The post is about building a secure, sovereign software factory on top of an Incus-based private cloud, using open-source tools such as Forgejo, ephemeral runners, Pulp, Cosign, and OpenBao. Instead of Kubernetes being used as the foundation, workloads are isolated by tenant and network. Challenges including key management, runner isolation, network security, and a self-service portal are discussed.
[link] [留言]