← Back to Axis

Engineering case study / Eren · Web & Tech

Axis.
Beyond the
interface.

A custom employee and admin portal, backed by a targeted modernization of Windows Server domain services, identity and recovery infrastructure.

  • Windows Server modernization
  • Full-stack application
  • IT operations
AXIS / IDENTITY & ACCESS
Axis public demo showing the People and access workspace with fictional directory records and account controls.
Public demo interface. Fictional records; changes reset on reload. The operational implementation is described below.
ApplicationIdentityOperations

01 / Problem & scope

The application was
one part of the work.

The work extended beyond building a portal. Identity, network services, device provisioning and backups needed an operating model that could be maintained together.

The project records document the retirement of Active Directory in May 2026 and the migration of specific domain services. Windows remained part of the environment; the scope was a deliberate change of service roles.

Identity & portal access

FreeIPA replaced the directory role. The Laravel portal signs in through LDAP with StartTLS and maps users to application permissions.

DNS & DHCP

Linux services using BIND and ISC DHCP took over name resolution and address assignment.

Mac device provisioning

Directory identity connects to Mosyle provisioning and local Mac accounts. Device management remains a distinct integration.

Windows retained

Windows 11 Pro Hyper-V hosts continue to run the virtual machines. Windows workstations use local accounts; this was not a replacement for Group Policy.

02 / Architecture

Behind the workspace.

A logical view of the application, its private integrations and the separate hosting and recovery plane.

  1. 01

    User interface

    Browser

    Employee and admin workflows.

    Vue 3 + Inertia

    The interface served by the Laravel application.

    Public HTTPS · Let’s Encrypt
  2. 02

    Application boundary

    Portal services

    AlmaLinux virtual machines.

    Apache / PHP-FPM

    Laravel 11 on PHP 8.2 handles requests, sessions and application permissions.

    MariaDB + database queue

    Persistent application records and queued background work.

    Private integration calls · separate protocols and responsibilities
  3. 03

    Integration boundary

    Operational systems

    Identity, devices and network services.

    FreeIPA identity

    Portal sign-in over LDAP with StartTLS.

    Device provisioning

    Device API: mutual TLS / step-ca. Mosyle: Mac management integration.

    Network services

    BIND / ISC DHCP snapshots and UniFi network integration.

Underlying infrastructure

Hosting & recovery plane

Supports the environment independently of the application request flow.

Virtualization

Windows 11 Pro Hyper-V hosts retain the VM infrastructure beneath the application and Linux services.

Recovery toolkit

A separate PowerShell toolkit manages reference points, differential exports, verified transfer journals and acknowledgments, standby retention and compaction.

Recovery boundaries

Isolated restore checks and fenced manual failover are distinct from portal features. There is no portal restore button.

Logical architecture, not a network map. The public Axis demo is a separate Vue/Vite application and does not connect to these operational systems.

03 / Engineering decisions

Choices with a purpose.

How application design and infrastructure support the way the product works.

  1. 01

    Separate identity from permissions

    Directory sign-in establishes identity. Database role mappings support manual and directory-based assignment of application permissions.

    Signing in and being allowed to perform an action are separate decisions.

  2. 02

    Protect sensitive actions

    Inactivity handling, password confirmation for sensitive actions, email two-factor authentication and recovery, and security events are implemented in the portal.

    Security controls extend beyond the login screen.

  3. 03

    Treat provisioning as background work

    Device provisioning uses queued jobs and drift checks, rather than relying on a single browser request to complete an operational change.

    Long-running work has an explicit place in the application.

  4. 04

    Use different trust paths

    Public HTTPS uses Let’s Encrypt. The device API uses mutual TLS with step-ca, while directory sign-in uses LDAP with StartTLS.

    Browser traffic, device access and identity each have their own trust boundary.

  5. 05

    Modernize specific service roles

    FreeIPA, BIND and ISC DHCP take on defined responsibilities while Hyper-V and Windows workstations remain in the environment.

    A bounded migration keeps the remaining operating model explicit.

  6. 06

    Make recovery independently inspectable

    The PowerShell recovery toolkit records transfer completion and acknowledgments, manages standby retention, and supports isolated restore and fenced manual failover.

    A backup record and a demonstrated production recovery are different evidence.

04 / Implementation & demo

Know what you’re exploring.

The public demo makes the workflows easy to try. This comparison explains the boundaries.

Axis implementation compared with its public demo
CapabilityFull implementationPublic demo
ApplicationLaravel / Vue / Inertia employee and admin portal.Separate Vue / Vite interface with a Manager or Employee persona chooser.
DataPersistent MariaDB records and a database-backed job queue.Fictional records held in memory. Changes reset on reload; expanded CRM and finance workflows illustrate the demo concept.
AccessDirectory authentication and database-mapped permissions, with additional session and sensitive-action controls.Personas let visitors explore the interface without authenticating to the real environment.
IntegrationsIdentity, device provisioning and network-service integrations.Sample statuses and interactions. No real email delivery or device commands.
RecoverySeparate Hyper-V recovery toolkit and recorded backup / isolated restore checks.The demonstration does not operate the backup infrastructure.

05 / Recorded outcomes · September 2026

Evidence, with its boundaries.

Recorded backup acceptance

The September 8, 2026 delivery record accepted incremental backups for five production VMs. The observed run included standby preparation, publication and cleanup.

Selected restore checks

Records show isolated, selected service checks for all five VMs. The captures are crash-consistent; full production failover and recovery time were not measured.

Clear limits on the evidence

Authenticated identity and phone workflows remained untested in those restore checks. These records document observed work and do not assert current operational health.

Incremental export payload1.452 GB

About 1.46% of the 99.384 GB baseline.

One observed backup run47m 56s

Includes standby preparation, publication and cleanup.

Rounded from the recorded 1.451701386 GB payload, 99.384466270 GB baseline and 47m 55.60s run. GB uses decimal units. Export payload is not network traffic or a daily forecast; backup duration is not recovery time.

Based on implementation and delivery records from May–September 2026. Operational identifiers have been omitted.

From the engineering to the everyday

See the workspace
in motion.

Explore the fictional workflows, or read how Axis can fit your operating environment.