GESH Lab — closed-loop AI for NetOps architecture Telemetry is sanitized before an LLM decides, a fail-closed guardrail gates writes against a 26-device digital twin, RFC 6241 confirmed-commit applies the change, and only a sealed HMAC evidence badge ever leaves the perimeter. FAIL-CLOSED PERIMETER GESH LAB The loop, closed. — observe · sanitize · decide · twin · guard · commit observe syslog · telemetry PII∅ sanitize never raw to LLM LLM decide Pydantic-AI · MCP 26-device twin Juniper · Arista · Nokia · FRR G1–G7 guard aegis · argus confirm commit RFC 6241 rollback HMAC · GAIT PCI · SOC2 sha256egress:none sealed evidence only the badge leaves
Network automationAI for NetOpsfail-closedegress none

The loop, closed.

Georgi Gaydarov builds AI-native network operations tooling — labs that remediate, changes that never leave the wall, and a 70,000-command CLI that actually compares vendors.

Nine public labs. Docs first. Fail-closed by default. Agents observe, a twin verifies, a human owns the blast radius.

0years on the wire
0public labs & tools
0CLI commands indexed
0devices in the AI lab
0vendors compared
Work

Nine public labs and tools

Docs first. Fail-closed by default. Every project is meant to be cloned.

Security

argus

Fail-closed defensive assessment orchestrator. Supervised V1 release candidate; experimental V2 with an out-of-band HMAC signer and operator-gated evidence graph. Isolated lab only — unattended mode stays locked. 315 tests.

7-layer guardrailOOB HMAC signer315 testssupervised V1
Security

aegis

Air-gapped pre-deployment network change validation against a real containerlab digital twin. v0.2.0: 11 frameworks, HMAC approvals, detached Ed25519 seals, OSCAL/CAB export. Zero egress.

v0.2.0HMAC + Ed25519OSCAL AR11 frameworks
Closed-loop

multivendor-ai-network-lab

26-device lab that closes the loop — anomalies auto-remediate, risk-gated, with RFC 6241 confirmed-commit rollback. Interactive Lab Ops portal, Pydantic-AI orchestrator, 69 MCP tools. Phase 6.

26 devices69 MCP toolsPhase 6
Closed-loop

napalm-live-lab

Honest, live multivendor NAPALM coverage — Arista cEOS, Nokia SR Linux and FRR — plus a safe-by-default console of 2,361 curated commands.

NAPALM2,361 commandsread-only guard
Closed-loop

netlog-ai

Sanitize-first AI log analyzer. Syslog in, ranked CLI playbooks out. v0.6.0 shipped: Grok backend, causal timeline, blast radius, 80 patterns, 423 tests. Local, Claude, or Grok — the model never sees a credential.

v0.6.0423 tests80 patternsGrok
Reference

multivendor-cli-configurator

70,000+ CLI commands across 17 vendors — searchable, concept-aligned N-vendor compare, NETCONF / Ansible drawers. CLI Studio adds intent, migrate, recipes, EOS/FRR/VyOS parsers, and a 10-node FRR lab map.

70k commandsCLI Studiozero-dep
Reference

network-observability-architecture

v2.0 interactive console: OTLP/Alloy, Tempo, gNMI, freshness SLOs, dual-signal lab, and a read-only AI control plane. Discovery never writes NetBox.

v2.0OTLPNetBoxdual-signal
LLM tooling

claude-mastery-hub

Interactive single-page guide to mastering Claude — the app, Claude Code, the API, MCP, skills, subagents, and hooks. Zero-dependency reference.

Claude CodeMCPskills
LLM tooling

claude-skill-lint

v0.5 zero-dependency linter for Claude Code Agent Skills — 90+ checks, 2026 model IDs (Opus 5 / Sonnet 5), computer-use safety, and a 22-skill NetOps pack.

v0.590+ checksNetOps pack
Architecture

Inside the perimeter

Everything public here is a closed loop: observe, sanitize, decide, verify against a twin, then write only with a human on the blast radius. Nothing leaves the wall but evidence.

Closed-loop cycle live

Packets ride the ring. The LLM never sees raw syslog. Writes never skip the guard.

GESH loop closed Observenetlog · telemetry Sanitizeno raw syslog DecidePydantic-AI CommitRFC 6241 Twin26-device lab Guardaegis · argus
System context map

Nine labs as one control plane. Click a node to open its docs.

AIR-GAPPED / FAIL-CLOSED Operatorintent Approvertoken Auditorbadge only GESH control planefail-closed · sanitize-first netlog-aiobserve AI network lab26 devices · MCP aegispreflight twin argus7-layer pentest CLI configurator70k · 17 vendors observabilityNetBox · dual-signal napalm labhonest coverage Claude hubskills · lint
  1. 1

    Operator submits intent or a sanitized running-config — never a credential, never raw syslog.

  2. 2

    Sanitize-first: netlog-ai redacts before any model. The LLM sees a problem, not a secret.

  3. 3

    Pydantic-AI + 69 MCP tools propose a change against the 26-device multivendor lab.

  4. 4

    AEGIS preflights on a throwaway containerlab twin. ARGUS stays read-only behind 7 guardrail layers.

  5. 5

    Risk gate: auto / approve / page-out. RFC 6241 confirmed-commit with rollback. A person owns blast radius.

  6. 6

    Only a sealed HMAC / PCI / SOC2 / NIST evidence badge leaves. Egress: none.

Principles

How the lab is built

And why the agents do not get a blank check.

01

Read-only by default

Agents observe first. Writes are gated, confirmed, and reversible.

02

Sanitize before the model

Raw syslog never meets an LLM. The model sees a problem, not a credential.

03

Fail closed

A 7-layer guardrail. Risk gates of auto / approve / page-out. Unclear policy means nothing fires.

04

Evidence, not screenshots

What leaves the wall is a sealed badge. HMAC-audited runs. Immutable GAIT.

05

Honest coverage

Publish what actually works on Arista, Nokia SR Linux, and FRR — not a marketing matrix.

06

Human-approved change

RFC 6241 confirmed-commit with rollback. Automation proposes; a person owns the blast radius.

Stack

Vendors, protocols, automation, AI

What actually runs in the labs — not a marketing matrix.

Vendors

JuniperAristaCiscoNokiaPalo AltoFortinetFRRVyOSSONiC

Protocols

BGPMPLSEVPNSD-WANSASEZero TrustNETCONF

Automation

PythonAnsibleNornirNAPALMcontainerlabMCP

AI

ClaudeGrokPydantic-AIon-prem LLMsOllamasanitize-first
About

Senior network engineering leader. AI tools builder.

Twenty-plus years on multivendor networks — Juniper, Arista, Cisco, Palo Alto, Fortinet — spanning BGP/MPLS, SD-WAN, SASE, and Zero Trust. The last few years have been about putting that craft into agents that can see, decide, and (only then) change a fabric.

GESH Lab is the public documentation hub for those projects. Private work stays private. Everything here is documented and meant to be cloned.