An internal infrastructure foundation that reproduces our home CI server fleet from code. It bases pass/fail decisions on real-machine kill-tests rather than design documents, ensuring uninterrupted availability even during failures.
Provides ×10 org self-hosted runners (light/docker/security), security-pr/main/scheduled workflows, Dependabot, and DefectDojo vulnerability ledger integration.
A monitoring stack of Grafana, Loki, Prometheus, Alertmanager (Slack + email), Tempo + Alloy (OTel), node_exporter, cAdvisor, and Promtail.
OpenSearch and Dashboards deliver log ingestion via Vector (importance-based sampling) and ISM retention.
Semgrep, Trivy, Gitleaks, CodeQL, and Safe Chain are built into runner images and workflows.
S3, Glue (partition projection), Athena, and IAM, with a verified log path from Firehose through S3 to Athena.
Cloudflare Access (GitHub login) controls access to graph, DefectDojo, and kibana.eln.ne.jp (Grafana uses JWT SSO, DefectDojo uses two layers, Dashboards uses Access only).
Status: Internal use
Feel free to contact us with any questions about adoption or integration.