
Le Panthéon de la Souveraineté — Updated!
Infrastructure cloud modulaire, redondante et 100% souveraine pour s'affranchir des GAFAM. Guides techniques, architecture Zero-Trust et chiffrement interne (DoT/DoH)
🏛️ The Pantheon of Sovereignty
A 100% sovereign, redundant and secure cloud infrastructure, designed to completely break free from GAFAM. Version 1.1: Private network foundation, DNS request encryption for servers (DoT) and multi-datacenter backup architecture (Switzerland, Germany, Finland).
⚠️ Important Notices & Methodology
1. Project Context & Versioning
This project was born from a need for total sovereignty and follows an iterative evolution:
- Context: An infrastructure hosted mainly in Switzerland (Infomaniak), whose data is replicated in encrypted form on two secondary sites in Germany and Finland (Hetzner). No data rests on a single site.
- v1.0 (Foundations): Definition of the Private Network and Perimeter Firewall (HS-01 & HS-02). Foundation acquired. Servers communicate over the private network, but their resolution (DNS) queries can still transit in clear text.
- v1.1 (Current - Server Sovereignty): Native integration of DoT (DNS-over-TLS). Now, each server (like VULCAIN) encrypts its own DNS queries (updates, service resolution) to the AEGIS foundation. No server talks to DNS in clear text anymore, even on the private network.
- Under Consideration (mTLS): Study of a major hardening via mTLS (Mutual TLS) to authenticate services between each other. This track is still being studied and does not yet have an assigned version number.
2. Author Profile & Transparency
I am not a degreed IT professional. This project is the fruit of a passion for system administration, built through self-training over the past 5 years.
- Risk of error: Although I scrupulously rely on official documentation, I am not exempt from mistakes in understanding or interpretation.
- AI Assistance (EURIA & PROMÉTHÉE Duality):
- Currently: EURIA (Infomaniak) handles both documentation writing and technical assistance for commands and architecture.
- Future (PROMÉTHÉE Project): A dedicated local AI will take over purely technical aspects and sensitive automation, while Euria will focus on documentation and methodology.
- Note: Every command is human-verified.
- Ethical Posture: Immediate abandonment of any tool whose privacy policy is questionable.
3. Project Status & Warning
This project is in the active construction phase (v1.1).
- Documentation: Guides are written as the real deployment progresses.
- Service status:
- HS-01 (Private Network): 🚧 FINALIZATION (D-4). The network is already operational in production; the written guide is coming within 96 hours.
- HS-02 (Firewall): ✅ VALIDATED. Rule matrix v1.1 corrected (DNS closed inbound, ICMP outbound blocked).
- HS-03 (Gold Image): ✅ VALIDATED. Ready for creating the reference snapshot.
- VULCAIN: Being deployed (Priority #1). Will be configured to use DoT toward AEGIS.
- AEGIS: DoT/DoH architecture defined, ready for deployment.
- Backups (ARK): Multi-DC architecture (Switzerland, Germany, Finland) validated in the specs, being deployed.
- 🛑 WARNING: Do not deploy anything in production without validating each step in a test environment.
4. Limitation of Liability
Educational and personal project. The security of your data and the backup strategy are your full responsibility.
📜 Philosophy & Objectives
Demonstrate that it is possible to build a redundant, end-to-end encrypted and independent infrastructure.
The 3 Fundamental Pillars (v1.1):
- Sovereignty & Redundancy: Main hosting in Switzerland (Infomaniak) with backup replication in Germany and Finland (Hetzner).
- Security by Design (Server Encryption):
- Current (v1.1): The servers themselves encrypt their DNS queries via the DoT (DNS-over-TLS) protocol toward AEGIS.
- Flow Rule: Any non-essential outbound flow is strictly blocked by the firewall OR filtered at the DNS level.
- Future (mTLS Consideration): Potential implementation of mutual certificate-based authentication.
