Why curl can't reach example.com anymore
Debugging TLS failures in a NixOS microvm that turned out to be a system-wide Cloudflare certificate chain issue.
Yak shaving, documented.
Debugging TLS failures in a NixOS microvm that turned out to be a system-wide Cloudflare certificate chain issue.
Squeezing more throughput out of qBittorrent in a WireGuard VPN namespace with BBR congestion control, TCP buffer tuning, and systemd tweaks.
Using iBGP over a WireGuard tunnel to automatically propagate DN42 routes from a VPS to the home network, replacing fragile static routes.
Setting up Prometheus and Loki monitoring for Radarr, Sonarr, and Prowlarr with Exportarr metrics and log-based alerting on NixOS.
Routing Cloudflare traffic through a VPS via Tailscale subnet routing to work around Telekom's peering bottleneck. Connection times dropped from 11s to under 400ms.
Deutsche Telekom's refusal to peer properly with Cloudflare degrades a fifth of the internet for German fiber customers. A rant about monopoly rent-seeking.
Connecting a Cloudflare Workers blog to a homelab Prometheus instance to display live uptime, storage, network, and DNS stats.
Setting up CAKE SQM on a 1 Gbit fiber connection to eliminate bufferbloat and keep latency low under heavy load.
Building automatic failover for multiple WireGuard VPN endpoints using systemd services and Prometheus-based health monitoring.
Automating ESPHome firmware updates across multiple devices using Home Assistant automations.