Caddy Reverse Proxy Deployment — Pi-hole TLS Termination on fablehaven
Deploying Caddy as a reverse proxy on fablehaven to terminate TLS for Pi-hole admin UIs across the three-node cluster, using Step-CA certs and internal DNS.
Deploying Caddy as a reverse proxy on fablehaven to terminate TLS for Pi-hole admin UIs across the three-node cluster, using Step-CA certs and internal DNS.
The Ansible vault password was available to PR-controlled workflow code, creating a path for any contributor to exfiltrate the credential that unlocks every secret in TheBurrow.
Building IoT network isolation on TheBurrow — VLAN 94 design, Kea DHCP subnet activation, OPNsense firewall rules, DNS enforcement NAT redirects, and migrating 31 devices via CSV import.
A compound failure across three bugs left Pi-hole VRRP failover silently broken for weeks — no keepalived on mistborn, wrong VIP ownership, and Kea serving raw IPs instead of VIPs.
Lab exercise examining PSU fan function, airflow direction, system cooling contribution, and failure scenarios.
Case study on electrostatic discharge risks, contributing factors, prevention best practices, and the connection to preparation and wise decision-making.
Step-CA failed to initialize after vault_edit.py wrote a Python dict string representation instead of valid JSON for the JWK encryptedKey field in ca.json, breaking CA initialization fleet-wide.
Diagnosing SMB authentication failures in a peer-to-peer Windows network caused by duplicate SIDs from improper VM cloning.
Reproducible lab guide for building a peer-to-peer Windows network, injecting a VM cloning identity failure, and resolving it.