View modem7's full-sized avatar

Organizations

@borgmatic-collective

Block or report modem7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
modem7/README.md

Header

GitHub FollowersOmegaWikiBuy Me A CoffeeProfile Views


👨‍💻 About Me

  • 🔭 I’m a Platform Engineer focused on building and managing CI/CD pipelines, internal tooling, and scalable infrastructure. Day to day that means everything from writing automation to bench-testing hardware and making sure software gets from dev to production reliably. Currently that includes ROS 2 pipeline infrastructure in the subsea/marine robotics space — Linux packaging with bloom and debhelper, Aptly-managed package repositories with GPG signing and environment promotion, and Fast-DDS discovery server configuration for distributed development teams.

  • 🔧 I work across the full stack of infrastructure — containers, virtualisation (ESXi, Proxmox, vSphere), IaC (Ansible, Terraform, Packer), and GitOps — with a strong lean towards automating anything that shouldn’t be done by hand. Prior to my current role I was a Linux Sysadmin, so I’m just as comfortable racking servers and hardening systems as I am writing pipelines.

  • 👥 I collaborate closely with software and engineering teams, and have worked across vendors, procurement, and SoC teams to keep projects moving. Happy switching between writing technical docs on Confluence, reviewing pipelines, or configuring switches and firewalls depending on what the day calls for. I also integrate AI tooling (Claude, GitLab Duo, Microsoft Copilot) into engineering workflows — pipeline automation, code review assistance, documentation, changelog generation, and infrastructure work. A force multiplier, not a substitute for understanding what's actually going on.

  • 🌍 I've worked my way up through infrastructure roles across high-stakes sectors like defence, energy, transport, and telecoms — picking up everything from large-scale VDI environments to Linux systems engineering along the way. I'm also a fluent Brazilian Portuguese speaker, which has come in handy supporting global and multilingual teams throughout.

  • ⚡ Outside of work I run a two-node Proxmox cluster (Samwise + Frodo) with 20+ VMs and LXC containers, ZFS storage, a dedicated Proxmox Backup Server, and a self-hosted GitHub Actions runner that ties it all into real CI/CD pipelines. IaC VMs for Packer, Ansible, and Terraform are spun up on demand from cloud-init templates I build and maintain myself. Ansible is my go-to for automating it all — I've also picked up both the Ansible Essential and Advanced Playbooks certifications to back that up.

  • 🧟 For nearly a decade I helped organise World Zombie Day — a global charity event that raised money for food banks through city-wide zombie walks. Coordinating sponsors, volunteers, routes, and day-of logistics across London, UK was genuinely great experience, and a lot of fun.

  • 🧑‍🤝‍🧑 I'm active in the open source community — opening PRs, contributing commits, reviewing code, and raising issues and bug reports across projects I use and care about. Not just a consumer.

  • ✍️ I write up what I learn over on OmegaWiki — mostly Linux, Docker, and homelab guides.

  • 📫 Reach me:LinkedIn


🛠️ Languages and Tools

Operating Systems

Shell

Editors
Containers & CI/CD

Robotics

Virtualisation

Source Control
Hardware & Other

Enterprise Systems

Project Management

AI Tooling

🚀 Featured Projects

ProjectDescriptionStars
public_scriptsA collection of practical scripts covering Proxmox automation, Docker management, server administration, and media processing — built for real use and shared publicly with sensitive values scrubbedStars
docker-borgmatic(co-maintainer)Multiarch Docker container packaging Borg, Borgmatic, and Apprise for automated backup orchestration with container stop/start hook support — part of the official borgmatic-collective. 7.2M+ pulls on Docker HubStars
docker-borgmatic(personal fork)Self-maintained fork of the above with custom builds and personal modifications running on S6 Overlay, supporting amd64 and arm64Stars
cibuildwheelCI pipeline that builds Python wheels for packages missing from PyPI, used to supply dependencies for the docker-borgmatic image — packages published to CloudsmithStars
crowdsec-troubleshooterUnprivileged, run-once Docker tool for diagnosing CrowdSec + Traefik setups — a wellness check, an IP block checker, and an optional live "does blocking actually work" test. No daemon, no docker.sock, no host networking, no capabilities requiredStars
docker-rickrollDockerised Rick RollStars

🏠 Home Lab

Two-node Proxmox cluster backed by a dedicated Proxmox Backup Server, ZFS on both nodes, and an Unraid NAS for secondary storage. The PBS doubles as a QDevice — third vote in the quorum, keeping the cluster clean in a node failure without split-brain.

Everything is managed as code. Cloud-init templates are built with a custom script (multi-backend storage detection, SHA256 image verification, reusable config profiles) and kept current by a template update pipeline that patches source VMs concurrently via QEMU Guest Agent, handles reboots, then clones and converts to templates automatically.

Network infrastructure managed with Terraform, services provisioned with Ansible.

Storage, by the drive count: 19 physical disks spread across the cluster, backup server, and NAS — 4 NVMe, 11 SATA SSD, 4 HDD.

Samwise(primary — 20c / 256GB / ~1TB ZFS | IPMI for out-of-band management)

ServiceTypeRole
DNS + NTP (primary)VMPihole + Unbound — full recursive DNS with DNSSEC validation, qname minimisation, DNS rebinding protection, and rate limiting. No upstream DNS dependency. Chrony NTP. HA primary — adlists synced to replica via Nebula-Sync
Home AutomationVMHome automation
Cloud StorageVMSelf-hosted cloud storage
Docker ServerVM50+ container Docker stack — media, productivity, security, and monitoring
NASVMNetwork attached storage
IaC ServerVMAnsible / Packer / Terraform (on-demand)
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
CI/CD RunnerLXCSelf-hosted GitHub Actions runner
Claude CodeVMSelf-hosted agent environment for AI-assisted infra work

Frodo(secondary — 4c / 32GB / ~100GB ZFS)

ServiceTypeRole
DNS + NTP (replica)VMPihole + Unbound + Chrony NTP — HA replica, gravity and adlists synced from primary
Transcoding NodeVMAutomated media transcoding
APT CacheLXCLocal APT package cache
BastionLXCSSH jump host
NetbootLXCPXE / network boot server
Patch ManagementLXCTracks and reports pending updates across all systems
IoT BuilderLXCESPHome firmware builds
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
Push NotificationsLXCSelf-hosted push notifications
Network MonitorLXCNetwork device tracking and new device detection

Network(because the lab doesn't stop at the hypervisor)

Managed via a UniFi stack — everything named after Lord of the Rings characters because of course it is.

DeviceModelRole
GandalfUDM ProGateway / firewall — WireGuard VPN, SFP+ uplink to core switch
GimliUSW Pro Max 24 PoECore switch — 10GbE SFP+ backbone, SFP+ uplinks to gateway and NVR
DwalinUSW Flex 2.5G 52.5G distribution switch
DainUSW Lite 8 PoEAccess switch
BalinUSW Pro Max 16 PoEDistribution switch
Legolas / Galadriel / HaldirU6 Pro ×3Wi-Fi APs
SauronUNVRNetwork video recorder — SFP+ uplink to core switch
CategoryDetail
ProtectIP camera system — isolated on a dedicated camera VLAN
IoTSLZB-MR1u (PoE) — standalone Zigbee + Thread/Matter coordinator
VLANsDefault · IoT · Guest · VM · Camera
ClientsLarge number of devices spread across multiple VLANs

🖥️ Self-Hosted Services

The Docker server runs a 50+ container stack across three isolated networks — a main bridge, an outbound-only network, and a fully internal network with no external routing. All services sit behind Traefik (HTTP/3, dual internal/external entrypoints, Cloudflare wildcard TLS), with Authentik as the SSO layer and CrowdSec handling threat intelligence via both a Traefik bouncer and a Cloudflare Worker bouncer.

