Skip to main content

Infrastructure

The Dash runs on DigitalOcean infrastructure deployed inside a private Virtual Private Cloud (VPC), which keeps all platform traffic on an isolated internal network rather than the public internet. Compute, storage, and database resources are provisioned within this VPC using infrastructure-as-code, so every environment is reproducible, version-controlled, and auditable. 

Introduction & Scope

Document purpose, platform context, referenced documents

Infrastructure Overview

DigitalOcean account structure, region selection, environment topology (production / staging)

Network Architecture

VPC design, subnets, internal routing, egress control, firewall rules

DNS & Domain Architecture

sbsdash.com zone, three-subdomain tenant model, record inventory, DNSSEC

TLS & Edge Security

Certificate management, reverse proxy configuration, hardening headers

Compute & Application Layer

Droplet/container inventory, sizing, per-Compartment isolation mapping to infrastructure resources

Storage & Data Layer

Managed databases, object storage, volume encryption, data isolation boundaries

Secrets Management

Vault deployment, secret lifecycle, rotation policy, application integration

Identity & Access

IdP integration, SSO, SCIM provisioning, admin access paths, least-privilege model

Infrastructure as Code

IaC tooling, repository structure, change workflow, drift detection

Supply-Chain Controls

Image provenance, dependency pinning, artifact signing, registry policy

Observability

Monitoring stack, logging pipeline, alert routing, dashboards, health checks

Audit Infrastructure

Hash-chained audit log architecture, retention, integrity verification

Backup & Disaster Recovery

Backup schedule, RPO/RTO targets, restore procedures, DR test cadence

Capacity & Scaling

Baseline sizing, growth thresholds, scaling procedures

Maintenance & Patching

Patch windows, upgrade procedure, rollback

Appendices

Resource inventory, firewall rule table, acronym table, references (NIST SP 800-207, OWASP ASVS L2)