VirtuArchitect / Personal platform engineering lab

Enterprise infrastructure architecture and automation for complex environments.

I am currently working on practical automation patterns for Nutanix, virtualisation, migration readiness, disconnected infrastructure, and platform operations.

Designed for complex, controlled, and disconnected environments.

Proof before change Lab-safe workflows Offline-ready planning Reviewable runs AI governance patterns
6 active engineering projects
v1.7.10 ZTF-Orchestrator release baseline
CI public portfolio with demo-backed and test-backed evidence

Latest update

Portfolio evidence refreshed across the current repository baselines.

Updated Aug 25, 2026: ZTF-Orchestrator now reflects the v1.7.10 release line, including post-cluster hardening workflows, an AHV Security Hardening wizard, installed build identity, and checksum-backed appliance update package evidence. The portfolio also reflects NDC Studio v9.8.0, Migration Readiness stateful operations console foundations, and StrataOne container vulnerability scanning.

Review project evidence

About

Architecture experience translated into working platform tools.

I am John Goulden, an enterprise architect and infrastructure engineer with a long-standing interest in cloud, virtualisation, infrastructure platforms, and AI systems. This independent portfolio documents personal engineering projects, experiments, and demonstrations built outside my professional responsibilities.

My focus is on environments where change needs to be planned, bounded, reviewed, and handed over cleanly: Nutanix platforms, VMware-to-Nutanix readiness, NKP deployment paths, disconnected or proxied infrastructure, and internal platform operating models.

The projects here turn that background into working consoles, frameworks, readiness tools, and demos. The common thread is operational clarity: reduce manual ambiguity, make risks visible before action, and leave behind evidence someone else can inspect.

Flagship console

ZTF-Orchestrator is the flagship case study.

The portfolio leads with a working control surface rather than a list of repositories. ZTF-Orchestrator shows the operating style: readiness checks, run history, inventory, queue status, and review points in one view.

ZTF-Orchestrator static UI demo dashboard showing readiness, execution metrics, inventory, queue, and governance panels.
Static ZTF-Orchestrator demo dashboard. Demo data is simulated and does not connect to Nutanix targets. Open larger image.
Readiness checks Health signals before operational workflows run.
Run history Visible outcomes, failures, and review points.
Approvals Clear checkpoints before risky actions.
Inventory Installed components, generated configuration, and gaps.

Project portfolio

One coherent body of work across platform operations and AI governance.

Develop Prototype
Nutanix Developer Cloud Studio live demo showing developer portal environment operations and approval queue. Live demo snapshot

Nutanix Developer Cloud Studio

MIT license Last updated Aug 22, 2026 Changelog

A self-service portal pattern for requesting Nutanix-backed lab environments, now including controlled source VM clone and PE/PC validation-ring evidence.

v9.8.0 Prototype Mock mode Prism-safe Source VM clone

Demonstrates catalog, request, approval, and environment views, including Prism Element and Prism Central validation rings, read-only inventory, controlled source VM clone gates, and guarded lifecycle enablement.

  • For exploring internal developer platform patterns.
  • Static demo and mock mode keep the experience safe to inspect.
  • v9.8.0 documents a lab-only source VM clone path for approved golden VM inventory.
Deploy Framework
NKP ZeroTouch Framework live demo showing operations console, deployment modes, readiness cards, and environment status. Live demo snapshot

NKP ZeroTouch Framework

MIT license Last updated Aug 12, 2026 Changelog

A deployment-planning framework for connected, proxied, and air-gapped NKP paths.

v0.1.0 Framework Air-gapped Validation

Focuses on deployment modes, prerequisites, validation, RS256/JWKS OIDC evidence, and offline-package thinking before a cluster is touched.

  • For comparing connected, proxied, and disconnected operating paths.
  • Shows runner, dashboard, validation, and bundle-preparation concepts.
Generalize Control framework
StrataOne infrastructure orchestrator dashboard showing control plane status, deployment actions, fleet readiness, operational runbook, and result inspector. Live demo snapshot

StrataOne

MIT license Last updated Aug 22, 2026 Changelog

A vendor-neutral orchestration experiment for distributed infrastructure operations, with production-control-plane hardening, queued-credential safeguards, SBOM attestation, Trivy container scanning, and explicit live-operation boundaries.