Media

  • Self-hosted media server with NVIDIA GPU passthrough for hardware transcoding
  • Automated media management and transcoding pipeline with multi-node remote transcoding
  • Request management, stats, and library maintenance tooling

Security & Access

  • Traefik — reverse proxy, HTTP/3, Cloudflare TLS

  • Authentik — SSO / OIDC provider for all services

  • CrowdSec — collaborative IPS feeding threat intelligence into both a Traefik bouncer and a Cloudflare Worker bouncer, so malicious traffic is blocked at the CDN edge before it reaches the network

  • Cloudflare — WAF rules, firewall policies, and proxied DNS layered on top of CrowdSec blocklists for defence-in-depth at the perimeter

  • Self-hosted password manager with SSO, YubiKey & Duo MFA

  • Docker Socket Proxy — restricted docker.sock proxy deployed across select fleet hosts, limiting containers to only the Docker API access they need

Productivity

Monitoring & Management

  • Grafana · Prometheus · Telegraf
  • Dozzle — Docker log aggregation across multiple hosts
  • Uptime Kuma — uptime monitoring running on an external VPS for genuine outside-in visibility
  • Netdata — real-time performance monitoring on all VMs
  • Monocker — container state alerts via Telegram
  • Speedtest Tracker
  • PatchMon — patch management across all systems, tracking and reporting pending updates
  • PiAlert — network device tracking and new device detection across VLANs

Backup & CI/CD


🔥 My Stats

GitHub Trophies

GitHub StatsTop Languages

GitHub Streak

Github activity graph

AI Code Time

🐱 My GitHub Data

📦 2.6 MB Used in GitHub's Storage

🏆 1,159 Contributions in the Year 2026

🚫 Not Opted to Hire

📜 46 Public Repositories

🔑 10 Private Repositories

I'm a Night 🦉

🌞 Morning 2516 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 09.01 % 🌆 Daytime 7290 commits ███████░░░░░░░░░░░░░░░░░░ 26.11 % 🌃 Evening 9652 commits █████████░░░░░░░░░░░░░░░░ 34.57 % 🌙 Night 8465 commits ████████░░░░░░░░░░░░░░░░░ 30.32 % 

📅 I'm Most Productive on Wednesday

Monday 4645 commits ████░░░░░░░░░░░░░░░░░░░░░ 16.64 % Tuesday 4910 commits ████░░░░░░░░░░░░░░░░░░░░░ 17.58 % Wednesday 5387 commits █████░░░░░░░░░░░░░░░░░░░░ 19.29 % Thursday 3574 commits ███░░░░░░░░░░░░░░░░░░░░░░ 12.80 % Friday 4086 commits ████░░░░░░░░░░░░░░░░░░░░░ 14.63 % Saturday 2876 commits ███░░░░░░░░░░░░░░░░░░░░░░ 10.30 % Sunday 2445 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 08.76 % 

📊 This Week I Spent My Time On

🕑︎ Time Zone: Europe/London
💬 Programming Languages: No Activity Tracked This Week
🔥 Editors: No Activity Tracked This Week
🐱‍💻 Projects: No Activity Tracked This Week
💻 Operating System: No Activity Tracked This Week

🤖 AI Coding This Week

No AI Coding Activity Tracked This Week

I Mostly Code in Shell

Shell 22 repos ██████████░░░░░░░░░░░░░░░ 39.29 % Python 8 repos ████░░░░░░░░░░░░░░░░░░░░░ 14.29 % HTML 4 repos ██░░░░░░░░░░░░░░░░░░░░░░░ 07.14 % JavaScript 3 repos █░░░░░░░░░░░░░░░░░░░░░░░░ 05.36 % HCL 1 repo ░░░░░░░░░░░░░░░░░░░░░░░░░ 01.79 % 

Last Updated on 04/09/2026 05:36:06 UTC

🎮 Steam playtime leaderboard

⚔️ Dota 2 🕘 2309 hrs 19 mins
🎮 HELLDIVERS™ 2 🕘 1195 hrs 47 mins
🎮 Creeper World 4 🕘 889 hrs 58 mins
🎮 Overwatch® 🕘 270 hrs 19 mins
🌏 Sid Meier's Civilization V 🕘 226 hrs 21 mins

✍️ Latest Wiki Posts :

✍️ Personal Websites :

Pinned Loading

  1. docker-rickrolldocker-rickrollPublic

    Dockerised Rick Roll

    Shell 57 16

  2. docker-borgmaticdocker-borgmaticPublic

    Container to automate Borgbackups (https://github.com/borgbackup) using Borgmatic (https://github.com/witten/borgmatic)

    Shell 47 8

  3. public_scriptspublic_scriptsPublic

    Scripts for the general public

    Shell 92 18

  4. cibuildwheelcibuildwheelPublic

    CIBuildWheel

    Shell 1

  5. docker-devenvdocker-devenvPublic

    Docker Dev Environments

    Shell 5 1

  6. docker-starwarsdocker-starwarsPublic

    Self hosted, self contained Docker image of the classic www.asciimation.co.nz/Blinkenlights ASCII Star Wars animation.

    HTML 17 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content
View modem7's full-sized avatar

Organizations

@borgmatic-collective

Block or report modem7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
modem7/README.md

Header

GitHub FollowersOmegaWikiBuy Me A CoffeeProfile Views


👨‍💻 About Me

  • 🔭 I’m a Platform Engineer focused on building and managing CI/CD pipelines, internal tooling, and scalable infrastructure. Day to day that means everything from writing automation to bench-testing hardware and making sure software gets from dev to production reliably. Currently that includes ROS 2 pipeline infrastructure in the subsea/marine robotics space — Linux packaging with bloom and debhelper, Aptly-managed package repositories with GPG signing and environment promotion, and Fast-DDS discovery server configuration for distributed development teams.

  • 🔧 I work across the full stack of infrastructure — containers, virtualisation (ESXi, Proxmox, vSphere), IaC (Ansible, Terraform, Packer), and GitOps — with a strong lean towards automating anything that shouldn’t be done by hand. Prior to my current role I was a Linux Sysadmin, so I’m just as comfortable racking servers and hardening systems as I am writing pipelines.

  • 👥 I collaborate closely with software and engineering teams, and have worked across vendors, procurement, and SoC teams to keep projects moving. Happy switching between writing technical docs on Confluence, reviewing pipelines, or configuring switches and firewalls depending on what the day calls for. I also integrate AI tooling (Claude, GitLab Duo, Microsoft Copilot) into engineering workflows — pipeline automation, code review assistance, documentation, changelog generation, and infrastructure work. A force multiplier, not a substitute for understanding what's actually going on.

  • 🌍 I've worked my way up through infrastructure roles across high-stakes sectors like defence, energy, transport, and telecoms — picking up everything from large-scale VDI environments to Linux systems engineering along the way. I'm also a fluent Brazilian Portuguese speaker, which has come in handy supporting global and multilingual teams throughout.

