Get in touch →
To be done
16
Completed
20
§1

Still open, by area

A. Identity & Secrets
Actually turn SSO on for every internal service, not just have it availableNot started
Stop pasting secrets by hand — make Infisical the real source of truthNot started
B. Data Durability & High Availability
Buy a NAS to centralize data and make backups/migrations possibleNot started
Mirror the critical machines — proxies, databases, key sites — so one dying doesn't take everything downNot started
Get backups running on a schedule, automaticallyNot started
C. Automation & Infrastructure-as-Code
Stop maintaining hosts by hand — automate itNot started
Adopt Ansible and OpenTofu so servers are configured from code, not memoryNot started
Fix Wake-on-LAN so machines can be powered on remotelyNot started
D. Observability
Turn on log-based alerts in Loki, not just metric-based onesNot started
Make the monitoring stack itself survive a node going downNot started
E. Physical Infrastructure
Move the hardware into a proper rackNot started
Redo the ethernet cabling properlyNot started
Buy and install a UPS, so a power blip doesn't take everything downNot started
Get hardware capable of real local AI experimentationNot started
F. Security & Edge
Put public-facing services behind something like Cloudflare for attack protectionNot started
G. Documentation
Write up more of the real day-to-day processes, not just the reference pagesNot started
§2

Filed as done

ItemStatus
Split the network into isolated zones instead of one flat trust areaComplete
Write firewall rules for exactly what each zone is allowed to reachComplete
Give DNS a second server, so one machine dying doesn't break lookupsComplete
Build a secure way to reach everything remotely, without being on-siteComplete
Route traffic through three separate proxies, one per trust levelComplete
every node has a clear job the whole network is documented — services, IPs, all of it runbook for adding a remote-access peer runbook for adding a remote-access tunnel runbook for bringing a new network zone online real databases running S3-compatible file storage my own file cloud (OpenCloud) my own photo cloud (Immich) a complete build-and-deploy pipeline the whole stack is watched — metrics and alerts single sign-on set up (Authentik) centralized secrets set up (Infisical) my own sites and apps, self-hosted every link in one dashboard