§2
Filed as done
| Item | Status |
|---|
| Split the network into isolated zones instead of one flat trust area | Complete |
| Write firewall rules for exactly what each zone is allowed to reach | Complete |
| Give DNS a second server, so one machine dying doesn't break lookups | Complete |
| Build a secure way to reach everything remotely, without being on-site | Complete |
| Route traffic through three separate proxies, one per trust level | Complete |
✓ every node has a clear job✓ the whole network is documented — services, IPs, all of it✓ runbook for adding a remote-access peer✓ runbook for adding a remote-access tunnel✓ runbook for bringing a new network zone online✓ real databases running✓ S3-compatible file storage✓ my own file cloud (OpenCloud)✓ my own photo cloud (Immich)✓ a complete build-and-deploy pipeline✓ the whole stack is watched — metrics and alerts✓ single sign-on set up (Authentik)✓ centralized secrets set up (Infisical)✓ my own sites and apps, self-hosted✓ every link in one dashboard