  • ⚡ Outside of work I run a two-node Proxmox cluster (Samwise + Frodo) with 20+ VMs and LXC containers, ZFS storage, a dedicated Proxmox Backup Server, and a self-hosted GitHub Actions runner that ties it all into real CI/CD pipelines. IaC VMs for Packer, Ansible, and Terraform are spun up on demand from cloud-init templates I build and maintain myself. Ansible is my go-to for automating it all — I've also picked up both the Ansible Essential and Advanced Playbooks certifications to back that up.

  • 🧟 For nearly a decade I helped organise World Zombie Day — a global charity event that raised money for food banks through city-wide zombie walks. Coordinating sponsors, volunteers, routes, and day-of logistics across London, UK was genuinely great experience, and a lot of fun.

  • 🧑‍🤝‍🧑 I'm active in the open source community — opening PRs, contributing commits, reviewing code, and raising issues and bug reports across projects I use and care about. Not just a consumer.

  • ✍️ I write up what I learn over on OmegaWiki — mostly Linux, Docker, and homelab guides.

  • 📫 Reach me:LinkedIn


🛠️ Languages and Tools

Operating Systems

Shell

Editors
Containers & CI/CD

Robotics

Virtualisation

Source Control
Hardware & Other

Enterprise Systems

Project Management

AI Tooling

🚀 Featured Projects

ProjectDescriptionStars
public_scriptsA collection of practical scripts covering Proxmox automation, Docker management, server administration, and media processing — built for real use and shared publicly with sensitive values scrubbedStars
docker-borgmatic(co-maintainer)Multiarch Docker container packaging Borg, Borgmatic, and Apprise for automated backup orchestration with container stop/start hook support — part of the official borgmatic-collective. 7.2M+ pulls on Docker HubStars
docker-borgmatic(personal fork)Self-maintained fork of the above with custom builds and personal modifications running on S6 Overlay, supporting amd64 and arm64Stars
cibuildwheelCI pipeline that builds Python wheels for packages missing from PyPI, used to supply dependencies for the docker-borgmatic image — packages published to CloudsmithStars
crowdsec-troubleshooterUnprivileged, run-once Docker tool for diagnosing CrowdSec + Traefik setups — a wellness check, an IP block checker, and an optional live "does blocking actually work" test. No daemon, no docker.sock, no host networking, no capabilities requiredStars
docker-rickrollDockerised Rick RollStars

🏠 Home Lab

Two-node Proxmox cluster backed by a dedicated Proxmox Backup Server, ZFS on both nodes, and an Unraid NAS for secondary storage. The PBS doubles as a QDevice — third vote in the quorum, keeping the cluster clean in a node failure without split-brain.

Everything is managed as code. Cloud-init templates are built with a custom script (multi-backend storage detection, SHA256 image verification, reusable config profiles) and kept current by a template update pipeline that patches source VMs concurrently via QEMU Guest Agent, handles reboots, then clones and converts to templates automatically.

Network infrastructure managed with Terraform, services provisioned with Ansible.

Storage, by the drive count: 19 physical disks spread across the cluster, backup server, and NAS — 4 NVMe, 11 SATA SSD, 4 HDD.

Samwise(primary — 20c / 256GB / ~1TB ZFS | IPMI for out-of-band management)

ServiceTypeRole
DNS + NTP (primary)VMPihole + Unbound — full recursive DNS with DNSSEC validation, qname minimisation, DNS rebinding protection, and rate limiting. No upstream DNS dependency. Chrony NTP. HA primary — adlists synced to replica via Nebula-Sync
Home AutomationVMHome automation
Cloud StorageVMSelf-hosted cloud storage
Docker ServerVM50+ container Docker stack — media, productivity, security, and monitoring
NASVMNetwork attached storage
IaC ServerVMAnsible / Packer / Terraform (on-demand)
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
CI/CD RunnerLXCSelf-hosted GitHub Actions runner
Claude CodeVMSelf-hosted agent environment for AI-assisted infra work

Frodo(secondary — 4c / 32GB / ~100GB ZFS)

ServiceTypeRole
DNS + NTP (replica)VMPihole + Unbound + Chrony NTP — HA replica, gravity and adlists synced from primary
Transcoding NodeVMAutomated media transcoding
APT CacheLXCLocal APT package cache
BastionLXCSSH jump host
NetbootLXCPXE / network boot server
Patch ManagementLXCTracks and reports pending updates across all systems
IoT BuilderLXCESPHome firmware builds
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
Push NotificationsLXCSelf-hosted push notifications
Network MonitorLXCNetwork device tracking and new device detection

Network(because the lab doesn't stop at the hypervisor)

Managed via a UniFi stack — everything named after Lord of the Rings characters because of course it is.

DeviceModelRole
GandalfUDM ProGateway / firewall — WireGuard VPN, SFP+ uplink to core switch
GimliUSW Pro Max 24 PoECore switch — 10GbE SFP+ backbone, SFP+ uplinks to gateway and NVR
DwalinUSW Flex 2.5G 52.5G distribution switch
DainUSW Lite 8 PoEAccess switch
BalinUSW Pro Max 16 PoEDistribution switch
Legolas / Galadriel / HaldirU6 Pro ×3Wi-Fi APs
SauronUNVRNetwork video recorder — SFP+ uplink to core switch
CategoryDetail
ProtectIP camera system — isolated on a dedicated camera VLAN
IoTSLZB-MR1u (PoE) — standalone Zigbee + Thread/Matter coordinator
VLANsDefault · IoT · Guest · VM · Camera
ClientsLarge number of devices spread across multiple VLANs

🖥️ Self-Hosted Services

The Docker server runs a 50+ container stack across three isolated networks — a main bridge, an outbound-only network, and a fully internal network with no external routing. All services sit behind Traefik (HTTP/3, dual internal/external entrypoints, Cloudflare wildcard TLS), with Authentik as the SSO layer and CrowdSec handling threat intelligence via both a Traefik bouncer and a Cloudflare Worker bouncer.

Media

  • Self-hosted media server with NVIDIA GPU passthrough for hardware transcoding
  • Automated media management and transcoding pipeline with multi-node remote transcoding
  • Request management, stats, and library maintenance tooling

Security & Access

  • Traefik — reverse proxy, HTTP/3, Cloudflare TLS

  • Authentik — SSO / OIDC provider for all services

  • CrowdSec — collaborative IPS feeding threat intelligence into both a Traefik bouncer and a Cloudflare Worker bouncer, so malicious traffic is blocked at the CDN edge before it reaches the network

  • Cloudflare — WAF rules, firewall policies, and proxied DNS layered on top of CrowdSec blocklists for defence-in-depth at the perimeter

  • Self-hosted password manager with SSO, YubiKey & Duo MFA

  • Docker Socket Proxy — restricted docker.sock proxy deployed across select fleet hosts, limiting containers to only the Docker API access they need

Productivity

Monitoring & Management

  • Grafana · Prometheus · Telegraf
  • Dozzle — Docker log aggregation across multiple hosts
  • Uptime Kuma — uptime monitoring running on an external VPS for genuine outside-in visibility
  • Netdata — real-time performance monitoring on all VMs
  • Monocker — container state alerts via Telegram
  • Speedtest Tracker
  • PatchMon — patch management across all systems, tracking and reporting pending updates
  • PiAlert — network device tracking and new device detection across VLANs

