VK WorkSpace Federation Enables Secure Multi-Organization On-Premise Messaging Without Infrastructure Merge
VK Tech has introduced federation support for VK WorkSpace that links separate On-Premise installations while ensuring each organization retains complete sovereignty over its servers, databases, and security policies.
The solution addresses the common requirement for project teams to communicate with contractors, partners, and subsidiary companies without moving work conversations to public services. In the initial November 2025 pilot, two installations could exchange messages after one side issued an invitation and the other confirmed the trust relationship. The July 2026 release 26.2 removed the pairwise limitation, allowing a single group chat to include participants from multiple independent On-Premise environments.
Access is governed at two levels. First, a mutual trust is established between installations. Second, each administrator explicitly grants external-communication rights to selected employees for that specific trust. Only approved users see external contacts and can initiate dialogues or join federated group chats. The corporate directory is not replicated; only minimal profile data—name, work email, and organization flag—is shared.
Three architectural approaches were evaluated. A single-host model with proxy access was rejected because loss of the host would break history availability for all other parties. Adoption of the open Matrix protocol was also declined because it would have required extensive remapping of existing entities, rights, and APIs. The chosen design replicates only federation-related objects and events at the application layer so that each installation stores its own copy of permitted messages and files.
This local-replication model delivers several security and operational benefits: data remains under each organization’s control, local DLP, audit, and retention policies continue to apply, and no user session is created in a foreign environment. When a trust is revoked, already-received history stays in the local instance.
Client applications continue to connect exclusively to their own installation. A dedicated federation layer intercepts relevant operations, forwards them through secure gateways, and replays them via the local messenger API on the receiving side. The core messenger logic remains unchanged, although every new feature must still be validated for multi-party federation compatibility.
Extensive dogfooding on internal test stands helped refine both the protocol and the user interface, particularly the hiding of unsupported actions to prevent user errors. The feature is now deployed in production On-Premise environments at several customer sites.
Related articles
Tools Alone Won't Suffice: Building Systemic Kubernetes Security Across Hundreds of Clusters at Alfa-Bank
Alexander, lead of the K8S and cloud security department at Alfa-Bank, explains how the bank moved from fragmented tools and ad-hoc practices to a comprehensive process-driven security function covering more than 500 Kubernetes clusters. The approach centers on a threat lifecycle model that includes threat modeling, requirements definition, project expertise, auditing, risk assessment, platform operations, and SOC integration. A RACI matrix formalizes responsibilities across security, DevOps, AppSec Business Partners, and IT teams to ensure consistent execution at scale. Four specialized roles—an architect, analyst-engineer, auditor, and platform DevOps engineer—handle the workload that no single individual could manage. The bank emphasizes that commercial scanners and policies deliver value only when embedded in repeatable processes tied to a living threat model and clear accountability.
Luna Decisions Integration with n8n for Real Estate Listing Parsing: Workflow Architecture, Limitations and Open Questions
A detailed technical discussion explores the use of n8n workflows to monitor real estate advertisements by combining scheduled data collection, normalization, and comparison logic with potential AI-driven decision layers. The article examines the boundary between raw parsing and actionable decisions, highlighting how simple code-based event detection can be augmented by structured outputs from models such as OpenAI GPT-6 Luna Decisions. Key components include a Dispatcher node that identifies new listings, price drops, and removals, while storing state in Google Sheets and generating Telegram summaries. Limitations around data completeness, currency conversion, and false positives for sold status are analyzed in depth. The author proposes an experimental branch that routes validated price-change events to Luna Decisions API for typed scoring before any human notification. Overall the piece invites community feedback on whether a dedicated Decisions API provides measurable advantages over rule-based conditions or standard structured LLM outputs.
Bureau 1440 Unveils Satellite Internet Terminals Reaching 700 Mbps for Industrial and Rail Use
Bureau 1440 presented three satellite terminal models at the Digital Solutions forum in Russia. The 1440 ULTRA model supports data speeds up to 700 Mbps and is designed for remote industrial sites and infrastructure, operating both stationary and in motion. The company reduced the terminal's weight by 30 percent while maintaining 600 by 600 mm dimensions and adding IP67 dust and water protection. The 1440 ZEMLYA variant is already undergoing tests on Russian Railways trains, including Lastochka and Sapsan services, and is rated for operation at speeds up to 400 km/h. A compact 1440 MINI concept aims for around 100 Mbps in a 300 by 300 mm portable form factor intended for rescue teams and expeditions. All models are being developed alongside the company's low-orbit satellite constellation, with test connections already active on rail lines and in remote settlements. Sales have not yet begun, and the company will announce availability separately while noting that maximum speeds are not guaranteed in every environment.
GTA V Unofficial Browser Port Runs Locally via WebAssembly Using Leaked Rockstar Sources
Enthusiasts created an unofficial port of GTA V that executes the game directly in the browser through WebAssembly without any cloud streaming. The project compiled the original RAGE engine to wasm64 and built a compatibility layer translating DirectX 11 calls to WebGPU. Game assets were served over HTTP while JavaScript handled input and saves, and AudioWorklet managed audio. The port retained Euphoria physics and Scaleform interfaces but removed Bink video playback. Requirements ranged from 3 to 16 GB of RAM, supporting both story mode and free roam. The site was taken offline shortly after launch, first displaying a thank-you message and later redirecting to adult content. Analysis of the build confirmed debug symbols and developer file paths consistent with leaked Rockstar source code.