API v1.14 for self-managed fleets: the object model, why ClusterClass is still alpha, delete-first rollouts, and the failure modes that bite. (2026-08-16, Infrastructure) - [Default Deny, Actually: Auditing Kubernetes Network Policy](https://stribog.com/blog/network-policy-enforcement-audit-default-deny-kubernetes-segmentation) — Kubernetes network policy is asserted from manifests far more often than it is tested. Roll out default-deny safely, then prove enforcement with real traffic. (2026-08-15, Networking) - [Distroless Without a Vendor: Building Your Own Base Images](https://stribog.com/blog/sovereign-container-base-images-distroless-self-built-provenance) — Distroless base images you build yourself: apko and melange, reproducible builds, signed provenance, and the rebuild cadence that decides build versus buy. (2026-08-14, Supply Chain) - [Immutable Backups: Object Lock and Proving You Can Restore](https://stribog.com/blog/immutable-backups-object-lock-ransomware-recovery-sovereign-storage) — An immutable backup is not a bucket flag: S3 Object Lock on storage you run, the credential split that makes it real, and restore drills that leave evidence. (2026-08-13, Resilience) - [Pyroscope and eBPF: Profiling Without a Vendor Agent](https://stribog.com/blog/ebpf-observability-without-agents-continuous-profiling-sovereign) — Self-hosted continuous profiling with Pyroscope: the two collection paths, their real privilege cost, the kernel 5.10 floor, and what still needs code. (2026-08-12, Observability) - [CCPA Compliance: Deletion, Opt-Out, and the 45-Day Clock](https://stribog.com/blog/ccpa-cpra-consumer-privacy-deletion-architecture-self-hosted) — CCPA compliance as an engineering problem: honouring the GPC opt-out signal at the edge, deletion that survives a backup restore, and a clock you can evidence. (2026-08-11, Compliance) - [DevPod and Coder: Sovereign Dev Environments on Kubernetes](https://stribog.com/blog/devpod-coder-self-hosted-developer-environments-codespaces-exit) — DevPod upstream stopped cutting stable releases in March 2025. Build the self-hosted inner loop on devcontainer.json so the runtime stays replaceable. (2026-08-10, Platform Engineering) - [ITAR Compliance Is an Access Problem, Not a Cloud Region](https://stribog.com/blog/itar-export-controlled-workloads-us-person-access-enclave) — ITAR compliance turns on who obtains technical data, not where it sits. Why a sovereign cloud region cannot settle that, and how to build an enclave that does. (2026-08-09, Compliance) - [Trusted Time: Chrony, PTP, and Logs That Hold Up in Audit](https://stribog.com/blog/ntp-ptp-time-synchronisation-audit-evidence-sovereign-infrastructure) — CERT-In and EU MiFIR both mandate synchronised clocks. Run traceable time with chrony, PTP and a stratum-1 you own — then prove the error bound afterwards. (2026-08-08, Operations) - [AMD ROCm as a Second Source for GPU Inference](https://stribog.com/blog/amd-rocm-gpu-alternative-nvidia-dependency-sovereign-ai-compute) — What actually runs on AMD ROCm today: Instinct partitioning, the amdgpu driver line, vLLM's documented gaps, and keeping the GPU choice reversible. (2026-08-07, Sovereign AI) - [QLoRA Infrastructure: Fine-Tuning You Actually Own](https://stribog.com/blog/qlora-fine-tuning-infrastructure-self-hosted-sovereign-model-customization) — QLoRA on your own GPUs: quota-admitted training Jobs, adapters as registry artifacts, multi-LoRA vLLM serving, and the EU AI Act compute arithmetic. (2026-08-06, Sovereign AI) - [Cloudflare Email Obfuscation Breaks Next.js Hydration (#418)](https://stribog.com/blog/cloudflare-email-obfuscation-react-hydration-error-418) — Cloudflare rewrites email addresses at the edge, after Next.js has rendered. React hydrates against text it never produced and throws #418 on every page. (2026-08-06, Operations) - [KubeVirt: The VMware Exit for VMs You Cannot Containerise](https://stribog.com/blog/kubevirt-vm-workloads-kubernetes-vmware-exit-sovereign-virtualization) — KubeVirt