Update architecture and evidence snapshots
This commit is contained in:
@@ -0,0 +1,53 @@
|
||||
<svg xmlns="http://www.w3.org/2000/svg" width="1600" height="900" viewBox="0 0 1600 900">
|
||||
<defs>
|
||||
<linearGradient id="bg" x1="0" y1="0" x2="1" y2="1"><stop offset="0" stop-color="#05070a"/><stop offset="1" stop-color="#0b0f15"/></linearGradient>
|
||||
<marker id="a" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto"><path d="M0 0 L10 5 L0 10 z" fill="#52d4ff"/></marker>
|
||||
<marker id="p" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto"><path d="M0 0 L10 5 L0 10 z" fill="#9a6cff"/></marker>
|
||||
<style>
|
||||
.title{font:700 28px monospace;fill:#f4f7fb;letter-spacing:2px}.sub{font:500 13px monospace;fill:#74808f;letter-spacing:1px}
|
||||
.group{fill:#0b1017;stroke:#202a35;stroke-width:1.5}.node{fill:#0d131b;stroke:#324151;stroke-width:1.5}.cyan{fill:#0d131b;stroke:#52d4ff;stroke-width:1.7}.purple{fill:#0d131b;stroke:#9a6cff;stroke-width:1.7}
|
||||
.h{font:700 17px monospace;fill:#f1f5f9}.t{font:500 12px monospace;fill:#96a2b1}.tag{font:700 11px monospace;fill:#52d4ff;letter-spacing:1px}.tagp{font:700 11px monospace;fill:#9a6cff;letter-spacing:1px}
|
||||
.line{stroke:#52d4ff;stroke-width:2;fill:none;marker-end:url(#a)}.linep{stroke:#9a6cff;stroke-width:2;fill:none;marker-end:url(#p)}.dash{stroke:#546273;stroke-width:1.5;fill:none;stroke-dasharray:7 7}
|
||||
</style>
|
||||
</defs>
|
||||
<rect width="1600" height="900" fill="url(#bg)"/>
|
||||
<g stroke="#0f1720" stroke-width="1"><path d="M0 120H1600M0 300H1600M0 480H1600M0 660H1600"/><path d="M200 0V900M400 0V900M600 0V900M800 0V900M1000 0V900M1200 0V900M1400 0V900"/></g>
|
||||
<text x="60" y="60" class="title">BYTEGEIST CLOUD / INFRASTRUCTURE MAP</text>
|
||||
<text x="60" y="88" class="sub">REV 05 / OCT 2026 / HETZNER HEL1 / LIVE TELEMETRY PATH INCLUDED</text>
|
||||
|
||||
<rect x="50" y="135" width="300" height="185" rx="10" class="group"/><text x="72" y="165" class="tag">EDGE / ACCESS</text>
|
||||
<rect x="75" y="185" width="250" height="52" rx="7" class="cyan"/><text x="92" y="207" class="h">DNS + HTTPS</text><text x="92" y="227" class="t">casko.dev service routing</text>
|
||||
<rect x="75" y="250" width="250" height="52" rx="7" class="node"/><text x="92" y="272" class="h">Nginx Proxy Manager</text><text x="92" y="292" class="t">TLS termination / reverse proxy</text>
|
||||
|
||||
<rect x="400" y="135" width="340" height="185" rx="10" class="group"/><text x="422" y="165" class="tagp">IDENTITY / CONTROL</text>
|
||||
<rect x="425" y="185" width="290" height="52" rx="7" class="purple"/><text x="442" y="207" class="h">Authentik</text><text x="442" y="227" class="t">OIDC / SSO / 2FA</text>
|
||||
<rect x="425" y="250" width="140" height="52" rx="7" class="node"/><text x="442" y="272" class="h">Gitea</text><text x="442" y="292" class="t">source control</text>
|
||||
<rect x="575" y="250" width="140" height="52" rx="7" class="node"/><text x="592" y="272" class="h">Woodpecker</text><text x="592" y="292" class="t">CI / deployment</text>
|
||||
|
||||
<rect x="790" y="135" width="760" height="185" rx="10" class="group"/><text x="812" y="165" class="tag">DOCKER HOST / APPLICATIONS</text>
|
||||