- Logical Deployment Order: Private Network → Entry Point (VULCAIN) → DNS Foundation (AEGIS) → Business Services.
🤝 The Assumed Trusted Third Parties
| Third Party | Role | Why this choice? | Sovereignty |
|---|---|---|---|
| Infomaniak 🇨🇭 | Main Hosting Provider | Data in Switzerland. DPA signed. Real ecology. | ✅ Total |
| Hetzner 🇩🇪 🇫🇮 | Secondary Hosting Provider (Backup) | Strict redundancy: Cold storage replicated across two DCs (Germany & Finland). | ✅ European |
| CrowdSec 🇫🇷 | Threat Intelligence | Community sharing of malicious IPs. | ✅ European |
| Certum 🇵🇱 | SSL & S/MIME Certificates | European authority, eIDAS compliant. Replaces Let's Encrypt. | ✅ European |
| Debian 🌍 | Operating System | Universal, stable, community-based base. | ✅ Open Standard |
| Docker 🇺🇸 | Containerization | De facto standard. Used without active telemetry. | ✅ Standard |
🗺️ Project Architecture (The 12 Deities)
| Order | Deity | Role | Validated Technology Stack | Origin | Status |
|---|---|---|---|---|---|
| 01 | VULCAIN 🔥 | Reverse Proxy & WAF | Traefik + CrowdSec + ALTCHA (PoW) | 🇫🇷/🇦🇹 | 🚧 In Progress |
| 02 | AEGIS 🛡️ | Sovereign DNS & VPN | WireGuard + AdGuard (DoH/DoQ) + Unbound (DoT + DNSSEC) | 🇺🇸/🇨🇾/🇳🇱 | ⏳ Coming Soon |
| 03 | ARGUS 👁️ | Monitoring | Grafana + Prometheus + Node Exporter | 🇸🇪/🇺🇸 | ⏳ Coming Soon |
| 04 | JANUS 🚪 | Identity & SSO | Bitwarden + Authentik (SSO)* | 🇺🇸/🇺🇸* | 📋 Audit to do |
| 05 | ARK 🗄️ | Multi-DC Backups | Restic + Swift (CH) + S3 (DE/FI) | 🇩🇪/🇨🇭/🇫🇮 | ✅ Validated |
| 06 | HERMÈS 📧 | (Pending) | - | ⚪ Blank | |
| 07 | MIDAS 💰 | Finances | (Pending) | - | ⚪ Blank |
| 08 | DIANE 🏹 | Maps & NTP | Valhalla + Photon | 🇩🇪 | ✅ Validated |
| 09 | VERITAS 🔍 | Search | SearXNG | 🇫🇷 | ✅ Validated |
| 10 | HÉPHAÏSTOS 🔨 | Git Forge | Forgejo | 🌍 | ✅ Validated |
| 11 | MNÉMOSYNE ☁️ | Cloud & Files | Nextcloud Hub | 🇩🇪 | ✅ Validated |
| 12 | PROMÉTHÉE 🔥 | Local AI | Ollama + Mixtral | 🇫🇷 | ✅ Validated |
🔍 Evolution Focus: From DoT to mTLS
- Version 1.1 (DoT): Each server encrypts its DNS queries toward AEGIS.
- Future Consideration (mTLS): Mutual certificate-based authentication for total Zero-Trust.
🧩 "Lego" Philosophy: Modularity & Universality
- 🏗️ Special Editions (Cloud-Specific): The foundation guides (Network, Firewall, Image) are designed specifically for the Public Cloud.
- 🌍 Universality of Deities: Once the foundation is in place, the installation guides are compatible with Public Cloud, VPS and Local.
The construction order (v1.1):
- Network Foundation (HS-01): The invisible foundation (finally in its place!).
- Firewall (HS-02): The walls and the reinforced door.
- Gold Image (HS-03): The secure system mold.
- Services: Deployed and connected.