runs the VMs you cannot containerise on your own metal. Live migration, RWX disks, CPU pinning, and what it still does worse than vSphere. (2026-08-05, Infrastructure) - [Vendor Lock-In in the Cloud: Pricing Your Exit as a Number](https://stribog.com/blog/vendor-lock-in-exit-cost-modelling-data-gravity-architecture) — Cloud vendor lock-in is a liability you can compute: egress bytes times price, proprietary API surface, data gravity, retraining. Here is the ledger. (2026-08-04, Optionality) - [OpenBao vs Vault: Three Gates Before You Move a Secret](https://stribog.com/blog/openbao-vault-license-exit-sovereign-secrets-migration) — The documented Vault-to-OpenBao path stops at Vault 1.14.x, Raft storage and Shamir unseal. Three gates decide which route your cluster is actually on. (2026-08-04, Security) - [OpenTofu Migration: The Registry Is the Hard Part](https://stribog.com/blog/opentofu-terraform-licence-migration-sovereign-infrastructure-as-code) — Migrating to OpenTofu past the licence debate: how state provider addresses translate, why lock-file hashes do not carry over, and how to mirror the registry. (2026-08-03, Optionality) - [The Cyber Resilience Act Reaches Your Build Pipeline](https://stribog.com/blog/eu-cyber-resilience-act-cra-open-source-obligations-self-hosted) — Cyber Resilience Act reporting starts 11 September 2026. Map manufacturer and open-source steward obligations onto a self-hosted build pipeline. (2026-08-02, Compliance) - [GDPR Article 32: Technical Measures an Auditor Can Verify](https://stribog.com/blog/gdpr-article-32-technical-measures-self-hosted-infrastructure) — GDPR compliance at the infrastructure layer: encryption, pseudonymisation, provable restore, and erasure across backups, logs and vector stores. (2026-08-01, Compliance) - [MeitY Empanelment: Architecting for Indian Government Cloud](https://stribog.com/blog/meity-empanelment-government-cloud-india-sovereign-hosting-requirements) — MeitY empanelment certifies the provider, not your product. Workload classification, STQC audit access and exit clauses, mapped to real architecture. (2026-07-31, Compliance) - [Own the Registry: Harbor and Zot for Air-Gapped Images](https://stribog.com/blog/harbor-zot-self-hosted-container-registry-supply-chain-replication) — A self-hosted container registry you actually operate: Harbor versus zot, proxy cache and replication for air-gapped delivery, and the disk arithmetic. (2026-07-30, Supply Chain) - [Kubernetes Upgrade Debt: Skew, Dead APIs, Safe Paths](https://stribog.com/blog/kubernetes-version-upgrade-deprecated-api-skew-migration-playbook) — A Kubernetes version upgrade strategy: skew windows as scheduling constraints, deprecated API scans that hold up, sequential minors, and exit ramps. (2026-07-30, Operations) - [ISO 27001 Without Inherited Controls: Annex A You Operate](https://stribog.com/blog/iso-27001-annex-a-controls-self-hosted-kubernetes-isms-scope) — ISO 27001 compliance on infrastructure you run: how to scope the ISMS, write a Statement of Applicability, and evidence Annex A 8.9, 8.16, 8.13 and 5.23. (2026-07-30, Compliance) - [Catalogue Audit: 49 Articles, 342 Defects — What We Found](https://stribog.com/blog/catalogue-audit-49-articles-342-defects-what-we-found) — An audit of 49 live articles. Stage-1 mechanical checks found zero blockers; independent review verified 342 defects. Method, failures, residual risk. (2026-07-30, Governance) - [SOC 2 on Self-Hosted Kubernetes: Own the Evidence](https://stribog.com/blog/soc2-compliance-self-hosted-kubernetes-trust-services-criteria-evidence) — SOC 2 compliance on self-hosted Kubernetes: what carve-out really means, which Trust Services Criteria you must evidence yourself, and how to prove it. (2026-07-29, Compliance) - [Self-Hosted DORA: The Case Against Concentrated Risk](https://stribog.com/blog/dora-compliance-operational-resilience-self-hosted-ict-third-party-risk) — DORA's five pillars mapped to self-hosted controls — ICT third-party risk, the 4h/72h incident clock, resilience testing, and exits you have rehearsed. (2026-07-29, Compliance) - [WebAssembly on Kubernetes: SpinKube and runwasi](https://stribog.com/blog/spinkube-runwasi-wasmcloud-webassembly-sovereign-runtime-kubernetes) — Running WebAssembly on Kubernetes: the runwasi shim, SpinKube and wasmCloud, the honest limits, and why Wasm is the exit ramp from proprietary serverless. (2026-07-28, Runtime) - [NetBird vs Tailscale vs Headscale: Self-Hosted Mesh VPN](https://stribog.com/blog/headscale-netbird-self-hosted-tailscale-alternative-mesh-vpn) — Replacing the Tailscale coordination plane with self-hosted Headscale or NetBird: Kubernetes subnet routers, owned exit nodes, failure modes and the exit ramp. (2026-07-27, Networking) - [Rook/Ceph vs Longhorn vs OpenEBS: Kubernetes Storage](https://stribog.com/blog/rook-ceph-longhorn-openebs-sovereign-block-storage-kubernetes) — Choosing a self-hosted block storage layer for Kubernetes CSI: Rook/Ceph RBD vs Longhorn vs OpenEBS Mayastor, with hardware numbers and the exit ramp. (2026-07-26, Storage) - [On-Prem RAG: Qdrant vs pgvector for Sovereign Retrieval](https://stribog.com/blog/qdrant-pgvector-self-hosted-vector-database-on-prem-rag) — Choosing and operating a self-hosted vector database for on-premises RAG: Qdrant vs pgvector vs Weaviate, HNSW tuning, quantization, and the exit ramp. (2026-07-25, Sovereign AI) - [K3s and Rancher Fleet: Kubernetes at the Disconnected Edge](https://stribog.com/blog/k3s-rancher-fleet-edge-kubernetes-disconnected-air-gapped) — Operate K3s edge clusters over intermittent WAN with pull-based Rancher Fleet GitOps, air-gapped image delivery, per-site overlays, and offline reconciliation. (2026-07-25, Edge) - [Self-Hosted Chaos Engineering as Audit-Grade Evidence](https://stribog.com/blog/litmuschaos-chaos-mesh-resilience-verification-audit-evidence) — Structure LitmusChaos and Chaos Mesh fault injection as signed, ID-tagged artifacts that satisfy scenario-based operational resilience testing mandates. (2026-07-24, Resilience) - [KEDA and Descheduler: Two-Tier Autoscaling on Bare Metal](https://stribog.com/blog/keda-descheduler-bare-metal-event-driven-autoscaling-scale-to-zero) — KEDA event-driven autoscaling on Kubernetes scales pods to zero on queue depth; the descheduler bin-packs survivors to reclaim bare-metal nodes — no Karpenter. (2026-07-23, Scaling) - [MetalLB vs kube-vip: Bare-Metal Ingress with Gateway API](https://stribog.com/blog/metallb-kube-vip-gateway-api-bare-metal-ingress-cloudflare-exit) — Run a Kubernetes bare-metal load balancer without a cloud provider — MetalLB BGP, kube-vip control-plane VIP, and Envoy Gateway API, exiting Cloudflare's proxy. (2026-07-22, Networking) - [OpenCost: Kubernetes Namespace Showback and Chargeback](https://stribog.com/blog/opencost-namespace-showback-chargeback-kubernetes-finops) — Namespace-level Kubernetes cost allocation with OpenCost: run showback and graduate to chargeback on bare-metal clusters where no cloud billing API exists. (2026-07-21, FinOps) - [Internal PKI with step-ca and cert-manager: Private ACME](https://stribog.com/blog/step-ca-cert-manager-sovereign-internal-pki-private-acme) — Run a self-hosted certificate authority for internal Kubernetes names: step-ca as a private ACME server, cert-manager as the client, no CT-log leakage. (2026-07-20, Security) - [NATS vs Kafka: Strimzi and Redpanda Off Confluent Cloud](https://stribog.com/blog/strimzi-redpanda-nats-self-managed-event-backbone-confluent-exit) — A production ops playbook for a self-owned event backbone: Strimzi's Kafka lifecycle on Kubernetes, Redpanda's single binary, and NATS — off Confluent Cloud. (2026-07-19, Streaming) - [MIG vs Time-Slicing: Sharing GPUs on Kubernetes](https://stribog.com/blog/nvidia-gpu-operator-mig-time-slicing-kubernetes-sharing) — MIG gives hard, isolated GPU partitions; time-slicing shares one context with none; DRA makes fractional GPU scheduling a