//:Proof · Test Matrix
Verification tests
The same automated test matrix as the dashboard — install gates, CRS parity, FP, ban latency, corpus recall and 72h soak. All measured and reproducible.
Security researcher note: This is not a shop or WooCommerce site. No /products.json, /wp-json/, or /api/item — the 89-gate verification matrix lives here.
Install and security gates · 9
- PASS
API fail-closed — unauthenticated requests return 403
Ban/consult/metrics endpoints reject requests without a token.
FAIL: 0 · WARN: 0
FAIL: 0WARN: 0scripts/api_fail_closed_test.sh - PASS
auth.log sshd ingest — parse + brute threshold
Non-nginx SSH failed-password lines enter the anomaly path.
FAIL: 0 · WARN: 0
FAIL: 0WARN: 0scripts/auth_log_e2e.sh - PASS
Helm chart — template smoke
Helm template validation for customer K8s installs.
FAIL: 0 · WARN: 0
FAIL: 0WARN: 0scripts/helm_install_smoke.sh - PASS
journald export — short-iso + sudo rhost spike
Journald usec timestamps and sudo rhost brute spike ingest.
FAIL: 0 · WARN: 0
FAIL: 0WARN: 0scripts/journald_e2e.sh - PASS
Local security audit — IPC, JWT, secret hygiene
Pre-prod security script matrix; demo password WARN on laptop is OK.
FAIL: 0 · WARN: 0
FAIL: 0WARN: 0scripts/local_security_audit.sh - PASS
Wasm marketplace — signed package gate
Proves unsigned marketplace packages are rejected.
FAIL: 0 · WARN: 0
FAIL: 0WARN: 0scripts/marketplace_sig_gate.sh - PASS
Mesh etcd — fleet policy
etcd mesh backend and MESH_PUB_ENABLED=0 validation.
FAIL: 0 · WARN: 0
FAIL: 0WARN: 0scripts/mesh_etcd_e2e.sh - PASS
Install gate — services, IPC, API fail-closed
systemd, --health, metrics :9091, API_BIND and nginx format green matrix.
FAIL: 0 · WARN: 0
FAIL: 0WARN: 0scripts/post_install_verify.sh - PASS
VM demo gate — post_install 0 FAIL
Final check before laptop/VM demo (repair: sudo vm_demo_gate).
FAIL: 0 · WARN: 0
FAIL: 0WARN: 0scripts/vm_demo_gate.sh
Competitive and security proof · 80
- PASS
72h prod stability + low FP
72.0h VPS soak PASS: 863 samples, 0 failures — services up, max RSS 122 MB benign FP 0.2%.
- PASS
5-minute stability gate (no VPS required)
Confirms daemon and analyzer stay up during a short production-like window.
5m soak: 10 samples, 0 failures — PASS.
Sure: 5 dkMax RSS: 110 MBscripts/soak_short_proof.sh - PASS
API mutation audit — ban/unban jsonl trail
Append-only jsonl after POST /ban (/var/lib/log-guardian/).
audit trail OK — /var/lib/log-guardian/api-mutation-audit.jsonl.
audit: OKscripts/api_mutation_audit_e2e.sh - PASS
API mutation token — read/mutate POST split
Enterprise: API_TOKEN (GET) + API_MUTATION_TOKEN (POST ban/unban/consult).
split=ON; read POST 403; mutation POST 200.
split: onscripts/api_mutation_token_e2e.sh - PASS
ARM64 (aarch64) build smoke
Build path for embedded/ARM Linux targets (no AVX2).
mode=cross-gnu; target=aarch64.
mode: cross-gnuhost: x86_64scripts/build_arm64.sh - PASS
Attack map — geo markers + live bans
Proves banned IP locations on the home globe via /api/attack-geo.
1 markers, source=live; ack=1 ban=0; nav=4 parity=OK.
markers: 1ack: 1ban: 0nav: 4bans: ipsetscripts/attack_map_e2e.sh - PASS
Ban API mTLS — edge client cert + mutation token
Enterprise: nginx mTLS terminate + internal mutation token inject.
read POST 403; mutation OK; mTLS edge verify.
mtls: onread_post: 403caddy: onstrict: onscripts/ban_api_mtls_e2e.sh - PASS
Time from threat detection to kernel ban
Median 28.71 ms — target <75.0 ms, ipset confirmed.
