Skip to main content

Posts

Welcome to the archive. Here you’ll find custom scripts, projects, and rants.

2026

From Prometheus Alerts to 500 Job Apps: When My SRE Agent Terrorized LinkedIn

It is a well-established law of homelab physics: if a task can be automated, it will be automated—until it violently consumes your entire digital existence. In our Night-Tower setup, our self-hosted Hermes Agent (containerized on docker-vm and wired to NVIDIA’s Nemotron 70B endpoint) has had exactly one job for the past six months: ruthless Site Reliability Engineering. Hermes lives in a world of pure, unadulterated paranoia. Her brain only understands five nines of uptime (99.999%), CPU thermal throttling, killing runaway memory leaks with SIGKILL -9, and screaming into our private Discord channel whenever a ping packet dares to take longer than 2.4 milliseconds. So, naturally, when I got tired of scrolling through the endless dystopian wasteland of modern DevOps job listings demanding 70 job titles, I had a brilliant 2:00 AM homelab idea: “Hermes, write a browser automation script, parse LinkedIn jobs, tailor my resume to pass ATS filters, and submit applications for senior infrastructure roles. Keep it efficient.” Twelve minutes later, my LinkedIn account was flagged for automated domestic terrorism, a Fortune 500 VP of Talent received a P0 PagerDuty escalation alert, and I was officially in the candidate pool for Chief Astronaut at NASA.

The Great ArgoCD Yak Shave: How a Simple GitOps Dream Sidetracked into a 16GB Harbor & Proxmox Nightmare

It all started with an innocent, reasonable goal on a lazy Saturday afternoon: “I just want to test ArgoCD in my homelab.” That’s it. Just install ArgoCD, hook up a sample repo, and watch green synchronization badges light up like a digital Christmas tree as declarative GitOps magic takes over my local Kubernetes cluster. A 30-minute side quest. tops. The Golden Law of Homelab Yak Shaving: No homelab project ever stays within its original scope. A simple software trial will inevitably expand until it consumes your weekend, your RAM, and your will to live.

Open-Heart Surgery at 120 MPH: The Hilarious (and Terrifying) Guide to Kernel Livepatching on HA Debian Hosts

The HA Sysadmin's Dilemma No-Reboot Zone Security Officer: “A critical CVSS 9.8 vulnerability was found in the kernel network stack! We must reboot all 12 HA Debian nodes immediately!” HA Cluster Engineer: “If I reboot Node 01 right now, Pacemaker will migration-fence Node 02, 14,000 active WebSocket streams will die, and the database cluster will enter a split-brain existential crisis. I will patch it live or die trying.” Enter Linux Kernel Livepatching (klp): The black magic of hot-swapping kernel C code in RAM without dropping a single packet or restarting a system service. Picture this: It’s 2:15 PM on a Friday. You are monitoring your pristine 4-node Debian High Availability cluster handling live production traffic. You’re sitting back, enjoying a cold iced tea, when a red banner flashes across your terminal: [ CRITICAL SECURITY ALERT ] CVE-2026-9999: Remote Code Execution in kernel net/ipv4/ [ MITIGATION REQUIRED ] Upgrade kernel vmlinuz or apply patch immediately. In a non-HA world, you run sudo apt upgrade && sudo reboot, stretch your legs, and wait three minutes. In a Debian HA world (think Corosync, Pacemaker, Proxmox VE clusters, or high-throughput Docker/K8s ingress nodes), typing reboot is equivalent to pulling the pin on a flashbang in a quiet library. Corosync heartbeats miss a pulse, quorum timers panic, Virtual IPs start bouncing around like ping-pong balls, and three regional database replicas begin arguing over who is the real primary master. So how do you fix a gaping hole in the operating system’s brain without shutting it off? You perform open-heart surgery at 120 MPH. Welcome to Kernel Livepatching (klp).

Game Over, Man! How I Saved a Production Jenkins Cluster from a 70,000-File Storage Swarm

Late Friday night. 23:14 hours. The motion tracker—our secondary Zabbix monitoring channel—emitted a faint, rhythmic ping. A subtle ripple of disk consumption was crawling across our primary CI/CD infrastructure. At this enterprise, our engineering teams build heavy multi-domain physical system modeling platforms—compiling intricate thermodynamic loops, vehicle dynamics matrices, and standardized Functional Mock-up Units (FMUs) across hundreds of automated test suites. It turns out that four separate development teams had independently reached a tactical consensus: “Let’s trigger a full regression deployment before leaving for the weekend!” Author’s Note: Sysadmin & SRE work is usually pretty quiet and uneventful… so I had to spice it up a bit! Why not turn a chaotic Saturday morning storage incident into a blockbuster action thriller?