Backup & CI/CD


🔥 My Stats

GitHub Trophies

GitHub StatsTop Languages

GitHub Streak

Github activity graph

AI Code Time

🐱 My GitHub Data

📦 2.6 MB Used in GitHub's Storage

🏆 1,159 Contributions in the Year 2026

🚫 Not Opted to Hire

📜 46 Public Repositories

🔑 10 Private Repositories

I'm a Night 🦉

🌞 Morning 2516 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 09.01 % 🌆 Daytime 7290 commits ███████░░░░░░░░░░░░░░░░░░ 26.11 % 🌃 Evening 9652 commits █████████░░░░░░░░░░░░░░░░ 34.57 % 🌙 Night 8465 commits ████████░░░░░░░░░░░░░░░░░ 30.32 % 

📅 I'm Most Productive on Wednesday

Monday 4645 commits ████░░░░░░░░░░░░░░░░░░░░░ 16.64 % Tuesday 4910 commits ████░░░░░░░░░░░░░░░░░░░░░ 17.58 % Wednesday 5387 commits █████░░░░░░░░░░░░░░░░░░░░ 19.29 % Thursday 3574 commits ███░░░░░░░░░░░░░░░░░░░░░░ 12.80 % Friday 4086 commits ████░░░░░░░░░░░░░░░░░░░░░ 14.63 % Saturday 2876 commits ███░░░░░░░░░░░░░░░░░░░░░░ 10.30 % Sunday 2445 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 08.76 % 

📊 This Week I Spent My Time On

🕑︎ Time Zone: Europe/London
💬 Programming Languages: No Activity Tracked This Week
🔥 Editors: No Activity Tracked This Week
🐱‍💻 Projects: No Activity Tracked This Week
💻 Operating System: No Activity Tracked This Week

🤖 AI Coding This Week

No AI Coding Activity Tracked This Week

I Mostly Code in Shell

Shell 22 repos ██████████░░░░░░░░░░░░░░░ 39.29 % Python 8 repos ████░░░░░░░░░░░░░░░░░░░░░ 14.29 % HTML 4 repos ██░░░░░░░░░░░░░░░░░░░░░░░ 07.14 % JavaScript 3 repos █░░░░░░░░░░░░░░░░░░░░░░░░ 05.36 % HCL 1 repo ░░░░░░░░░░░░░░░░░░░░░░░░░ 01.79 % 

Last Updated on 04/09/2026 05:36:06 UTC

🎮 Steam playtime leaderboard

⚔️ Dota 2 🕘 2309 hrs 19 mins
🎮 HELLDIVERS™ 2 🕘 1195 hrs 47 mins
🎮 Creeper World 4 🕘 889 hrs 58 mins
🎮 Overwatch® 🕘 270 hrs 19 mins
🌏 Sid Meier's Civilization V 🕘 226 hrs 21 mins

✍️ Latest Wiki Posts :

✍️ Personal Websites :

Pinned Loading

  1. docker-rickrolldocker-rickrollPublic

    Dockerised Rick Roll

    Shell 57 16

  2. docker-borgmaticdocker-borgmaticPublic

    Container to automate Borgbackups (https://github.com/borgbackup) using Borgmatic (https://github.com/witten/borgmatic)

    Shell 47 8

  3. public_scriptspublic_scriptsPublic

    Scripts for the general public

    Shell 92 18

  4. cibuildwheelcibuildwheelPublic

    CIBuildWheel

    Shell 1

  5. docker-devenvdocker-devenvPublic

    Docker Dev Environments

    Shell 5 1

  6. docker-starwarsdocker-starwarsPublic

    Self hosted, self contained Docker image of the classic www.asciimation.co.nz/Blinkenlights ASCII Star Wars animation.

    HTML 17 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View modem7's full-sized avatar

Organizations

@borgmatic-collective

Block or report modem7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
modem7/README.md

Header

GitHub FollowersOmegaWikiBuy Me A CoffeeProfile Views


👨‍💻 About Me

  • 🔭 I’m a Platform Engineer focused on building and managing CI/CD pipelines, internal tooling, and scalable infrastructure. Day to day that means everything from writing automation to bench-testing hardware and making sure software gets from dev to production reliably. Currently that includes ROS 2 pipeline infrastructure in the subsea/marine robotics space — Linux packaging with bloom and debhelper, Aptly-managed package repositories with GPG signing and environment promotion, and Fast-DDS discovery server configuration for distributed development teams.

  • 🔧 I work across the full stack of infrastructure — containers, virtualisation (ESXi, Proxmox, vSphere), IaC (Ansible, Terraform, Packer), and GitOps — with a strong lean towards automating anything that shouldn’t be done by hand. Prior to my current role I was a Linux Sysadmin, so I’m just as comfortable racking servers and hardening systems as I am writing pipelines.

  • 👥 I collaborate closely with software and engineering teams, and have worked across vendors, procurement, and SoC teams to keep projects moving. Happy switching between writing technical docs on Confluence, reviewing pipelines, or configuring switches and firewalls depending on what the day calls for. I also integrate AI tooling (Claude, GitLab Duo, Microsoft Copilot) into engineering workflows — pipeline automation, code review assistance, documentation, changelog generation, and infrastructure work. A force multiplier, not a substitute for understanding what's actually going on.

  • 🌍 I've worked my way up through infrastructure roles across high-stakes sectors like defence, energy, transport, and telecoms — picking up everything from large-scale VDI environments to Linux systems engineering along the way. I'm also a fluent Brazilian Portuguese speaker, which has come in handy supporting global and multilingual teams throughout.

  • ⚡ Outside of work I run a two-node Proxmox cluster (Samwise + Frodo) with 20+ VMs and LXC containers, ZFS storage, a dedicated Proxmox Backup Server, and a self-hosted GitHub Actions runner that ties it all into real CI/CD pipelines. IaC VMs for Packer, Ansible, and Terraform are spun up on demand from cloud-init templates I build and maintain myself. Ansible is my go-to for automating it all — I've also picked up both the Ansible Essential and Advanced Playbooks certifications to back that up.

  • 🧟 For nearly a decade I helped organise World Zombie Day — a global charity event that raised money for food banks through city-wide zombie walks. Coordinating sponsors, volunteers, routes, and day-of logistics across London, UK was genuinely great experience, and a lot of fun.

  • 🧑‍🤝‍🧑 I'm active in the open source community — opening PRs, contributing commits, reviewing code, and raising issues and bug reports across projects I use and care about. Not just a consumer.

  • ✍️ I write up what I learn over on OmegaWiki — mostly Linux, Docker, and homelab guides.

  • 📫 Reach me:LinkedIn


🛠️ Languages and Tools

Operating Systems

Shell

Editors
Containers & CI/CD

Robotics

Virtualisation

Source Control
Hardware & Other

Enterprise Systems

Project Management

AI Tooling

🚀 Featured Projects

ProjectDescriptionStars
public_scriptsA collection of practical scripts covering Proxmox automation, Docker management, server administration, and media processing — built for real use and shared publicly with sensitive values scrubbedStars
docker-borgmatic(co-maintainer)Multiarch Docker container packaging Borg, Borgmatic, and Apprise for automated backup orchestration with container stop/start hook support — part of the official borgmatic-collective. 7.2M+ pulls on Docker HubStars
docker-borgmatic(personal fork)Self-maintained fork of the above with custom builds and personal modifications running on S6 Overlay, supporting amd64 and arm64Stars
cibuildwheelCI pipeline that builds Python wheels for packages missing from PyPI, used to supply dependencies for the docker-borgmatic image — packages published to CloudsmithStars
crowdsec-troubleshooterUnprivileged, run-once Docker tool for diagnosing CrowdSec + Traefik setups — a wellness check, an IP block checker, and an optional live "does blocking actually work" test. No daemon, no docker.sock, no host networking, no capabilities requiredStars
docker-rickrollDockerised Rick RollStars

🏠 Home Lab

Two-node Proxmox cluster backed by a dedicated Proxmox Backup Server, ZFS on both nodes, and an Unraid NAS for secondary storage. The PBS doubles as a QDevice — third vote in the quorum, keeping the cluster clean in a node failure without split-brain.

