edris-hub/homelab-infrastructure

GitHub: edris-hub/homelab-infrastructure

该仓库记录了一套为期 12 周的企业级自托管基础设施从零搭建的完整过程,包含 Zero Trust 网络架构、身份管理、自动化运维和灾备方案。

Stars: 1 | Forks: 0

# 🔌 企业网络与系统实验室:12 周 Zero Trust 验证 本仓库记录了为期 12 周的完整生产级企业 IT 环境部署过程。该实验室在一台物理主机(i7-12700H,32GB RAM)上从零开始构建,复刻了现代 ESN 或 DSI 中所期望的基础设施与运维工作流。 该架构实施了严格的 **Zero Trust / Default-Deny** 安全态势,采用微分段 VLAN、联邦身份管理、集中式可观测性以及 Infrastructure as Code (IaC) 自动化。 ## 🗺️ 高层架构 网络在物理上进行了桥接,但在逻辑上被划分为 OPNsense 防火墙后三个严格的安全区域。 ``` [ Public Internet ] │ [ OPNsense Firewall ] (Default-Deny) │ ┌───────────────────────┼───────────────────────┐ │ │ │ VLAN 10 VLAN 20 VLAN 30 [ MGMT ] [ CORP ] [ DMZ ] Management Plane Internal Enterprise Public-Facing 192.168.10.0/24 192.168.20.0/24 192.168.30.0/24 🛠️ Core Technology Stack Routing & Security: OPNsense, WireGuard (Split-Tunneling), nftables, Fail2ban Identity & Access: Active Directory (Windows Server 2022), Keycloak (SSO / SAML / LDAP) ITSM & Ticketing: GLPI (Automated IMAPS ticket ingestion) Messaging: Sovereign Mailcow (Dockerized) with DKIM/DMARC/SPF via public VPS relay Automation (IaC): Ansible, Bash, PowerShell Observability: Zabbix (Telemetry & Webhooks), Grafana, Centralized rsyslog 📁 Repository Structure Detailed documentation, architectural diagrams, configurations, and scripts are categorized by their respective deployment week. /week-01/ — Network Architecture, IP Addressing, OPNsense Default-Deny Policies & VLANs. /week-02/ — Hybrid Identity: Active Directory deployment, OU structures, CSV automation, and Keycloak SSO federation. /week-03/ — ITSM & Sovereign Mail: GLPI deployment, Mailcow staging via WireGuard, and automated IMAPS mail-to-ticket routing. /week-04/ — Zero Trust Access: Bastion Host implementation and aggressive SSH hardening. (Upcoming) (Folders for Weeks 05 through 12 covering Ansible automation, Zabbix monitoring, HAProxy reverse proxies, and Disaster Recovery will be published as the deployment progresses.) 🚀 Project Roadmap Phase 1: Enterprise Foundation & Security Boundary (Weeks 1–4) Establishing the hypervisor, routing, default-deny perimeter, directory services, and ITIL ticketing workflows. Phase 2: Operations, Automation & Visibility (Weeks 5–8) Transitioning from manual configuration to Infrastructure as Code (Ansible), deploying enterprise telemetry (Zabbix/Grafana), and configuring reverse proxies (HAProxy) with automated PKI. Phase 3: Disaster Recovery & Production Handover (Weeks 9–12) Simulating ransomware attacks with timed backups/restores, high-availability failovers, vulnerability scanning (Lynis/Wazuh), and final TSSR jury dossier preparation. 👤 Contact Lead Infrastructure Engineer: Edris Ahmad Dost Portfolio & Full Documentation: protechcorp.net Professional Profile: LinkedIn ```
标签:AI合规, OPNsense, Terraform 安全, 企业IT架构, 应用安全, 系统提示词, 网络隔离, 自动化运维, 请求拦截, 身份与访问管理, 运维与基础设施, 零信任网络