- PASS
Ban policy audit + OPENAPI_STRICT
Ban/unban decision trail JSONL + schema; prod API schema validation on.
decision=force_waf; risk=80.0; OPENAPI_STRICT=1.
lines: 1decision: force_wafOPENAPI_STRICT: 1scripts/ban_policy_audit_e2e.sh - PASS
AUTO_BAN profile + consult cache + threat intel offline
AUTO_BAN_PROFILE preset, consult cache, threat intel offline fallback.
6 static checks PASS (AUTO_BAN_PROFILE, CONSULT_CACHE, GeoIP).
checks: 6scripts/ban_profile_e2e.sh - PASS
Bans + Telegram ack — operator panel API
Operator panel live data via /api/telegram-acks + /bans?search=.
IP 203.0.113.198; ack yes (utku); ban miss.
acks: 1ban: missoperator: utkuscripts/bans_telegram_ops_e2e.sh - PASS
Processing speed on same log corpus (transparent reference)
Guardian 11709 EPS (single-pass log-WAF); CRS replay 19761 EPS — different architecture, not a speed claim.
- PASS
Compliance — JSON/PDF export (Pro tier)
/api/reports/export — Pro tier PDF; Community gets 403.
mode=pro-live; tier=pro; controls=12; pdf=OK.
mode: pro-livetier: proscripts/compliance_export_e2e.sh - PASS
Copilot — optional Ollama + fallback
Copilot LLM (Ollama) optional; rule-based fallback when absent.
ollama=yes; source=ollama.
ollama: yessource: ollamascripts/copilot_ollama_e2e.sh - PASS
CrowdSec LAPI → log-guardian ban API
complementaryCrowdSec complementary (LAPI) — sync decisions to kernel ban path; not a Fail2ban replacement.
mode=dry-run; 50 decisions; ban API dry-run; LAPI OK.
mode: dry-runkarar: 50ban API: dry-runLAPI: OKscripts/crowdsec_bouncer_e2e.sh - PASS
Detection parity with OWASP CRS on same attack lines
Alerts on all 18 attack lines; recall 100.0%, parity 100.0%.
- PASS
Dashboard ban/unban — API + Docker relay (18090)
Proves operators can ban/unban from /bans via the live kernel path.
Host OK, relay OK, Docker OK — 203.0.113.248.
host: OKrelay: OKdocker: OKpath: ipc-xdpsoar: onstrict: onscripts/dashboard_ban_smoke.sh - PASS
Dashboard JWT idle — session timeout
middleware iat check; laptop 0m, internet-facing 480m recommended.
mode=on; idle=240m.
idle_min: 240scripts/dashboard_jwt_idle_gate.sh - PASS
Dashboard live demo — map + /bans ipset
Operator demo: 4 real kernel bans → LIVE map + /bans unban.
4 bans applied, 4 synced — http://127.0.0.1:8090.
applied: 4synced: 4api: 127.0.0.1:8090IPs: 203.0.113.211, 203.0.113.212, 203.0.113.213, 203.0.113.214scripts/dashboard_live_demo.sh - PASS
Dashboard login rate limit — brute-force protection
Prod: HTTP 429 after 10 failed attempts (X-Forwarded-For).
10 attempts → 429 (probe 203.0.113.88).
max: 10scripts/dashboard_login_rate_limit_e2e.sh - PASS
Demo rehearsal — presentation readiness gate
demo_3min + :8443 + PDF + live site presentation chain.
demo_3min=yes; dash=yes; proof 88/89.
PDF: yesproof: 88/89scripts/demo_rehearsal_gate.sh - PASS
Demo video — 04:00 recording readiness gate
demo_video + SIEM + PDF + presentation_ship — pre-recording automation.
pdf=yes; ship=yes; siem=yes; proof 88/89.
SIEM: yesproof: 88/89scripts/demo_video_gate.sh - PASS
DIST_RISK — distributed attack score proof
/24 + UA fp correlation → ban risk bonus; unit test + replay delta.
risk off=45.0 on=65.0; delta=20.0.
delta: 20.0risk_off: 45.0risk_on: 65.0scripts/dist_risk_proof_e2e.sh - PASS
Docs consistency — 64 test + HOSTING §8b
Doc vitrine consistency — 64 tests, Telegram cross-link.
checks OK=53; proof 88/89; hosting §8b=yes.
checks: 53proof: 88/89scripts/docs_consistency_gate.sh - PASS
Edge protection — nginx + XDP/ipset + threat intel
Origin edge: nginx log format, ipset/XDP ban, threat-intel summary DB.
