Prefer Bare-Metal Lab Compute For Windows Lab V1

labvirtualizationprivate-access

Windows Lab V1 needs a domain controller, a Windows workstation, private administration, snapshots and repeatable rebuilds. The current VPS is already ruled out for Windows VMs.

Use a KVM-capable local or dedicated bare-metal host for Lab V1, with Tailscale-first private administration and provider or local console access as break-glass. Defer Azure-first VM hosting to cloud identity work or short, costed experiments.

Use the current VPS

Pros
  • No new host to manage.
Cons
  • No nested KVM is available.
  • The host is too small for Windows VM workloads.
  • Production services would inherit lab risk.

Use a nested-virtualization VPS

Pros
  • Can be easier to order than dedicated hardware.
Cons
  • Depends heavily on provider support.
  • May create weaker performance and snapshot guarantees.

Start with Azure VMs

Pros
  • Fits later Microsoft cloud and identity work well.
Cons
  • Always-on Windows lab cost needs explicit budget approval.
  • Licensing, governance and disk costs add decision overhead.

Use local or dedicated bare metal

Pros
  • Gives the lab real virtualization support.
  • Keeps experiments isolated from the current VPS.
  • Supports private networking, console access and snapshots.
Cons
  • Requires owned hardware or a recurring dedicated-server budget.

The first lab should optimize for reliable Windows administration evidence without mixing experimental infrastructure into the public portfolio host. Bare-metal compute keeps the operational boundary simple, while Tailscale gives a practical private access path for the first build.

The review did not deploy infrastructure. It records the next approval gate: choose the concrete host/provider, approve the monthly budget or owned hardware, confirm the Windows evaluation/licensing path and approve the private access method before provisioning begins.