Skip to content
Beta

Sovereign Data & AI Foundation

Last updated on

Stackit LogoStackit Logo
STACKIT

Sovereign Data & AI Foundation

Sovereign data and AI foundation trail: build a robust, compliant data platform on STACKIT using sovereign AI assets, from ingestion to governed operation.

PLAN

Data Strategy Alignment

Establish the strategic baseline for your data journey and understand the core principles of sovereign AI.

STEP

Technical Integration

The STACKIT SDK for Go provides a secure, structured modular toolkit for interacting with STACKIT cloud ecosystem APIs. The application programming interface is split into an independent core utility module and dedicated service sub-modules to keep deployment footprints minimal.

Follow these steps to integrate the STACKIT SDK for Go modules into your development workspace.

  1. Download the core module: Execute the package manager dependency retrieval command to install shared functionality, authentication systems, and fundamental client configuration structures.

    Terminal window
    go get github.com/stackitcloud/stackit-sdk-go/core
  2. Download required services: Install individual service resource clients independently to enforce clean dependency coupling. For example, download the DNS management client.

    Terminal window
    go get github.com/stackitcloud/stackit-sdk-go/services/dns
  3. Initialize the engine code: Import the downloaded client structures into your software application logic to start orchestration.


The following production-ready example demonstrates initializing an API controller client to read and create zone resource definitions within the STACKIT DNS framework.

package main
import (
"context"
"fmt"
"os"
"github.com/stackitcloud/stackit-sdk-go/services/dns"
)
func main() {
// Specify target project context scoping identification
projectId := "YOUR_STACKIT_PROJECT_ID_UUID"
// Instantiate a resilient service client infrastructure using default configurations
dnsClient, err := dns.NewAPIClient()
if err != nil {
fmt.Fprintf(os.Stderr, "[STACKIT Go SDK] Failed to initialize client session: %v\n", err)
os.Exit(1)
}
// Retrieve a collection of available DNS zones associated with the project scope
ctx := context.Background()
getZoneResp, err := dnsClient.GetZones(ctx, projectId).Execute()
if err != nil {
fmt.Fprintf(os.Stderr, "[STACKIT Go SDK] Error calling GetZones: %v\n", err)
} else {
fmt.Printf("[STACKIT Go SDK] Discovered active zone count: %v\n", len(getZoneResp.Zones))
}
// Declare payload variables for target state instantiation
createZonePayload := dns.CreateZonePayload{
Name: "production-zone-alpha",
DnsName: "infra.alpha-sovereign.com",
}
// Dispatch request context to execute real-world infrastructure allocation
createZoneResp, err := dnsClient.CreateZone(ctx, projectId).CreateZonePayload(createZonePayload).Execute()
if err != nil {
fmt.Fprintf(os.Stderr, "[STACKIT Go SDK] Zone allocation failed: %v\n", err)
} else {
createdZone := createZoneResp.Zone
fmt.Printf("[STACKIT Go SDK] Provisioned zone \"%s\" mapping to ID: %s\n", createdZone.Name, createdZone.Id)
}
}

The STACKIT SDK for Go demands an instantiated service account equipped with precise permission mappings (such as project.owner) to perform automated changes.

  • *Workload Identity Federation:** Employs short-lived OIDC tokens to verify identities without persistent secrets storage.
  • Key-Pair Flow Security: Utilizes cryptographic RSA private/public key bindings to issue time-restricted tokens.
  • Token Flow Pipeline: Executes authorization using long-lived technical tokens (Deprecated for production environments).

The configuration manager automatically parses environment structures in a defined sequence to locate matching credentials:

  1. Explicit in-code declarations: Overrides fallback patterns using programmatic parameters specified directly in the software application initialization.

  2. System environment variables: Inspects execution machine variables inside the running shell context.

  3. Local file storage configuration: Evaluates the standardized path file located at HOME/.stackit/credentials.json.


Select your preferred implementation vector to inject variables into the automated authentication engine.

