ADR-0007
decides that Saruman hosts the defensive lab estate: a Windows domain, Wazuh,
Velociraptor, Proxmox Backup Server, and its own Loki/Grafana/Alloy under
stacks/lab/.
stacks/ contains exactly one directory: observability. None of this exists.
The roadmap has no entry for any of it, which is why this is being filed — an
accepted ADR with no tracked work is indistinguishable from a rejected one after
six months.
Worth deciding before starting
- The second observability stack is the interesting decision. The ADR calls
for lab telemetry to stay on Saruman rather than flow into the VLAN 99
stack, which keeps deliberately-hostile data out of the estate's real
monitoring. That is sound, and it doubles the number of Grafana instances,
alert routes and age keys to look after. The Makefile is already
stack-parameterised (STACK ?= observability), so the tooling supports it.
Saruman has no Alloy agent yet, so the host that is meant to run a
second stack is currently not monitored by the first one.
- Wazuh in particular is not a small thing to run — it is the heaviest component
in the ADR by a wide margin.
Probably wants breaking into per-component issues once the shape is settled;
this is the umbrella.
ADR-0007
decides that
Sarumanhosts the defensive lab estate: a Windows domain, Wazuh,Velociraptor, Proxmox Backup Server, and its own Loki/Grafana/Alloy under
stacks/lab/.stacks/contains exactly one directory:observability. None of this exists.The roadmap has no entry for any of it, which is why this is being filed — an
accepted ADR with no tracked work is indistinguishable from a rejected one after
six months.
Worth deciding before starting
for lab telemetry to stay on
Sarumanrather than flow into the VLAN 99stack, which keeps deliberately-hostile data out of the estate's real
monitoring. That is sound, and it doubles the number of Grafana instances,
alert routes and age keys to look after. The
Makefileis alreadystack-parameterised (
STACK ?= observability), so the tooling supports it.Sarumanhas no Alloy agent yet, so the host that is meant to run asecond stack is currently not monitored by the first one.
in the ADR by a wide margin.
Probably wants breaking into per-component issues once the shape is settled;
this is the umbrella.