- Platform Scope
- Private infrastructure cluster, K3s control layer, runner fleet, infrastructure services, development sandbox, AI control plane
- IaC Substrate
- OpenTofu with bpg/proxmox provider, Terragrunt multi-env DRY layer, modular VM compositions, generated Ansible inventory
- Delivery Layer
- Linux Docker and shell runners, Windows runner with optional GPU passthrough, Kubernetes runner via Helm, SonarQube quality gates
- Platform Services
- Traefik, CloudNativePG, Redis, MinIO, Grafana, Prometheus, Portainer, internal PKI, External Secrets, Infisical-backed secret flow
- AI Layer
- Dedicated OpenClaw control-plane VM with NVIDIA NIM as primary provider and optional GPU path for future local inference
- Validation
- Terratest for Terraform modules, Molecule for Ansible roles, Taskfile orchestration for repeatable provisioning and operations