πŸ“„ Candidroot

CyberMountain Execution Strategy v1.0

Why We Are Changing Our Approach

Author: Vikram Bhatnagar

Audience: CyberMountain Development Team (CandidRoot)

Status: Proposed Execution Strategy

Date: 29 July 2026

Executive Summary

After reviewing the Phase 1 architecture together with our current business situation, we have decided to adjust the execution strategy, not the target architecture.

The CyberMountain architecture remains our long-term target and is considered technically sound.

However, as a startup, our primary objective is to create customer value immediately while building a reusable deployment platform in parallel.

The platform should enable business growthβ€”not delay it.

Strategic Principle

Build revenue first. Build the factory in parallel. Automate what has already been proven.

CyberMountain is not the product.

CyberMountain is the deployment and operations factory that enables multiple customer environments to be deployed, operated and maintained consistently.

Our products are:

  • TEPA.swiss
  • Schwyz-Next
  • Kundi
  • Future customer platforms

CyberMountain exists to operate these products.

North Star

The objective is not to build a perfect platform.

The objective is to build a platform capable of operating many customers simultaneously.

Success is measured by:

  • Faster onboarding
  • Consistent deployments
  • Lower operational effort
  • Repeatability
  • Customer isolation
  • Security
  • Recoverability

Execution Model

                 Customer Value
                       β”‚
                       β–Ό
                TEPA.swiss Services
                       β”‚
                       β–Ό
             Real Customer Feedback
                       β”‚
                       β–Ό
      CyberMountain captures experience
                       β”‚
                       β–Ό
           Standardisation & Automation
                       β”‚
                       β–Ό
         Repeatable Customer Deployments

The business drives the platform.

The platform does not drive the business.

Guiding Principles

1. Every sprint must deliver business value.

Every development sprint should improve either:

  • customer experience
  • customer onboarding
  • customer operations
  • deployment automation

No sprint should deliver infrastructure only.

2. Infrastructure must directly reduce future deployment effort.

Every CyberMountain capability should answer:

How does this reduce the effort required to onboard the next customer?

If it does not, it is probably not Phase 1.

3. TEPA.swiss is our reference customer.

TEPA is not β€œspecial.”

It is simply our first production tenant.

Every improvement made for TEPA should become reusable for every future deployment.

Execution Tracks

Instead of building everything sequentially, we will execute three parallel tracks.

Track A – Customer Services

Highest business priority.

Deliver customer-facing functionality continuously.

Examples:

  • Supplier Portal
  • Export Verification
  • API Setu Integration
  • DigiLocker Integration
  • EntityLocker Integration
  • Odoo Modules
  • CRM Improvements
  • Helpdesk
  • Project Automation
  • Compliance Workflows

Deliverable:

Customer value.

Track B – CyberMountain Core

Highest technical priority.

Build only the foundation required to operate multiple customer environments.

Included:

  • Git / Forgejo
  • CI/CD
  • Keycloak
  • OpenBao
  • step-ca
  • Monitoring
  • Logging
  • Object Storage
  • Backup
  • DNS
  • Deployment Pipelines
  • Golden Images
  • Runbooks
  • Variable Management

Deliverable:

Repeatable deployments.

Track C – Enterprise Hardening

Lower priority during startup.

These capabilities remain part of the roadmap but are introduced when operational maturity requires them.

Examples:

  • Kyverno
  • Falco
  • Dependency Track
  • Advanced Supply Chain Security
  • PQC
  • CBOM
  • Advanced Cryptographic Policies
  • Advanced Admission Policies

Deliverable:

Enterprise maturity.

Customer Deployment Strategy

Every new customer shall be deployed using CyberMountain.

Current roadmap:

TEPA.swiss
        β”‚
        β–Ό
Reference Tenant

        β”‚

Schwyz-Next
        β”‚
First External Deployment

        β”‚

Kundi
        β”‚
Second External Deployment

        β”‚

Future Customers

Every deployment improves the platform.

TEPA.swiss Strategy

TEPA remains on the existing Odoo 18 platform while new services are developed.

Examples:

  • Supplier Verification
  • DigiLocker
  • EntityLocker
  • API Setu
  • Export Workflows
  • Customer Portals

This allows immediate customer value without delaying business.

TEPA will later migrate to CyberMountain once the platform has been validated by additional customer deployments.

CyberMountain Evolution

Phase 1

Minimum Viable Operations Platform

Focus:

  • identity
  • secrets
  • deployment
  • monitoring
  • backup
  • repeatability

Goal:

Support multiple isolated customer environments.

Phase 2

Deployment Factory

Introduce:

  • deployment automation
  • templates
  • tenant provisioning
  • reusable modules
  • infrastructure automation

Goal:

Deploy new customers consistently.

Phase 3

Enterprise Platform

Introduce:

  • advanced policy enforcement
  • runtime security
  • supply-chain security
  • compliance automation
  • advanced cryptographic controls

Goal:

Enterprise-scale operations.

Migration Strategy

We do not rebuild TEPA first.

Instead:

Existing TEPA
        β”‚
        β–Ό
Business Growth

        β”‚
        β–Ό
CyberMountain Matures

        β”‚
        β–Ό
Schwyz-Next Deployment

        β”‚
        β–Ό
Kundi Deployment

        β”‚
        β–Ό
Platform Proven

        β”‚
        β–Ό
TEPA Migration

        β”‚
        β–Ό
Odoo 19

The migration occurs only after the platform has proven itself in production.

Success Metrics

CyberMountain success is not measured by the number of Kubernetes services running.

It is measured by:

  • time to deploy a customer
  • deployment consistency
  • recovery time
  • onboarding effort
  • operational stability
  • customer isolation
  • customer satisfaction

Team Decision Framework

When discussing new platform work, ask:

  1. Does this enable onboarding of the next customer?
  2. Does this reduce operational effort?
  3. Can this wait until after the first external deployment?
  4. Does this directly improve customer value?
  5. Is this reusable across every customer?

If the answer to all five is No, it should probably not be included in Phase 1.

Final Decision

We are not changing the CyberMountain vision.

We are changing the order in which we build it.

Our strategy is:

Build customer value continuously. Build CyberMountain in parallel. Let every customer deployment improve the factory. Migrate TEPA only after CyberMountain has proven itself through real customer deployments.

This approach provides:

  • Faster time-to-market
  • Earlier customer feedback
  • Lower technical risk
  • Better capital efficiency
  • Higher platform quality
  • A repeatable multi-tenant operating model ready to scale with TEPA.swiss, Schwyz-Next, Kundi and future customers.