Platform & secure deployment
A controlled path from users to models.
A self-hosted platform for an enterprise environment where sensitive data could not be sent directly to public model APIs.
What I built
- LiteLLM as the single model gateway and Open WebUI as the user surface
- nginx with TLS termination and SSO through Microsoft Entra ID
- Four services operated independently, with only ingress exposed publicly
- Separate databases and database users per service
- Documented proxy handling for both the container runtime and image registry
Design decision
Identity, routing and policy stay at the platform boundary instead of being reimplemented inside each AI application.
Proof
Designed and delivered end to end; running in production with deployment runbooks, systemd units, GitLab CI and an operations cheatsheet.



