Logical flow from internet edge to persistent storage across 7 planes. Every inter-layer boundary enforces TLS, mTLS, or token-based authentication. Cluster: soc1–soc6 · Talos v1.12.6 · K8s v1.35.2.
All TLS certs derive from the Windows AD Root CA through Vault's intermediate engine. cert-manager automates issuance for all in-cluster services.