Technical Architecture
The exact architecture is stated in the Order or technical handoff. A typical environment may use third-party cloud infrastructure, Linux, Docker containers, a deployment platform, reverse-proxy routing, automated TLS certificates, and external DNS. Components can change as services, provider products, and workload requirements evolve.
Typical Components
| Layer | Possible implementation |
|---|---|
| Infrastructure | Hetzner virtual or dedicated servers where identified in the Order |
| Operating system | A supported Linux distribution |
| Application packaging | Docker containers |
| Deployment and orchestration | Dokploy and related container tooling |
| Routing and TLS | Reverse proxy with ACME-compatible certificate issuance |
| DNS and edge services | A third-party DNS or proxy provider such as Cloudflare |
| Data services | Application-specific relational databases, caches, queues, or object storage |
This table is descriptive, not a commitment that every environment uses every component.
Security Boundary
Basic server hardening may include restricted network access, key-based administration, timely Provider-controlled updates, and separation between application workloads. No single control makes an environment secure, and container or server isolation does not eliminate application, credential, dependency, configuration, or third-party risk.
The customer remains responsible for application-level security, user access, business continuity, compliance requirements, and independent backups unless the Order expressly assigns a responsibility to Panther & Cub.
Monitoring and Backups
Monitoring, alerting, backup, retention, restore testing, disaster recovery, and incident response are included only when the Order identifies their scope, frequency, storage, contacts, and limits. Logs or provider snapshots created for another purpose do not establish a backup or monitoring service.
Data Location
Available provider regions and services can change. If data location matters, the Order should identify the approved region and any customer requirement. Selecting a region alone does not establish compliance with privacy, industry, or data-residency law.
Administrative Access
Administrative access is limited to the methods and people required for the service. Customer database or server access may require a secure tunnel, individual credentials, and additional controls. Access, handoff, and revocation should be documented for the specific environment.