Trusted Infrastructure Demonstrations

Le Lab : Sovereign Engineering

Local AI, secured software supply chain, and native efficiency. Each PoC below is industrially validated and designed to solve sovereignty and budget optimization challenges for modern organizations.

1
AI Ops & Confidentiality

KubeLens: Kubernetes Incident Diagnostics via Sovereign AI

A live demonstration of a local Small Language Model (SLM) capable of analyzing error logs and correlating data with internal documentation (RAG). A sovereign, fast, and eco-designed alternative to externalized SaaS AI platforms.

Scaleway KapsuleQwen 0.5B (CPU)OllamaQdrant
Local CPU Inference Engine
Awaiting logs to start inference
The result will be streamed in real time by the local SLM.
Absolute Privacy
The model runs entirely local: sensitive logs and data never leave your trusted ecosystem.
Lean & Low-Cost Inference
Optimized to run natively on standard CPUs. No prohibitive GPU costs or unnecessary carbon emissions.
Local Business Context
Secure indexing and querying of internal technical guides via the Qdrant vector database.
2
Infrastructure as Code

IaC Industrialization & Drift Management

How to automate and standardize the complete lifecycle of a resilient cloud-native infrastructure. This demonstration implements strict guardrails to validate and secure production resource provisioning.

Infrastructure as CodeScaleway ARM64OpenTofu
OpenTofu Immutable Provisioning
Industrial Automation
Fully standardized, modular, and reproducible infrastructure rollouts using clean code, permanently eliminating manual interventions (ClickOps).
ARM64 Optimization
Systematic architecture validation on Scaleway ARM64 instances, delivering a price-performance ratio natively superior to traditional x86 topologies.
Zero Drift
Absolute compliance guarantee. Integration of automated validation and security auditing (IaC) pipelines into every commit within GitLab CI/CD.
3
Software Supply Chain & Zero Trust

Isolated Hybrid GitOps: Cloud deployment without public exposure

Automated continuous deployment via ArgoCD bridging an internal on-premise software forge and a Cloud cluster. Absolute protection against supply chain tampering and external access cuts.

Forge Isolée (On-Premise)Tailscale NAT TraversalArgoCD
ArgoCD Reconciliation Engine
Tailscale Private Networking
Infrastructure interconnection via an encrypted mesh. No firewall ports are opened to the public internet (full NAT Traversal).
Zero Secret Storage
Leveraging External Secrets Operator. Sensitive tokens remain encrypted and are injected dynamically from the cloud Secret Manager.
Disruption Resilience
Intellectual property (code) remains hosted on local hardware; only operational deployments utilize the Cloud environment.
4
Observability & Networking

Traefik Tailnet Monitor: High Availability & Network Metrics

Real-time, centralized monitoring of traffic passing through the routers of a decentralized private mesh network. This PoC demonstrates the ability to correlate network load and isolate anomalies.

TraefikPrometheusTailscaleK3s
Prometheus Metrics Collector
Communication Link StatusLink Disrupted
Local ProbePrometheus Scraper
Measurement PointTraefik Mesh Edge
Last Scrape--:--:--
Live Polling
Awaiting data from collector
Performance metrics will appear after the first valid communication handshake.
MTTR Reduction
Chirurgical alerting and KPI mapping designed to isolate network root causes in less than 3 minutes.
Multicloud Visibility
Unified centralization of traffic flowing from both physical (On-Premise) infrastructure and remote Cloud instances into a single pane of glass.
Performance Alerting
Instant identification of routing anomalies, bottlenecks, or traffic spikes to preempt infrastructure performance degradation.