SBOS Server

SBOS Server and Server Suite

SBOS Server is the server edition of SBOS. Server Suite is the administered set of server capabilities. An installation can run one role or combine several roles according to the services it needs to provide.

Server Suite

Server Suite brings identity, gateway, hosting, mail, file services, backup, remote access, containers, virtualization, deployment, diagnostics, health, and policy into the SBOS administration model. The roles share the operating system’s update, lifecycle, isolation, audit, and recovery systems without requiring every role to be installed on every server.

App Collections

An App Collection is a managed service made from several related components. It defines what is required, what is optional, how the pieces start and communicate, which identities and certificates they use, where they store data, which policies apply, how updates are handled, and what the administration dashboard should report.

Mail example

A mail collection can include transport, mailbox access, filtering, identity, storage, optional webmail, certificate requirements, network rules, health checks, diagnostics, and backup as one administered service.

Gateway example

An SBGS collection can require the policy, routing, and firewall core, then add DNS filtering, proxying, inspection, VPN, or threat-processing components according to the deployment.

FST ID

Directory objects

FST ID stores and organizes users, groups, devices, services, applications, organizational units, and other directory objects in a structure administrators can delegate and manage.

Authentication and certificates

It provides authentication gateways, certificates, certificate-authority integration, device and certificate enrollment, LDAP, Kerberos, RADIUS, SSO, and federation.

Policy

Native SBOS User Policies remain the source of truth. Policies can be inherited through the directory and translated into Windows or GPO-style behavior for Windows systems when required.

Deployment and migration

FST ID can run as a single service, replicated across servers, distributed across sites, or combined with existing directories. Migration and coexistence paths include Active Directory, LDAP, and eDirectory.

Star-Blade Gateway Services

The required SBGS core is policy, routing, and firewalling. Other components can be added independently so a deployment can remain small or distribute inspection and security work across several nodes.

DNS, web, and application controls

DNS controls, DNS filtering, web filtering, categories and subcategories, application control, web proxying, application proxying, TLS inspection, DPI, and QUIC handling are attached through policy.

Content and threat processing

Content scrubbing can remove ads and trackers, including content embedded in media delivery paths. Malware scanning, antivirus, antimalware, antispyware, IPS, sandboxing, and advanced threat processing can be placed in the service chain.

Access and traffic management

VPN, remote access, segmentation, traffic prioritization, QoS, and service chaining are managed with the same gateway policy model.

Health and resilience

Component health, dashboards, replication, failover, and FST ID integration allow gateway services to be distributed without making identity integration mandatory for basic routing and firewall operation.

SBN and SRWECMFA trustee rights

SBN is the Star-Blade Network protocol and services model for network file sharing and related network resources. It is comparable in role to SMB or NCP. SBN is not SBFS. SBN trustee rights apply only to SBN shares and file-tree resources.

Supervisor is the highest trustee right inside the applicable SBN directory, file, or subtree. It does not grant SBOS root access, installation control, authority over the Star System Kernel, authority over SBFS system files, or general server administration.

Letter Right Meaning
SSupervisorGrants all SBN trustee rights for the applicable directory or file and subordinate items.
RReadOpens and reads files, and opens, reads, or executes applicable applications.
WWriteModifies the contents of an existing file.
EEraseDeletes applicable files or directories.
CCreateCreates files or directories and salvages deleted files.
MModifyRenames files or directories and changes attributes without modifying file contents.
FFile ScanAllows applicable files and directories to be seen in the SBN namespace.
AAccess ControlManages trustee assignments and access-control behavior within the applicable SBN scope.

SBN can also apply inheritance, trustee assignments, per-file and per-directory rights, quotas, snapshots, versioning, audit, rollback, and mixed-platform client access. Other file-sharing protocols can remain available for interoperability.

Web and application hosting

SBOS Server can host static sites and applications using PHP, Node.js, Python, RTMP, WebDAV, reverse proxying, and other application services. A site or application can receive its own runtime, secrets, certificate handling, network policy, storage, access controls, resource limits, and diagnostics instead of sharing one unrestricted hosting environment.

Mail services

Mail services cover message transport, mailbox access, relay, filtering, archiving, domain authentication records, and optional user-facing access. A Mail App Collection can combine SMTP, IMAP, POP, DKIM, DMARC, SPF, webmail, multiple domains, and tenant separation. Available components depend on the installed SBOS release.

File and cloud-style services

File services can provide SBN, SMB/CIFS, NFS, WebDAV, shared storage, synchronization, distribution, snapshots, versioning, quotas, audit, backup integration, and recovery. SBN supplies the native trustee model while the other protocols support existing clients and migration paths.

Containers and virtualization

Containers

SBOS native containers and compatible container runtimes can isolate server applications, hosting configurations, dependencies, secrets, storage, networks, and resource limits.

Native hypervisor

The SBOS native hypervisor runs full guest operating systems with first-party integration for templates, snapshots, networks, storage, hardware assignment, and eligible SBOS guest trust inheritance. Migration and failover options depend on the installed release and deployment topology.

Third-party virtualization

VMware and VirtualBox remain separate compatibility applications. They can provide familiar lab and development workflows but do not participate in native SBOS guest trust inheritance.

Workload separation

Application environments, containers, and full virtual machines solve different problems. Server Suite selects the boundary that matches the service rather than treating every workload as a VM.

Remote access

Remote access can include VPN, remote desktops, published applications, browser access, and jump-host workflows. Some deployments also use thin-client or network-boot services. Identity, device state, policy, certificates, and service permissions determine what the remote user can reach.

Backup, monitoring, and deployment

Backup and recovery are platform services used by the server core and App Collections. Monitoring, posture, telemetry, health, audit, and diagnostics are aware of the services running on the server. Deployment management handles applications, App Collections, policies, certificates, configurations, templates, replication, rollout groups, and mixed SBOS, Windows, Linux, and macOS systems.

Service versions, topology options, client interoperability, migration features, clustering, and failover support vary by SBOS release.