Infrastructure
Rocky 10 VPS
Guarded provisioning, rootless services, reversible hardening, and explicit evidence boundaries for a small public edge.
Independent systems / 2026
Software, services, and infrastructure built with an eye for the boundary: what is public, what is private, and what can be explained plainly.
The operating idea
The interesting work is usually not the service itself. It is the line around it: the route, the policy, the rollback, the evidence.
Public endpoints stay small. Administrative surfaces stay private. Documentation describes the trade-offs instead of hiding them behind a status badge.
Available surfaces
DoH on the public edge. DoT on the tailnet. No account and no query history.
Setup and policy 02maintainedForgejo with HTTPS cloning through the edge and native SSH on a separate hostname.
Clone endpoints 03open workA concise index of the tools, infrastructure, and experiments that make up the surface.
View the indexSelected work
Infrastructure
Guarded provisioning, rootless services, reversible hardening, and explicit evidence boundaries for a small public edge.
Public service
A narrow DoH and tailnet DoT surface backed by filtered resolution, DNSSEC, rate limits, and no query history.
Open surfaceSoftware delivery
Private-by-default Git hosting with HTTPS through the edge and native SSH on a separate origin hostname.
Open surface