ABD Labs has two jobs that need to stay separate.
The public site should prove work: architecture notes, routing evidence, sanitized command output, lessons learned, diagrams and case-study narratives.
The lab itself should remain private by default. A Microsoft enterprise lab eventually contains domain controllers, Windows workstations, credentials, policies, directory structure, logs and intentionally weak configurations used for troubleshooting scenarios. Those are useful for learning, but they do not belong on the public internet.
What Can Be Public
- sanitized architecture diagrams;
- synthetic datasets;
- high-level implementation steps;
- command outputs with secrets and identifiers removed;
- troubleshooting narratives;
- lessons learned and follow-up decisions.
What Stays Private
- RDP, SMB, LDAP, Kerberos, DNS, WinRM and hypervisor consoles;
- passwords, tokens, private keys and activation material;
- raw admin screenshots that reveal sensitive identifiers;
- real tenant IDs, customer exports or personal production data.
The rule is simple: publish evidence of the work, not access to the environment.
That is why the first version of ABD Labs is static. It gives the portfolio a durable public home while the future lab network, compute and private access path can be designed deliberately.