first-class Kubernetes primitive. (2026-07-18, Sovereign AI) - [LiteLLM as an MCP Gateway: Sovereign AI Data Residency](https://stribog.com/blog/litellm-self-hosted-mcp-model-gateway-ai-data-residency) — Model residency is not agent residency. A self-hosted MCP gateway and LiteLLM proxy keep tool-calls, keys, and PII inside your own network boundary. (2026-07-17, Sovereign AI) - [Schrems II, Six Years On: EU Data on US Clouds Is Still Unsafe](https://stribog.com/blog/schrems-ii-data-transfer-eu-data-us-cloud-self-hosted) — Schrems II turns six today. The EU-US Data Privacy Framework is under fresh challenge, and CLOUD Act reach means US-parent clouds remain a live transfer risk. (2026-07-16, Compliance) - [European Sovereign Cloud: Build, Buy, or Self-Host Framework](https://stribog.com/blog/european-sovereign-cloud-build-vs-buy-self-hosted) — European sovereign cloud is three options, not one: hyperscaler region, EU-incorporated provider, or self-host — scored on control, jurisdiction, lock-in, cost. (2026-07-15, Sovereignty) - [Digital Sovereignty: From Slogan to Testable Architecture](https://stribog.com/blog/digital-sovereignty-engineering-architecture-cornerstone) — Digital sovereignty is not a slogan but five engineering control layers — compute, data, keys, identity, supply chain — each mapped to a testable control. (2026-07-14, Sovereignty) - [Gaia-X in Practice: Federation, Labels, and the Sovereignty Gap](https://stribog.com/blog/gaia-x-sovereign-cloud-europe-self-hosted-reality) — Gaia-X gives European cloud services a machine-verifiable trust layer — but not control-plane custody, key ownership, or immunity from foreign jurisdiction. (2026-07-09, Sovereignty) - [DPDP Compliance: Consent, Erasure and Breach Workflows](https://stribog.com/blog/dpdp-compliance-consent-data-principal-rights-breach-workflow) — Operationalizing the DPDPA: a consent flow, data-principal access and verifiable erasure across your stores, and a breach workflow on the DPB's clock. (2026-07-08, Compliance) - [CERT-In Log Retention: India's 6-Hour Rule and 180 Days](https://stribog.com/blog/cert-in-directions-6-hour-incident-reporting-180-day-log-retention) — CERT-In's 2022 Directions as engineering constraints: six-hour incident reporting, a rolling 180-day log-retention floor, and a synced NIC/NPL time source. (2026-07-07, Compliance) - [DPDP Act for Engineers: India's Data Residency Architecture](https://stribog.com/blog/dpdp-act-2023-data-residency-self-hosted-architecture-india) — The engineering read of India's DPDP Act 2023: data fiduciary duties, cross-border transfer, and the Significant Data Fiduciary tier as infrastructure. (2026-07-06, Compliance) - [EU AI Act High-Risk Systems: An On-Prem Compliance Path](https://stribog.com/blog/eu-ai-act-high-risk-ai-systems-onprem-inference-compliance) — The EU AI Act's high-risk obligations — Article 12 logging, conformity assessment, post-market monitoring — mapped onto on-prem inference infrastructure. (2026-07-05, Compliance) - [Tinkerbell vs Metal3 vs Sidero Omni: Bare-Metal Provisioning](https://stribog.com/blog/metal3-tinkerbell-sidero-omni-bare-metal-kubernetes-provisioning) — Bare metal Kubernetes provisioning compared: Tinkerbell's workflow engine, Metal3's Cluster API/Ironic path, and Sidero Omni's post-CAPI machine model. (2026-07-04, Bare Metal) - [Hard Multi-Tenancy with vCluster: Retire 30 Clusters](https://stribog.com/blog/vcluster-hard-multi-tenancy-kubernetes-cluster-consolidation) — Kubernetes hard multi-tenancy without cluster sprawl: when namespaces suffice, where Capsule and vCluster fit, and how node isolation makes tenancy real. (2026-07-03, Multi-Tenancy) - [ClickHouse, Iceberg, DuckLake: A Lakehouse Off Snowflake](https://stribog.com/blog/clickhouse-iceberg-ducklake-sovereign-analytics-snowflake-exit) — Self-hosted ClickHouse vs Snowflake: build a sovereign lakehouse with ClickHouse, Apache Iceberg, and DuckLake for teams past the warehouse cost ceiling. (2026-07-02, Data) - [GPU