The 5-Zone Topology.

A hierarchical trust model designed for resilience and security.

Opplet 5-Zone Architecture Diagram

Fig 1.0 - Logical Zone Segmentation

Zone Definitions

ZONE 0 :: UTILITY (ROOT)
Role: Critical Infrastructure.
Hardware: 3x Hetzner Cloud VPS (Cluster).
Services: OpenLDAP (Identity Root), Grafana/Loki (Observability), Tailscale Gateway (Ingress).
ZONE 1 :: SOVEREIGN (PRIVATE)
Role: Owner's Private Suite.
Hardware: Isolated Bare Metal (Auction Server).
Security: Local Authentication Only. Air-gapped from Learner traffic.
Services: n8n (Logic Brain), Nextcloud, Finance.
ZONE 2 :: GOVERNANCE (CORP)
Role: Management Plane.
Hardware: Hetzner Dedicated AX52.
Services: Authentik (SSO Federation), Proxmox VE Host.
ZONE 3 :: COMMUNITY (PROD)
Role: Collaborative Workspace.
Access: Authenticated via Zone 2 SSO.
Services: GitLab CE, Jitsi, Discourse, HumHub.
ZONE 4 :: ACADEMY (SIMULATION)
Role: Untrusted Sandbox.
Network: Internal Simulation (RFC-Compliant Mail/DNS). Egress Blocked.
Services: Learner VMs (Root Access).