SBOS Server and Server Suite
SBOS Server is the server edition of SBOS. Server Suite is the administered set of server capabilities. An installation can run one role or combine several roles according to the services it needs to provide.
Server Suite
Server Suite brings identity, gateway, hosting, mail, file services, backup, remote access, containers, virtualization, deployment, diagnostics, health, and policy into the SBOS administration model. The roles share the operating system’s update, lifecycle, isolation, audit, and recovery systems without requiring every role to be installed on every server.
App Collections
An App Collection is a managed service made from several related components. It defines what is required, what is optional, how the pieces start and communicate, which identities and certificates they use, where they store data, which policies apply, how updates are handled, and what the administration dashboard should report.
Mail example
A mail collection can include transport, mailbox access, filtering, identity, storage, optional webmail, certificate requirements, network rules, health checks, diagnostics, and backup as one administered service.
Gateway example
An SBGS collection can require the policy, routing, and firewall core, then add DNS filtering, proxying, inspection, VPN, or threat-processing components according to the deployment.
FST ID
Directory objects
FST ID stores and organizes users, groups, devices, services, applications, organizational units, and other directory objects in a structure administrators can delegate and manage.
Authentication and certificates
It provides authentication gateways, certificates, certificate-authority integration, device and certificate enrollment, LDAP, Kerberos, RADIUS, SSO, and federation.
Policy
Native SBOS User Policies remain the source of truth. Policies can be inherited through the directory and translated into Windows or GPO-style behavior for Windows systems when required.
Deployment and migration
FST ID can run as a single service, replicated across servers, distributed across sites, or combined with existing directories. Migration and coexistence paths include Active Directory, LDAP, and eDirectory.
Star-Blade Gateway Services
The required SBGS core is policy, routing, and firewalling. Other components can be added independently so a deployment can remain small or distribute inspection and security work across several nodes.
DNS, web, and application controls
DNS controls, DNS filtering, web filtering, categories and subcategories, application control, web proxying, application proxying, TLS inspection, DPI, and QUIC handling are attached through policy.
Content and threat processing
Content scrubbing can remove ads and trackers, including content embedded in media delivery paths. Malware scanning, antivirus, antimalware, antispyware, IPS, sandboxing, and advanced threat processing can be placed in the service chain.
Access and traffic management
VPN, remote access, segmentation, traffic prioritization, QoS, and service chaining are managed with the same gateway policy model.
Health and resilience
Component health, dashboards, replication, failover, and FST ID integration allow gateway services to be distributed without making identity integration mandatory for basic routing and firewall operation.
SBN and SRWECMFA trustee rights
SBN is the Star-Blade Network protocol and services model for network file sharing and related network resources. It is comparable in role to SMB or NCP. SBN is not SBFS. SBN trustee rights apply only to SBN shares and file-tree resources.
Supervisor is the highest trustee right inside the applicable SBN directory, file, or subtree. It does not grant SBOS root access, installation control, authority over the Star System Kernel, authority over SBFS system files, or general server administration.
| Letter | Right | Meaning |
|---|---|---|
S | Supervisor | Grants all SBN trustee rights for the applicable directory or file and subordinate items. |
R | Read | Opens and reads files, and opens, reads, or executes applicable applications. |
W | Write | Modifies the contents of an existing file. |
E | Erase | Deletes applicable files or directories. |
C | Create | Creates files or directories and salvages deleted files. |
M | Modify | Renames files or directories and changes attributes without modifying file contents. |
F | File Scan | Allows applicable files and directories to be seen in the SBN namespace. |
A | Access Control | Manages trustee assignments and access-control behavior within the applicable SBN scope. |
SBN can also apply inheritance, trustee assignments, per-file and per-directory rights, quotas, snapshots, versioning, audit, rollback, and mixed-platform client access. Other file-sharing protocols can remain available for interoperability.
Web and application hosting
SBOS Server can host static sites and applications using PHP, Node.js, Python, RTMP, WebDAV, reverse proxying, and other application services. A site or application can receive its own runtime, secrets, certificate handling, network policy, storage, access controls, resource limits, and diagnostics instead of sharing one unrestricted hosting environment.
Mail services
Mail services cover message transport, mailbox access, relay, filtering, archiving, domain authentication records, and optional user-facing access. A Mail App Collection can combine SMTP, IMAP, POP, DKIM, DMARC, SPF, webmail, multiple domains, and tenant separation. Available components depend on the installed SBOS release.
File and cloud-style services
File services can provide SBN, SMB/CIFS, NFS, WebDAV, shared storage, synchronization, distribution, snapshots, versioning, quotas, audit, backup integration, and recovery. SBN supplies the native trustee model while the other protocols support existing clients and migration paths.
Containers and virtualization
Containers
SBOS native containers and compatible container runtimes can isolate server applications, hosting configurations, dependencies, secrets, storage, networks, and resource limits.
Native hypervisor
The SBOS native hypervisor runs full guest operating systems with first-party integration for templates, snapshots, networks, storage, hardware assignment, and eligible SBOS guest trust inheritance. Migration and failover options depend on the installed release and deployment topology.
Third-party virtualization
VMware and VirtualBox remain separate compatibility applications. They can provide familiar lab and development workflows but do not participate in native SBOS guest trust inheritance.
Workload separation
Application environments, containers, and full virtual machines solve different problems. Server Suite selects the boundary that matches the service rather than treating every workload as a VM.
Remote access
Remote access can include VPN, remote desktops, published applications, browser access, and jump-host workflows. Some deployments also use thin-client or network-boot services. Identity, device state, policy, certificates, and service permissions determine what the remote user can reach.
Backup, monitoring, and deployment
Backup and recovery are platform services used by the server core and App Collections. Monitoring, posture, telemetry, health, audit, and diagnostics are aware of the services running on the server. Deployment management handles applications, App Collections, policies, certificates, configurations, templates, replication, rollout groups, and mixed SBOS, Windows, Linux, and macOS systems.
Service versions, topology options, client interoperability, migration features, clustering, and failover support vary by SBOS release.