429 lines
18 KiB
HTML
429 lines
18 KiB
HTML
<!DOCTYPE html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="UTF-8" />
|
|
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
|
<meta name="description" content="ByteGeist infrastructure control plane — architecture, monitoring, delivery, security, and recovery evidence from Keith Casko's self-hosted cloud lab." />
|
|
<title>ByteGeist / Control Plane</title>
|
|
<link rel="icon" href="assets/images/bytegeist-logo.png" />
|
|
<link rel="preconnect" href="https://fonts.googleapis.com" />
|
|
<link rel="preconnect" href="https://fonts.gstatic.com" crossorigin />
|
|
<link href="https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&family=JetBrains+Mono:wght@400;500;600&display=swap" rel="stylesheet" />
|
|
<link rel="stylesheet" href="style.css" />
|
|
<script src="script.js" defer></script>
|
|
</head>
|
|
<body>
|
|
<div class="scanline" aria-hidden="true"></div>
|
|
|
|
<header class="control-bar">
|
|
<a class="wordmark" href="#overview" aria-label="ByteGeist control plane">
|
|
<img src="assets/images/bytegeist-logo.png" alt="" />
|
|
<span>BYTEGEIST</span>
|
|
<small>/ CONTROL PLANE</small>
|
|
</a>
|
|
|
|
<div class="control-state">
|
|
<span class="status-dot"></span>
|
|
<span>LIVE TELEMETRY / CONFIG VERIFIED OCT 2026</span>
|
|
</div>
|
|
|
|
<nav aria-label="Control plane navigation">
|
|
<a href="#overview">Overview</a>
|
|
<a href="#topology">Topology</a>
|
|
<a href="#observability">Observability</a>
|
|
<a href="#services">Services</a>
|
|
<a href="#security">Security</a>
|
|
</nav>
|
|
|
|
<div class="clock" aria-label="Current local time">
|
|
<span id="local-time">--:--:--</span>
|
|
<small>AMERICA / DETROIT</small>
|
|
</div>
|
|
</header>
|
|
|
|
<main>
|
|
<section id="overview" class="command-grid">
|
|
<aside class="system-rail" aria-label="System status">
|
|
<div class="rail-heading">
|
|
<span>NODE</span>
|
|
<strong>BG-CORE-01</strong>
|
|
</div>
|
|
|
|
<dl class="rail-data">
|
|
<div><dt>Provider</dt><dd>Hetzner</dd></div>
|
|
<div><dt>OS</dt><dd>Ubuntu 24.04</dd></div>
|
|
<div><dt>Runtime</dt><dd>Docker</dd></div>
|
|
<div><dt>Region</dt><dd>EU-Central / HEL1</dd></div>
|
|
<div><dt>Ingress</dt><dd>NPM / TLS</dd></div>
|
|
<div><dt>Identity</dt><dd>Authentik</dd></div>
|
|
</dl>
|
|
|
|
<div class="rail-health">
|
|
<span>HOST TELEMETRY</span>
|
|
<strong>PROMETHEUS / NODE EXPORTER</strong>
|
|
</div>
|
|
|
|
<a href="https://wiki.casko.dev">OPEN RUNBOOKS <span>↗</span></a>
|
|
<a href="https://git.casko.dev">GIT SERVER <span>↗</span></a>
|
|
</aside>
|
|
|
|
<div class="overview-console">
|
|
<div class="console-label">
|
|
<span>INFRASTRUCTURE OVERVIEW</span>
|
|
<span id="refresh-indicator">CONNECTING TO TELEMETRY</span>
|
|
</div>
|
|
|
|
<div class="identity-block">
|
|
<div>
|
|
<p class="overline">SELF-HOSTED INFRASTRUCTURE ENVIRONMENT</p>
|
|
<h1>Personal cloud.<br />Operational by design.</h1>
|
|
</div>
|
|
<p class="operator-note">
|
|
A working infrastructure lab for identity, observability, delivery, security,
|
|
and recovery. Built and maintained as an evolving system—not a static demo.
