8 articles

Secure Hardware Telemetry with Caddy

Implementing a secure reverse proxy architecture for LibreHardwareMonitor using Caddy with internal TLS, HTTP Basic Authentication, granular firewall controls, and Tailscale overlay networking on Windows infrastructure.

Linux Double-Lock Deletion Protection - SOP

Standard Operating Procedure establishing dual-layer protection against catastrophic data loss from accidental rm -rf commands on Debian-based servers

Deep NAT OpenVPN Lab Access: Troubleshooting Silent Firewall Failures

A comprehensive guide to diagnosing and resolving OpenVPN connectivity through multiple NAT layers, including the discovery of a critical silent firewall rule loading failure in pfSense caused by broken aliases.

ntfy - Server Alerts

Self-hosted push notification stack deployed on vps-web, bound exclusively to Tailscale with TLS. Covers CrowdSec ban alerts, disk and service monitoring, SSH login detection, and sudo tracking via journald.

Tailscale: The Zero-Trust Network That Changed How I Manage Infrastructure

A comprehensive deep-dive into Tailscale's mesh networking technology, from WireGuard foundations to practical SSH and SMB configurations. Why this zero-trust VPN has become essential infrastructure for modern system administration.

Joining the War for Team Blue

A real-world analysis of attack attempts on a small VPS infrastructure running nginx and basic services