Read-only by default
Agents observe first. Writes are gated, confirmed, and reversible.
Georgi Gaydarov builds AI-native network operations tooling — labs that remediate, changes that never leave the wall, and a 70,000-command CLI that actually compares vendors.
Nine public labs. Docs first. Fail-closed by default. Agents observe, a twin verifies, a human owns the blast radius.
Docs first. Fail-closed by default. Every project is meant to be cloned.
Fail-closed defensive assessment orchestrator. Supervised V1 release candidate; experimental V2 with an out-of-band HMAC signer and operator-gated evidence graph. Isolated lab only — unattended mode stays locked. 315 tests.
SecurityAir-gapped pre-deployment network change validation against a real containerlab digital twin. v0.2.0: 11 frameworks, HMAC approvals, detached Ed25519 seals, OSCAL/CAB export. Zero egress.
Closed-loop26-device lab that closes the loop — anomalies auto-remediate, risk-gated, with RFC 6241 confirmed-commit rollback. Interactive Lab Ops portal, Pydantic-AI orchestrator, 69 MCP tools. Phase 6.
Closed-loopHonest, live multivendor NAPALM coverage — Arista cEOS, Nokia SR Linux and FRR — plus a safe-by-default console of 2,361 curated commands.
Closed-loopSanitize-first AI log analyzer. Syslog in, ranked CLI playbooks out. v0.6.0 shipped: Grok backend, causal timeline, blast radius, 80 patterns, 423 tests. Local, Claude, or Grok — the model never sees a credential.
Reference70,000+ CLI commands across 17 vendors — searchable, concept-aligned N-vendor compare, NETCONF / Ansible drawers. CLI Studio adds intent, migrate, recipes, EOS/FRR/VyOS parsers, and a 10-node FRR lab map.
Referencev2.0 interactive console: OTLP/Alloy, Tempo, gNMI, freshness SLOs, dual-signal lab, and a read-only AI control plane. Discovery never writes NetBox.
LLM toolingInteractive single-page guide to mastering Claude — the app, Claude Code, the API, MCP, skills, subagents, and hooks. Zero-dependency reference.
LLM toolingv0.5 zero-dependency linter for Claude Code Agent Skills — 90+ checks, 2026 model IDs (Opus 5 / Sonnet 5), computer-use safety, and a 22-skill NetOps pack.
No projects match that filter.
Everything public here is a closed loop: observe, sanitize, decide, verify against a twin, then write only with a human on the blast radius. Nothing leaves the wall but evidence.
Packets ride the ring. The LLM never sees raw syslog. Writes never skip the guard.
Nine labs as one control plane. Click a node to open its docs.
Operator submits intent or a sanitized running-config — never a credential, never raw syslog.
Sanitize-first: netlog-ai redacts before any model. The LLM sees a problem, not a secret.
Pydantic-AI + 69 MCP tools propose a change against the 26-device multivendor lab.
AEGIS preflights on a throwaway containerlab twin. ARGUS stays read-only behind 7 guardrail layers.
Risk gate: auto / approve / page-out. RFC 6241 confirmed-commit with rollback. A person owns blast radius.
Only a sealed HMAC / PCI / SOC2 / NIST evidence badge leaves. Egress: none.
And why the agents do not get a blank check.
Agents observe first. Writes are gated, confirmed, and reversible.
Raw syslog never meets an LLM. The model sees a problem, not a credential.
A 7-layer guardrail. Risk gates of auto / approve / page-out. Unclear policy means nothing fires.
What leaves the wall is a sealed badge. HMAC-audited runs. Immutable GAIT.
Publish what actually works on Arista, Nokia SR Linux, and FRR — not a marketing matrix.
RFC 6241 confirmed-commit with rollback. Automation proposes; a person owns the blast radius.
What actually runs in the labs — not a marketing matrix.
Twenty-plus years on multivendor networks — Juniper, Arista, Cisco, Palo Alto, Fortinet — spanning BGP/MPLS, SD-WAN, SASE, and Zero Trust. The last few years have been about putting that craft into agents that can see, decide, and (only then) change a fabric.
GESH Lab is the public documentation hub for those projects. Private work stays private. Everything here is documented and meant to be cloned.