Core Platform Infrastructure

Direct single sign-on access to administrative tools. Ingress traffic is strictly gated by the Forward-Auth Gatekeeper.

Platform User Directory

Manage customer tenant accounts and elevate authorized administrators.

User Role & Privilege Projects VPS Databases Registered Actions

Forward-Auth Gatekeeper Stream

Real-time audit log of internal service authorization checks handled by Ingress-Nginx.

Live Monitoring
Timestamp Status Service Method & URI Client IP Identity Policy Decision

Kubernetes Topology & Health

Multi-namespace cluster state and resource availability.

Total Users
-
Active platform accounts
Platform Admins
-
Privileged gatekeeper access
Infra Services
-
Protected core microservices
Kubernetes Control Plane
ONLINE
K3s Lightweight Engine

Zero-Trust Forward Auth Isolation

All traffic to Gitea, pgAdmin, and Headlamp requires a verified Admin session. Ingress-Nginx automatically queries admin-service:8099/auth/verify before any request is permitted to reach internal pods. Unauthenticated traffic is blocked at the perimeter.