|
|
</p>
|
|
</div>
|
|
|
|
<div class="metric-board" aria-label="Live infrastructure telemetry">
|
|
<article class="metric metric-primary">
|
|
<span>CPU LOAD</span>
|
|
<strong id="cpu-value" class="metric-value">--</strong><small>%</small>
|
|
<p>PROMETHEUS / NODE EXPORTER</p>
|
|
</article>
|
|
<article class="metric">
|
|
<span>MEMORY</span>
|
|
<strong id="memory-value" class="metric-value">--</strong><small>%</small>
|
|
<p>PROMETHEUS / NODE EXPORTER</p>
|
|
</article>
|
|
<article class="metric">
|
|
<span>HOST UPTIME</span>
|
|
<strong id="uptime-value" class="metric-value">--</strong>
|
|
<p>NODE EXPORTER</p>
|
|
</article>
|
|
<article class="metric">
|
|
<span>RUNNING CONTAINERS</span>
|
|
<strong id="containers-value" class="metric-value">--</strong>
|
|
<p>CADVISOR VIA PROMETHEUS</p>
|
|
</article>
|
|
<article class="metric">
|
|
<span>SCRAPE TARGETS</span>
|
|
<strong id="targets-value" class="metric-value">--</strong>
|
|
<p>PROMETHEUS TARGET HEALTH</p>
|
|
</article>
|
|
<article class="metric">
|
|
<span>TELEMETRY</span>
|
|
<strong id="telemetry-value" class="metric-value">CONNECTING</strong>
|
|
<p>PROMETHEUS / CADVISOR</p>
|
|
</article>
|
|
</div>
|
|
|
|
<div class="operations-window">
|
|
<div class="window-bar">
|
|
<span><i class="live-dot"></i> BYTEGEIST / LIVE OPERATIONS</span>
|
|
<small id="ops-source">PROMETHEUS / NODE EXPORTER / CADVISOR</small>
|
|
</div>
|
|
<div class="live-ops-panel" aria-label="Live ByteGeist operations telemetry">
|
|
<div class="ops-chart">
|
|
<div class="ops-chart-head">
|
|
<span>CPU LOAD</span>
|
|
<strong id="ops-cpu-value">--%</strong>
|
|
</div>
|
|
<div id="ops-cpu-bars" class="ops-bars" aria-hidden="true"></div>
|
|
</div>
|
|
<div class="ops-chart">
|
|
<div class="ops-chart-head">
|
|
<span>MEMORY</span>
|
|
<strong id="ops-memory-value">--%</strong>
|
|
</div>
|
|
<div id="ops-memory-bars" class="ops-bars" aria-hidden="true"></div>
|
|
</div>
|
|
<div class="ops-status-grid">
|
|
<div><span>HOST UPTIME</span><strong id="ops-uptime-value">--</strong></div>
|
|
<div><span>CONTAINERS</span><strong id="ops-containers-value">--</strong></div>
|
|
<div><span>SCRAPE TARGETS</span><strong id="ops-targets-value">--</strong></div>
|
|
<div><span>REFRESH</span><strong>15s</strong></div>
|
|
</div>
|
|
</div>
|
|
<p class="evidence-note">LIVE OPERATIONS VIEW · VALUES COME FROM THE SAME SANITIZED /API/STATUS TELEMETRY FEED</p>
|
|
</div>
|
|
</div>
|
|
|
|
<aside class="activity-panel">
|
|
<div class="panel-title">
|
|
<span>PLATFORM CONTROLS</span>
|
|
<small>DOCUMENTED</small>
|
|
</div>
|
|
<ol class="event-list">
|
|
<li>
|
|
<span class="event-info">AUTH</span>
|
|
<p>OIDC authentication through Authentik</p>
|
|
</li>
|
|
<li>
|
|
<span class="event-ok">BACKUP</span>
|
|
<p>Persistent data backup and documented recovery procedures</p>
|
|
</li>
|
|
<li>
|
|
<span class="event-info">TLS</span>
|
|
<p>Certificate and HTTPS management through the reverse proxy</p>
|
|
</li>
|
|
<li>
|
|
<span class="event-info">DNS</span>
|
|
<p>Domain routing and service exposure</p>
|
|
</li>
|
|
</ol>
|
|
|
|
</aside>
|
|
</section>
|
|
|
|
<section id="topology" class="module topology-module">
|
|
<header class="module-header">
|
|
<div>
|
|
<span class="module-id">SYS.01</span>
