Zero-ingress fleet — Oracle dev box + GCP Vaultwarden

Zero-ingress fleet — Oracle dev box + GCP Vaultwarden A architecture diagram generated by Archify. Oracle Cloud A1.Flex GCP e2-micro Browser · clients · Architecture component Browser clients Cloudflare edge · Zero Trust + Tunnel · Architecture component Cloudflare edge Zero Trust + Tunnel cloudflared · outbound · Oracle Cloud A1.Flex cloudflared outbound Oracle dev box · Ubuntu 24.04 · ttyd + DSH · Oracle Cloud A1.Flex Oracle dev box Ubuntu 24.04 · ttyd + DSH cloudflared · outbound · GCP e2-micro cloudflared outbound GCP Vaultwarden · loopback :8000 · GCP e2-micro GCP Vaultwarden loopback :8000 HTTPS tunnel loopback tunnel loopback Legend Cloud External

Oracle

  • • Dev box: ttyd, DSH, Hermes container
  • • Admin over the tunnel only

GCP

  • • Vaultwarden on loopback :8000
  • • IAP-only SSH, nightly backup

Posture

  • • No public listeners
  • • Outbound-only tunnels
  • • Emergency access = serial console / IAP