Engineering

The system view of AutomationLab

Engineering is the part of this site that explains the shape of the lab, how it is secured, how AI is used to build and run it, and how the public-facing observability pages stay honest about what they can and cannot prove. Start here, then follow the pages below for the detail.

Also in Engineering:

  1. Security. The controls that fail closed, the audit that broke one, and the boundaries that stay load-bearing. Read more →
  2. Applied AI. Build-time and operational AI, with budgets, logs, and the hard line between proposing and doing. Read more →
  3. Watchdog. Monitoring for the monitoring path itself, so silence never reads as green. Read more →

Architecture

The diagram page is the map. It shows the edge, the segmented network, the 5-node compute layer, Kubernetes, the systems that hold the truth, and the identity and backup layers underneath them. Every clickable region on that page fans out to the page that explains the subsystem it names, so it is the fastest way to get the whole lab onto one screen.

The public diagram keeps out addresses, segment numbers, and machine names on purpose. The internal copy carries that detail; this one keeps the shape and the boundaries.

Security

The security story here is two layers at once. The security page covers one secrets authority, fail-closed gates, zero trust at the edge, least privilege, and the practice of auditing a control by trying to break it. The Windows identity page covers the directory, the certificate authority, MFA on remote desktop, and a live investigation that stays visible as an honest in-progress branch rather than being cleaned up after the fact.

AI

The AI page is the broad view: where models are used in build and operations, why a local model and a paid API are split by purpose, and how spend is bounded by layered budgets. The point is not that AI is present. It is that it is treated like any other dependency, with written limits, logs, and operator review.

Observability

Observability is split between what you can see at a glance and what catches silence. The NOC page is the public overview, built around one screen and the rule that no-data never reads as green. The watchdog page explains the dead-man switches that alert when a job, digest, or checker stops reporting at all, which is exactly the failure ordinary dashboards miss.