IT-101 v1.0 — Initial Specification
IT-101 v1.0 — Initial Specification
This release establishes the complete open-source day-1 IT infrastructure stack specification, produced by a collaborative AI agent team (CTO, CISO, DevOps, SysAdmin roles).
What's included
- SPEC.md — Full 1.0 specification covering all 12 infrastructure categories
- Stack selection — 30+ open-source tools across identity, email, storage, monitoring, security, GitOps, and operations
- Oracle Cloud Free Tier topology — 5-VM deployment fitting entirely within always-free resources ($0/month at PoC scale)
- Security baseline — CIS Level 1, zero-trust networking, secrets management, audit logging requirements
- Operational playbook — Day-1 checklist, monitoring thresholds, mandatory runbooks, user lifecycle, SLAs
- Project scaffold — Directory structure for OpenTofu, Ansible, Helm, ArgoCD, and documentation
Key Technology Choices
| Category | Tool |
|---|---|
| Identity / SSO | Keycloak |
| Secrets | OpenBao (Vault fork, MPL-2.0) |
| Container Platform | K3s |
| GitOps | ArgoCD + Forgejo + Woodpecker CI |
| IaC | OpenTofu + Ansible |
| Stalwart Mail Server | |
| File Storage | Nextcloud |
| Monitoring | VictoriaMetrics + Grafana + Loki |
| Security | Wazuh + Trivy + Gitleaks |
| Backup | Restic + Velero |
Next Steps
PoC implementation on Oracle Cloud Free Tier — see README for roadmap.