Architecture¶
Architecture decision records, network diagrams, and the lab audit live here.
| Doc | Purpose |
|---|---|
| Lab Audit | Phase 0.5 — disposition of every entity |
| Current Network (live) | As-built scan (2026-08-09) + DNS posture |
| Firewall (live posture) | ZBF zones and matrix (2026-08-09 capture) |
| AdGuard Home | Authoritative DNS, Tailscale same-subnet caveat |
| Network Architecture | Intended VLANs, WiFi, DNS, Tailscale overlay |
| Network Diagram | Auto-generated from inventory |
| Firewall Policy | Inter-VLAN default-deny design (SEC-002) |
| Device-to-VLAN Mapping | Device placement reference |
| Proxmox consolidation | Complete (2026-06-25) — destroy queue empty |
| Compute disposition review | Owner keep/consolidate/retire matrix |
| Compute live | Proxmox / VMM scans + guest JSON artifacts |
| Prox storage snapshot (2026-06-24) | Point-in-time prox disk / NAS audit |
| Prox storage remediation proposal | Owner decisions — 114, saltierpoop, Whrrr upstream |
| Network Observations (2026-06-03) | Pre-cutover anomalies |
| ADR-001: Two Independent Traefik Instances | Reverse proxy decision |
| ADR-002: Authentik universal SSO | Authentik on all hosts; Plex exempt |
| ADR-003: OneUptime incident state | Incident ownership and platform decision |
| Operations and incident platform | Target observability and response architecture |
| Operational alert schema | Labels, annotations, fingerprints, and correlation |
| Operator shell inventory | zsh/p10k/atuin golden profile baseline |
| Operator Codex | Codex CLI + ~/.agents/skills fleet management |
| Operator Devtools | uv / mise / fvm + Tier-1 CLIs (central pins) |
| Saltbox monitoring migration | Observability consolidation policy |
| Coordinated OS Patching | Phase 8 — push-mode updates from infra-services |
| CI hosted-runner audit (2026-08-09) | Org-wide audit of GitHub-hosted runner usage vs. self-hosted pattern |