<rect x="815" y="185" width="215" height="52" rx="7" class="node"/><text x="832" y="207" class="h">Dashy</text><text x="832" y="227" class="t">service portal</text>
|
||||
<rect x="1045" y="185" width="215" height="52" rx="7" class="node"/><text x="1062" y="207" class="h">Wiki.js</text><text x="1062" y="227" class="t">runbooks / DR docs</text>
|
||||
<rect x="1275" y="185" width="250" height="52" rx="7" class="node"/><text x="1292" y="207" class="h">Vaultwarden + Tools</text><text x="1292" y="227" class="t">utility workloads</text>
|
||||
<rect x="815" y="250" width="215" height="52" rx="7" class="node"/><text x="832" y="272" class="h">Grafana</text><text x="832" y="292" class="t">dashboards / analysis</text>
|
||||
<rect x="1045" y="250" width="215" height="52" rx="7" class="node"/><text x="1062" y="272" class="h">Uptime Kuma</text><text x="1062" y="292" class="t">endpoint monitoring</text>
|
||||
<rect x="1275" y="250" width="250" height="52" rx="7" class="node"/><text x="1292" y="272" class="h">CrowdSec</text><text x="1292" y="292" class="t">threat detection evidence</text>
|
||||
|
||||
<rect x="50" y="370" width="1500" height="300" rx="12" class="group"/><text x="72" y="405" class="tag">OBSERVABILITY / LIVE TELEMETRY</text>
|
||||
<rect x="85" y="445" width="220" height="68" rx="8" class="node"/><text x="104" y="470" class="h">node_exporter</text><text x="104" y="493" class="t">host CPU / memory / uptime</text>
|
||||
<rect x="85" y="535" width="220" height="68" rx="8" class="node"/><text x="104" y="560" class="h">cAdvisor</text><text x="104" y="583" class="t">container metrics</text>
|
||||
<rect x="370" y="470" width="235" height="86" rx="8" class="cyan"/><text x="392" y="499" class="h">Prometheus</text><text x="392" y="523" class="t">scrapes + stores metrics</text><text x="392" y="544" class="t">target health exposed</text>
|
||||
<rect x="670" y="470" width="245" height="86" rx="8" class="cyan"/><text x="692" y="499" class="h">ByteGeist Status API</text><text x="692" y="523" class="t">sanitized JSON endpoint</text><text x="692" y="544" class="t">no admin API exposure</text>
|
||||
<rect x="980" y="470" width="225" height="86" rx="8" class="cyan"/><text x="1002" y="499" class="h">Nginx /api/status</text><text x="1002" y="523" class="t">same-origin proxy</text><text x="1002" y="544" class="t">no-store cache policy</text>
|
||||
<rect x="1270" y="470" width="240" height="86" rx="8" class="purple"/><text x="1292" y="499" class="h">Control Plane UI</text><text x="1292" y="523" class="t">15-second refresh</text><text x="1292" y="544" class="t">real CPU / RAM / uptime</text>
|
||||
<path d="M305 479H370" class="line"/><path d="M305 569C335 569 335 530 370 530" class="line"/><path d="M605 513H670" class="line"/><path d="M915 513H980" class="line"/><path d="M1205 513H1270" class="line"/>
|
||||
<rect x="85" y="625" width="220" height="28" rx="6" class="node"/><text x="104" y="645" class="t">Alloy - Loki - Grafana logs</text><path d="M305 639H815V302" class="dash"/>
|
||||
|
||||
<rect x="50" y="720" width="1500" height="125" rx="10" class="group"/><text x="72" y="750" class="tagp">DELIVERY / RECOVERY</text>
|
||||
