Get in touch →
The physical server running Albgott — a Dell PowerEdge T160

ENGINEERED TO RUN.
DESIGNED TO LAST.

For many years, we’ve been building and operating Albgott, a private cloud platform — improving it step by step, learning from what works, and making it better with every iteration.

Services in production
38
Network segments
08
Operated since
2023
Monitored
24/7

ALBGOTT is a private cloud built from the ground up and operated in-house.

It started as infrastructure for running a few services.Three years later, it has grown into a complete platform — with isolated networks, dedicated compute, its own access model, and observability across every layer.

It has been running in production since 2023, and it keeps evolving one improvement at a time.

  • Compute03 NODES
  • Network08 SEGMENTS
  • Workloads38 SERVICES
  • ObservabilityFULL STACK · 24/7
  • AutomationIN PROGRESS
02 — SystemFull breakdown →

System topology

Compute
pve01pve02 pve03
Network
Publicingress
Internalapps
Datastateful
CIbuild
Backuprestricted
Corpwork
Mgmtadmin
Homeuser
Access
AdministratorsDevelopers

Deliberate
trade-offs

Isolation over convenience. Some decisions make things harder to operate. They also make mistakes smaller, access more controlled, and failures easier to contain.

  • 01
    Asymmetric node roles
    Compute goes where the workload belongs — not simply where it is most convenient.
  • 02
    No implicit trust
    Two networks do not communicate just because both are considered “internal.” Access is explicit by design.
  • 03
    Access split by role
    Administrators and developers use separate access paths, keeping credentials, permissions, and blast radius apart.
03 — SecurityFull breakdown →

Nothing gets in by accident.

access-policy.conf
# default posture
deny   *               *

# explicit exceptions only
allow  public app :443
allow  internal tools, trusted net only
allow  corp-tunnel internal
allow  admin-tunnel mgmt console

# identity
rollout sso, secrets in progress, not finished

How trust
is controlled

Being on the network is not the same as being allowed to use it. Every boundary below exists on purpose.

  • 01
    Default deny, explicit allow
    Every connection between segments exists because it was written down, not because it was convenient.
  • 02
    Trust tiers, not one router doing everything
    Public traffic, internal tools, and hardware management sit behind three separate entry points, each with its own blast radius.
  • 03
    Identity, still rolling out
    Single sign-on and centralized secrets exist and work today — adopting them everywhere is honest, ongoing work, not a finished migration.
04 — OperationsSee operations →

OBSERVE.AUTOMATE.ALERT.

Every layer is monitored, measured, and instrumented to surface problems early before it becomes operational debt.

06 — RoadmapFull roadmap →

Not finished. Said out loud.

20/ 30+ goals shipped

There's no backup system running today. If a node goes down, whatever lived only there is gone — not degraded, gone. That gap is public on purpose, and so is everything else still open.

  • Split the network into isolated zones
  • Build a complete CI/CD pipeline
  • Watch the whole stack — metrics and alerts
  • Turn SSO on for every service
  • Get backups running automatically
  • Make the monitoring stack survive a node dying
  • Move the hardware into a proper rack

Built in the open, mistakes included.

Every outage, wrong call, and unfinished piece gets written down where it happened — not smoothed over afterward.

— A.M.

GOT SOMETHING THAT NEEDS TO RUN?

If you're working on infrastructure, platforms, or services where reliability matters beyond day one, we'd like to hear what you're building.

Get in touch →