traceroute ~/lab
Architecture
The lab is segmented for defense-in-depth: a hardened perimeter, a dedicated detection and threat-intel tier, and isolated self-hosted services behind the load balancer.
Edge / Perimeter
pfSense firewall · Suricata IDS/IPS · site-to-site VPN · Kemp load balancer (SSL offload)
Detection & Intel
Wazuh SIEM/EDR · MISP vulnerability feed · OpenCanary honeypots
Services
KASM isolated browser · SearXNG metasearch · Uptime Kuma monitoring