Okustera Cloud Platform Documentation
Welcome to the official developer and operator documentation for Okustera (docs.okustera.com), the open-standard sovereign cloud platform engineered to transform bare-metal infrastructure into enterprise-grade public and private clouds.
⚡ Quickstart Examples
Get up and running immediately with production workloads deployed on Okustera:
- 🚀 Simple Demo: Webhook Data Lake — Multi-tenant event ingestion engine, Apache APISIX gateway, and Ceph S3 data lake deployed via Terraform.
- 📄 Document Intelligence & Vector Lakehouse — Zero-trust document intelligence, OIDC token projection, gVisor serverless parsing, Apache Airflow orchestration, and Qdrant semantic vector search.
- 🛡️ Sovereign AI Security Gateway & Zero-Trust Perimeter — Fortinet FortiGate-VM NGFW, Octavia LBaaS, Microsoft Presidio in-line PII sanitization, Model Context Protocol (MCP) anti-SSRF protection, and sovereign LLM inference.
- 🔄 Zero-Downtime Database Migration & Upgrades — Automated in-place rolling upgrades (PostgreSQL 16.2 → 16.5) and Blue-Green live CDC migrations (PostgreSQL 16 → 17) with live traffic verification and zero dropped transactions.
Explore by Platform
☁️ Cloud Infrastructure (IaaS)
Upstream Kubernetes via Magnum & Cluster API (CAPI), Nova KVM compute instances, OVN/Neutron VPC networking, Ceph NVMe block storage, and S3 object storage.
🗄️ Managed Databases (DBaaS)
Production-grade managed database clusters: CloudNativePG PostgreSQL 16, Spotahome Valkey Sentinel, Percona XtraDB MySQL, and Percona MongoDB.
⚡ Developer Platform (PaaS)
Apache APISIX API Gateway & Ingress, OpenFaaS serverless (gVisor sandboxed), RabbitMQ message queuing, Managed Apache Airflow workflows, AI Model Foundry & vLLM inference, Artifact Keeper universal registry, and Grafana/Loki observability.
🛠️ Automation & Tools
Official HashiCorp Terraform Provider (terraform-provider-okustera), Workload Identity GitOps, OpenStack CLI cheatsheets, and Go / Python SDKs.
🛡️ Security & Governance
Keystone multi-tenant IAM, OpenStack Barbican enterprise secrets vault, Workload Identity & Pod IAM tokens, and sovereign compliance controls.
🔌 REST API Reference
Complete interactive OpenAPI 3.1 REST API documentation for the Okustera Core API, Container Infrastructure (Magnum), DBaaS, and Identity endpoints.
5-Minute Quickstart
Provision your first production infrastructure stack using Terraform:
terraform {
required_providers {
okustera = {
source = "okustera/okustera"
version = "~> 1.0.0"
}
}
}
provider "okustera" {
endpoint = "https://portal.okustera.com/api/v1"
api_token = var.okustera_api_token
tenant_id = "tenant-production"
}
# 1. High-Availability PostgreSQL 16 Cluster
resource "okustera_database_postgresql" "crm_db" {
name = "production-crm-db"
instances = 3
storage_size_gb = 50
storage_class = "ceph-rbd"
database_name = "crm"
enable_backups = true
}
# 2. Valkey Sentinel Cache
resource "okustera_database_valkey" "cache" {
name = "session-cache"
replicas = 3
memory_limit = "4Gi"
sentinel_replicas = 3
}
# 3. S3-Compatible Object Storage Bucket
resource "okustera_s3_bucket" "assets" {
name = "customer-assets"
versioning = true
quota_gb = 100
}
🚀 Live Interactive Showcase
Experience complete production reference architectures running live on Okustera:
- 🌐 Live Portal & Webhook Simulator: https://demo.okustera.com — Event ingestion engine, Keystone IAM, and S3 data lake. (Read the Simple Demo Guide).
- 📄 Live Document Lakehouse & Semantic Search: https://doclake.okustera.com — Document intelligence, gVisor sandboxing, Airflow DAGs, and Qdrant RAG. (Read the Document Processing Guide).
- 🛡️ Live AI Security Gateway & FortiGate Perimeter: https://shield.okustera.com — FortiGate-VM NGFW, Octavia LBaaS, Presidio in-line PII sanitization, and Model Context Protocol (MCP). (Read the AI Security Shield Guide).