Blueprints
Deployable operating patterns built from reusable modules. Choose a blueprint, then execute with policy profiles.
Featured Blueprints
Opinionated patterns for common HybridOps deployment goals.
Always-on edge control surface with Thanos query path, DNS cutover logic, and evidence-first decision output.
core/hetzner/edge-networkplatform/observability/thanos-edgeplatform/decision/serviceplatform/dns/cutover
Primary runtime on prem with policy-driven failover to cloud targets using deterministic module execution.
platform/rke2/onprem-clusterplatform/postgres/replica-targetplatform/dr/activateplatform/dns/failover
Normal operations on prem with event-based burst for peak windows, while keeping cost guardrails intact.
platform/moodle/baseplatform/burst/prewarmplatform/ingress/cutoverplatform/evidence/drill-report
Module Catalog
Reusable module families that compose the blueprints.
core/hetzner/edge-networkcore/identity/bootstrapcore/ipam/netbox-basecore/vpn/ipsec-bgp
platform/observability/thanos-edgeplatform/decision/serviceplatform/dns/cutoverplatform/dr/activate
workloads/keycloak/baseworkloads/nextcloud/baseworkloads/moodle/baseworkloads/academy/docsgpt
Execution Architecture
Operational topology used by the featured blueprints.
Full topology: on-prem primary runtime, always-on edge decisioning, event-driven cloud burst and DR. Hover any box for detail.
Prometheus scrapes on-prem cluster metrics and remote-writes them to the Thanos edge receiver for a global view.
The Decision service evaluates policy rules against aggregated Thanos metrics. If thresholds breach, it emits action signals.
DNS cutover module executes the traffic shift. Evidence envelopes are written to external object storage.
Cloud target cluster activates (warm or cold), DR data promotes, and failover ingress begins receiving traffic.
For detailed signal and control mapping, see the docs and ADR references in documentation.
Primitive chain
Every blueprint execution flows through the same four-primitive model.
WAN topology
Hetzner edge pair, BGP peering to GCP hub, and HA VPN tunnels — as deployed by the networking blueprints.