IPC ok; ipset-fallback; nginx OK; ipset 0.
ipc: okxdp: ipset-fallbackipset: 0scripts/edge_protection_gate.sh - PASS
Enterprise escalation — operator playbook
P1-P4 runbook + Telegram/edge operator gates.
Doc sections 14; live gates 3/3.
doc: 14gates: 3/3scripts/enterprise_escalation_gate.sh - PASS
Enterprise SOAR gate — Caddy :9443 mTLS + strict
Operator gate: enable/disable SOAR API — split token, Caddy mTLS, loopback strict.
mode=enterprise; SOAR on; strict=on.
mode: enterprisesoar: onstrict: oncaddy: OKban_smoke: OKscripts/enterprise_soar_gate.sh - PASS
Fleet multi-node — 2+ agents + targeted dispatch
Proves 2+ telemetry agents and targeted /fleet/dispatch routing.
4 agents, 4 online; dispatch→node-vm-02; HMAC=OK.
agents: 4online: 4target: node-vm-02HMAC: OKscripts/fleet_multi_node_e2e.sh - PASS
Fleet offline gate — heartbeat report freshness
Verifies fleet agent report freshness and at least one agent online.
4/4 online; mode=laptop-simulated; max_age=15.0m.
online: 4total: 4mode: laptop-simulatedmax_age_m: 15.0scripts/fleet_offline_gate.sh - PASS
FP learn — trusted IP excluded from cluster ban
trusted=10.0.0.50 cluster_banned=False flush=True.
- PASS
False positive rate on benign traffic
500 benign lines, 0.2% FP — target <5.0%.
- PASS
GitHub ship — full pre-push gate
presentation_ship + security_closure + secret scan — git push readiness.
ship=yes; closure=yes; secret=yes; proof 88/89.
closure: yesproof: 88/89scripts/github_ship_gate.sh - PASS
Grafana — dashboard $tenant + alert rules
Proves Prometheus tenant variable and Grafana alert provisioning.
uid log-guardian-01; 13 alerts (13 tenant_id).
dashboard: log-guardian-01alerts: 13tenant: yesscripts/grafana_alert_gate.sh - PASS
Grafana parity — dashboard mini panels ↔ JSON
grafanaPanels.ts metrics match grafana-dashboard.json.
Panel 41; dashboard 43 metrics matched.
panel: 41dash: 43scripts/grafana_parity_gate.sh - PASS
Hardening rollback — rollback readiness
Pre-hardening backup + demo password detection (read-only).
checks 7/7 OK.
checks: 7/7scripts/hardening_rollback_gate.sh - PASS
Honeypot / deception — trap metrics
Proves trap_watcher + tarpit deception via Prometheus counters.
mode=metrics honey=0 lfi=0 c2=0.
mode: metricshoney: 0lfi: 0c2: 0scripts/honeypot_feed_e2e.sh - PASS
INTEL_BAN_DB — ban_events size + TTL
SQLite ban_events bloat check — does not change ban logic.
ban_events 1219; legacy 0; stale 0; TTL 7d.
rows: 1219legacy: 0TTL: 7dscripts/intel_ban_db_ops_check.sh - PASS
IPv6 ban — ipset v6 + API/CLI
RFC 3849 doc prefix — ipset v6 proof vs v4-only rivals.
via=api; path=ipc-xdp; ip=2001:db8::dead:beef.
via: apipath: ipc-xdpscripts/ipv6_ban_e2e.sh - PASS
Distributed attack (same UA, different IPs) cluster recall
80 IPs, recall 100.0% (80/80).
- PASS
Live nginx log -> JA3/UA cluster -> ban_pipeline
mode=live-append delta=8 flush=True block=203.0.113.162-203.0.113.166.
- PASS
K8s admission webhook — deny label + allow
Operator admission rejects pods with deny security label.
mode=docker-standalone; deny label=security.log-guardian.io/deny.
mode: docker-standalonescripts/k8s_admission_test.sh - PASS
K8s kind cluster — helm dry-run / live
Optional Pro: kind cluster + helm chart live or dry-run proof.
cluster=lg; mode=dry-run-server.
mode: dry-run-servercluster: lgscripts/k8s_kind_e2e.sh - PASS
L7 eBPF HTTP probe — prod readiness
Proves daemon IPC + http_l7_probe.o L7 telemetry.
IPC ok; l7_probe ON; hits=15; xdp=ipset-fallback.