|
|
<h2>Infrastructure topology</h2>
|
|
</div>
|
|
<p>Traffic, identity, workloads, telemetry, and recovery paths documented for the Hetzner host.</p>
|
|
<div class="module-state"><i></i> DOCUMENTED</div>
|
|
</header>
|
|
|
|
<div class="topology-layout">
|
|
<div class="stack-index">
|
|
<div>
|
|
<span>EDGE</span>
|
|
<strong>Nginx Proxy Manager</strong>
|
|
<small>TLS termination / routing</small>
|
|
</div>
|
|
<div>
|
|
<span>IDENTITY</span>
|
|
<strong>Authentik</strong>
|
|
<small>OIDC / SSO / 2FA</small>
|
|
</div>
|
|
<div>
|
|
<span>COMPUTE</span>
|
|
<strong>Docker Compose</strong>
|
|
<small>Containerized workloads</small>
|
|
</div>
|
|
<div>
|
|
<span>TELEMETRY</span>
|
|
<strong>Prometheus + Loki</strong>
|
|
<small>Metrics / logs / alerts</small>
|
|
</div>
|
|
</div>
|
|
<figure class="system-map">
|
|
<a href="assets/images/bytegeist-architecture-v5.svg" target="_blank">
|
|
<img src="assets/images/bytegeist-architecture-v5.svg" alt="ByteGeist infrastructure architecture diagram including the live Prometheus telemetry path" />
|
|
</a>
|
|
<figcaption>
|
|
<span>BYTEGEIST-CLOUD / REV 05</span>
|
|
<span>LIVE TELEMETRY PATH INCLUDED</span>
|
|
</figcaption>
|
|
</figure>
|
|
</div>
|
|
</section>
|
|
|
|
<section id="observability" class="module evidence-module">
|
|
<header class="module-header">
|
|
<div>
|
|
<span class="module-id">OBS.02</span>
|
|
<h2>Monitoring stack</h2>
|
|
</div>
|
|
<p>Host metrics, container telemetry, centralized logs, and independent uptime checks.</p>
|
|
<div class="module-state"><i></i> LIVE + EVIDENCE</div>
|
|
</header>
|
|
|
|
<div class="evidence-grid">
|
|
<figure class="evidence evidence-wide">
|
|
<figcaption>
|
|
<span>LOG PIPELINE</span>
|
|
<strong>Loki / Grafana Alloy</strong>
|
|
<small>Container output searchable by service and host</small>
|
|
</figcaption>
|
|
<a href="assets/images/portfolio-grafana-logs.png" target="_blank">
|
|
<img src="assets/images/portfolio-grafana-logs.png" alt="Centralized logs snapshot in Grafana" />
|
|
</a>
|
|
<p class="evidence-note">OCT 2026 · LOGGING EVIDENCE</p>
|
|
</figure>
|
|
|
|
<div class="coverage-matrix">
|
|
<div class="panel-title"><span>MONITORING COVERAGE</span><small>CONFIGURED</small></div>
|
|
<ul>
|
|
<li><span>Host metrics</span><i>CONFIGURED</i></li>
|
|
<li><span>Container metrics</span><i>CONFIGURED</i></li>
|
|
<li><span>Application logs</span><i>CONFIGURED</i></li>
|
|
<li><span>Endpoint uptime</span><i>CONFIGURED</i></li>
|
|
<li><span>Resource alerts</span><i>CONFIGURED</i></li>
|
|
<li><span>Security events</span><i>CONFIGURED</i></li>
|
|
</ul>
|
|
<div class="stack-list">
|
|
<span>Grafana</span><span>Prometheus</span><span>Loki</span>
|
|
<span>Alloy</span><span>Node Exporter</span><span>cAdvisor</span>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
<section id="services" class="module services-module">
|
|
<header class="module-header">
|
|
<div>
|
|
<span class="module-id">APP.03</span>
|
|
<h2>Service inventory</h2>
|
|
</div>
|
|
<p>Core applications represented in the internal service portal configuration.</p>
|
|
<div class="module-state"><i></i> LIVE HEALTH / CONFIG SNAPSHOT</div>
|
|
</header>
|
|
|
|
<div class="service-layout">
|
|
