Zero-Trust Edge & Identity
Expose private AI services through centralized identity and outbound-only tunnel ingress.
Interactive platform map
Architecture in context
The focused blueprint, its required foundation, and declared recommendations.
Zero-Trust Edge & Identity
Expose private AI services through centralized identity and outbound-only tunnel ingress.
What this replaces
Self-hosted services commonly accumulate public ports, inconsistent login methods and ad-hoc per-app security.
What your team gains
A centralized edge with SSO, access policy, reverse-proxy controls and a tunnel architecture that does not require a publicly routable origin service port.
What is inside the blueprint
How it fits the platform
User -> Cloudflare network/tunnel -> Traefik -> Authentik authorization middleware -> protected application; origin initiates outbound tunnel connections.
cloudflared, Traefik, Authentik, authentik-worker, authentik-postgres, Redis
- AICORTEX Core PlatformThe edge terminates onto services Core deploys and routes.
From prerequisites to operation
- Domain/Cloudflare account
- Identity source/user model
- TLS and route inventory
- Create tunnel and routes
- Deploy Traefik routing
- Deploy Authentik server/worker/database/Redis
- Configure forward auth or OIDC per app
- Apply route-level policies
- Providers/flows
- Groups/policies
- SCIM/LDAP/SAML if needed
- Forward-auth mode
- Tunnel replicas
- Traefik middleware and health checks
- User lifecycle
- Credential/token rotation
- Tunnel health
- Proxy header trust
- Policy review
- Auth database backups
What this unlocks with other layers
Zero-Trust AI Service
Remote AI access without exposing origin service ports, with centralized authentication and behavioral remediation.