Everything is managed as code. Cloud-init templates are built with a custom script (multi-backend storage detection, SHA256 image verification, reusable config profiles) and kept current by a template update pipeline that patches source VMs concurrently via QEMU Guest Agent, handles reboots, then clones and converts to templates automatically.

Network infrastructure managed with Terraform, services provisioned with Ansible.

Storage, by the drive count: 19 physical disks spread across the cluster, backup server, and NAS — 4 NVMe, 11 SATA SSD, 4 HDD.

Samwise(primary — 20c / 256GB / ~1TB ZFS | IPMI for out-of-band management)

ServiceTypeRole
DNS + NTP (primary)VMPihole + Unbound — full recursive DNS with DNSSEC validation, qname minimisation, DNS rebinding protection, and rate limiting. No upstream DNS dependency. Chrony NTP. HA primary — adlists synced to replica via Nebula-Sync
Home AutomationVMHome automation
Cloud StorageVMSelf-hosted cloud storage
Docker ServerVM50+ container Docker stack — media, productivity, security, and monitoring
NASVMNetwork attached storage
IaC ServerVMAnsible / Packer / Terraform (on-demand)
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
CI/CD RunnerLXCSelf-hosted GitHub Actions runner
Claude CodeVMSelf-hosted agent environment for AI-assisted infra work

Frodo(secondary — 4c / 32GB / ~100GB ZFS)

ServiceTypeRole
DNS + NTP (replica)VMPihole + Unbound + Chrony NTP — HA replica, gravity and adlists synced from primary
Transcoding NodeVMAutomated media transcoding
APT CacheLXCLocal APT package cache
BastionLXCSSH jump host
NetbootLXCPXE / network boot server
Patch ManagementLXCTracks and reports pending updates across all systems
IoT BuilderLXCESPHome firmware builds
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
Push NotificationsLXCSelf-hosted push notifications
Network MonitorLXCNetwork device tracking and new device detection

Network(because the lab doesn't stop at the hypervisor)

Managed via a UniFi stack — everything named after Lord of the Rings characters because of course it is.

DeviceModelRole
GandalfUDM ProGateway / firewall — WireGuard VPN, SFP+ uplink to core switch
GimliUSW Pro Max 24 PoECore switch — 10GbE SFP+ backbone, SFP+ uplinks to gateway and NVR
DwalinUSW Flex 2.5G 52.5G distribution switch
DainUSW Lite 8 PoEAccess switch
BalinUSW Pro Max 16 PoEDistribution switch
Legolas / Galadriel / HaldirU6 Pro ×3Wi-Fi APs
SauronUNVRNetwork video recorder — SFP+ uplink to core switch
CategoryDetail
ProtectIP camera system — isolated on a dedicated camera VLAN
IoTSLZB-MR1u (PoE) — standalone Zigbee + Thread/Matter coordinator
VLANsDefault · IoT · Guest · VM · Camera
ClientsLarge number of devices spread across multiple VLANs

🖥️ Self-Hosted Services

The Docker server runs a 50+ container stack across three isolated networks — a main bridge, an outbound-only network, and a fully internal network with no external routing. All services sit behind Traefik (HTTP/3, dual internal/external entrypoints, Cloudflare wildcard TLS), with Authentik as the SSO layer and CrowdSec handling threat intelligence via both a Traefik bouncer and a Cloudflare Worker bouncer.

Media

  • Self-hosted media server with NVIDIA GPU passthrough for hardware transcoding
  • Automated media management and transcoding pipeline with multi-node remote transcoding
  • Request management, stats, and library maintenance tooling

Security & Access

  • Traefik — reverse proxy, HTTP/3, Cloudflare TLS

  • Authentik — SSO / OIDC provider for all services

  • CrowdSec — collaborative IPS feeding threat intelligence into both a Traefik bouncer and a Cloudflare Worker bouncer, so malicious traffic is blocked at the CDN edge before it reaches the network

  • Cloudflare — WAF rules, firewall policies, and proxied DNS layered on top of CrowdSec blocklists for defence-in-depth at the perimeter

  • Self-hosted password manager with SSO, YubiKey & Duo MFA

  • Docker Socket Proxy — restricted docker.sock proxy deployed across select fleet hosts, limiting containers to only the Docker API access they need

Productivity

Monitoring & Management

  • Grafana · Prometheus · Telegraf
  • Dozzle — Docker log aggregation across multiple hosts
  • Uptime Kuma — uptime monitoring running on an external VPS for genuine outside-in visibility
  • Netdata — real-time performance monitoring on all VMs
  • Monocker — container state alerts via Telegram
  • Speedtest Tracker
  • PatchMon — patch management across all systems, tracking and reporting pending updates
  • PiAlert — network device tracking and new device detection across VLANs

Backup & CI/CD


🔥 My Stats

GitHub Trophies

GitHub StatsTop Languages

GitHub Streak

Github activity graph

AI Code Time

🐱 My GitHub Data

📦 2.6 MB Used in GitHub's Storage

🏆 1,159 Contributions in the Year 2026

🚫 Not Opted to Hire

📜 46 Public Repositories

🔑 10 Private Repositories

I'm a Night 🦉

🌞 Morning 2516 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 09.01 % 🌆 Daytime 7290 commits ███████░░░░░░░░░░░░░░░░░░ 26.11 % 🌃 Evening 9652 commits █████████░░░░░░░░░░░░░░░░ 34.57 % 🌙 Night 8465 commits ████████░░░░░░░░░░░░░░░░░ 30.32 % 

📅 I'm Most Productive on Wednesday

Monday 4645 commits ████░░░░░░░░░░░░░░░░░░░░░ 16.64 % Tuesday 4910 commits ████░░░░░░░░░░░░░░░░░░░░░ 17.58 % Wednesday 5387 commits █████░░░░░░░░░░░░░░░░░░░░ 19.29 % Thursday 3574 commits ███░░░░░░░░░░░░░░░░░░░░░░ 12.80 % Friday 4086 commits ████░░░░░░░░░░░░░░░░░░░░░ 14.63 % Saturday 2876 commits ███░░░░░░░░░░░░░░░░░░░░░░ 10.30 % Sunday 2445 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 08.76 % 

📊 This Week I Spent My Time On

🕑︎ Time Zone: Europe/London
💬 Programming Languages: No Activity Tracked This Week
🔥 Editors: No Activity Tracked This Week
🐱‍💻 Projects: No Activity Tracked This Week
💻 Operating System: No Activity Tracked This Week

🤖 AI Coding This Week

No AI Coding Activity Tracked This Week

I Mostly Code in Shell

Shell 22 repos ██████████░░░░░░░░░░░░░░░ 39.29 % Python 8 repos ████░░░░░░░░░░░░░░░░░░░░░ 14.29 % HTML 4 repos ██░░░░░░░░░░░░░░░░░░░░░░░ 07.14 % JavaScript 3 repos █░░░░░░░░░░░░░░░░░░░░░░░░ 05.36 % HCL 1 repo ░░░░░░░░░░░░░░░░░░░░░░░░░ 01.79 % 

