Security Lab — roadmap and sprints

Goals, phases, sprint targets, and GitHub tracking model for the security lab.

The lab roadmap is tracked in the private GitHub repository with milestones, issues, labels, and a GitHub Project board.

Goals

GoalOutcome
Recoverable workLong-running tasks run in tmux, with task notes and logs where useful
Practical security learningVAPT, vulnerability management, detection, telemetry, and remediation workflows
Cisco data center networkingNX-OS, MP-BGP EVPN, VXLAN, multisite, Nexus Dashboard, and NDFC
Safe documentationPublic/protected docs include learning notes and architecture, not secrets
Repeatable phasesEach phase produces runbooks, verification evidence, and next-step issues

Phases

PhaseTarget
Phase 0 — Governance and resume protocolComplete
Phase 1 — Lab stabilizationComplete for current lab services
Phase 2 — Single-site EVPN/VXLANComplete for the two-spine, two-leaf Nexus lab
Phase 3 — Dual-border and services VRFComplete for current tenant border and services leak-control drills
Phase 4 — Security validation loopsComplete for current SOC evidence and daily health model
Phase 5 — Nexus Dashboard and NDFCNext Cisco data center expansion
Phase 6 — Cisco expansion trackFuture: ISE, FTDv/FMCv, ASAv, Catalyst 8000V, ACI, or IOS XRv
Phase 7 — NetApp / StorageGRIDPaused until official evaluation media and license are staged

Sprint Targets

SprintDatesTarget outcome
Sprint 012026-05-13 to 2026-05-26Lab baseline stable, Security Onion verified, EVE-NG ready for Nexus 9300v first boot
Sprint 022026-05-27 to 2026-06-09Single-site EVPN/VXLAN underlay, overlay, and tenant reachability working
Sprint 032026-06-10 to 2026-06-23Multisite design and border gateway workflow working
Sprint 042026-06-24 to 2026-07-07Detection, scanning, and VAPT evidence loops documented
Sprint 052026-07-08 to 2026-07-21Nexus Dashboard deployed and NDFC evaluated against manual fabric workflows
Sprint 062026-07-22 to 2026-08-04Next Cisco expansion track selected and first appliance staged

GitHub Tracking Model

ObjectUse
GitHub ProjectBoard for status, phase, sprint, priority, and workstream
MilestonesPhase boundaries
IssuesConcrete implementation, validation, research, and documentation tasks
LabelsArea, priority, type, and sprint filtering
ADRsDurable technical decisions
Task logsResume state for long-running or state-changing work

Current Closure

The current Nexus/SOC phase is closed for lab use. The closure criteria were:

  • full Nexus validation completed;
  • services VRF guard returned healthy;
  • SOC daily health returned healthy;
  • scenario evidence had no failed or partial cases;
  • endpoint checks responded;
  • private documentation and replay commands were committed and pushed.

The next recommended sprint is operations hardening: schedule the services VRF guard, add alerting for guard failures, keep the dashboard current, and then decide whether to proceed with Nexus Dashboard/NDFC or the paused NetApp/StorageGRID track.

Last reviewed: 2026-05-15