Framework FastAPI RBAC Live demo Redfish gated SBOM attestation Trivy scan

Tests how inventory, runbooks, approvals, lifecycle controls, approval-gated live Redfish, credential-reference guarded queued jobs, SBOM-backed supply-chain evidence, Trivy high/critical fixable-CVE gates, and OEM validation boundaries could work when the model is not tied to one platform.

  • For exploring a broader infrastructure orchestration pattern.
  • Live demo shows the console shape; repository carries the implementation boundary.
Migrate Alpha / readiness
Migration Readiness Control Plane operations console demo showing source and target providers, readiness counts, and connection forms. Live demo snapshot

Nutanix Migration & Readiness Control Plane

MIT license Last updated Aug 22, 2026 Commit history

A readiness and handoff model for VMware-to-Nutanix migration planning with a stateful operations console foundation.

0.3.0-alpha.1 Alpha Readiness Handoff Stateful console

Separates assessment, planning, workflow state, and handoff artifacts from the act of executing a migration.

  • For making migration gaps visible before a change window.
  • Alpha status is explicit; planning evidence is not presented as executed migration proof.
Govern Research / AI governance

Enterprise AI Architecture Pattern

Public repo Last updated Aug 13, 2026 Status

EAAP Control Plane is a production-oriented reference implementation for governing AI-assisted enterprise decisions through deterministic controls, approval boundaries, execution tokens, and audit evidence.

AI governance GR-001 to GR-011 36 tests OpenAPI Security scan Token persistence
Problem

AI-assisted decisions need deterministic controls before recommendations can become operational action.

Implemented

Governance evaluator, approval workflow scaffolding, scoped execution-token validation, token persistence, release gates, local users demo console link, audit utilities, HLD, ADRs, and threat model.

Evidence

Public source, passing CI, 36 unit tests, OpenAPI validation, security scan, and explicit STATUS.md maturity boundary.

Boundary

Reference implementation and personal architecture experiment, not a certified standard or production-ready enterprise platform.

Differentiator

Clear proof, careful boundaries, and tools people can actually inspect.

Review before action

Roles, approvals, governance checks, run history, and visible readiness states before important changes.

Proof of behaviour

Smoke tests, release checks, sanitized UAT records, compatibility review, CI checks, and exported evidence.

Real delivery paths

Container, appliance, GitHub Pages, hosted demo, reference architecture, and offline package paths where the project calls for them.

Engineering journal

Short notes on why the projects exist and what they are teaching.

Architecture notes, lab lessons, and project rationale for the operating models behind the portfolio.

Published research

Research papers behind the AI governance work.

Published preprints that document the governance ideas behind the Enterprise AI Architecture Pattern and related constraint-focused research.

Primary paper Enterprise AI governance

Enterprise AI Architecture Pattern

Sets out the governance model behind the EAAP Control Plane reference implementation: model-as-component, deterministic control layers, evidence classification, approval boundaries, execution gateways, and auditability.

Deterministic controls Evidence classification Execution boundary Auditability
Related research Constraint-focused governance

EAAP-LGF: AI Governance for Lethal Decision Support

Applies the same control-plane thinking to lethal decision-support governance, arguing for stronger prohibition layers, evidence classification, calibrated confidence gates, independent legal review, multi-authoriser approval, and immutable accountability.

Constraint-focused governance research; not a weapons development, procurement, or autonomous lethal systems document.

John Goulden ยท ORCID 0009-0000-5626-6535

Contact

A personal engineering portfolio for infrastructure automation, readiness, and platform ideas.

These are independent engineering projects developed outside my professional responsibilities. I welcome technical feedback, architecture discussions, and ideas from people working in similar environments. Email me at john@johngoulden.de, message me on LinkedIn, or open a GitHub issue when the discussion belongs with a specific repository.