此页面由我们自己的 AI 自动翻译,因此可能包含错误。 阅读英文原文

我们如何运营

Kreative Kompas 运行于办公室的一台服务器上。无需云服务费,无供应商锁定,且每一部分均为开源软件,我们可阅读、修复并改进。

访客与客户团队成员来自世界的邮件路由器与防火墙 · 仅我们选择的门是敞开的一台 Ubuntu 服务器前门(反向代理)Nginx Proxy Manager · HTTPS私人 VPN员工版 WireGuard邮件服务器TLS · DKIM · DMARC · SPF单点登录 · 每位团队成员一个 Keycloak 账户CollaborationEveryday toolsDevelopment & AIMedia & contentBuilding & automationCommunity & commerce出站隧道Gluetun 隔离所选应用数据层每个应用一个数据库配置之外的秘密在您自己的磁盘上进行备份每个服务独立容器 · 配置托管于 Git · 按预定计划更新

我们如何运行它

让单服务器公司保持可靠与安全的规则。

One service, one container

Every app lives in its own container with its own network and database, so one failure stays one failure.

One front door

Nothing is exposed directly. All web traffic enters through the reverse proxy, always over HTTPS.

One login

Team members sign in with a single account. When someone leaves, one switch closes every door.

Admin stays inside

Management tools answer only on the office network or over the staff VPN, never to the open internet.

Secrets out of config

Configuration is shared in Git; passwords and keys live in separate, locked-down files that never leave the server.

Our data, our disks

Mail, files, photos and AI prompts stay on hardware we own, and so do the backups.

机器

Used Intel Arc cards, no Nvidia, and open-source software from the drivers up.

CPU

AMD Ryzen 7 3700X

8 cores, 16 threads

Memory

62 GB RAM

Shared by every service

AI GPU

Intel Arc A770 16 GB

Local AI models through OpenVINO

Media GPU

Intel Arc A580 8 GB

Video transcoding, kept free of AI work

Storage

~27 TB pooled

Three disks, one media pool

Containers

~130 containers

Single sign-on, WireGuard for staff

请求,逐步完成

  1. 域名已解析。 所有公共地址均指向办公室连接。
  2. 路由器允许其进入。 仅网页、邮件、VPN、流媒体和游戏通道已开启,管理工具均未开放。
  3. 前门(反向代理)接收请求。 HTTPS 通过免费且自动续期的证书终止,并将请求路由至一个容器。
  4. 团队只需登录一次。 Keycloak 验证您的身份,随后所有已连接的应用程序均予以信任。
  5. 应用完成它的工作。 每个应用程序仅通过其专属私有网络与其自身数据库通信。
一栈,一文件夹
# every service is a folder with a compose file
Services/
  wiki/
    docker-compose.yml   # what runs, and how
    .env.example         # which settings it needs
    .env                 # the real secrets, never in Git

# deploy or update a service
docker compose pull
docker compose up -d

54 服务,单服务器

逐一查看:每个项目为我们做什么,以及背后的项目。