../_images/kup6s-icon-argocd.svg

Deployed Applications

This section contains documentation for applications deployed on the KUP6S cluster.

Each application follows the Diátaxis framework, with documentation organized into:

  • Explanation - Understanding WHY architectural decisions were made

  • Reference - Complete technical specifications for lookup

  • How-To - Step-by-step guides for specific tasks

  • Tutorials - Complete learning-oriented walkthroughs

Applications

AAF

AAF Application

View Documentation →

AAF
AlpineCity

Legacy Plone Site (alpinecity.tirol)

Frozen Plone 5 website with:

  • PostgreSQL 9.6 StatefulSet

  • Memcached cache layer

  • Traefik VirtualHostBase URL rewriting

  • ESO-managed credentials

View Documentation →

AlpineCity
CloudNativePG

PostgreSQL Operator and Backup Management

PostgreSQL cluster lifecycle management with:

  • CloudNativePG operator for PostgreSQL orchestration

  • Automated backups to S3 with Barman Cloud Plugin

  • High availability with automatic failover

  • Connection pooling with PgBouncer

  • Point-in-time recovery (PITR)

View Documentation →

CloudNativePG Operator
CrowdSec

Web Application Firewall and IP-Reputation Bouncer

Traefik plugin with community-sourced and curated threat intelligence:

  • Default-middleware bouncer on the websecure entrypoint

  • CAPI community feed plus selectable premium blocklists

  • AppSec component for OWASP-CRS WAF (Phase 3, not yet attached to routes)

  • ESO cross-namespace bridge for the bouncer API key

  • CDK8S infrastructure-as-code with ArgoCD GitOps management

View Documentation →

CrowdSec WAF
GitLab BDA

Complete Git Platform with CI/CD and Container Registry

GitLab deployment for Blue Dynamics Alliance with:

  • GitLab CE with external PostgreSQL and Redis

  • Harbor container registry with Trivy vulnerability scanning

  • GitLab Pages for static site hosting

  • S3 object storage for artifacts, uploads, and LFS

  • High availability with CloudNativePG and Redis Sentinel

View Documentation →

GitLab BDA
Monitoring Stack

Complete Observability Platform with Metrics and Logs

Monitoring stack providing cluster-wide observability with:

  • Prometheus + Thanos for metrics collection and long-term storage

  • Grafana for visualization and dashboards

  • Loki for log aggregation with S3 storage

  • Alloy for unified metrics and logs collection

  • Alertmanager for alert routing and notification

View Documentation →

Monitoring Stack
Mailu Mail Server

Complete Mail Server with SMTP, IMAP, and Webmail

Mailu deployment providing full-featured mail services with:

  • SMTP sending/receiving with spam filtering (Rspamd)

  • IMAP and POP3 with Dovecot

  • Roundcube webmail interface

  • Traefik TLS termination for all protocols

  • Cilium egress gateway for consistent sender IP (SPF compliance)

  • PostgreSQL backend with CloudNativePG

  • Integrated admin interface and SSO

View Documentation →

Mailu Mail Server
Capsule Multi-Tenancy

Self-Service Namespace Management for Teams

Capsule deployment providing multi-tenancy with:

  • Self-service namespace creation for tenant owners

  • Automatic RBAC inheritance within tenant namespaces

  • Aggregated resource quotas across tenant namespaces

  • Namespace prefix-based tenant assignment

  • Network policy isolation between tenants

View Documentation →

Capsule Multi-Tenancy
Cloud-Vinyl

Kubernetes Operator for Varnish Cache Clusters

Declarative Varnish Cache management with:

  • VinylCache CRD for cache cluster lifecycle

  • Agent-based VCL configuration delivery

  • PURGE, BAN, and xkey cache invalidation

  • Prometheus metrics and alerting

  • Integration with Plone’s cachepurging

View Documentation →

Cloud-Vinyl Operator
Nextcloud

Self-Hosted File Sync and Collaboration Platform

Nextcloud deployment providing file storage and collaboration with:

  • File sync, sharing, and versioning

  • Collabora Online for browser-based document editing

  • Whiteboard for real-time collaboration

  • S3 primary storage with Hetzner Object Storage

  • CloudNativePG PostgreSQL with automated backups

  • Multiple instances with shared CDK8S constructs

View Documentation →

Nextcloud
kup6s-pages

Multi-Tenant Static Site Hosting Operator

Static site hosting from Git repositories with:

  • StaticSite CRD for declarative site management

  • Automatic TLS via cert-manager integration

  • Traefik IngressRoute creation

  • Webhook support for instant updates on push

  • Private repository support with deploy tokens

  • Multi-tenant architecture with shared nginx

View Documentation →

kup6s-pages
Plausible Analytics

Self-Hosted Web Analytics (stats.cloud.kup.tirol)

Plausible Community Edition serving ~25 sites with:

  • Single-replica app (CE v3.2.1), migrated from groot 2026-07

  • CloudNativePG database with barman-cloud backups (fsn1)

  • ClickHouse StatefulSet with tamed system logs

  • Mailjet SMTP, MaxMind GeoIP, registration disabled

View Documentation →

Plausible Analytics
Solidtime

Self-Hosted Time Tracking (time.kup.tirol)

Clockify replacement with:

  • CloudNativePG database with barman-cloud backups (fsn1)

  • Hot app file storage on Hetzner S3 (hel1)

  • Three CONTAINER_MODE roles plus Gotenberg PDF export

  • Mailjet SMTP, Passport OAuth, invite-only registration

  • Built-in Clockify data migration

View Documentation →

Solidtime time tracking
Renovate

Dependency-Update Bot (GitOps)

Self-hosted Renovate watching upstream releases:

  • Nightly CronJob against dp-kup and dp-infra

  • Opens merge requests with regenerated CDK8S manifests

  • GitLab bot token via ESO, maintainer notified by email

  • Merge is deploy; no auto-merge

View Documentation →

Renovate

Table of Contents

Deployments