Skip to content

Architecture

Architecture decision records, network diagrams, and the lab audit live here.

Doc Purpose
Lab Audit Phase 0.5 — disposition of every entity
Current Network (live) As-built scan (2026-08-09) + DNS posture
Firewall (live posture) ZBF zones and matrix (2026-08-09 capture)
AdGuard Home Authoritative DNS, Tailscale same-subnet caveat
Network Architecture Intended VLANs, WiFi, DNS, Tailscale overlay
Network Diagram Auto-generated from inventory
Firewall Policy Inter-VLAN default-deny design (SEC-002)
Device-to-VLAN Mapping Device placement reference
Proxmox consolidation Complete (2026-06-25) — destroy queue empty
Compute disposition review Owner keep/consolidate/retire matrix
Compute live Proxmox / VMM scans + guest JSON artifacts
Prox storage snapshot (2026-06-24) Point-in-time prox disk / NAS audit
Prox storage remediation proposal Owner decisions — 114, saltierpoop, Whrrr upstream
Network Observations (2026-06-03) Pre-cutover anomalies
ADR-001: Two Independent Traefik Instances Reverse proxy decision
ADR-002: Authentik universal SSO Authentik on all hosts; Plex exempt
ADR-003: OneUptime incident state Incident ownership and platform decision
Operations and incident platform Target observability and response architecture
Operational alert schema Labels, annotations, fingerprints, and correlation
Operator shell inventory zsh/p10k/atuin golden profile baseline
Operator Codex Codex CLI + ~/.agents/skills fleet management
Operator Devtools uv / mise / fvm + Tier-1 CLIs (central pins)
Saltbox monitoring migration Observability consolidation policy
Coordinated OS Patching Phase 8 — push-mode updates from infra-services
CI hosted-runner audit (2026-08-09) Org-wide audit of GitHub-hosted runner usage vs. self-hosted pattern