Skip to main content

Third-Party Application Integration

Most of the applications running on this platform are third-party software — I did not write ERPNext, Authentik, or Vault. But deploying, integrating, configuring, hardening and operating them into a coherent, governed information system is real engineering work, and it is version-controlled and auditable. This page is the engineer's view of that fleet: for each app, what I actually did and where the evidence lives.

:::note This is an integration view, not a business catalog For what each application does for the business (functional domains, the IARD insurer model, coverage and build order), see the Business Applications Catalog and the EA Blueprint. This page instead answers "what engineering did the operator do to each off-the-shelf app?" :::

How to read the "What I did" column — verbs, not ownership​

I never claim to have built a third-party app. The honest, and still substantial, verbs are:

VerbMeaning
DeployedPackaged as a GitOps-delivered Helm release (ArgoCD app + version-pinned helm-values), dev/prod overlays
SSOIntegrated with Authentik as the identity provider (OIDC or forward-auth) + MFA
SecretsSecrets sourced from Vault via External Secrets Operator (ESO) — no plaintext in Git
TLSCertificates issued by cert-manager (internal CA / Let's Encrypt); ingress + NetworkPolicy
ConfiguredTuned to a real domain (e.g. ERPNext → French PCG 2025 / TSCA / Factur-X)
Custom codeI wrote code around the app — a custom image or an integration service (own repo)
Backup/DRVelero + object-storage backups, restore-tested
HardenedGatekeeper policies, PSA, egress default-deny, image scanning

The uniform pattern applied to (almost) every app on the fleet: GitOps-delivered Helm · Authentik SSO + MFA · ESO/Vault secrets · cert-manager TLS · default-deny NetworkPolicies · Velero backup. That repeatable "off-the-shelf chart → governed, SSO'd, backed-up service" pipeline is the capability this page evidences.


Digital workplace (the M365 / Google-Workspace alternative)​

AppWhat I didCustom code?Evidence
Stalwart MailDeployed; configured SMTP/IMAP/JMAP; wired Amazon SES outbound relay + the inbound SES→S3→SQS pipeline; Alertmanager STARTTLS integration—helm-values/…/…, apps/workloads/stalwart.yaml; docs: Collaboration / Mail
Matrix Synapse + ElementDeployed; Authentik OIDC SSO; dedicated postgresql-synapse; federation config—apps/workloads/matrix-synapse.yaml, helm-values/…/synapse-values.yaml
Jitsi MeetDeployed; JVB on hostNetwork (pinned node) for WebRTC; Authentik forward-auth—apps/workloads/jitsi.yaml, helm-values/…/jitsi-values.yaml
Nextcloud + OnlyOfficeDeployed; Authentik OIDC (user_oidc auto-provision); document editing✅ OnlyOffice (minicloud-onlyoffice — CA cert + NODE_EXTRA_CA_CERTS)apps/workloads/nextcloud.yaml
DocusealDeployed; e-signature (eIDAS Simple); insurance templates—apps/workloads/docuseal.yaml

Business applications​

AppWhat I didCustom code?Evidence
ERPNext / FrappeDeployed; configured for a French insurer — 845-account PCG 2025 chart, TSCA tax templates, Factur-X Minimum PoC; HR as source of truth✅ minicloud-erpnext — custom DSN + SEPA payroll apps (erpnext_dsn, erpnext_sepa), 108 unit tests / ~76% coverageapps/workloads/erpnext.yaml, helm-values/…/erpnext-values.yaml
Plane CEDeployed; project management for non-technical stakeholders✅ minicloud-plane — Go API + webhook→NATS bridge + Backstage pluginapps/workloads/plane.yaml
n8nDeployed; workflow automation (5Gi RWO)—apps/workloads/n8n.yaml
TemporalDeployed; durable workflow engine; PostgreSQL backend; Authentik OIDC—apps/workloads/temporal.yaml

:::warning Honesty: installed ≠ operational Following the platform's "installed ≠ operational" rule (see HR Tooling), ERPNext HR is claimed precisely: the payroll modules (custom DSN/SEPA) are genuinely built + tested; Appraisal / Leave / Attendance / Job-Opening are installed but empty. Deploying an app is not the same as operating a populated business process, and this catalog says which is which. :::

AI platform (third-party components)​

AppWhat I didCustom code?Evidence
LiteLLMDeployed as the AI gateway; configured multi-provider routing, virtual keys, department budgets, Presidio PII/DLP pre-call hook, Prometheus cost metrics—apps/workloads/litellm.yaml, litellm-manifests.yaml
Open WebUIDeployed; Authentik OIDC; RAG chat✅ minicloud-open-webui — CA cert + French BM25 preprocessorapps/workloads/open-webui.yaml
LangfuseDeployed; Authentik OIDC; ClickHouse + Valkey analytics backend; traces every LLM call—apps/workloads/langfuse.yaml, helm-values/…/langfuse-values.yaml
Flowise / MLflow / QdrantDeployed; visual LLM flows / experiment tracking / vector store for RAG—ai namespace manifests

Platform & IS foundations (third-party)​

AppWhat I didCustom code?Evidence
AuthentikDeployed; it is the SSO/identity hub — configured OIDC + forward-auth providers for every other app, department RBAC, MFA enforced—apps/platform/authentik.yaml, helm-values/…/authentik-values.yaml
HashiCorp VaultDeployed; AWS KMS auto-unseal; PKI; Raft; the ESO backend for all platform secrets—apps/platform/vault.yaml, helm-values/…/vault-values.yaml
HarborDeployed; proxy-cache mirrors (docker/ghcr/quay/k8s) + tag-retention + scheduled GC; Trivy scanning—apps/platform/harbor.yaml, helm-values/…/harbor-values.yaml
Grafana + PrometheusDeployed (kube-prometheus-stack); Authentik OIDC; custom dashboards (LiteLLM cost, cert expiry, backup DR)—apps/platform/kube-prometheus-stack.yaml
Loki · Tempo · OTelDeployed; logs/traces pipeline; OTTL transforms; Alertmanager routing—apps/platform/{loki,tempo,otelcol}.yaml
BackstageDeployed; developer portal✅ minicloud-backstage — custom image, K8s/ArgoCD/TechDocs/Grafana plugins, Software Templatesapps/workloads/backstage.yaml
VaultwardenDeployed (Timshel fork for the SSO button); Authentik SSO; human credential store—apps/workloads/vaultwarden.yaml
ArgoCD · cert-manager · ESO · Cilium · Gatekeeper · Falco · KEDA · NATS · Velero · KargoDeployed + configured the GitOps, security, networking, autoscaling, messaging and backup control plane the whole fleet depends on—apps/platform/*.yaml

The takeaway​

Roughly 95 ArgoCD applications run on this platform; most are third-party charts. What makes the fleet a portfolio artifact isn't the software — it's that every app was taken from an off-the-shelf chart to a GitOps-delivered, SSO-gated, secrets-managed, TLS-terminated, network-isolated, backed-up service, and a handful were extended with real custom code in their own repos (minicloud-erpnext, minicloud-open-webui, minicloud-onlyoffice, minicloud-backstage, minicloud-plane). The version-controlled proof of the deployment + integration work lives in minicloud-gitops (apps/, helm-values/, services/).