Security, Identity & Governance
Security and data sovereignty are fundamental architectural tenets of Okustera.
Built for regulated industries, public sector organizations, and privacy-first enterprises, Okustera enforces zero-trust isolation, comprehensive identity governance, and strict physical and logical multi-tenancy.
Security Pillars
Identity & Access Management (/security/iam)
Fine-grained multi-tenant access control powered by OpenStack Keystone:
- Project-level and domain-level boundary isolation.
- Role-Based Access Control (RBAC) with pre-built and custom policy roles.
- Interactive IAM Policy Simulator to validate permissions.
- Workload Identity & Pod IAM: Eliminate static credentials by projecting ephemeral JWT identity tokens into Kubernetes pods.
- Declarative IAM roles and role assignments via Terraform (
okustera_iam_role,okustera_pod_identity_binding).
Multi-Factor Authentication (/security/mfa)
Enforcing strong account security with Time-based One-Time Passwords (TOTP):
- Self-service QR code enrollment for Google Authenticator, 1Password, and Bitwarden.
- Mandatory or opt-in two-factor verification on portal logins and sensitive API calls.
- CLI, API, and Terraform integration with rolling 6-digit TOTP verification codes.
Enterprise Secrets & Multi-Layer Encryption (/security/secrets)
Secure secrets storage and cryptographic key escrow powered by OpenStack Barbican:
- Hardware Security Module (HSM) and software-backed cryptographic key generation.
- Block Volume Encryption (Cinder LUKS): Transparent AES-256 envelope encryption with automated per-tenant Barbican key generation and GDPR Art. 17 crypto-shredding.
- S3 Server-Side Encryption (SSE-KMS): Automatic bucket encryption-at-rest enveloped by Barbican master keys.
- In-Transit Mesh Encryption: Pod-to-pod transparent WireGuard kernel encryption across nodes (Cilium CNI) and Ceph Messenger v2 secure mode wire encryption.
- Virtual TPM 2.0 (vTPM): Software-emulated security chip (
swtpm) enabling measured boot and BitLocker/LUKS for tenant VMs. - Dynamic Kubernetes Secret synchronization via external-secrets operators.
Multi-Layer Firewall Architecture (/security/firewall)
Five-tier defense-in-depth perimeter and runtime protection:
- Tier 1 (Border Edge): Physical Fortinet FortiGate hardware pair for volumetric DDoS mitigation, IPS, and BGP border peering.
- Tier 2 (SDN Layer): OpenStack Neutron stateful distributed security groups and control plane isolation.
- Tier 3 (Ingress WAF): Apache APISIX + Coraza WAF with OWASP Core Rule Set 4.0 blocking SQLi, XSS, and RCE.
- Tier 4 (Kernel Runtime): Cilium eBPF and Tetragon real-time kernel syscall interception (
SIGKILLon unauthorized binaries). - Tier 5 (vNGFW Marketplace): Glance catalog (
pfSense-CE,OPNsense,FortiGate-VM) and Transit Inspection VPC blueprints.
Infrastructure Hardening & Rotation (/security/hardening)
Eliminating default credentials and establishing zero-trust credential hygiene:
- Automated pre-deployment cryptographic entropy generation.
- Post-installation lifecycle credential rotation runbooks (RabbitMQ, MariaDB, Keystone).
Sovereign Compliance & Data Governance (/security/compliance)
Strict jurisdictional integrity, European regulatory compliance, and multi-standard security frameworks:
- 100% European Data Sovereignty: Physical bare-metal servers, NVMe storage pools, and network routes remain strictly pinned within designated national boundaries; immune to US CLOUD Act and foreign extraterritorial warrants.
- AICPA SOC 2 Type II Alignment: Defense-in-depth perimeter firewalls, least-privilege Keystone RBAC, automated recovery runbooks, and continuous predictive anomaly telemetry.
- GDPR Compliance Framework: Comprehensive implementation of lawful processing transparency, privacy by design, 72-hour breach alerts, standard DPAs, non-proprietary data portability, and Barbican KMS crypto-shredding (Art. 17 right-to-be-forgotten).
- Cloud ISO Standards & NIS2: Mapped to ISO/IEC 27001, 27017, 27018, 22301, 19941, and EU NIS2 Directive (2022/2555).
- Automated Compliance Inspector (
okustera-audit): Internal CLI and Backoffice automation verifying 19 technical controls across security, resiliency, and encryption. - Important Notice: Compliance Inspector assessments are automated technical checks for internal gap analysis and pre-audit readiness, rather than a 100% valid attestation or certification from an external audit company.
Authoritative Sources:
compliance: soc 2, sources: https://www.onetrust.com/blog/soc-2-compliance/, https://www.splunk.com/en_us/blog/learn/soc-2-compliance-checklist.htmlcompliance: gdpr, sources: https://gdpr.eu/checklist/, https://gdpr.eu/privacy-notice/, https://gdpr.eu/right-to-erasure-request-form/compliance: cloud-security-standards, sources: https://www.wiz.io/academy/compliance/cloud-security-standardscompliance: cloud-compliance-fast-track, sources: https://www.wiz.io/academy/compliance/cloud-compliance-fast-track-guide