Goal: a practical, demo-ready stack that shows cloud-native patterns and compliance evidence end-to-end: IaC → policy → scans → artifacts → dashboard.
- Platform: Ubuntu Server Pro VM (hypervisor host) or any Linux VM
- K8s: containerd • Cilium (CNI) • ingress-nginx • Kata Containers (optional isolation)
- Build: Podman / Buildah (no Docker daemon)
- Data: Couchbase (local) or Couchbase Capella (managed)
- App: Streamlit “Evidence Dashboard”
- Policy/Scans: OPA/Conftest • Checkov • Trivy/Grype • Bandit • Gitleaks • Syft (SBOM)
- Observability: Loki + Grafana (optional)
- LLM (optional): Amazon Bedrock / Google Gemini → human-readable findings
- Datasets: synthetic (Synthea / Data4Citizen)
This repo is designed to run fully local (zero cloud bill) and optionally on AWS/K8s later.
- Architecture
- Repo Layout
- Quick Start (Local)
- GitHub Actions Workflows
- Kubernetes (Optional)
- Couchbase & Capella
- LLM Summaries (Bedrock/Gemini – Optional)
- Compliance Evidence
- Make Targets
- Secrets
- Notes & Credits
flowchart LR
%% ===== Build & CI =====
subgraph CI[Build & CI]
Dev[Podman/Buildah] --> Img[Container Image]
CIpipe[GitHub Actions CI]
Policy[OPA/Conftest & Checkov] --> Evidence[(evidence/*.json)]
SecScan[Trivy/Grype\nBandit/Gitleaks\nSyft SBOM] --> Evidence
Img -. "scan image" .-> SecScan
CIpipe --> Policy
CIpipe --> SecScan
end
%% ===== Infrastructure =====
subgraph Infra[Infrastructure]
IaC[Terraform] -->|plan/apply| Cloud[(LocalStack/AWS)]
end
%% ===== Data =====
subgraph Data
Couch[(Couchbase / Capella)]
end
%% ===== App Layer =====
subgraph App[App Layer]
AppUI[Streamlit Evidence Dashboard]
end
%% ===== Flows =====
Evidence --> AppUI
Couch --> AppUI
AppUI -->|Ingress| K8s[(Kubernetes\ncontainerd + Cilium + ingress-nginx)]
Kata[Kata Containers] --- K8s
K8s --> Logs[(Loki/Grafana)]
%% ===== Readable cylinder styles (dark/light friendly) =====
style Evidence fill:#1f2937,stroke:#93c5fd,stroke-width:1.6px,color:#eef2ff
style Cloud fill:#1f2937,stroke:#93c5fd,stroke-width:1.6px,color:#eef2ff
style Couch fill:#1f2937,stroke:#93c5fd,stroke-width:1.6px,color:#eef2ff
style K8s fill:#1f2937,stroke:#93c5fd,stroke-width:1.6px,color:#eef2ff
style Logs fill:#1f2937,stroke:#93c5fd,stroke-width:1.6px,color:#eef2ff