§ THE RIG · HARDWARE LOG

The physical layer.

Sovereignty starts at the silicon. Each rig below is in production, running, hardened, and documented end to end.

The Vault
RIG-01LIVE
Perimeter firewall / pfSense

The Vault

§ PARTS LIST
ChassisProtectli VP2420, 4× 2.5GbE
CPUIntel J6412, 4C, 10W TDP
Memory16 GB DDR4 SO-DIMM
Storage256 GB NVMe (mirrored boot)
OSpfSense CE 2.7.x on bare metal (ZFS)

§ BUILD LOG

Coreboot flashed first; AMI firmware never touched the disk. WAN on igc0, LAN on igc1, two VLAN trunks on igc2/3. Suricata in IPS mode on WAN, WireGuard road-warrior on UDP 51820.

Sentinel Node
RIG-02LIVE
Headless services / DNS sinkhole

Sentinel Node

§ PARTS LIST
BoardRaspberry Pi 5, 8 GB
CaseArgon ONE V3 (passive + fan)
Storage512 GB NVMe via M.2 HAT
OSDebian 12, full-disk encrypted
StackUnbound + AdGuard Home + Tailscale

§ BUILD LOG

Built headless from a Mac. SSH key-only on a non-standard port, fail2ban on, unattended-upgrades on, full DNS-over-TLS upstream to a node I trust. Power draw idle: 3.1 W.

§ 00, BOOTING FIELD MANUAL
● LINK · NEGOTIATING
JTA //

JUSTIN · THE · ARCHITECT

> establishing secure channel…

HANDSHAKE004%READY
● STATUS: HANDSHAKE
LAT 00.000 · LON 00.000