Deploying the MariaDB Privacy-First Stack Anywhere with Terraform

In my previous post, I introduced the MariaDB Privacy-First Stack.

Nextcloud for collaboration, Passbolt for passwords and secrets, and MariaDB Server for the data.

Simple enough.

But after explaining what the stack is, the next question is usually very practical:

Where can I deploy it?

And the answer should not be:

On the cloud provider the template was written for.

That would be a strange way to talk about digital sovereignty.

If the architecture is really meant to give you more control, you should also have some freedom regarding where it runs.

MariaDB Privacy-First Stack: Nextcloud, Passbolt and MariaDB Server

I hear this sentence a lot: “We care about privacy.”

Good.

But then you look a bit closer.

Files are on some cloud platform. Nobody is completely sure which settings were changed two years ago. Passwords are in browsers, in chat messages, sometimes in a document with a name like credentials-final-v3. Backups? “The provider handles that.” Maybe. Where is the data exactly? “In Europe, normally.” Who has access? That’s when the room becomes quiet.

I don’t call that a privacy strategy.

I call that hoping nothing goes wrong.