<div class="service-table" role="table" aria-label="Service inventory">
|
|
<div class="service-row service-head" role="row">
|
|
<span>Service</span><span>Role</span><span>Access</span>
|
|
</div>
|
|
<div class="service-row"><strong>Gitea</strong><span>Source control</span><span>SSO</span></div>
|
|
<div class="service-row"><strong>Wiki.js</strong><span>Documentation</span><span>SSO</span></div>
|
|
<div class="service-row"><strong>Dashy</strong><span>Service portal</span><span>SSO</span></div>
|
|
<div class="service-row"><strong>Vaultwarden</strong><span>Secrets</span><span>DIRECT</span></div>
|
|
<div class="service-row"><strong>Stirling PDF</strong><span>Document tools</span><span>SSO</span></div>
|
|
<div class="service-row"><strong>IT Tools</strong><span>Utilities</span><span>SSO</span></div>
|
|
<div class="service-row"><strong>Uptime Kuma</strong><span>Availability</span><span>SSO</span></div>
|
|
</div>
|
|
|
|
<div class="portal-shot live-service-panel" aria-label="Live service health">
|
|
<figcaption>
|
|
<span>LIVE SERVICE HEALTH</span>
|
|
<small>SANITIZED ENDPOINT CHECKS</small>
|
|
</figcaption>
|
|
<div class="service-health-grid">
|
|
<div><span>GITEA</span><strong id="health-gitea">CHECKING</strong><small>SOURCE CONTROL</small></div>
|
|
<div><span>WOODPECKER</span><strong id="health-woodpecker">CHECKING</strong><small>CI / DELIVERY</small></div>
|
|
<div><span>UPTIME KUMA</span><strong id="health-kuma">CHECKING</strong><small>AVAILABILITY</small></div>
|
|
<div><span>PROMETHEUS</span><strong id="health-prometheus">CHECKING</strong><small>METRICS</small></div>
|
|
</div>
|
|
<p class="evidence-note">LIVE HEALTH CHECKS · REFRESHED WITH /API/STATUS EVERY 15s</p>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
<section class="module devops-module">
|
|
<header class="module-header">
|
|
<div>
|
|
<span class="module-id">DEV.04</span>
|
|
<h2>Delivery pipeline</h2>
|
|
</div>
|
|
<p>Git-based workflows from repository change to automated deployment.</p>
|
|
<div class="module-state"><i></i> LIVE DELIVERY</div>
|
|
</header>
|
|
|
|
<div class="pipeline">
|
|
<div class="pipeline-flow" aria-label="Deployment pipeline">
|
|
<div><span>01</span><strong>COMMIT</strong><small>Gitea repository</small></div>
|
|
<b>→</b>
|
|
<div><span>02</span><strong>BUILD</strong><small>Woodpecker runner</small></div>
|
|
<b>→</b>
|
|
<div><span>03</span><strong>VERIFY</strong><small>Static checks</small></div>
|
|
<b>→</b>
|
|
<div><span>04</span><strong>DEPLOY</strong><small>Docker host</small></div>
|
|
</div>
|
|
|
|
<div class="pipeline-shots live-pipeline-shots">
|
|
<div class="live-delivery-card">
|
|
<figcaption>GITEA / SOURCE CONTROL</figcaption>
|
|
<div class="delivery-state">
|
|
<span class="delivery-kicker">SERVICE STATE</span>
|
|
<strong id="pipeline-gitea-state">CHECKING</strong>
|
|
<small>REPOSITORY HOST</small>
|
|
</div>
|
|
<div class="delivery-meta">
|
|
<span>ROLE</span><strong>REPOSITORY HOST</strong>
|
|
<span>TRANSPORT</span><strong>SSH / 2222</strong>
|
|
</div>
|
|
</div>
|
|
<div class="live-delivery-card">
|
|
<figcaption>WOODPECKER / DELIVERY</figcaption>
|
|
<div class="delivery-state">
|
|
<span class="delivery-kicker">SERVICE STATE</span>
|
|
<strong id="pipeline-woodpecker-state">CHECKING</strong>