and VRAM Sizing for Self-Hosted LLM Inference](https://stribog.com/blog/self-hosted-llm-hardware-gpu-vram-sizing-sovereign-inference-capacity) — Self-hosted LLM hardware sizing: VRAM math per model size and quantization, consumer vs datacenter GPU economics, and throughput-versus-latency planning. (2026-07-01, Sovereign AI) - [GitHub Self-Hosted Runners on Kubernetes with ARC](https://stribog.com/blog/self-hosted-github-actions-runners-kubernetes-arc-sovereign-ci-compute) — GitHub self-hosted runners on Kubernetes with actions-runner-controller: ephemeral, autoscaling, network-isolated CI compute you own, without leaving GitHub. (2026-06-30, CI/CD) - [Tabby vs Continue: Self-Hosted Coding Assistants on vLLM](https://stribog.com/blog/self-hosted-coding-llm-continue-tabby-vllm-sovereign-developer-assistant) — Run a self-hosted LLM for coding: Continue and Tabby wired to an open-weight code model served on vLLM, so your proprietary source code never reaches a vendor. (2026-06-29, Sovereign AI) - [HIPAA-Compliant LLM: On-Prem PHI Inference Without a BAA](https://stribog.com/blog/hipaa-compliant-self-hosted-llm-phi-on-prem-inference-baa) — How a covered entity runs a HIPAA-compliant LLM on-premises: PHI never leaves your perimeter, no third-party BAA to manage, every inference logged for audit. (2026-06-28, Sovereign AI) - [Falco vs Tetragon: Why Kernel-Time Detection Needs Both](https://stribog.com/blog/falco-tetragon-kubernetes-runtime-threat-detection-ebpf) — Kubernetes runtime threat detection with eBPF: Falco for broad MITRE ATT&CK detection, Tetragon for in-kernel enforcement, alerts piped to a self-hosted SIEM. (2026-06-27, Security) - [Keycloak vs Authentik vs Zitadel: Self-Hosted SSO After Okta](https://stribog.com/blog/keycloak-authentik-zitadel-self-hosted-identity-okta-exit) — Own your identity plane: a trust-model decision matrix comparing Keycloak, Authentik, and Zitadel as self-hosted SSO — the engineering exit from Okta. (2026-06-26, Identity) - [Forgejo, Woodpecker and Zot: CI Off GitHub Actions](https://stribog.com/blog/forgejo-woodpecker-zot-sovereign-ci-cd-github-actions-exit) — A self-hosted CI/CD alternative to GitHub Actions: Forgejo for git, Woodpecker for pipelines, Zot for OCI artifacts — the delivery chain as owned infra. (2026-06-25, CI/CD) - [SPIFFE/SPIRE on Kubernetes: Zero-Trust Workload Identity](https://stribog.com/blog/spiffe-spire-zero-trust-workload-identity-kubernetes-mtls) — SPIFFE/SPIRE issues cryptographic, attested workload identity — X.509 and JWT SVIDs — so Kubernetes services get mutual TLS and zero long-lived static secrets. (2026-06-24, Security) - [Replacing MinIO: Ceph vs SeaweedFS vs Garage](https://stribog.com/blog/minio-exit-rook-ceph-seaweedfs-garage-sovereign-object-storage) — MinIO archived its open-source edition. Choosing its replacement — Rook/Ceph, SeaweedFS or Garage — by tenancy, throughput and jurisdiction, not by benchmark. (2026-06-24, Storage) - [PostgreSQL on Kubernetes with CloudNativePG](https://stribog.com/blog/postgres-on-kubernetes-cloudnativepg-sovereign-stateful-data) — Production PostgreSQL on Kubernetes with CloudNativePG: streaming-replication HA, WAL archiving and PITR to your own object store, and a clean exit from RDS. (2026-06-24, Kubernetes) - [Kubernetes Disaster Recovery: Velero, etcd, RPO/RTO](https://stribog.com/blog/kubernetes-disaster-recovery-backup-velero-etcd-rpo-rto) — Kubernetes disaster recovery you can evidence: Velero and CSI data-mover for volumes, etcd snapshots for cluster state, and restore drills that prove RPO/RTO. (2026-06-24, Resilience) - [Confidential Computing on Kubernetes: TEEs and Attestation](https://stribog.com/blog/confidential-computing-kubernetes-remote-attestation-tee) — Confidential computing on Kubernetes: AMD SEV-SNP, Intel TDX and Confidential Containers protect data-in-use, with remote attestation gating key release. (2026-06-24, Sovereignty) - [EU AI Act, NIS2 and DORA: Moving Workloads