Problem
Security controls are easier to reason about when infrastructure is intentionally segmented, observable, and testable. The lab was designed to create clear trust boundaries and measurable policy behavior.
Architecture approach
The environment separates management, workstation, server, and governed AI workloads. Firewall policy controls inter-segment communication and approved service paths.
- OPNsense firewall policy
- Managed VLAN segmentation
- Proxmox virtualization
- Linux management and service hosts
- Central observability
- Reusable policy/compliance benchmarks
Governed AI design
Local AI workers operate without direct public Internet access. External research and tool use are mediated through approved pathways, with role boundaries and evidence retention designed into the system.
Public disclosure boundary
This case study intentionally omits live IP addresses, detailed control-plane configuration, private hostnames, credentials, and other operationally sensitive information.