Reviewed public architecture summary. Sensitive addresses, hostnames, and operating details are intentionally abstracted.

Lab Architecture Overview

This page is the public architecture view: readable at a glance, intentionally abstracted, and focused on how the lab supports security engineering work. The full operator diagrams remain available as references at the end of the page.


Public System Shape

Public site kryssar.se

Static Astro portfolio, sanitized writeups, services, status, roadmap, and selected architecture notes.

Review boundary Publication Gate

Curated content, Astro build, redaction checks, link checks, and Loopia dry-run before publish.

Private lab CGE Lab

Scenario range, blue-team telemetry, agent bridge, knowledge graph, evidence storage, and local inference.

Architectural Layers

01

Control Plane

Agent tools, model routing, workflow automation, approval gates, and publication checks.

  • Astro build gate
  • OpenBao secret boundary
  • Capability registry
02

Scenario Range

Repeatable security exercises against isolated lab systems, not production infrastructure.

  • Active Directory scenarios
  • Web and Linux targets
  • Resettable baselines
03

Detection Stack

Telemetry and evidence collection turn exercises into measurable blue-team outcomes.

  • SIEM correlation
  • Endpoint hunts
  • Network evidence
04

Knowledge Layer

Validated findings become reusable notes, public-safe summaries, and retrieval context.

  • Knowledge graph
  • Writeup library
  • State summaries

Publication Flow

  1. CurateChoose public-safe material

    Architecture, research lessons, service positioning, and sanitized lab results.

  2. BuildRender with Astro

    Markdown and static assets become the local public_html/ artifact.

  3. AuditBlock leaks and drift

    Local links, assets, unsafe HTML, stale routes, and private markers are checked.

  4. PreviewDry-run Loopia transfer

    The exact file transfer is reviewed before any live action.

  5. PublishTransfer and verify

    The approved artifact is deployed to Loopia and checked over HTTPS.

Purple-Team Feedback Loop

Controlled loop Scope -> Exercise -> Evidence -> Detection -> Knowledge

Every public story starts with bounded lab work and ends as reviewed, reusable knowledge.

01

Scope

Operator-approved exercise boundaries and no live action outside scope.

02

Exercise

Repeatable attack or validation path inside the isolated scenario range.

03

Evidence

Artifacts, telemetry, and observations captured for review.

04

Detection

Blue-team stack measures what happened and where coverage improved.

05

Knowledge

Findings feed internal docs, retrieval context, and public-safe writeups.

Public Reference Diagrams

The full diagrams are still available for detail work, but they are reference material rather than the primary public overview.

ServicesAI Infrastructure

Automation, model routing, and observability services.

View SVGEdit source

Quick Reference Table

Host IP Role Key Services
Gateway tier private lab Firewall, VPN, and network control Segmented lab access
Virtualization tier private lab Cyber-range VM host SAGA domain, workstation, and Linux targets
Blue-team tier private lab Detection and orchestration plane Telemetry, model routing, dashboards, and automation
AI compute tier private lab Local inference workers GPU-backed analysis and content generation
Storage tier private lab Evidence and knowledge storage Backups, sanitized exports, and ingest queues
Attacker tier private lab Scoped exercise workstation Approved internal validation tooling
SAGA domain targets private lab Active Directory lab hosts Exercise objectives and telemetry sources
SAGA application targets private lab Linux and web services Vulnerable training applications
Observability tier private lab SIEM and evidence collection Blue-team proof and analyst workflows

External Infrastructure

Host IP Role Key Services
Hostinger VPS [CLOUD-IP-REDACTED] External research face (standalone) VPN-reachable n8n/Hermes experiments, routing/proxy utilities, and scoped bug-bounty workflow tests
hacklab.cloud [CLOUD-IP-REDACTED] Parked domain (Hostinger DNS) No live services — domain not pointed at VPS
kryssar.se Loopia hosting Public portfolio Astro static site, published from approved public_html/ artifacts