Skip to content
Open access

Efficiency and Security Analysis of Self-Hosted Cloud Storage: A Containerized ZTNA, Docker, and PostgreSQL Approach

Aug 2026 · Jurnal Teknik Informatika (Jutif) · Vol 7, pp. 3246-3257 · 0 citations

TL;DR

A secure, containerized self-hosted cloud architecture integrating Nextcloud, PostgreSQL, and Docker, secured via a Zero Trust Network Access (ZTNA) tunnel to achieve a "Closed-Default" security posture is proposed.

Abstract

The enforcement of digital sovereignty mandates, specifically Indonesia's Government Regulation No. 71 of 2019, necessitates the adoption of private cloud infrastructures that facilitate strict data localization; however, traditional bare-metal deployments may exhibit less flexibility, while typical containerized solutions may not fully address the database integrity required for institutional scale1. This study proposes a secure, containerized self-hosted cloud architecture integrating Nextcloud, PostgreSQL, and Docker, secured via a Zero Trust Network Access (ZTNA) tunnel to achieve a "Closed-Default" security posture. To evaluate this architecture, the system was validated against a traditional bare-metal LAPP (Linux, Apache, PostgreSQL, PHP) stack using a novel Resource Efficiency Index (REI) designed to quantify the computational overhead of compliance alongside network throughput analysis over 50 iterations. Empirical results indicate that while the containerized architecture incurs a tangible virtualization overhead, resulting in a lower Resource Efficiency Index (69.44 vs. 83.51), it maintains statistical performance parity in network throughput (p > 0.05). Furthermore, the proposed architecture achieves superior CPU optimization (0.97% vs. 1.15%) and structurally reduces external attack surfaces. These findings provide a compliant, reproducible blueprint for Indonesian institutions, demonstrating that.

Read PDF

Similar papers

Open access Aug 2026

On the Resilience of Secure Remote-Access VPN Solutions: A System-Level Evaluation of WireGuard, OpenVPN and IPsec (strongSwan)

R resilience in remote-access VPNs should be interpreted as a system-level property emerging from the interaction of implementation architecture, endpoint characteristics, and deployment conditions, underline that resilience in remote-access VPNs should be interpreted as a system-level property emerging from the intera...

Rene Forsung, R. Pirmagomedov, A. Mezina et al. · 0 citations
#data science Open access Oct 2026

Zero Trust for SQL Server: A Three-Layer Security Architecture

This study designed and empirically validated a three-layer Zero Trust architecture for Microsoft SQL Server that natively integrates instance-level authentication governance, enhanced Role-Based Access Control with Row-Level Security and Just-in-Time privilege elevation, and metadata-driven Attribute-Based Access Cont...

Maynard Capil, D. Dasig · 0 citations
Conference Aug 2026

Zero Trust–Driven Security Orchestration: An API-Centric Framework for Integrating IAM, PAM, and SIEM in Hybrid Cloud Environments

The disintegration of the traditional network perimeter, precipitated by the accelerated adoption of hybrid cloud architectures and the proliferation of remote work, has necessitated a fundamental shift in cybersecurity strategy. This research presents an API-centric framework for security orchestration, grounded in th...

Sunnykumar Kamani · 0 citations
Review Open access Aug 2026

Cloud-Native Identity and Access Management for Enterprise Platforms

A four-plane theoretical model can be introduced to separate authentication, authorization reasoning, enforcement, and auditability into four closely coupled but independent evolving planes for the system, providing a unified point of reference for both researchers and practitioners in the field of secure and scalable...

Ravi Kumar Kotapati · 0 citations
Open access Aug 2026

Cloud in the crosshairs: exposing vulnerabilities in web-based management interfaces of open-source IaaS platforms

This study conducts a large-scale empirical security analysis of the web-based management interfaces of ten widely used open-source Infrastructure-as-a-Service (IaaS) platforms, identifying 16 vulnerabilities spanning nine classes, including high-severity flaws that enable account takeover.

Alexandros Perrakis, Efstratios Chatzoglou, Vyron Kampourakis et al. · 0 citations
Conference Aug 2026

A Multi-Layer Zero Trust Security Framework for Kubernetes

Kubernetes is a powerful container orchestration platform. However, its clustered nature expands the attack surface across workload identity, runtime security, network, and secret management layers. Existing Zero Trust solutions for Kubernetes are layer-specific, creating opportunities for attackers to bypass one contr...

M. Shakishnavi, K. P. N. Jayasena, S. Nishankar · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.