Skip to main content

Security, Identity & Governance

Security and data sovereignty are fundamental architectural tenets of Okustera.

Built for regulated industries, public sector organizations, and privacy-first enterprises, Okustera enforces zero-trust isolation, comprehensive identity governance, and strict physical and logical multi-tenancy.


Security Pillars​

Identity & Access Management (/security/iam)​

Fine-grained multi-tenant access control powered by OpenStack Keystone:

  • Project-level and domain-level boundary isolation.
  • Role-Based Access Control (RBAC) with pre-built and custom policy roles.
  • Interactive IAM Policy Simulator to validate permissions.
  • Workload Identity & Pod IAM: Eliminate static credentials by projecting ephemeral JWT identity tokens into Kubernetes pods.
  • Declarative IAM roles and role assignments via Terraform (okustera_iam_role, okustera_pod_identity_binding).

Multi-Factor Authentication (/security/mfa)​

Enforcing strong account security with Time-based One-Time Passwords (TOTP):

  • Self-service QR code enrollment for Google Authenticator, 1Password, and Bitwarden.
  • Mandatory or opt-in two-factor verification on portal logins and sensitive API calls.
  • CLI, API, and Terraform integration with rolling 6-digit TOTP verification codes.

Enterprise Secrets & Multi-Layer Encryption (/security/secrets)​

Secure secrets storage and cryptographic key escrow powered by OpenStack Barbican:

  • Hardware Security Module (HSM) and software-backed cryptographic key generation.
  • Block Volume Encryption (Cinder LUKS): Transparent AES-256 envelope encryption with automated per-tenant Barbican key generation and GDPR Art. 17 crypto-shredding.
  • S3 Server-Side Encryption (SSE-KMS): Automatic bucket encryption-at-rest enveloped by Barbican master keys.
  • In-Transit Mesh Encryption: Pod-to-pod transparent WireGuard kernel encryption across nodes (Cilium CNI) and Ceph Messenger v2 secure mode wire encryption.
  • Virtual TPM 2.0 (vTPM): Software-emulated security chip (swtpm) enabling measured boot and BitLocker/LUKS for tenant VMs.
  • Dynamic Kubernetes Secret synchronization via external-secrets operators.

Multi-Layer Firewall Architecture (/security/firewall)​

Five-tier defense-in-depth perimeter and runtime protection:

  • Tier 1 (Border Edge): Physical Fortinet FortiGate hardware pair for volumetric DDoS mitigation, IPS, and BGP border peering.
  • Tier 2 (SDN Layer): OpenStack Neutron stateful distributed security groups and control plane isolation.
  • Tier 3 (Ingress WAF): Apache APISIX + Coraza WAF with OWASP Core Rule Set 4.0 blocking SQLi, XSS, and RCE.
  • Tier 4 (Kernel Runtime): Cilium eBPF and Tetragon real-time kernel syscall interception (SIGKILL on unauthorized binaries).
  • Tier 5 (vNGFW Marketplace): Glance catalog (pfSense-CE, OPNsense, FortiGate-VM) and Transit Inspection VPC blueprints.

Infrastructure Hardening & Rotation (/security/hardening)​

Eliminating default credentials and establishing zero-trust credential hygiene:

  • Automated pre-deployment cryptographic entropy generation.
  • Post-installation lifecycle credential rotation runbooks (RabbitMQ, MariaDB, Keystone).

Sovereign Compliance & Data Governance (/security/compliance)​

Strict jurisdictional integrity, European regulatory compliance, and multi-standard security frameworks:

  • 100% European Data Sovereignty: Physical bare-metal servers, NVMe storage pools, and network routes remain strictly pinned within designated national boundaries; immune to US CLOUD Act and foreign extraterritorial warrants.
  • AICPA SOC 2 Type II Alignment: Defense-in-depth perimeter firewalls, least-privilege Keystone RBAC, automated recovery runbooks, and continuous predictive anomaly telemetry.
  • GDPR Compliance Framework: Comprehensive implementation of lawful processing transparency, privacy by design, 72-hour breach alerts, standard DPAs, non-proprietary data portability, and Barbican KMS crypto-shredding (Art. 17 right-to-be-forgotten).
  • Cloud ISO Standards & NIS2: Mapped to ISO/IEC 27001, 27017, 27018, 22301, 19941, and EU NIS2 Directive (2022/2555).
  • Automated Compliance Inspector (okustera-audit): Internal CLI and Backoffice automation verifying 19 technical controls across security, resiliency, and encryption.
  • Important Notice: Compliance Inspector assessments are automated technical checks for internal gap analysis and pre-audit readiness, rather than a 100% valid attestation or certification from an external audit company.

Authoritative Sources:

  • compliance: soc 2, sources: https://www.onetrust.com/blog/soc-2-compliance/, https://www.splunk.com/en_us/blog/learn/soc-2-compliance-checklist.html
  • compliance: gdpr, sources: https://gdpr.eu/checklist/, https://gdpr.eu/privacy-notice/, https://gdpr.eu/right-to-erasure-request-form/
  • compliance: cloud-security-standards, sources: https://www.wiz.io/academy/compliance/cloud-security-standards
  • compliance: cloud-compliance-fast-track, sources: https://www.wiz.io/academy/compliance/cloud-compliance-fast-track-guide