Last Updated on 04/09/2026 05:36:06 UTC

🎮 Steam playtime leaderboard

⚔️ Dota 2 🕘 2309 hrs 19 mins
🎮 HELLDIVERS™ 2 🕘 1195 hrs 47 mins
🎮 Creeper World 4 🕘 889 hrs 58 mins
🎮 Overwatch® 🕘 270 hrs 19 mins
🌏 Sid Meier's Civilization V 🕘 226 hrs 21 mins

✍️ Latest Wiki Posts :

✍️ Personal Websites :

Pinned Loading

  1. docker-rickrolldocker-rickrollPublic

    Dockerised Rick Roll

    Shell 57 16

  2. docker-borgmaticdocker-borgmaticPublic

    Container to automate Borgbackups (https://github.com/borgbackup) using Borgmatic (https://github.com/witten/borgmatic)

    Shell 47 8

  3. public_scriptspublic_scriptsPublic

    Scripts for the general public

    Shell 92 18

  4. cibuildwheelcibuildwheelPublic

    CIBuildWheel

    Shell 1

  5. docker-devenvdocker-devenvPublic

    Docker Dev Environments

    Shell 5 1

  6. docker-starwarsdocker-starwarsPublic

    Self hosted, self contained Docker image of the classic www.asciimation.co.nz/Blinkenlights ASCII Star Wars animation.

    HTML 17 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View modem7's full-sized avatar

Organizations

@borgmatic-collective

Block or report modem7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
modem7/README.md

Header

GitHub FollowersOmegaWikiBuy Me A CoffeeProfile Views


👨‍💻 About Me

  • 🔭 I’m a Platform Engineer focused on building and managing CI/CD pipelines, internal tooling, and scalable infrastructure. Day to day that means everything from writing automation to bench-testing hardware and making sure software gets from dev to production reliably. Currently that includes ROS 2 pipeline infrastructure in the subsea/marine robotics space — Linux packaging with bloom and debhelper, Aptly-managed package repositories with GPG signing and environment promotion, and Fast-DDS discovery server configuration for distributed development teams.

  • 🔧 I work across the full stack of infrastructure — containers, virtualisation (ESXi, Proxmox, vSphere), IaC (Ansible, Terraform, Packer), and GitOps — with a strong lean towards automating anything that shouldn’t be done by hand. Prior to my current role I was a Linux Sysadmin, so I’m just as comfortable racking servers and hardening systems as I am writing pipelines.

  • 👥 I collaborate closely with software and engineering teams, and have worked across vendors, procurement, and SoC teams to keep projects moving. Happy switching between writing technical docs on Confluence, reviewing pipelines, or configuring switches and firewalls depending on what the day calls for. I also integrate AI tooling (Claude, GitLab Duo, Microsoft Copilot) into engineering workflows — pipeline automation, code review assistance, documentation, changelog generation, and infrastructure work. A force multiplier, not a substitute for understanding what's actually going on.

  • 🌍 I've worked my way up through infrastructure roles across high-stakes sectors like defence, energy, transport, and telecoms — picking up everything from large-scale VDI environments to Linux systems engineering along the way. I'm also a fluent Brazilian Portuguese speaker, which has come in handy supporting global and multilingual teams throughout.

  • ⚡ Outside of work I run a two-node Proxmox cluster (Samwise + Frodo) with 20+ VMs and LXC containers, ZFS storage, a dedicated Proxmox Backup Server, and a self-hosted GitHub Actions runner that ties it all into real CI/CD pipelines. IaC VMs for Packer, Ansible, and Terraform are spun up on demand from cloud-init templates I build and maintain myself. Ansible is my go-to for automating it all — I've also picked up both the Ansible Essential and Advanced Playbooks certifications to back that up.

  • 🧟 For nearly a decade I helped organise World Zombie Day — a global charity event that raised money for food banks through city-wide zombie walks. Coordinating sponsors, volunteers, routes, and day-of logistics across London, UK was genuinely great experience, and a lot of fun.

  • 🧑‍🤝‍🧑 I'm active in the open source community — opening PRs, contributing commits, reviewing code, and raising issues and bug reports across projects I use and care about. Not just a consumer.

  • ✍️ I write up what I learn over on OmegaWiki — mostly Linux, Docker, and homelab guides.

  • 📫 Reach me:LinkedIn


🛠️ Languages and Tools

Operating Systems

Shell

Editors
Containers & CI/CD

Robotics

Virtualisation

Source Control
Hardware & Other

Enterprise Systems

Project Management

AI Tooling

🚀 Featured Projects

ProjectDescriptionStars
public_scriptsA collection of practical scripts covering Proxmox automation, Docker management, server administration, and media processing — built for real use and shared publicly with sensitive values scrubbedStars
docker-borgmatic(co-maintainer)Multiarch Docker container packaging Borg, Borgmatic, and Apprise for automated backup orchestration with container stop/start hook support — part of the official borgmatic-collective. 7.2M+ pulls on Docker HubStars
docker-borgmatic(personal fork)Self-maintained fork of the above with custom builds and personal modifications running on S6 Overlay, supporting amd64 and arm64Stars
cibuildwheelCI pipeline that builds Python wheels for packages missing from PyPI, used to supply dependencies for the docker-borgmatic image — packages published to CloudsmithStars
crowdsec-troubleshooterUnprivileged, run-once Docker tool for diagnosing CrowdSec + Traefik setups — a wellness check, an IP block checker, and an optional live "does blocking actually work" test. No daemon, no docker.sock, no host networking, no capabilities requiredStars
docker-rickrollDockerised Rick RollStars

🏠 Home Lab

Two-node Proxmox cluster backed by a dedicated Proxmox Backup Server, ZFS on both nodes, and an Unraid NAS for secondary storage. The PBS doubles as a QDevice — third vote in the quorum, keeping the cluster clean in a node failure without split-brain.

Everything is managed as code. Cloud-init templates are built with a custom script (multi-backend storage detection, SHA256 image verification, reusable config profiles) and kept current by a template update pipeline that patches source VMs concurrently via QEMU Guest Agent, handles reboots, then clones and converts to templates automatically.

Network infrastructure managed with Terraform, services provisioned with Ansible.

Storage, by the drive count: 19 physical disks spread across the cluster, backup server, and NAS — 4 NVMe, 11 SATA SSD, 4 HDD.

Samwise(primary — 20c / 256GB / ~1TB ZFS | IPMI for out-of-band management)

ServiceTypeRole
DNS + NTP (primary)VMPihole + Unbound — full recursive DNS with DNSSEC validation, qname minimisation, DNS rebinding protection, and rate limiting. No upstream DNS dependency. Chrony NTP. HA primary — adlists synced to replica via Nebula-Sync
Home AutomationVMHome automation
Cloud StorageVMSelf-hosted cloud storage
Docker ServerVM50+ container Docker stack — media, productivity, security, and monitoring
NASVMNetwork attached storage
IaC ServerVMAnsible / Packer / Terraform (on-demand)
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
CI/CD RunnerLXCSelf-hosted GitHub Actions runner
Claude CodeVMSelf-hosted agent environment for AI-assisted infra work

Frodo(secondary — 4c / 32GB / ~100GB ZFS)

ServiceTypeRole
DNS + NTP (replica)VMPihole + Unbound + Chrony NTP — HA replica, gravity and adlists synced from primary
Transcoding NodeVMAutomated media transcoding
APT CacheLXCLocal APT package cache
BastionLXCSSH jump host
NetbootLXCPXE / network boot server
Patch ManagementLXCTracks and reports pending updates across all systems
IoT BuilderLXCESPHome firmware builds
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
Push NotificationsLXCSelf-hosted push notifications
Network MonitorLXCNetwork device tracking and new device detection

Network(because the lab doesn't stop at the hypervisor)

Managed via a UniFi stack — everything named after Lord of the Rings characters because of course it is.

