OCI Hybrid Cloud & DevSecOps Platform

Enterprise Zero-Trust Infrastructure, High-Availability VRRP Gateways, Native ARM64 Tekton CI/CD & SLSA Level 3 Supply Chain Governance

System Operational ARM64 Ampere Altra 0 Worker Public IPs VRRP ID 77 (< 3s Failover) Let's Encrypt Public TLS SLSA Build Level 3
Active Fleet Nodes
8 Nodes
Public Ingress VIP
141.148.149.104
Private Gateway VIP
10.0.0.200
Worker Public IPs
0 (Zero)
VRRP Heartbeat
1.0s / ID 77
SLSA Compliance
Level 3

Hybrid Cloud Network Architecture

Interactive topology showing VCN segmentation, VRRP dual gateways, isolated ARM compute, and Tailscale interconnects.
flowchart TB subgraph Internet["🌐 Public Internet & Clients"] Clients["Clients / Browsers"] end subgraph OCI_VCN["☁️ Oracle Cloud Infrastructure (Region: us-phoenix-1 / VCN: 10.0.0.0/16)"] subgraph VIP_Layer["Floating Gateway Layer (VRRP ID 77)"] PubVIP["Public VIP: 141.148.149.104
(Ports 80 & 443 Forwarded)"] PrivVIP["Private VIP: 10.0.0.200
(Default Gateway for Workers)"] end subgraph Gateways["HA Edge Gateway Pair (VM.Standard.E2.1.Micro)"] G1["oci-micro-1 (Master)
Priority 101 | IP: 10.0.0.29
Public IP: 132.226.113.118"] G2["oci-micro-2 (Backup)
Priority 100 | IP: 10.0.0.149
Public IP: 129.153.212.1"] end subgraph Private_Subnet["🔒 Private Compute Subnet (Zero Public IPs)"] ARM1["oci-arm-1 (Builder Node)
Ampere Altra (1 OCPU, 6GB RAM)
Private IP: 10.0.0.8
Role: Tekton Native ARM64 Builder"] ARM2["oci-arm-2 (Workload Node)
Ampere Altra (1 OCPU, 6GB RAM)
Private IP: 10.0.0.105
Role: Production Workload Deploy Target"] end end subgraph Tailscale_Mesh["🔒 Tailscale Encrypted Overlay (100.64.0.0/10)"] S66["sweetsixty6 (Control Plane)
Debian 13 | 100.92.249.20
K3s Master & Control Tower"] RPI1["raspberrypi-20b640d0"] RPI2["raspberrypj-5723f461"] CRALEX["cralex (x64 Builder)"] end Clients -->|"HTTPS (80/443)"| PubVIP PubVIP -.->|"Active Forwarding"| G1 PubVIP -.->|"Failover (<3s)"| G2 G1 <===>|"VRRP Heartbeat (ID 77)"| G2 G1 --- PrivVIP G2 --- PrivVIP PrivVIP -->|"Default Route (rt-arm-private)"| ARM1 PrivVIP -->|"Default Route (rt-arm-private)"| ARM2 S66 <===>|"WireGuard Mesh"| ARM1 S66 <===>|"WireGuard Mesh"| ARM2 S66 <===>|"WireGuard Mesh"| G1 S66 <===>|"WireGuard Mesh"| G2

SLSA Level 3 & DevSecOps Governance

Supply-chain Levels for Software Artifacts (SLSA v1.0) compliance matrix and infrastructure hardening measures.

SLSA v1.0 Level 3 Verification

Requirement Implementation Status
Hosted Build Platform Tekton Pipelines executed exclusively on dedicated builder node (oci-arm-1) VERIFIED
Isolated Environments Ephemeral Kaniko container execution; no shared host docker.sock or root daemon VERIFIED
Hermetic & Deterministic Pinned base images (python:3.12-slim-bookworm), locked dependencies via requirements.txt VERIFIED
Provenance Generation In-toto attestation format with image SHA256 cryptographic digest pinning VERIFIED
Artifact Immutability Local K3s registry with digest-based image references and immutable tags VERIFIED

Infrastructure Defense-in-Depth

  • Worker Public IPs: 0 Public IPs (Fully Isolated)
  • Egress Routing Table: rt-arm-private via 10.0.0.200
  • Gateway Failover Protocol: VRRP ID 77 (< 3s failover)
  • Automated Ingress TLS: Cert-Manager Let's Encrypt (HTTP-01)
  • Container Security Context: Non-root UID 1000 / drop all caps
  • Control Plane Overlay: Tailscale WireGuard Mesh (256-bit)

Cloud-Native CI/CD: Tekton + ArgoCD

GitOps-driven continuous integration and deployment with native multi-architecture execution.

Tekton Pipeline Architecture

Builds are executed natively on Ampere Altra ARM64 (oci-arm-1), eliminating emulation bottlenecks and guaranteeing 100% binary compatibility for ARM production workloads.

  • Build Engine: Kaniko v1.23.2 (Daemonless)
  • Target Architecture: linux/arm64 (aarch64)
  • Assigned Builder Node: oci-arm-1 (10.0.0.8)
  • Target Registry: localhost:32500/oci-fastapi-docs
  • Active TaskRun: oci-fastapi-docs-build

ArgoCD GitOps Framework

The entire cluster state is managed declaratively through GitOps repositories, providing continuous drift reconciliation and zero-touch continuous deployment.

  • Git Repository: jpaquay/control-tower
  • Deployment Target: oci-arm-2 (Namespace: oci-docs)
  • Sync Policy: Automated (Prune & Self-Heal)
  • Health Status: ● Healthy / Synced
  • Revision Tracking: HEAD (main)

SRE Cluster Telemetry (Read-Only)

Live metrics, cluster health telemetry, and resource saturation indicators.
Polling 5s
Cluster Load & Network Latency Monitor
Updated: Just now
ARM Workload CPU
14.2%
Ampere Altra 1 OCPU
Worker RAM Load
38.5%
2.31 / 6.0 GB Used
VRRP RTT Latency
0.42 ms
Keepalived Group 77
TLS Cert Validity
89 Days
Let's Encrypt (Prod)

Heterogeneous Node Fleet Health Matrix

Node Name Role Architecture Private IP Public IP OS / Kernel Status

REST Telemetry & Management APIs

FastAPI OpenAPI 3.1 endpoints accessible for programmatic integration and agentic tooling.