Prefer Bare-Metal Lab Compute For Windows Lab V1
Context
Windows Lab V1 needs a domain controller, a Windows workstation, private administration, snapshots and repeatable rebuilds. The current VPS is already ruled out for Windows VMs.
Decision
Use a KVM-capable local or dedicated bare-metal host for Lab V1, with Tailscale-first private administration and provider or local console access as break-glass. Defer Azure-first VM hosting to cloud identity work or short, costed experiments.
Alternatives Considered
Use the current VPS
- No new host to manage.
- No nested KVM is available.
- The host is too small for Windows VM workloads.
- Production services would inherit lab risk.
Use a nested-virtualization VPS
- Can be easier to order than dedicated hardware.
- Depends heavily on provider support.
- May create weaker performance and snapshot guarantees.
Start with Azure VMs
- Fits later Microsoft cloud and identity work well.
- Always-on Windows lab cost needs explicit budget approval.
- Licensing, governance and disk costs add decision overhead.
Use local or dedicated bare metal
- Gives the lab real virtualization support.
- Keeps experiments isolated from the current VPS.
- Supports private networking, console access and snapshots.
- Requires owned hardware or a recurring dedicated-server budget.
Reasoning
The first lab should optimize for reliable Windows administration evidence without mixing experimental infrastructure into the public portfolio host. Bare-metal compute keeps the operational boundary simple, while Tailscale gives a practical private access path for the first build.
The review did not deploy infrastructure. It records the next approval gate: choose the concrete host/provider, approve the monthly budget or owned hardware, confirm the Windows evaluation/licensing path and approve the private access method before provisioning begins.