Posts
- My Mac, Declared in Nix
How I run my MacBook from a nix-darwin flake: Homebrew under control, secrets in git, a lint gate on a Linux runner, and the gotchas along the way.
- Corv: my Hermes agent.
A tour of the AI agent that lives on my homelab: what runs it, what it can reach, and how it stays useful without being babysat.
- Time Machine over SMB in my homelab
A small Debian LXC, Samba's fruit module, and a bind mount to the USB drive that already holds my homelab data.
- How I Manage My Homelab Remotely
Tailscale gets me into the lab, Termius gives me a shell, and Forgejo makes sure a train-terminal fix still gets a plan and a review.
- Rook, My Agent Workstation
How I run coding agents inside a Debian LXC, and keep their infrastructure changes behind OpenTofu plans, Ansible playbooks, and Forgejo review.
- In-Place Still Reboots
OpenTofu said 16 in-place updates and 0 replacements. It restarted all 16 containers, including the one running the apply.
- The [model-dependent] Caveat, Executed
Last time I measured whether a model obeys an injection. I never let it act. So I ran the same chains against real servers, and half my numbers didn't survive.
- Trading n8n for Kestra
Why I moved my homelab's scheduled jobs onto a YAML-first orchestrator, and what it does better than n8n.
- The [model-dependent] Caveat, Measured
My MCP audits proved a malicious instruction reaches the agent. They never checked whether it obeys. So I measured it across thirteen models.
- Auditing MCP Servers with an AI on a Short Leash
The methodology behind my MSc dissertation: depth-first security audits of MCP servers, using an LLM as an instrument I'm not allowed to trust.
- Ansible for updating LXCs
How I filled the gap in my homelab patching system.
- Real HTTPS for a .lan Network
How Pi-hole, step-ca, and Traefik combine to give every internal service a green padlock — no warnings, no public certificates.
- Corvidae Cluster Homelab
An overview of the stack I've been building at home.