Insights
Technical writing
From my personal blog
Grafana Alloy in My Homelab: Why I Run Three Separate Instances
How I split Grafana Alloy across three separate instances in my own cluster, and why clustering — not tidy separation of concerns — is the reason for the split.
VyOS Firewall Rules: A Real Zone-Based Config, Explained
A real zone-based VyOS firewall configuration pulled from production routers, including a syntax change the official docs don't cover yet.
Using FreeIPA CA as an ACME Provider for cert-manager
Using FreeIPA's built-in CA as an ACME provider for cert-manager in Kubernetes, including DNS-01 challenges and TSIG key setup.
VyOS as a Reverse Proxy Load Balancer
Configuring VyOS as a HAProxy-based reverse proxy and load balancer, including bypassing CGNAT and preserving client IPs with the PROXY protocol.
How to Redirect Hardcoded DNS with VyOS
Redirecting hardcoded DNS queries on a home network using VyOS NAT rules — useful for enforcing ad-blocking with Pi-hole or Blocky.