Executive Summary & Architecture Scope 🔗
A unified, open-source IaC framework for sovereign, high-performance Knowledge Graph & Database Management System (DBMS) provisioning.
🎯 Primary Purpose
Deploy single self-managed Virtuoso instances with consistent OpenTofu-based workflows, automated credential generation, and modular cloud architectures.
🛡️ Publishing Boundary
Strictly scoped for self-managed deployments. Excludes AWS Marketplace SaaS registration, metering handlers, seller portals, and control-plane Lambdas.
🔒 Security & Remote State
Generated Database Administrator (DBA) passwords exist in state files; production deployments require encrypted remote state backends (S3+KMS, Azure Blob, GCS) per docs/REMOTE_STATE.md.
🏷️ Container Pinning
Production environments must pin container images to tested release tags or immutable SHA256 digests rather than mutable latest tags.
Multi-Cloud Deployment Architecture Matrix 🔗
Head-to-head architectural analysis across supported cloud provider modules.
| Architecture Dimension | AWS (aws/) | Azure VM (azure/) | Azure ACI (azure/aci/) | Google Cloud (gcp/) |
|---|---|---|---|---|
| Compute & Orchestration Model | Amazon ECS Fargate (Serverless Container) | Azure Virtual Machine (Linux IaaS) | Azure Container Instances (Serverless Container) | Compute Engine VM with Docker Container Runtime |
| Storage Backend & Volume Type | Amazon EFS (NFS mount) | Azure Premium Managed SSD Disk (Block Volume) | Azure Files (SMB Network File Share) | Google Cloud Persistent Disk (Standard / SSD Block Storage) |
| Active Database I/O Latency | Moderate (Network NFS latency, suitable for typical read/write) | Ultra-Low (Direct block storage, optimal for active databases) | High (SMB latency causes transaction lag on active loads) | Ultra-Low (Direct block storage, optimal for active databases) |
| DBA Secret & Credential Handling | OpenTofu Random Password in state / Task Def ENV | OpenTofu Generated Password injected into cloud-init | OpenTofu Generated Password in container secure env | Google Cloud Secret Manager + OpenTofu State |
| Production Maturity & Status | Available / Recommended | Available / Recommended Baseline | Experimental Baseline | Available / Recommended |
| Virtuoso Editions Supported | VOS 7.x & Commercial V8.x | VOS 7.x & Commercial V8.x | VOS 7.x & Commercial V8.x | VOS 7.x & Commercial V8.x |
| Multi-Tenant / Multi-Deployment Support | Supported via isolated state + project_name prefix |
Supported via isolated state + project_name prefix |
Supported via isolated state + project_name prefix |
Supported via isolated state + project_name prefix |
OpenTofu Deployment Pipeline 🔗
Seven-step standardized procedure to provision, secure, and verify Virtuoso Universal Server instances.
Clone the repository and navigate into the target cloud provider module (aws/, azure/, or gcp/).
cd virtuoso-opentofu/aws # or azure/ or gcp/
Configure an encrypted remote backend with state locking (AWS S3+KMS, Azure Blob, or GCS) to protect generated DBA credentials per docs/REMOTE_STATE.md.
tofu {
backend "s3" { bucket = "my-tofu-state" key = "virtuoso/aws.tfstate" encrypt = true }
}
Copy terraform.tfvars.example to terraform.tfvars. Define unique project_name, instance sizes, and pin the container image tag or digest.
# Set project_name = "virtuoso-prod-01", virtuoso_image = "openlink/virtuoso-opensource-7:7.2.14"
Initialize cloud provider plugins and modules, then validate configuration syntax.
tofu validate
Preview planned cloud resource allocations, security group ingress rules (8890, 1111), and volume mounts before applying changes.
Apply the execution plan to provision cloud infrastructure and initialize the Virtuoso DBMS container.
Inspect OpenTofu outputs, access the Virtuoso Conductor UI at port 8890, execute a test SPARQL query at /sparql, and verify SQL connectivity on port 1111.
curl -I http://<instance-ip>:8890/conductor
curl -G "http://<instance-ip>:8890/sparql" --data-urlencode "query=SELECT * WHERE { ?s ?p ?o } LIMIT 1"
Frequently Asked Questions 🔗
Operational, security, and architectural guidance for self-managed deployments.
What is the primary purpose of the virtuoso-opentofu repository?
Why does this repository standardize on OpenTofu instead of proprietary tools?
What is excluded by design from this repository under the Publishing Boundary?
Which cloud providers and compute models are currently supported?
Why is Azure VM the recommended baseline over Azure Container Instances (ACI)?