IPC: okl7_probe: ONhits: 15xdp: ipset-fallbackscripts/l7_probe_prod_e2e.sh - PASS
Laptop Core — edge + SOC + ban operator gate
nginx→WAF→ban Core promise — edge, Telegram SOC, ban API.
edge=skip; soc=yes; ban=yes; xdp=ipset-fallback; proof 88/89.
xdp: ipset-fallbaproof: 88/89scripts/laptop_core_gate.sh - PASS
Laptop excellence — demo readiness gate
Laptop demo chain — services, :8443, fleet, proof.
OK=14 WARN=0 FAIL=0; proof 88/89.
OK: 14FAIL: 0scripts/laptop_excellence_gate.sh - PASS
Lineage → auto incident (single scenario)
INC-* correlation from LOG_SQLI + EBPF_EXECVE signals; single auto-incident proof.
INC-6a4ecb0c-2382; active=1; signals=LOG_SQLI+EBPF_EXECVE.
INC: INC-6a4ecb0c-2382IP: 10.0.0.99active: 1scripts/lineage_incident_e2e.sh - PASS
eBPF lineage — openat/execve/connect chain
risk=91.2 events=4 (EXEC_SHELL · FILE_READ · FILE_WRITE · NET_CONNECT) source=daemon_file.
- PASS
Live nginx :80 attack harness (tester + ban)
sent=525 refused=525 kernel=True waf=True.
- PASS
Live ban pipeline (IPC -> XDP/ipset)
IPC ok; 0 IPC, 0 XDP, 0 ipset.
- PASS
Marketplace — signed API (Enterprise tier)
Enterprise /api/marketplace/signed — signature verify; Pro/Community get 403.
mode=tier_gate; tier=pro; signed=0.
mode: tier_gatetier: proscripts/marketplace_signed_api_e2e.sh - PASS
Mesh etcd — docker lab endpoint
Optional fleet: live etcd docker endpoint smoke.
endpoint=http://127.0.0.1:12379; container=lg-etcd-smoke.
mode: docker-livescripts/mesh_etcd_docker_smoke.sh - PASS
Mesh etcd — live PUT/GET
Docker etcd v3 round-trip; fleet policy key read/write proof.
mode=docker-live-rw; key=lg/fleet/policy/test; round_trip=True.
mode: docker-live-rwendpoint: http://127.0.0.1:12379scripts/mesh_etcd_live_e2e.sh - FAIL
Morning operator — fast morning readiness
Report-first morning gate — no demo_3min, does not disturb other gates.
presentation_ship
core: raporproof: 88/89scripts/morning_operator_gate.sh - PASS
mTLS certificate expiry — SOAR lab
client/server/ca.crt expiry — rotation runbook warning.
min 822 days (warn<=14).
min_days: 822scripts/mtls_cert_expiry_check.sh - PASS
nginx inline consult API (WAF+CRS before auth_request)
union=403 or1=403 benign=200.
scripts/nginx_inline_consult_proof.sh - PASS
nginx hybrid — inline consult + log replay
ModSec/Fail2ban gap: auth_request WAF + access_log single-chain proof.
mode=inline+log hybrid; edge_sqli=403; replay_alerts=1.
edge_sqli: 403replay: 1scripts/nginx_hybrid_proof.sh - PASS
OWASP CRS test corpus recall
112.1% recall — 199 lines.
- PASS
Parser fuzz — malformed corpus + mutation
No crash/UB on deterministic malformed log lines; nginx/auth parse reliability.
593 parses; corpus=36; file=40; mutations=512.
runs: 593corpus: 36file: 40mutations: 512scripts/parser_fuzz_e2e.sh - PASS
phase100 fast gate — Phases 0-6
Fast gate for phase 0-6 E2E scripts (excluding VPS soak).
mode=fast; phases=0-6.
mode: fastphases: 0-6scripts/phase100_fast_gate.sh - PASS
Presentation ship — demo rehearsal + release chain
demo_rehearsal + release_ready — one-command presentation and ship.
demo=yes; release=yes; artefakt 3/3; proof 88/89.
artefakt: 3/3proof: 88/89scripts/presentation_ship_gate.sh - PASS
Prod stack — Wasm native + lineage + L7
Stub→prod chain: native Wasm plugin, live lineage, L7 probe.
wasm=native; lineage=91.2; L7=active; ipc=ok.
wasm: nativeL7: yesxdp: ipset-fallbackscripts/prod_stack_e2e.sh - PASS
Real attack corpus (SQLi/XSS/LFI/RCE/scanner) detection rate
999 lines, avg recall 101.0% — target >=85.0%.