Self-Hosted](https://stribog.com/blog/nis2-dora-eu-ai-act-self-hosted-kubernetes-compliance) — The EU AI Act, NIS2, and DORA are one architecture constraint, not three checklists — the technical evidence for why hyperscaler SaaS cannot satisfy them. (2026-06-23, Compliance) - [Talos Linux: The Security Case for an Immutable OS](https://stribog.com/blog/talos-linux-immutable-kubernetes-os-security-case) — Talos Linux vs Ubuntu for Kubernetes security: an immutable, API-only node ships almost no userspace to carry CVEs, and hardening Ubuntu cannot close that gap. (2026-06-18, Infrastructure) - [Self-Hosted Grafana vs Datadog: Kubernetes Observability](https://stribog.com/blog/self-hosted-observability-opentelemetry-prometheus-grafana-loki-kubernetes) — The Grafana stack — OpenTelemetry, Prometheus, Loki, Tempo — against Datadog and Elasticsearch: sovereign telemetry on Kubernetes with no per-GB ingestion bill. (2026-06-18, Observability) - [Argo Rollouts: Evidence-Gated Progressive Delivery](https://stribog.com/blog/progressive-delivery-argo-rollouts-canary-blue-green-kubernetes) — Progressive delivery on Kubernetes with Argo Rollouts: metric-driven AnalysisRuns, automatic rollback, Gateway API traffic shaping, audit-grade promotion. (2026-06-18, Progressive Delivery) - [Cloud Repatriation: The Kubernetes Engineering Playbook](https://stribog.com/blog/cloud-repatriation-kubernetes-on-premises-engineering-playbook) — A no-hype cloud repatriation playbook for Kubernetes: dependency audit, stateful workload triage, a real TCO model, and why most attempts fail inside 18 months. (2026-06-09, Cloud Exit) - [Self-Hosted AI on Kubernetes: Production vLLM](https://stribog.com/blog/self-hosted-llm-kubernetes-vllm-production-deployment) — How to run self-hosted LLM inference on Kubernetes with vLLM at production grade: GPU sizing, cost crossover analysis, audit logging for EU AI Act compliance. (2026-06-02, Sovereign AI) - [Supply Chain Security: SBOM, Sigstore and Admission Control](https://stribog.com/blog/oss-supply-chain-security-sbom-sigstore-slsa-kubernetes) — Kubernetes supply chain security end to end: SBOMs with Syft, SLSA L3 provenance, Sigstore keyless signing, and Kyverno admission control that actually blocks. (2026-05-28, Supply Chain) - [Kyverno vs OPA Gatekeeper: Policy as Code at Cluster Scale](https://stribog.com/blog/policy-as-code-kyverno-kubernetes-governance-scale) — Kyverno against OPA Gatekeeper on Kubernetes, then the lifecycle nobody budgets for: versioning, testing, exceptions and reporting are 80% of the work. (2026-05-19, Governance) - [Multi-Cluster GitOps at 100+ Clusters: Argo CD's Limits vs Flux](https://stribog.com/blog/multi-cluster-gitops-argocd-flux-scaling-100-clusters) — Multi-cluster GitOps past 20 clusters: where Argo CD's hub saturates, where Flux shifts that cost onto your Git origin, and the load model to find your ceiling. (2026-05-12, GitOps) - [Kubernetes Secrets Are Still Broken: ESO Over Vault](https://stribog.com/blog/kubernetes-secrets-management-external-secrets-operator-vault) — Vault is the right backend, not the right interface. ESO + dynamic credentials + etcd encryption eliminate long-lived secrets from Kubernetes clusters. (2026-05-05, Security) - [Cilium vs Calico: eBPF Zero Trust Without the Sidecar Tax](https://stribog.com/blog/cilium-ebpf-kubernetes-zero-trust-networking-service-mesh) — Cilium against Calico for zero-trust Kubernetes networking: identity-based policy, WireGuard node encryption and Hubble visibility, without the sidecar tax. (2026-04-28, Networking) - [Platform Engineering: Golden Paths Need Enforcement](https://stribog.com/blog/platform-engineering-golden-paths-policy-enforcement-kubernetes) — Platform engineering on Kubernetes: golden paths without admission enforcement are only suggestions. How to make the golden path the only path that works. (2026-04-21, Platform Engineering) ## Full content The complete text of every article is available at https://stribog.com/llms-full.txt