Architecture
Rendered infrastructure architecture diagrams
This tree contains infrastructure as code. Tracked source follows the repository’s public-source policy. Infrastructure facts are not confidential merely because they are operational, generated, or live. Reports may include them unless they contain credentials, other secrets, or personal information. Inspect raw state, plans, inventories, and decrypted configuration because those artifacts can contain prohibited content; do not track the artifacts themselves.
The commands below are state-changing operator examples. An agent must use
bazel_agent, apply the repository Terraform and secret-handling procedures,
and receive explicit authority for the exact operation and environment before
running an equivalent command.
bazel_agent bazel run //infra/vault/tf:tf.apply
bazel_agent bazel run //infra/yandex_cloud/org1/tf:tf.apply
bazel_agent bazel run //infra/pve/tf:tf.apply
Rendered infrastructure architecture diagrams
Ceph
Dns setup for alwaldend.com
Fluxcd deployment
forgejo.alwaldend.com
Forgejo Actions runner deployment
GitHub Pages repositories for project landing sites
Harbor deployment
ingress
Mikrotik setup for dc1.alwaldend.com
TrueNAS deploy
Proxmox cluster pve.alwaldend.com
3x-ui
Setup for vault.dc1.alwaldend.com
XCP-ng infrastructure
Yandex Cloud (yandex.cloud)