- PASS
Corpus 10K — extended attack set recall
10000 lines, recall 100.1%.
- PASS
Release ready — pre-GitHub release chain gate
ZIP/PDF + docs + live site + fleet chain.
release=yes; docs=yes; artefakt 3/3; proof 88/89.
artefakt: 3/3proof: 88/89scripts/release_ready_gate.sh - PASS
SIEM forwarder — alert + ban JSON (:5044)
Proves JSON event_type stream to Splunk/Elastic/Vector targets.
alert=yes ban=yes port=15044.
alert: yesban: yesport: 15044scripts/siem_export_e2e.sh - PASS
TAXII/STIX IOC → ban API (confidence gate)
Filters STIX 2.1 indicators by confidence; skips low-trust IOCs from ban path.
dry-run; 2 IOC (≥70); skipped=1.
mode: dry-runIOC: 2min conf: 70atlanan: 1scripts/taxii_feed_e2e.sh - PASS
Telegram operator undo — SIGUSR2 (WL/mute)
Reverts mistaken WL/mute/unban without interrupting Telegram poll.
SIGUSR2 · sigusr2 · IP 203.0.113.198.
mode: sigusr2ip: 203.0.113.198pass: OKscripts/telegram_operator_undo_e2e.sh - PASS
Telegram SOC — timeline + map + webhook
Proves three operator surfaces emit live evidence together.
SOC 11 (ack 8); map 1; bans ack 1; webhook undo.
soc: 11map: 1bans: 1webhook: undoscripts/telegram_soc_gate.sh - PASS
Multi-tenant isolation
Tenant musteri1: 4/4 checks passed.
- PASS
Threat intel sync -> ipset
sync 0s, ioc=10, ipset_delta=0.
- PASS
TR hosting corpus (synthetic anonymized)
100.0% recall — 500 lines · customer_corpus %100.1 (15 attack cat, log_guardian format).
customer recall: 100.1%attack cats: 15 - PASS
VM fleet keepalive — host + node-vm-02
LAPTOP_OPS fleet + VM keepalive — two nodes Online.
node-kurtulus-01=Online; node-vm-02=skip; online=2.
host: Onlinevm: skipscripts/vm_fleet_gate.sh - PASS
VM host prep — pre-sync evidence
Laptop HOST proof before vm_sync.
ctx host-vbox; proof 88/89; post_install FAIL=0.
proof: 88/89ctx: host-vboxscripts/vm_host_prep_gate.sh - PASS
VPS XDP — kernel-xdp (laptop: ipset-fallback)
eBPF XDP on real NIC/VPS; laptop ipset-fallback is expected.
xdp_mode=ipset-fallback; iface=—.
mode: ipset-fallbackiface: —scripts/vps_xdp_proof.sh - PASS
Wasm native — block-sqli plugin smoke
Proves compiled Wasmtime plugin alerts on SQLi in log replay.
mode native; 2 native plugins, 1 alerts, 992 B.
mode: nativeplugins: 2alerts: 1bytes: 992scripts/wasm_gate.sh - PASS
Telegram route + batch — #waf/#ban routing
Proves WARN→DM, CRIT/ban→channel and batch summary routing.
Mode dry-run; route ON, batch 10s.
mode: dry-runroute: ONbatch: 10prod: skipscripts/webhook_route_proof.sh - PASS
Telegram Ack — DB counter (24h)
Proves inline Ack bumps events.db and guardian-status/metrics counters.
ack 3->4; unacked 0->0.
ack: 3->4unacked: 0->0prom: 4scripts/webhook_ack_e2e.sh - PASS
Telegram prod — live alert/ban/trap/batch
Proves real bot token delivers CRIT/WARN route + batch summary to Telegram.
mode prod; route ON, batch 10s — alert, ban, trap, batch.
route: ONbatch: 10kinds: alert,ban,trap,batchscripts/webhook_install_prod.sh --test-all - PASS
Website live — production /tests parity
Production domain SRI + test card parity.
ceniklinuxlogguardian.org None/89; CSS=yes.
live: None/89domain: ceniklinuxlogguardian.orscripts/website_live_gate.sh - PASS
Site preview — landing test parity
landing/lib/tests.ts parity with competitive-proof (local test cards).
Site 89/89 parity; grafana yes; edge yes.
site: 89proof: 89scripts/website_preview_gate.sh