BasedToronto, Canada
Updated01 · Jun · 2026
Volumevol. ii — public
Filed underAgents · Infra · Audio · Security

Oliver Studio /06

A working notebook for verifiable systems, honest agents, and the quiet infrastructure beneath both. This is the public surface — production lives elsewhere.

Editor
Oliver Z.
Format
Open lab · seasonal
Status
In flight
Pages
vi + 72 (digital)

Bias toward verifiable builds. Reproducible infra, observable systems, explicit trust boundaries — every layer should answer for itself.

Editor's note · I — Oliver, 2026
Filed · 01 Jun 2026

Move fast, break things. Move fast with stable infra.

Optimize the output. Reason from first principles.

Automate the human away. Keep the human in the loop.

Trust the model. Trust, but verify the trace.

Hide the seams. Show your work.

Sixteen threads, one
running lab.

Tiles 01–09 are homelab GitOps; 10–15 mix live agents with early proposals; 16 is the onegraph monorepo — repo intelligence plus agent evidence, built beside the lab. Click for a dossier overlay — no hostnames, credentials, or internal runbooks on this page.

What's on the desk right now.

  • This week Agent egress gateway — Envoy forward proxy, ext_authz Policy API, and TTL-bounded approvals before agents reach the public internet. Agents
  • In flight OTel anomaly planning control plane — durable run store, worker loop, and advisory digests (no autoscaling mutations yet). OTel
  • This month AI L7 dogfood — Teleport app access, LiteLLM gateway, and a read-only Kubernetes MCP server on the sandbox cluster. Access
  • Steady state Mimir · Loki · Tempo on the hub; fleet collectors shipping RED and infra metrics without copying high-cardinality labels. Observability
  • Next More public write-ups on agent sandbox boundaries — what the policy layer guarantees, and what it deliberately does not. Writing

The stack, from kernel to keys.

What I reach for in the homelab today — patterns and families, not an inventory of hostnames or secrets.

L0 · Substrate

Hardware, kernel, network.

  • Linux
  • eBPF
  • WireGuard
  • Tailscale
  • Pi-hole
L1 · Platform

Cluster shape and lifecycle.

  • k3s
  • Argo CD
  • Cilium
  • Crossplane
  • External Secrets
  • Cloudflare
L2 · Mesh & agents

Identity, ingress, and sandboxes.

  • SPIRE
  • Istio ambient
  • Envoy Gateway
  • gVisor sandboxes
  • LiteLLM
  • Teleport
L3 · Observability

How we know it's working.

  • Mimir
  • Loki
  • Tempo
  • Grafana
  • OpenTelemetry
  • Honest dashboards
16 Active experiments
2 GitOps clusters
99.2% Deploy success (Argo)
Margin notes

Send a signal.

Email and GitHub are the durable channels. Everything else — internal Grafana, cluster APIs, private notes — stays behind the homelab boundary.