Architecture
Rendered infrastructure architecture diagrams
This tree contains infrastructure as code. Tracked source follows the repository’s public-source policy. Infrastructure facts are not confidential merely because they are operational, generated, or live. Reports may include them unless they contain credentials, other secrets, or personal information. Inspect raw state, plans, inventories, and decrypted configuration because those artifacts can contain prohibited content; do not track the artifacts themselves.
Each infrastructure project owns its specifications and maintained changes
in <project>/openspec/. Use the pinned OpenSpec workflow
with that project selected. These specifications describe checked-in definitions;
they do not establish deployed state or authorize infrastructure operations.
The commands below are state-changing operator examples. An agent must use
bazel_agent, apply the repository Terraform and secret-handling procedures,
and receive explicit authority for the exact operation and environment before
running an equivalent command.
bazel_agent bazel run //infra/vault/tf:tf.apply
bazel_agent bazel run //infra/yandex_cloud/org1/tf:tf.apply
bazel_agent bazel run //infra/pve/tf:tf.apply
bazel_agent bazel run //infra/xcp_ng/tf:tf.apply
tf_backend plugin creates state and lock KV entries on first use.Rendered infrastructure architecture diagrams
Ceph
Shared PVE-based infrastructure VM bootstrap configuration
Project-owned DNS declarations for alwaldend.com
Fluxcd deployment
git.alwaldend.com
Forgejo Actions runner deployment
GitHub organization, repositories, access, and Pages configuration
GitLab resource management
Harbor deployment
ingress
Mikrotik setup for dc1.alwaldend.com
TrueNAS deploy
openhands.alwaldend.com
Proxmox cluster pve.alwaldend.com
Shared organization, repository, and access configuration
Repository evolution specifications and workflow history
3x-ui
Setup for vault.dc1.alwaldend.com
XCP-ng infrastructure
Yandex Cloud (yandex.cloud)