DeviceModelRole
GandalfUDM ProGateway / firewall — WireGuard VPN, SFP+ uplink to core switch
GimliUSW Pro Max 24 PoECore switch — 10GbE SFP+ backbone, SFP+ uplinks to gateway and NVR
DwalinUSW Flex 2.5G 52.5G distribution switch
DainUSW Lite 8 PoEAccess switch
BalinUSW Pro Max 16 PoEDistribution switch
Legolas / Galadriel / HaldirU6 Pro ×3Wi-Fi APs
SauronUNVRNetwork video recorder — SFP+ uplink to core switch
CategoryDetail
ProtectIP camera system — isolated on a dedicated camera VLAN
IoTSLZB-MR1u (PoE) — standalone Zigbee + Thread/Matter coordinator
VLANsDefault · IoT · Guest · VM · Camera
ClientsLarge number of devices spread across multiple VLANs

🖥️ Self-Hosted Services

The Docker server runs a 50+ container stack across three isolated networks — a main bridge, an outbound-only network, and a fully internal network with no external routing. All services sit behind Traefik (HTTP/3, dual internal/external entrypoints, Cloudflare wildcard TLS), with Authentik as the SSO layer and CrowdSec handling threat intelligence via both a Traefik bouncer and a Cloudflare Worker bouncer.

Media

  • Self-hosted media server with NVIDIA GPU passthrough for hardware transcoding
  • Automated media management and transcoding pipeline with multi-node remote transcoding
  • Request management, stats, and library maintenance tooling

Security & Access

  • Traefik — reverse proxy, HTTP/3, Cloudflare TLS

  • Authentik — SSO / OIDC provider for all services

  • CrowdSec — collaborative IPS feeding threat intelligence into both a Traefik bouncer and a Cloudflare Worker bouncer, so malicious traffic is blocked at the CDN edge before it reaches the network

  • Cloudflare — WAF rules, firewall policies, and proxied DNS layered on top of CrowdSec blocklists for defence-in-depth at the perimeter

  • Self-hosted password manager with SSO, YubiKey & Duo MFA

  • Docker Socket Proxy — restricted docker.sock proxy deployed across select fleet hosts, limiting containers to only the Docker API access they need

Productivity

Monitoring & Management

  • Grafana · Prometheus · Telegraf
  • Dozzle — Docker log aggregation across multiple hosts
  • Uptime Kuma — uptime monitoring running on an external VPS for genuine outside-in visibility
  • Netdata — real-time performance monitoring on all VMs
  • Monocker — container state alerts via Telegram
  • Speedtest Tracker
  • PatchMon — patch management across all systems, tracking and reporting pending updates
  • PiAlert — network device tracking and new device detection across VLANs

Backup & CI/CD


🔥 My Stats

GitHub Trophies

GitHub StatsTop Languages

GitHub Streak

Github activity graph

AI Code Time

🐱 My GitHub Data

📦 2.6 MB Used in GitHub's Storage

🏆 1,159 Contributions in the Year 2026

🚫 Not Opted to Hire

📜 46 Public Repositories

🔑 10 Private Repositories

I'm a Night 🦉

🌞 Morning 2516 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 09.01 % 🌆 Daytime 7290 commits ███████░░░░░░░░░░░░░░░░░░ 26.11 % 🌃 Evening 9652 commits █████████░░░░░░░░░░░░░░░░ 34.57 % 🌙 Night 8465 commits ████████░░░░░░░░░░░░░░░░░ 30.32 % 

📅 I'm Most Productive on Wednesday

Monday 4645 commits ████░░░░░░░░░░░░░░░░░░░░░ 16.64 % Tuesday 4910 commits ████░░░░░░░░░░░░░░░░░░░░░ 17.58 % Wednesday 5387 commits █████░░░░░░░░░░░░░░░░░░░░ 19.29 % Thursday 3574 commits ███░░░░░░░░░░░░░░░░░░░░░░ 12.80 % Friday 4086 commits ████░░░░░░░░░░░░░░░░░░░░░ 14.63 % Saturday 2876 commits ███░░░░░░░░░░░░░░░░░░░░░░ 10.30 % Sunday 2445 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 08.76 % 

📊 This Week I Spent My Time On

🕑︎ Time Zone: Europe/London
💬 Programming Languages: No Activity Tracked This Week
🔥 Editors: No Activity Tracked This Week
🐱‍💻 Projects: No Activity Tracked This Week
💻 Operating System: No Activity Tracked This Week

🤖 AI Coding This Week

No AI Coding Activity Tracked This Week

I Mostly Code in Shell

Shell 22 repos ██████████░░░░░░░░░░░░░░░ 39.29 % Python 8 repos ████░░░░░░░░░░░░░░░░░░░░░ 14.29 % HTML 4 repos ██░░░░░░░░░░░░░░░░░░░░░░░ 07.14 % JavaScript 3 repos █░░░░░░░░░░░░░░░░░░░░░░░░ 05.36 % HCL 1 repo ░░░░░░░░░░░░░░░░░░░░░░░░░ 01.79 % 

Last Updated on 04/09/2026 05:36:06 UTC

🎮 Steam playtime leaderboard

⚔️ Dota 2 🕘 2309 hrs 19 mins
🎮 HELLDIVERS™ 2 🕘 1195 hrs 47 mins
🎮 Creeper World 4 🕘 889 hrs 58 mins
🎮 Overwatch® 🕘 270 hrs 19 mins
🌏 Sid Meier's Civilization V 🕘 226 hrs 21 mins

✍️ Latest Wiki Posts :

✍️ Personal Websites :

Pinned Loading

  1. docker-rickrolldocker-rickrollPublic

    Dockerised Rick Roll

    Shell 57 16

  2. docker-borgmaticdocker-borgmaticPublic

    Container to automate Borgbackups (https://github.com/borgbackup) using Borgmatic (https://github.com/witten/borgmatic)

    Shell 47 8

  3. public_scriptspublic_scriptsPublic

    Scripts for the general public

    Shell 92 18

  4. cibuildwheelcibuildwheelPublic

    CIBuildWheel

    Shell 1

  5. docker-devenvdocker-devenvPublic

    Docker Dev Environments

    Shell 5 1

  6. docker-starwarsdocker-starwarsPublic

    Self hosted, self contained Docker image of the classic www.asciimation.co.nz/Blinkenlights ASCII Star Wars animation.

    HTML 17 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content
View modem7's full-sized avatar

Organizations

@borgmatic-collective

Block or report modem7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
modem7/README.md

Header

GitHub FollowersOmegaWikiBuy Me A CoffeeProfile Views


👨‍💻 About Me

  • 🔭 I’m a Platform Engineer focused on building and managing CI/CD pipelines, internal tooling, and scalable infrastructure. Day to day that means everything from writing automation to bench-testing hardware and making sure software gets from dev to production reliably. Currently that includes ROS 2 pipeline infrastructure in the subsea/marine robotics space — Linux packaging with bloom and debhelper, Aptly-managed package repositories with GPG signing and environment promotion, and Fast-DDS discovery server configuration for distributed development teams.

