Reference documentation of the openEduSuite system architecture β Kubernetes orchestration, SAML federation, SSO, storage and component alternatives.
Persistent storage, database backends, S3 object storage with SeaweedFS, backup integration, and data lifecycle β from storage classes to k8up/restic backups.
How openEduSuite ships Typst as a first-class document typesetting service β upstream-tracked fork, multi-arch container images, HTTP render API, and deployment as a suite service for theses, exams, lecture notes, and administrative letters.
How the openEduSuite intercom-service brokers browser-based cross-application communication β OIDC session handling, silent login, portal navigation, file picking and video rooms β and how it integrates with the suite's identity and application layers.
A companion technical document. Detailed capacity planning for deployments of any scale, and the governance model for operating an openEduSuite platform.
The complete authentication chain in openEduSuite β from DFN-AAI federation through Keycloak SSO to SAML and OIDC service connections, attribute mapping, and multi-IdP scenarios.
How network traffic enters the openEduSuite cluster, traverses DNS, TLS termination, ingress routing, and network policies to reach services β the complete traffic flow path.
The security architecture of openEduSuite β secret management with SOPS and age encryption, network policies, RBAC, audit logging, and compliance framework mapping to BSI IT-Grundschutz, GDPR, and ISO 27001.
Compare the alternative components available in openEduSuite, including email, video conferencing, file storage, and whiteboard solutions.
An overview of the openEduSuite system architecture, including Kubernetes orchestration, SAML federation with DFN-AAI and eduGAIN, unified Keycloak SSO, and the full service catalog.