<rect x="85" y="770" width="250" height="50" rx="7" class="node"/><text x="104" y="792" class="h">Gitea - Woodpecker</text><text x="104" y="811" class="t">commit / build / verify / deploy</text>
|
||||
<rect x="390" y="770" width="250" height="50" rx="7" class="node"/><text x="409" y="792" class="h">Docker Compose</text><text x="409" y="811" class="t">repeatable service definitions</text>
|
||||
<rect x="695" y="770" width="250" height="50" rx="7" class="node"/><text x="714" y="792" class="h">Persistent data</text><text x="714" y="811" class="t">volumes / databases / backups</text>
|
||||
<rect x="1000" y="770" width="250" height="50" rx="7" class="node"/><text x="1019" y="792" class="h">Wiki.js runbook</text><text x="1019" y="811" class="t">documented rebuild sequence</text>
|
||||
<rect x="1305" y="770" width="205" height="50" rx="7" class="node"/><text x="1324" y="792" class="h">Validation</text><text x="1324" y="811" class="t">DNS / TLS / identity</text>
|
||||
<path d="M350 276H425" class="linep"/><path d="M715 276H790" class="linep"/><path d="M335 795H390" class="linep"/><path d="M640 795H695" class="linep"/><path d="M945 795H1000" class="linep"/><path d="M1250 795H1305" class="linep"/>
|
||||
<text x="1515" y="875" text-anchor="end" class="sub">BYTEGEIST / CONTROL PLANE</text>
|
||||
</svg>
|
||||
|
After Width: | Height: | Size: 7.2 KiB |
+18
-12
@@ -122,7 +122,8 @@
|
||||
<span>GRAFANA / BYTEGEIST OPERATIONS</span>
|
||||
<a href="assets/images/portfolio-grafana-operations.png" target="_blank">FULL RES ↗</a>
|
||||
</div>
|
||||
<img src="assets/images/portfolio-grafana-operations.png" alt="Grafana operations dashboard screenshot from the ByteGeist monitoring stack" />
|
||||
<img src="assets/images/portfolio-grafana-operations.png" alt="Grafana operations dashboard snapshot from the ByteGeist monitoring stack" />
|
||||
<p class="evidence-note">CAPTURED OCT 2026 · GRAFANA OPERATIONS SNAPSHOT · LIVE VALUES ABOVE REFRESH EVERY 15s</p>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -208,12 +209,12 @@
|
||||
</div>
|
||||
</div>
|
||||
<figure class="system-map">
|
||||
<a href="assets/images/bytegeist-architecture.png" target="_blank">
|
||||
<img src="assets/images/bytegeist-architecture.png" alt="ByteGeist infrastructure architecture diagram" />
|
||||
<a href="assets/images/bytegeist-architecture-v5.svg" target="_blank">
|
||||
<img src="assets/images/bytegeist-architecture-v5.svg" alt="ByteGeist infrastructure architecture diagram including the live Prometheus telemetry path" />
|
||||
</a>
|
||||
<figcaption>
|
||||
<span>BYTEGEIST-CLOUD / REV 04</span>
|
||||
<span>SELECT DIAGRAM TO INSPECT</span>
|
||||
<span>BYTEGEIST-CLOUD / REV 05</span>
|
||||
<span>LIVE TELEMETRY PATH INCLUDED</span>
|
||||
</figcaption>
|
||||
</figure>
|
||||
</div>
|
||||
@@ -237,8 +238,9 @@
|
||||
<small>Container output searchable by service and host</small>
|
||||
</figcaption>
|
||||
<a href="assets/images/portfolio-grafana-logs.png" target="_blank">
|
||||
<img src="assets/images/portfolio-grafana-logs.png" alt="Centralized logs in Grafana" />
|
||||
<img src="assets/images/portfolio-grafana-logs.png" alt="Centralized logs snapshot in Grafana" />
|
||||
</a>
|
||||
<p class="evidence-note">CAPTURED OCT 2026 · LOGGING EVIDENCE SNAPSHOT · VALUES SHOWN ARE FROM CAPTURE TIME</p>