Spaceballs: The Log Triage — How I Nearly Melted an Intel NUC with Vector, n8n, and Naive AI Dreams

In Part 1 of our Lazy SRE Automation series, we painted a glorious, utopian vision: a world where Vector listens to container logs, n8n orchestrates workflows, Ollama writes code fixes, and you sleep soundly while Pull Requests open themselves. It sounded majestic on paper. Then reality hit. And by “reality,” I mean my innocent little Intel NUC screaming in acoustic agony as its cooling fan spun at 140,000 RPM while melting into a pool of radioactive silicon. Welcome to Spaceballs: The Log Triage. Here is everything I learned after accidentally turning my homelab into a self-inflicted Distributed Denial of Service attack.

Logs, Burnt Rubber, and Nostalgia: A Whimsical Guide to Tech Burnout

Have you ever paused mid-debug, leaned back in your mesh chair, and thought: “If my brain had a console, what error code would it be spamming right now?” Burnout in the tech world is usually talked about with heavy sighs, hushed tones, and clinical lecture slides. But let’s drop the guilt trips for a moment. What if we looked at burnout not as a catastrophic personal failure, but with genuine wonder, curiosity, and a healthy dose of absurdity?

Debian 13 Trixie Kernel Alert: Updating to 6.12.100+deb13-amd64 Without Losing Your Mind

The 30-Second Maintenance Promise TL;DR Worried that updating your Debian 13 client will take all weekend? Keeping your workstation or server patched is literally a 2-command affair: sudo apt update && sudo apt install linux-image-amd64 && sudo reboot That’s it! Read on to learn how to check your exact kernel version and verify your system against official security tracker records in under two minutes. Lazy sysadmin tip: Want your machine to fetch security patches automatically while you sleep? Check out the official guide on setting up Debian UnattendedUpgrades. It is a quiet Sunday morning. Your Night-Tower homelab is idling gracefully, CPU temperatures are at a cool 32°C, and you are admiring a pristine 214-day uptime counter on your primary Debian host. You take a triumphant sip of warm coffee, open your browser, and glance at the security security tracker. Then it hits you like a rogue DMA packet: a flurry of CVE security fixes just dropped for Debian 13 (Trixie) in kernel package linux-image-6.12.100+deb13-amd64. [ ALERT ] CVE-2026-XXXX: Local Privilege Escalation via obscure subsystem [ ALERT ] CVE-2026-YYYY: Out-of-bounds memory write when handling malformed packets [ STATUS ] Fixed in linux version 6.12.100+deb13-1 Suddenly, your beloved uptime counter feels less like a badge of honor and more like an open invitation to cosmic chaos. But don’t panic! Upgrading your kernel and double-checking your security status against Debian’s official security tracker is quick, painless, and completely survival-approved. Here is your ultra-simple, funny survival guide to staying secure on Debian 13 Trixie.

Lazy SRE Automation: How n8n and Ollama Write Their Own Pull Requests When Servers Crash

Getting woken up by an alert at 2:15 AM because a container crashed on a port conflict is a rite of passage every DevOps engineer despises. Standard engineering response: Wake up, open your laptop in the dark, SSH into the host, parse docker logs, realize a memory limit or port mapping is misconfigured, edit the docker-compose.yml, commit the fix, and go back to sleep angry. Lazy homelab engineering response: Build an automated n8n + Vector + Ollama AI pipeline that catches the crash log, diagnoses the root cause, writes the code patch, creates a Git branch, opens a Pull Request, and pings your phone on Discord so you can click “Merge” without leaving bed. Here is how I built the SRE Log Triage & Auto-PR Workflow using n8n—the premier open-source workflow automation platform.

The Great Database Wipeout: How a Single 'DROP DATABASE' Taught Me Everything About Backups

There is a specific kind of cold sweat known only to software engineers and database administrators. It happens in a microsecond. You press Enter in your terminal, expect a clean 3-millisecond query response, and instead watch the terminal freeze. You glance up at your tab title and realize with horror: You weren’t connected to staging. You were connected to production.