|
|
<small>AUTOMATED DEPLOYMENT</small>
|
|
</div>
|
|
<div class="delivery-meta">
|
|
<span>DEPLOYED COMMIT</span><strong id="deployed-commit">-------</strong>
|
|
<span>TARGET</span><strong>BYTEGEIST.CASKO.DEV</strong>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</div>
|
|
</section>
|
|
|
|
<section id="security" class="module security-module">
|
|
<header class="module-header">
|
|
<div>
|
|
<span class="module-id">SEC.05</span>
|
|
<h2>Identity & perimeter</h2>
|
|
</div>
|
|
<p>Central authentication, protected services, and documented hostile-traffic detection controls.</p>
|
|
<div class="module-state"><i></i> CONTROLS DOCUMENTED</div>
|
|
</header>
|
|
|
|
<div class="security-layout">
|
|
<div class="security-data">
|
|
<div class="security-score">
|
|
<span>IDENTITY / ACCESS POSTURE</span>
|
|
<strong>HARDENED</strong>
|
|
<small>AUTHENTIK / KEY-ONLY SSH / SSO / TLS</small>
|
|
</div>
|
|
<ul>
|
|
<li><span>OIDC providers</span><strong>CONFIGURED</strong></li>
|
|
<li><span>Forward-auth apps</span><strong>CONFIGURED</strong></li>
|
|
<li><span>2FA policy</span><strong>ENFORCED</strong></li>
|
|
<li><span>Public SSH password</span><strong>DISABLED</strong></li>
|
|
</ul>
|
|
</div>
|
|
|
|
<figure class="crowdsec-shot">
|
|
<figcaption>
|
|
<span>CROWDSEC / DECISION HISTORY</span>
|
|
<small>Captured evidence of hostile-source decisions</small>
|
|
</figcaption>
|
|
<a href="assets/images/portfolio-crowdsec-decisions.png" target="_blank">
|
|
<img src="assets/images/portfolio-crowdsec-decisions.png" alt="CrowdSec firewall decision evidence snapshot" />
|
|
</a>
|
|
<p class="evidence-note">OCT 2026 · DECISION-HISTORY EVIDENCE</p>
|
|
</figure>
|
|
</div>
|
|
</section>
|
|
|
|
<section class="module recovery-module">
|
|
<header class="module-header">
|
|
<div>
|
|
<span class="module-id">DR.06</span>
|
|
<h2>Recovery state</h2>
|
|
</div>
|
|
<p>Configuration in Git, persistent data backups, and an explicit rebuild sequence.</p>
|
|
<div class="module-state"><i></i> RUNBOOK DOCUMENTED</div>
|
|
</header>
|
|
|
|
<div class="recovery-layout">
|
|
<div class="recovery-sequence">
|
|
<div><span>01</span><strong>Provision host</strong><small>Ubuntu / firewall / SSH</small></div>
|
|
<div><span>02</span><strong>Restore config</strong><small>Git / Compose / secrets</small></div>
|
|
<div><span>03</span><strong>Restore data</strong><small>Volumes / databases</small></div>
|
|
<div><span>04</span><strong>Validate edge</strong><small>DNS / TLS / identity</small></div>
|
|
</div>
|
|
<figure>
|
|
<a href="assets/images/portfolio-wiki-disaster-recovery.png" target="_blank">
|
|
<img src="assets/images/portfolio-wiki-disaster-recovery.png" alt="ByteGeist disaster recovery runbook documentation snapshot" />
|
|
</a>
|
|
<p class="evidence-note">OCT 2026 · RUNBOOK CAPTURE</p>
|
|
</figure>
|
|
</div>
|
|
</section>
|
|
</main>
|
|
|
|
<footer>
|
|
<div class="footer-mark">
|
|
<img src="assets/images/bytegeist-logo.png" alt="" />
|
|
<div><strong>BYTEGEIST</strong><span>KEITH CASKO / INFRASTRUCTURE LAB</span></div>
|
|
</div>
|
|
<p>HTML / CSS / JAVASCRIPT · PYTHON STATUS API · NGINX</p>
|
|
<p>VERIFICATION: <span class="status-text">OCT 2026</span></p>
|
|
</footer>
|
|
</body>
|
|
</html>
|