|
||||
</figure>
|
||||
|
||||
<div class="coverage-matrix">
|
||||
@@ -289,8 +291,9 @@
|
||||
<small>Dashy / internal access layer</small>
|
||||
</figcaption>
|
||||
<a href="assets/images/portfolio-cloud-dashboard-overview.png" target="_blank">
|
||||
<img src="assets/images/portfolio-cloud-dashboard-overview.png" alt="ByteGeist Dashy service portal" />
|
||||
<img src="assets/images/portfolio-cloud-dashboard-overview.png" alt="ByteGeist Dashy service portal snapshot" />
|
||||
</a>
|
||||
<p class="evidence-note">CAPTURED OCT 2026 · SERVICE PORTAL CONFIGURATION SNAPSHOT</p>
|
||||
</figure>
|
||||
</div>
|
||||
</section>
|
||||
@@ -318,13 +321,13 @@
|
||||
|
||||
<div class="pipeline-shots">
|
||||
<figure>
|
||||
<figcaption>GITEA / REPOSITORIES</figcaption>
|
||||
<figcaption>GITEA / REPOSITORIES · OCT 2026 SNAPSHOT</figcaption>
|
||||
<a href="assets/images/portfolio-gitea-dashboard.png" target="_blank">
|
||||
<img src="assets/images/portfolio-gitea-dashboard.png" alt="Gitea repositories dashboard" />
|
||||
</a>
|
||||
</figure>
|
||||
<figure>
|
||||
<figcaption>WOODPECKER / PIPELINE</figcaption>
|
||||
<figcaption>WOODPECKER / PIPELINE · DEPLOYMENT EVIDENCE</figcaption>
|
||||
<a href="assets/images/portfolio-woodpecker-pipeline.png" target="_blank">
|
||||
<img src="assets/images/portfolio-woodpecker-pipeline.png" alt="Successful Woodpecker CI pipeline" />
|
||||
</a>
|
||||
@@ -350,8 +353,9 @@
|
||||
<small>Protected applications / OIDC / 2FA policy</small>
|
||||
</figcaption>
|
||||
<a href="assets/images/portfolio-authentik-applications.png" target="_blank">
|
||||
<img src="assets/images/portfolio-authentik-applications.png" alt="Applications protected by Authentik" />
|
||||
<img src="assets/images/portfolio-authentik-applications.png" alt="Authentik protected applications configuration snapshot" />
|
||||
</a>
|
||||
<p class="evidence-note">CAPTURED OCT 2026 · IDENTITY CONFIGURATION EVIDENCE</p>
|
||||
</figure>
|
||||
|
||||
<div class="security-data">
|
||||
@@ -374,8 +378,9 @@
|
||||
<small>Threat detection and firewall-decision history</small>
|
||||
</figcaption>
|
||||
<a href="assets/images/portfolio-crowdsec-decisions.png" target="_blank">
|
||||
<img src="assets/images/portfolio-crowdsec-decisions.png" alt="CrowdSec firewall decision evidence" />
|
||||
<img src="assets/images/portfolio-crowdsec-decisions.png" alt="CrowdSec firewall decision evidence snapshot" />
|
||||
</a>
|
||||
<p class="evidence-note">CAPTURED OCT 2026 · SECURITY EVIDENCE SNAPSHOT · NOT A LIVE DECISION FEED</p>
|
||||
</figure>
|
||||
</div>
|
||||
</section>
|
||||
@@ -399,8 +404,9 @@
|
||||
</div>
|
||||
<figure>
|
||||
<a href="assets/images/portfolio-wiki-disaster-recovery.png" target="_blank">
|
||||
<img src="assets/images/portfolio-wiki-disaster-recovery.png" alt="ByteGeist disaster recovery runbook" />
|
||||
<img src="assets/images/portfolio-wiki-disaster-recovery.png" alt="ByteGeist disaster recovery runbook documentation snapshot" />
|
||||
</a>
|
||||
<p class="evidence-note">CAPTURED OCT 2026 · DOCUMENTED RECOVERY PROCEDURE</p>
|
||||
</figure>
|
||||
</div>
|
||||
</section>
|
||||
|
||||
Reference in New Issue
Block a user