此頁面由我們自己的 AI 自動翻譯,因此可能包含錯誤。 請閱讀英文原版

我們如何運作

Kreative Kompas 在辦公室的一台伺服器上運行。沒有雲端帳單,沒有供應商鎖定,且每一項都是我們能夠閱讀、修復與改進的開源軟體。

訪客與客戶團隊成員來自世界的郵件路由器與防火牆 · 僅我們選擇的門是敞開的單一 Ubuntu 伺服器前門(反向代理)Nginx Proxy Manager · HTTPS私人 VPN員工專用的 WireGuard郵件伺服器TLS · DKIM · DMARC · SPF單一簽入:每位團隊成員一個 Keycloak 帳戶CollaborationEveryday toolsDevelopment & AIMedia & contentBuilding & automationCommunity & commerce出站隧道Gluetun 隔離您選取的應用程式資料層每個應用程式獨立資料庫配置之外的祕密在我們自己的磁碟上備份每項服務皆獨立運行於容器中 · 配置存儲於 Git · 按時自動更新

我們如何營運

讓單一伺服器公司保持可靠與安全的規則。

One service, one container

Every app lives in its own container with its own network and database, so one failure stays one failure.

One front door

Nothing is exposed directly. All web traffic enters through the reverse proxy, always over HTTPS.

One login

Team members sign in with a single account. When someone leaves, one switch closes every door.

Admin stays inside

Management tools answer only on the office network or over the staff VPN, never to the open internet.

Secrets out of config

Configuration is shared in Git; passwords and keys live in separate, locked-down files that never leave the server.

Our data, our disks

Mail, files, photos and AI prompts stay on hardware we own, and so do the backups.

機器

Used Intel Arc cards, no Nvidia, and open-source software from the drivers up.

CPU

AMD Ryzen 7 3700X

8 cores, 16 threads

Memory

62 GB RAM

Shared by every service

AI GPU

Intel Arc A770 16 GB

Local AI models through OpenVINO

Media GPU

Intel Arc A580 8 GB

Video transcoding, kept free of AI work

Storage

~27 TB pooled

Three disks, one media pool

Containers

~130 containers

Single sign-on, WireGuard for staff

一個請求,逐步解析

  1. 名稱已解析。 所有公開地址均指向辦公室連接。
  2. 路由器允許其進入。 僅有網頁、郵件、VPN、串流與遊戲的門戶已開啟,管理工具則無任何門戶。
  3. 前門(反向代理)接收請求。 HTTPS 由免費且自動續期的憑證終止,請求再被轉送到對應的單一容器。
  4. 團隊只需登入一次。 Keycloak 驗證您的身份,隨後所有連接的應用程式皆予以信任。
  5. 應用程式運作正常。 每個應用程式僅與自身資料庫通訊,並運行於其專屬的私有網路中。
一疊,一資料夾
# every service is a folder with a compose file
Services/
  wiki/
    docker-compose.yml   # what runs, and how
    .env.example         # which settings it needs
    .env                 # the real secrets, never in Git

# deploy or update a service
docker compose pull
docker compose up -d

54 服務,單一伺服器

逐一查看:每個專案為我們做什麼,以及背後的開源專案。