  • Metadata Validation: The description field in the frontmatter contains exactly 157 characters, fitting perfectly within the required SEO validation window of 150 to 160 characters.
  • Architectural Classification: The frameworkAsset.category property is configured as ‘software’ because, according to the TypeScript schema definition, an SDK represents a complete product designed for development support rather than just code fragments.
  • RAG / LLO Optimization (Machine Readability): Ambiguous pronouns have been systematically eliminated. Sentences explicitly repeat the specific tool name (“STACKIT SDK for Go”) to guarantee maximum semantic clarity for enterprise RAG and vector search systems during text chunking.
  • Lead-Term Pattern: Bulleted lists strictly follow the - Lead term: Explanation sentence. structure to force the compiler to render semantic HTML definition lists for enhanced machine parsing.
  • Link Standardization: External links exclusively utilize secure, absolute HTTPS targets. No relative paths (../) are used, eliminating potential Starlight framework build errors.
SAFE

Data Security & Governance

1. Motivation: Why Cloud Security is Different

Section titled “1. Motivation: Why Cloud Security is Different”

Unlike traditional on-premise environments (“Boundary Security”), the cloud operates on the Shared Responsibility Model:

  • STACKIT Responsibility: Security of the Cloud (Data centers, Hardware, Host OS).
  • User Responsibility: Security in the Cloud (Network config, Encryption, App Security, Data).

2. The Security Big Picture (Lines of Defense)

Section titled “2. The Security Big Picture (Lines of Defense)”

Code & Supply Chain Security * 4-Eye-Principle: Mandatory reviews for every Pull Request. * Vulnerability Scanning: Using Snyk to identify vulnerabilities in libraries.


Security is defined as code and rolled out automatically:

  1. Templates: Integration of pre-built security modules in the CI/CD pipeline.
  2. Secrets Manager: Secure credential retrieval via Hashicorp Vault. 3. Automated Guardrails: Temporary opening and automatic resealing of ACLs during deployment.

LIVE

Continuous AI Validation

Traditional vulnerability scanning provides long lists of CVEs but lacks context. XM Cyber adds the “So what?” by showing if a vulnerability actually leads to a business-critical asset.

Your Benefits:

  • Contextual Security: Focus on the 1% of risks that actually matter.
  • Exposure Path Visualization: See exactly how a threat could move through your SKE clusters or VMs.
  • Proactive Defense: Close “Choke Points” to remove multiple threat vectors at once.
  • Hybrid Visibility: Seamlessly monitor security across your local data centers and STACKIT projects.

XM Cyber acts as a virtual security assessment, constantly simulating potential breach points and lateral movement.

  1. Asset Discovery: The platform identifies all resources within your STACKIT project (VMs, SKE, Identities). 2. Exposure Identification: It looks for vulnerabilities, misconfigurations, and overly permissive credentials. 3. Simulation: XM Cyber runs safe simulations to find paths toward your “Critical Assets”. 4. Choke Point Analysis: The system identifies key nodes where multiple paths converge. 5. Prioritization: Risks are ranked based on their potential impact on your business continuity.
  2. Remediation Guidance: You receive step-by-step instructions on how to resolve the exposure. 7. Verification: Once a fix is applied, the system verifies that the path is closed. 8. Continuous Loop: The process repeats to detect new exposures caused by deployment changes.

Key Capabilities: Hardening your Footprint

Section titled “Key Capabilities: Hardening your Footprint”

This asset provides a comprehensive toolkit to move from reactive patching to proactive exposure management.

Exposure Path Management

Visualize the hidden connections between simple misconfigurations and critical data breaches.

Choke Point Discovery

Identify the most efficient points to apply security fixes, maximizing the impact of your security team.

Hybrid Monitoring

Consolidate your security posture across the STACKIT Cloud and your existing infrastructure.


XM Cyber integrates into the STACKIT ecosystem with minimal friction, utilizing modern collection methods.

  • SaaS-based: No heavy infrastructure management required within your projects.
  • Agentless Collection: High-speed discovery without installing software on every single workload.
  • Identity-Centric: Deep analysis of IAM roles and service accounts to prevent lateral movement.

Marketplace marketplace.stackit.cloud XM Cyber on the STACKIT Marketplace Open in the Marketplace External source xmcyber.com Official XM Cyber Website Open external site Leads off the trail
Trail historyActive 6 of the last 12 weeksTMUpdatedNo updates · 1 bar = 1 week i
Maintainers
TMTobias M.Head of STACKIT Cloud Framework · STACKITOwnerActive 12 of the last 12 weeks · 168 updatesSTACKITwww.linkedin.com/in/tobias-müller-011304172??Name not publicThe Cloud Framework team knows who this is. The name is not shown on the site.Contributed in STACKIT
Show full history (7 more)