How is the Virtuoso DBA administrative password secured?
Why should production deployments avoid the 'latest' container tag?
Can multiple independent Virtuoso instances run within the same cloud account?
How are database backups and restores managed in these deployments?
How does commercial licensing work for Virtuoso Commercial Enterprise 8?
What future Kubernetes-based deployment variants are planned?
How do operators tear down and clean up provisioned cloud resources?
Core Technical Glossary 🔗
Formal definitions and concepts governing the Virtuoso OpenTofu multi-cloud architecture.
The practice of managing, automating, and provisioning IT infrastructure (compute, storage, and networking) through machine-readable definition files rather than manual interactive configuration.
An open-source, community-driven fork of Terraform managed under the Linux Foundation for declarative IaC.
A high-performance hybrid DBMS (Database Management System) supporting relational tables (SQL), knowledge graphs (RDF/SPARQL), XML, and web application server capabilities.
A serverless, pay-as-you-go compute engine for containers on Amazon Web Services (AWS) that eliminates the need to manage EC2 virtual machines.
A serverless, fully elastic Network File System (NFS) storage service for AWS compute instances.
Block-level storage volumes managed by Microsoft Azure for Azure Virtual Machines providing high IOPS and low latency.
Durable, high-performance network block storage attached to Compute Engine instances in Google Cloud Platform (GCP).
The W3C standard declarative query language and protocol for querying and manipulating RDF knowledge graph data.
A W3C standard model for data interchange and knowledge representation on the Web based on subject-predicate-object triples.
The primary administrative role responsible for database configuration, security, user permissions, and operations.
A centralized, encrypted storage service (e.g. S3, Azure Blob, GCS) with state locking used by OpenTofu to manage deployment state securely across teams.
Knowledge Graph Explorer 🔗
Interactive D3.js force-directed visualization of entities, cloud architectures, and pipeline steps. Drag nodes to reposition; double-click to unpin. Click node to inspect entity.
Graph data embedded from companion RDF at generation time. Controls tray is closed by default; Advanced mode exposes physics settings and predicate filters.
SPARQL Workbench & Query Recipes 🔗
Live queries scoped to the URIBurner Knowledge Graph named graph.
Recipe 1: Entity Type Summary Query
PREFIX schema: <http://schema.org/>
PREFIX rdf: <http://www.w3.org/1999/02/22-rdf-syntax-ns#>
SELECT ?type (SAMPLE(?s) AS ?sampleEntity) (COUNT(?s) AS ?entityCount)
FROM <https://linkeddata.uriburner.com/DAV/demos/daas/virtuoso-opentofu-gemini_3_7_flash-1.ttl>
WHERE {
?s a ?type .
}
GROUP BY ?type
ORDER BY DESC(?entityCount)
Recipe 2: Cloud Deployment Modules & Providers
PREFIX schema: <http://schema.org/>
SELECT ?deployment ?name ?serviceType ?providerName
FROM <https://linkeddata.uriburner.com/DAV/demos/daas/virtuoso-opentofu-gemini_3_7_flash-1.ttl>
WHERE {
?deployment a schema:SoftwareApplication ;
schema:name ?name ;
schema:serviceType ?serviceType ;
schema:provider ?provider .
?provider schema:name ?providerName .
}
ORDER BY ?name
Recipe 3: Deployment Pipeline Steps in Order
PREFIX schema: <http://schema.org/>
SELECT ?position ?stepName ?stepText
FROM <https://linkeddata.uriburner.com/DAV/demos/daas/virtuoso-opentofu-gemini_3_7_flash-1.ttl>
WHERE {
?howto a schema:HowTo ;
schema:step ?step .
?step schema:position ?position ;
schema:name ?stepName ;
schema:text ?stepText .
}
ORDER BY ?position
Recipe 4: Glossary Defined Terms & DBpedia Links
PREFIX schema: <http://schema.org/>
PREFIX skos: <http://www.w3.org/2004/02/skos/core#>
PREFIX owl: <http://www.w3.org/2002/07/owl#>
SELECT ?term ?label ?definition ?sameAs
FROM <https://linkeddata.uriburner.com/DAV/demos/daas/virtuoso-opentofu-gemini_3_7_flash-1.ttl>
WHERE {
?term a schema:DefinedTerm ;
skos:prefLabel ?label ;
skos:definition ?definition .
OPTIONAL { ?term owl:sameAs ?sameAs . }
}
ORDER BY ?label
text/x-html+tr format; DESCRIBE/CONSTRUCT queries use text/x-html-nice-turtle. Queries execute against the URIBurner SPARQL engine.