Reviewed public architecture summary. Sensitive addresses, hostnames, and operating details are intentionally abstracted.
Lab Architecture Overview
This page is the public architecture view: readable at a glance, intentionally abstracted, and focused on how the lab supports security engineering work. The full operator diagrams remain available as references at the end of the page.
Public System Shape
Static Astro portfolio, sanitized writeups, services, status, roadmap, and selected architecture notes.
Curated content, Astro build, redaction checks, link checks, and Loopia dry-run before publish.
Scenario range, blue-team telemetry, agent bridge, knowledge graph, evidence storage, and local inference.
Architectural Layers
Control Plane
Agent tools, model routing, workflow automation, approval gates, and publication checks.
- Astro build gate
- OpenBao secret boundary
- Capability registry
Scenario Range
Repeatable security exercises against isolated lab systems, not production infrastructure.
- Active Directory scenarios
- Web and Linux targets
- Resettable baselines
Detection Stack
Telemetry and evidence collection turn exercises into measurable blue-team outcomes.
- SIEM correlation
- Endpoint hunts
- Network evidence
Knowledge Layer
Validated findings become reusable notes, public-safe summaries, and retrieval context.
- Knowledge graph
- Writeup library
- State summaries
Publication Flow
- CurateChoose public-safe material
Architecture, research lessons, service positioning, and sanitized lab results.
- BuildRender with Astro
Markdown and static assets become the local
public_html/artifact. - AuditBlock leaks and drift
Local links, assets, unsafe HTML, stale routes, and private markers are checked.
- PreviewDry-run Loopia transfer
The exact file transfer is reviewed before any live action.
- PublishTransfer and verify
The approved artifact is deployed to Loopia and checked over HTTPS.
Purple-Team Feedback Loop
Every public story starts with bounded lab work and ends as reviewed, reusable knowledge.
Scope
Operator-approved exercise boundaries and no live action outside scope.
Exercise
Repeatable attack or validation path inside the isolated scenario range.
Evidence
Artifacts, telemetry, and observations captured for review.
Detection
Blue-team stack measures what happened and where coverage improved.
Knowledge
Findings feed internal docs, retrieval context, and public-safe writeups.
Public Reference Diagrams
The full diagrams are still available for detail work, but they are reference material rather than the primary public overview.
Hardware and hosting tiers at a glance.
View SVGEdit sourceSanitized routing and segmentation reference.
View SVGEdit sourceAutomation, model routing, and observability services.
View SVGEdit sourceSanitized summary of exercise flow and validation paths.
View SVGEdit sourceQuick Reference Table
| Host | IP | Role | Key Services |
|---|---|---|---|
| Gateway tier | private lab | Firewall, VPN, and network control | Segmented lab access |
| Virtualization tier | private lab | Cyber-range VM host | SAGA domain, workstation, and Linux targets |
| Blue-team tier | private lab | Detection and orchestration plane | Telemetry, model routing, dashboards, and automation |
| AI compute tier | private lab | Local inference workers | GPU-backed analysis and content generation |
| Storage tier | private lab | Evidence and knowledge storage | Backups, sanitized exports, and ingest queues |
| Attacker tier | private lab | Scoped exercise workstation | Approved internal validation tooling |
| SAGA domain targets | private lab | Active Directory lab hosts | Exercise objectives and telemetry sources |
| SAGA application targets | private lab | Linux and web services | Vulnerable training applications |
| Observability tier | private lab | SIEM and evidence collection | Blue-team proof and analyst workflows |
External Infrastructure
| Host | IP | Role | Key Services |
|---|---|---|---|
| Hostinger VPS | [CLOUD-IP-REDACTED] | External research face (standalone) | VPN-reachable n8n/Hermes experiments, routing/proxy utilities, and scoped bug-bounty workflow tests |
| hacklab.cloud | [CLOUD-IP-REDACTED] | Parked domain (Hostinger DNS) | No live services — domain not pointed at VPS |
| kryssar.se | Loopia hosting | Public portfolio | Astro static site, published from approved public_html/ artifacts |