geedge.lantern.io
deployment confidence: high public

A MESA Lab Minio object-storage cluster repo (zhangchengwei/MinioRelated) provisions and Prometheus/Grafana-monitors separate environments explicitly named "Astana" and "Almaty" — the two primary Kazakhstan site codenames documented under K18 — confirming dedicated per-city storage and monitoring infrastructure for the Kazakhstan deployment as far back as 2018-2019.

File tree: AKAOnlineEnv/Almaty/Minio_AVlog_Almaty-1547616128360.json, AKAOnlineEnv/Almaty/Minio_Cache_Almaty-1547616156161.json, AKAOnlineEnv/Almaty/prometheus.yml, AKAOnlineEnv/Astana/Minio_AVlog_Astana-1547639754326.json, AKAOnlineEnv/Astana/Minio_Filelog_Astana-1547639819865.json, AKAOnlineEnv/Astana/prometheus.yml. Commit: "更新AstanaMinio列表" (update Astana Minio list), 2018-12-09
censorskz
capabilitydeployment-config

extracted_by: claude-sonnet-5 · added 2026-08-26 · id: 2026-minio-k18-sites-57b705

Related findings

deployment

pangu_valve.conf explicitly binds the 'PanguValve' traffic-control daemon (阀门, ASMIS_PROC_NAME=Pangu/PanguValve) to the Astana, Kazakhstan (K18) site — REMOTE_DIR=ASTANA and a MAAT_EFFECTIVE_RANGE tag of location=Astana — and configures it to receive live rule updates from a MAAT Redis backend rather than static files, tying this enforcement component directly to a real-time MAAT rule-dispatch pipeline at a named export deployment.

export/sales

The T1/NTC (text-content DPI) node's wired-config manifest (main.conf, dated 2019-01-30) sets REMOTE_DIR=ASTANA/KAZAKHTELECOM/, directly naming Kazakhtelecom — Kazakhstan's dominant state-linked telecom operator — as the carrier context for this K18 deployment. The NTC_MAAT module's EFFECTIVE_FLAG further scopes rules to {location: Astana, isp: Tanstelecom}, naming a second Kazakhstani ISP (Transtelecom) tied to the same deployment.

export/sales

The tango/adc_hardware repo ([email protected], 2019-2021) contains a dedicated "K18 演示环境交换板配置" (K18 demo-environment switch board config) commit and a nezha_monitor_K18/ directory of NEZHA monitoring dashboards/alert rules for "ADC" hardware. This is direct evidence that Geedge's ADC compute-board hardware line (documented elsewhere as used for the Pakistan/WMS-UTR site) is also deployed for the K18 (Kazakhstan) site.

deployment

A recurring weekly 'Tiangou Secure Gateway — Server IP and Location of Overview' report, spanning Jan 2023 through Jan 2024 in this batch alone, tracks per-app top server IPs/geolocations/bytes for named foreign platforms (Instagram, Netflix, Reddit, Skype, Pinterest, Quora, Line, Likee, Medium, Pandora). Top consumer-side IP rows consistently resolve to Kazakhstan cities (Almaty, Pavlodar, Nur-Sultan/Astana), matching the K18 site codename. Processed-row counts grow roughly 10x over the year (889B rows/week in Jan 2023 to 9.4T rows/week in Jan 2024), and one instance reports Total Bytes Transferred of 14.66 PB and an average of 218.34 Gbps for a single week.

deployment

A custom Prometheus-backed infrastructure-monitoring platform (MySQL schema dumped from source "nz-prometheus", schema "nz-temp", dated 2020-10-16) has its sys_area reference table seeded with exactly the five Kazakhstan cities named in the K18 site-codename entry — Aktau, Almaty, Nur-Sultan (the pre-2022 name for Astana), Karaganda, and Zhezkazgan — and a companion live alert-message dump (dated Nov 2020) shows real "endpoint down" P2 alerts tagged Data center: Nur-Sultan / Aktau, Project: ADC, across modules named MXN-NODE and MCN0-3-NODE/SRV, pushing the earliest confirmed evidence of the K18 Kazakhstan deployment back to at least October-November 2020.

detection

Commit history for the K18 (Kazakhstan) argus-ntc console reveals its concrete feature set: a scheduled "网页关键字定时器" (webpage-keyword timer/scheduler) for keyword filtering, ASN/IP block-list configuration pages, a "BGP泛收" (BGP wide-collection) page, an SSL-interception config toggle, a file-scanning results page with MALWARE TYPE/MALWARE NAME columns, app-identification entries including a WhatsApp rename, and a VoIP business-config approval workflow, with blocking actions relabeled from "阻断" (block) to "封堵(丢弃)" (interdict/drop).