Back to updates
UpdatedJul 24, 2026

Le Panthéon de la Souveraineté — Updated!

Infrastructure cloud modulaire, redondante et 100% souveraine pour s'affranchir des GAFAM. Guides techniques, architecture Zero-Trust et chiffrement interne (DoT/DoH)

Share

🏠 Developed on: GitLab | 🪞 Automated mirror on: GitHub

🏛️ The Pantheon of Sovereignty

A 100% sovereign, redundant and secure cloud infrastructure, designed to completely break free from GAFAM. Version 1.1: Private network foundation, DNS request encryption for servers (DoT) and multi-datacenter backup architecture (Switzerland, Germany, Finland).

Version Status License Stack Privacy


⚠️ Important Notices & Methodology

1. Project Context & Versioning

This project was born from a need for total sovereignty and follows an iterative evolution:

  • Context: An infrastructure hosted mainly in Switzerland (Infomaniak), whose data is replicated in encrypted form on two secondary sites in Germany and Finland (Hetzner). No data rests on a single site.
  • v1.0 (Foundations): Definition of the Private Network and Perimeter Firewall (HS-01 & HS-02). Foundation acquired. Servers communicate over the private network, but their resolution (DNS) queries can still transit in clear text.
  • v1.1 (Current - Server Sovereignty): Native integration of DoT (DNS-over-TLS). Now, each server (like VULCAIN) encrypts its own DNS queries (updates, service resolution) to the AEGIS foundation. No server talks to DNS in clear text anymore, even on the private network.
  • Under Consideration (mTLS): Study of a major hardening via mTLS (Mutual TLS) to authenticate services between each other. This track is still being studied and does not yet have an assigned version number.

2. Author Profile & Transparency

I am not a degreed IT professional. This project is the fruit of a passion for system administration, built through self-training over the past 5 years.

  • Risk of error: Although I scrupulously rely on official documentation, I am not exempt from mistakes in understanding or interpretation.
  • AI Assistance (EURIA & PROMÉTHÉE Duality):
    • Currently: EURIA (Infomaniak) handles both documentation writing and technical assistance for commands and architecture.
    • Future (PROMÉTHÉE Project): A dedicated local AI will take over purely technical aspects and sensitive automation, while Euria will focus on documentation and methodology.
    • Note: Every command is human-verified.
  • Ethical Posture: Immediate abandonment of any tool whose privacy policy is questionable.

3. Project Status & Warning

This project is in the active construction phase (v1.1).

  • Documentation: Guides are written as the real deployment progresses.
  • Service status:
    • HS-01 (Private Network): 🚧 FINALIZATION (D-4). The network is already operational in production; the written guide is coming within 96 hours.
    • HS-02 (Firewall): ✅ VALIDATED. Rule matrix v1.1 corrected (DNS closed inbound, ICMP outbound blocked).
    • HS-03 (Gold Image): ✅ VALIDATED. Ready for creating the reference snapshot.
    • VULCAIN: Being deployed (Priority #1). Will be configured to use DoT toward AEGIS.
    • AEGIS: DoT/DoH architecture defined, ready for deployment.
    • Backups (ARK): Multi-DC architecture (Switzerland, Germany, Finland) validated in the specs, being deployed.
  • 🛑 WARNING: Do not deploy anything in production without validating each step in a test environment.

4. Limitation of Liability

Educational and personal project. The security of your data and the backup strategy are your full responsibility.


📜 Philosophy & Objectives

Demonstrate that it is possible to build a redundant, end-to-end encrypted and independent infrastructure.

The 3 Fundamental Pillars (v1.1):

  1. Sovereignty & Redundancy: Main hosting in Switzerland (Infomaniak) with backup replication in Germany and Finland (Hetzner).
  2. Security by Design (Server Encryption):
    • Current (v1.1): The servers themselves encrypt their DNS queries via the DoT (DNS-over-TLS) protocol toward AEGIS.
    • Flow Rule: Any non-essential outbound flow is strictly blocked by the firewall OR filtered at the DNS level.
    • Future (mTLS Consideration): Potential implementation of mutual certificate-based authentication.
  3. Logical Deployment Order: Private Network → Entry Point (VULCAIN) → DNS Foundation (AEGIS) → Business Services.

🤝 The Assumed Trusted Third Parties

Third PartyRoleWhy this choice?Sovereignty
Infomaniak 🇨🇭Main Hosting ProviderData in Switzerland. DPA signed. Real ecology.✅ Total
Hetzner 🇩🇪 🇫🇮Secondary Hosting Provider (Backup)Strict redundancy: Cold storage replicated across two DCs (Germany & Finland).✅ European
CrowdSec 🇫🇷Threat IntelligenceCommunity sharing of malicious IPs.✅ European
Certum 🇵🇱SSL & S/MIME CertificatesEuropean authority, eIDAS compliant. Replaces Let's Encrypt.✅ European
Debian 🌍Operating SystemUniversal, stable, community-based base.✅ Open Standard
Docker 🇺🇸ContainerizationDe facto standard. Used without active telemetry.✅ Standard

🗺️ Project Architecture (The 12 Deities)

OrderDeityRoleValidated Technology StackOriginStatus
01VULCAIN 🔥Reverse Proxy & WAFTraefik + CrowdSec + ALTCHA (PoW)🇫🇷/🇦🇹🚧 In Progress
02AEGIS 🛡️Sovereign DNS & VPNWireGuard + AdGuard (DoH/DoQ) + Unbound (DoT + DNSSEC)🇺🇸/🇨🇾/🇳🇱⏳ Coming Soon
03ARGUS 👁️MonitoringGrafana + Prometheus + Node Exporter🇸🇪/🇺🇸⏳ Coming Soon
04JANUS 🚪Identity & SSOBitwarden + Authentik (SSO)*🇺🇸/🇺🇸*📋 Audit to do
05ARK 🗄️Multi-DC BackupsRestic + Swift (CH) + S3 (DE/FI)🇩🇪/🇨🇭/🇫🇮✅ Validated
06HERMÈS 📧Email(Pending)-⚪ Blank
07MIDAS 💰Finances(Pending)-⚪ Blank
08DIANE 🏹Maps & NTPValhalla + Photon🇩🇪✅ Validated
09VERITAS 🔍SearchSearXNG🇫🇷✅ Validated
10HÉPHAÏSTOS 🔨Git ForgeForgejo🌍✅ Validated
11MNÉMOSYNE ☁️Cloud & FilesNextcloud Hub🇩🇪✅ Validated
12PROMÉTHÉE 🔥Local AIOllama + Mixtral🇫🇷✅ Validated

🔍 Evolution Focus: From DoT to mTLS

  • Version 1.1 (DoT): Each server encrypts its DNS queries toward AEGIS.
  • Future Consideration (mTLS): Mutual certificate-based authentication for total Zero-Trust.

🧩 "Lego" Philosophy: Modularity & Universality

  • 🏗️ Special Editions (Cloud-Specific): The foundation guides (Network, Firewall, Image) are designed specifically for the Public Cloud.
  • 🌍 Universality of Deities: Once the foundation is in place, the installation guides are compatible with Public Cloud, VPS and Local.

The construction order (v1.1):

  1. Network Foundation (HS-01): The invisible foundation (finally in its place!).
  2. Firewall (HS-02): The walls and the reinforced door.
  3. Gold Image (HS-03): The secure system mold.
  4. Services: Deployed and connected.

Categories