Skip to main content

Digital Workplace β€” architecture & the Nextcloud Hub decision

The ktayl-solution IS runs a self-hosted M365 alternative β€” the "digital workplace" (GitHub Projects board #10, home repo ktayl-workplace). This page is the map: what replaces what, the deliberate best-of-breed design, and a recorded decision on Nextcloud Hub (why we do not consolidate onto it today). It fits the BYOD / browser-first posture (see the EA Blueprint scope boundary).

The architecture principle β€” browser-first, data-server-side, identity-enforced​

The whole workplace follows one constraint, now codified as an auto-loaded platform rule (.claude/rules/workplace-architecture.md) so every new user-facing app inherits it:

The enterprise operates a browser-first BYOD workplace. Employee endpoints are considered UNTRUSTED and are not centrally managed. Security is enforced primarily at the identity, session, application, API and data layers. Corporate information should remain server-side whenever possible, with web-based collaboration preferred over local synchronization or storage. Strong authentication, fine-grained authorization, auditability, data classification and restricted handling of sensitive information are foundational architectural requirements.

DEVICE = UNTRUSTED β†’ identity is the perimeter. Every user-facing app must clear eight admission requirements: (1) SSO via Authentik only (proxy/forward-auth for non-OIDC apps); (2) group-gated authz β€” never "any authenticated user" (membership governed by ktayl-iam dual-approval; ABAC for cross-border domains); (3) session controls sized to sensitivity + passkey; (4) data stays server-side (in-browser edit over download); (5) honour data classification (INTERNAL/CONFIDENTIAL/RESTRICTED); (6) auditable to who Β· when Β· where Β· app Β· action Β· resource; (7) default-deny egress + private datastores; (8) no device-trust assumptions.

Out of scope by consequence (the BYOD boundary): Intune Β· Fleet/osquery Β· MDM Β· device enrollment Β· remote wipe Β· endpoint config. The residual BYOD risk (local copy / screenshot) is mitigated by keeping data server-side + a sensitive-workforce tier (browser isolation / VDI for finance-approval, legal, exec docs), not by managing the device.

What replaces M365 (deployed today)​

Everything below is deployed and running, each behind Authentik SSO + MFA, reached over Tailscale / Cloudflare β€” an intentionally BYOD, zero-trust shape.

M365 capabilityktayl toolNotes
OneDrive / SharePoint (files)Nextcloudfile storage + sharing
Word/Excel/PowerPoint (office)Nextcloud + ONLYOFFICEin-browser document editing
Teams β€” chatMatrix (Synapse) + Elementfederated chat
Teams β€” video/meetingsJitsi Meetconferencing
Outlook β€” mail (server)StalwartSMTP/IMAP/JMAP mail server; SES outbound relay
Outlook β€” calendarNextcloud Calendarβœ… enabled (v6.5.1); CalDAV live at /remote.php/dav
Outlook β€” contactsNextcloud Contactsβœ… enabled (v8.7.4); CardDAV live
E-signatureDocuseal(not an M365 feature, but part of the workplace)
Automation / flows (Power Automate)n8nlow-code integration
Identity (Entra ID / SSO)Authentikthe sovereign workforce IdP

Design principle: best-of-breed, not a suite. Each capability is the strongest self-hostable OSS tool for that job, unified by SSO rather than by one monolith. This is a deliberate choice β€” see the Nextcloud Hub decision below for the trade-off.

Gaps (honest)​

  • Calendar + Contacts β€” already deployed and working (verified 2026-09-18): Nextcloud Calendar 6.5.1 + Contacts 8.7.4 are enabled, CalDAV/CardDAV endpoints return 401 (healthy, auth-required) at cloud.devandre.sbs/remote.php/dav. Users can manage calendars/contacts in the Nextcloud UI and sync them to phone/desktop clients. (An earlier draft of this doc wrongly listed these as a gap β€” corrected.)
  • Mail delivery β€” resolved (2026-09-18). During the swift-mac outage aftermath, external send and receive were briefly broken. Root causes were not Stalwart: outbound needed SES-direct (swift-mac PM); inbound was a bug in the ses-inbound bridge (relaying external recipients β†’ Stalwart rate-limit storm), fixed in the bridge (inbound mail stall PM). Mail is now working both directions, with SPF+DKIM+DMARC aligned via a custom MAIL FROM. A transport problem, since resolved β€” not a workplace-architecture problem.
  • The real open gap is the DATA LAYER (not app access). The BYOD model protects application access very well and data-after-it-reaches-the-device barely β€” the known trade-off of browser-first BYOD. Outstanding, in priority order: (1) data classification β†’ file-handling tiers (INTERNAL/CONFIDENTIAL/RESTRICTED) applied to Nextcloud β€” hardening public/anonymous/external share, desktop/mobile sync limits, web-only for RESTRICTED (top regulated-insurer item, DORA/GDPR evidence); (2) RBAC β†’ ABAC (country / line-of-business attribute checks) for International Programs, into ktayl-iam; (3) passkey/WebAuthn + per-app session tiers in Authentik; (4) a sensitive-workforce tier (browser isolation / VDI); (5) a unified audit/SOC plane (Authentik + app + Falco β†’ one queryable view). These are the honest next steps, tracked against the workplace board (#10).

Decision: Nextcloud Hub β€” evaluated, NOT adopted (2026-09-18)​

Nextcloud Hub is the all-in-one Nextcloud bundle (Files + Office + Talk chat/video + Mail client + Calendar/Contacts + Deck/Notes…). It's the closest single-product M365 equivalent, and a reasonable default for a greenfield self-hosted workplace.

Why we do NOT consolidate onto it here:

  1. Most of Hub is already deployed as best-of-breed β€” Files+Office (Nextcloud/ONLYOFFICE), chat (Matrix), video (Jitsi) all exist and work. Adopting Hub's Talk/Mail would duplicate capability, not add it β€” with real migration cost and a period of two-tools-for-one.
  2. Best-of-breed is stronger per-capability. Matrix (federated, portable) > Nextcloud Talk for chat; Jitsi is a dedicated conferencing stack; Stalwart is a full mail server. Hub's versions are convenient but generally less capable.
  3. Nextcloud Mail does not fix mail. It is a webmail client, not a server β€” it still needs Stalwart/SES underneath. It would not resolve the current outage (gitops#1154); it only changes the inbox UI.
  4. SSO already provides the "one login" unification that Hub's main UX benefit promises β€” without a monolith.

What we DO take from the evaluation: Nextcloud's Calendar + Contacts β€” which turned out to be already enabled and working, so the workplace already covers that Outlook capability with no work needed.

Revisit trigger: reconsider full Hub consolidation if operational overhead of N separate tools becomes the bottleneck, or if a unified end-user UX becomes a hard requirement (e.g. real non-technical employees at volume). Until then, best-of-breed + SSO is the standard. Apply the cloud-adoption.md need-first gate logic: don't consolidate for uniformity's sake.

Where the detail lives​