Death to TL;DR: Fighting Unnecessary Tech Abbreviations with n8n, Ollama & Discord

Reading modern technical documentation has officially turned into deciphering WWII Enigma machine code. You open a blog post expecting a simple explanation of a system, and within three paragraphs you are hit with: “Our CI/CD pipeline deploys an eBPF probe into a K8s pod using ACME TLS certs stored in 1P, monitored via PROM and logged to LOKI (TL;DR: it works).” Whatever happened to using actual words? When did software engineering decide that typing six extra letters was a medical emergency? I genuinely detest unnecessary tech abbreviations. And because I am a homelab engineer, I didn’t just complain about it—I built an automated n8n + Ollama AI Acronym Police bot (building on my n8n multi-LLM orchestration setup) to catch abbreviations red-handed and force them to explain themselves on Discord.

Inside Night-Tower: The Over-Engineered Homelab Powered by Fighter Jets and AI Chaos

Most normal human beings buy a single-bay Synology NAS, plug it into their router, copy their family photos over, and call it a day. Then there are homelab enthusiasts. We look at a simple home network and think: “You know what this single-bedroom apartment really needs? A three-node high-availability baremetal Proxmox hypervisor cluster, enterprise-grade OPNsense firewalling, automated GitOps CI/CD pipelines, local AI LLM orchestration, and 1Password-vaulted Ansible playbooks.” Welcome to Night-Tower—the homelab where enterprise-grade architecture meets absurd levels of over-engineering.

Excuse Me, But... /btw: The Ultimate Antigravity Slash Command for Terminal ADHD

Picture this: It’s 2:45 AM. Your Antigravity AI agent is elbow-deep in a delicate, high-stakes refactor of your legacy C++ codebase. It’s balancing pointer arithmetic, resolving dependencies, and refactoring memory leaks like a digital maestro. And then, right in the middle of total focus, your brain violently derails: “Wait… is cereal technically cold soup? And why did we call it a ‘microservice’ if the binary is 4 Gigabytes?” In the past, asking your AI assistant a totally random tangent meant ruining its context, derailing its focus, and watching it apologize for 400 words before forgetting what line of code it was editing. Not anymore. Meet /btw.

The Great Mesh VPN Paranoia: Tailscale, Headscale, NetBird, ZeroTier, Nebula & Twingate Compared

It is 11:42 PM on a Sunday. Your homelab is purring softly. The Grafana dashboards are all green, Plex is transcoding smoothly for your cousin in Ohio, and your local DNS is resolving ad-free at blistering speeds. You take a satisfying sip of tea and open HackerNews for a quick nightcap. Then you see it. “Show HN: Minor Telemetry Edge-Case Found in [Your Current VPN’s] Key Exchange Protocol” Panic sets in. Your heart rate spikes to 140 BPM. Your teeth chatter. Within four minutes, you have opened a terminal, SSH’d into your core router, deleted your configuration files, and embarked on a full 3 AM infrastructure rewrite—leaving your spouse entirely unable to watch The Office on local Wi-Fi. Welcome to the Great Homelab Mesh VPN Paranoia.

Cerberus: Guarding Your LAN When Users Walk Straight Into Internet Security Holes

You can spend three weeks configuring strict VLAN isolation, 802.1X authentication, and enterprise-grade firewall rules. You can lock down every port, block every suspicious domain, and write a 40-page security compliance handbook. And yet, within twenty minutes of going live, a user will plug in a “smart toaster” with 2012 firmware, click a blinking banner ad promising “Free RAM Download (100% Legit)”, and walk your entire network straight into every security hole known to modern computing.

Ragnar: The Ultimate Autonomous E-Ink Security Scanner for Pi Zero

Portable hacking gadgets are having a massive moment, and if you loved the cyber-companion vibes of the Pwnagotchi, it is time to meet its network-probing successor. Enter Ragnar (by developer PierreGode)—a fully autonomous, network-scanning, service-mapping, wardriving powerhouse built for the Raspberry Pi and paired with a high-contrast Waveshare e-paper display.

My Newly Found Love for Grafana: Visualizing My Homelab Metrics

Every homelabber reaches a point where running htop and df -h in a loop simply isn’t enough anymore. When your self-hosted ecosystem grows, having real-time, historical visibility into your hardware becomes a necessity. This is the story of my newly found love for Grafana and how I set up a robust, visually stunning monitoring stack for my personal homelab repository, night-tower.

2025

2024

2023

Welcome to Entropyasm

·138 words·1 min
Välkommen till Malmö? Yes, this is where it all begins. Welcome to Entropyasm, my personal playground and digital garden. If you’ve stumbled upon this corner of the internet, you’re in for a ride.

2022

2021

2020

2019