  • 🔧 I work across the full stack of infrastructure — containers, virtualisation (ESXi, Proxmox, vSphere), IaC (Ansible, Terraform, Packer), and GitOps — with a strong lean towards automating anything that shouldn’t be done by hand. Prior to my current role I was a Linux Sysadmin, so I’m just as comfortable racking servers and hardening systems as I am writing pipelines.

  • 👥 I collaborate closely with software and engineering teams, and have worked across vendors, procurement, and SoC teams to keep projects moving. Happy switching between writing technical docs on Confluence, reviewing pipelines, or configuring switches and firewalls depending on what the day calls for. I also integrate AI tooling (Claude, GitLab Duo, Microsoft Copilot) into engineering workflows — pipeline automation, code review assistance, documentation, changelog generation, and infrastructure work. A force multiplier, not a substitute for understanding what's actually going on.

  • 🌍 I've worked my way up through infrastructure roles across high-stakes sectors like defence, energy, transport, and telecoms — picking up everything from large-scale VDI environments to Linux systems engineering along the way. I'm also a fluent Brazilian Portuguese speaker, which has come in handy supporting global and multilingual teams throughout.

  • ⚡ Outside of work I run a two-node Proxmox cluster (Samwise + Frodo) with 20+ VMs and LXC containers, ZFS storage, a dedicated Proxmox Backup Server, and a self-hosted GitHub Actions runner that ties it all into real CI/CD pipelines. IaC VMs for Packer, Ansible, and Terraform are spun up on demand from cloud-init templates I build and maintain myself. Ansible is my go-to for automating it all — I've also picked up both the Ansible Essential and Advanced Playbooks certifications to back that up.

  • 🧟 For nearly a decade I helped organise World Zombie Day — a global charity event that raised money for food banks through city-wide zombie walks. Coordinating sponsors, volunteers, routes, and day-of logistics across London, UK was genuinely great experience, and a lot of fun.

  • 🧑‍🤝‍🧑 I'm active in the open source community — opening PRs, contributing commits, reviewing code, and raising issues and bug reports across projects I use and care about. Not just a consumer.

  • ✍️ I write up what I learn over on OmegaWiki — mostly Linux, Docker, and homelab guides.

  • 📫 Reach me:LinkedIn


🛠️ Languages and Tools

Operating Systems

Shell

Editors
Containers & CI/CD

Robotics

Virtualisation

Source Control
Hardware & Other

Enterprise Systems

Project Management

AI Tooling

🚀 Featured Projects

ProjectDescriptionStars
public_scriptsA collection of practical scripts covering Proxmox automation, Docker management, server administration, and media processing — built for real use and shared publicly with sensitive values scrubbedStars
docker-borgmatic(co-maintainer)Multiarch Docker container packaging Borg, Borgmatic, and Apprise for automated backup orchestration with container stop/start hook support — part of the official borgmatic-collective. 7.2M+ pulls on Docker HubStars
docker-borgmatic(personal fork)Self-maintained fork of the above with custom builds and personal modifications running on S6 Overlay, supporting amd64 and arm64Stars
cibuildwheelCI pipeline that builds Python wheels for packages missing from PyPI, used to supply dependencies for the docker-borgmatic image — packages published to CloudsmithStars
crowdsec-troubleshooterUnprivileged, run-once Docker tool for diagnosing CrowdSec + Traefik setups — a wellness check, an IP block checker, and an optional live "does blocking actually work" test. No daemon, no docker.sock, no host networking, no capabilities requiredStars
docker-rickrollDockerised Rick RollStars

🏠 Home Lab

Two-node Proxmox cluster backed by a dedicated Proxmox Backup Server, ZFS on both nodes, and an Unraid NAS for secondary storage. The PBS doubles as a QDevice — third vote in the quorum, keeping the cluster clean in a node failure without split-brain.

Everything is managed as code. Cloud-init templates are built with a custom script (multi-backend storage detection, SHA256 image verification, reusable config profiles) and kept current by a template update pipeline that patches source VMs concurrently via QEMU Guest Agent, handles reboots, then clones and converts to templates automatically.

Network infrastructure managed with Terraform, services provisioned with Ansible.

Storage, by the drive count: 19 physical disks spread across the cluster, backup server, and NAS — 4 NVMe, 11 SATA SSD, 4 HDD.

Samwise(primary — 20c / 256GB / ~1TB ZFS | IPMI for out-of-band management)

ServiceTypeRole
DNS + NTP (primary)VMPihole + Unbound — full recursive DNS with DNSSEC validation, qname minimisation, DNS rebinding protection, and rate limiting. No upstream DNS dependency. Chrony NTP. HA primary — adlists synced to replica via Nebula-Sync
Home AutomationVMHome automation
Cloud StorageVMSelf-hosted cloud storage
Docker ServerVM50+ container Docker stack — media, productivity, security, and monitoring
NASVMNetwork attached storage
IaC ServerVMAnsible / Packer / Terraform (on-demand)
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
CI/CD RunnerLXCSelf-hosted GitHub Actions runner
Claude CodeVMSelf-hosted agent environment for AI-assisted infra work

Frodo(secondary — 4c / 32GB / ~100GB ZFS)

ServiceTypeRole
DNS + NTP (replica)VMPihole + Unbound + Chrony NTP — HA replica, gravity and adlists synced from primary
Transcoding NodeVMAutomated media transcoding
APT CacheLXCLocal APT package cache
BastionLXCSSH jump host
NetbootLXCPXE / network boot server
Patch ManagementLXCTracks and reports pending updates across all systems
IoT BuilderLXCESPHome firmware builds
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
Push NotificationsLXCSelf-hosted push notifications
Network MonitorLXCNetwork device tracking and new device detection

Network(because the lab doesn't stop at the hypervisor)

Managed via a UniFi stack — everything named after Lord of the Rings characters because of course it is.

DeviceModelRole
GandalfUDM ProGateway / firewall — WireGuard VPN, SFP+ uplink to core switch
GimliUSW Pro Max 24 PoECore switch — 10GbE SFP+ backbone, SFP+ uplinks to gateway and NVR
DwalinUSW Flex 2.5G 52.5G distribution switch
DainUSW Lite 8 PoEAccess switch
BalinUSW Pro Max 16 PoEDistribution switch
Legolas / Galadriel / HaldirU6 Pro ×3Wi-Fi APs
SauronUNVRNetwork video recorder — SFP+ uplink to core switch
CategoryDetail
ProtectIP camera system — isolated on a dedicated camera VLAN
IoTSLZB-MR1u (PoE) — standalone Zigbee + Thread/Matter coordinator
VLANsDefault · IoT · Guest · VM · Camera
ClientsLarge number of devices spread across multiple VLANs

🖥️ Self-Hosted Services

The Docker server runs a 50+ container stack across three isolated networks — a main bridge, an outbound-only network, and a fully internal network with no external routing. All services sit behind Traefik (HTTP/3, dual internal/external entrypoints, Cloudflare wildcard TLS), with Authentik as the SSO layer and CrowdSec handling threat intelligence via both a Traefik bouncer and a Cloudflare Worker bouncer.

Media

  • Self-hosted media server with NVIDIA GPU passthrough for hardware transcoding
  • Automated media management and transcoding pipeline with multi-node remote transcoding
  • Request management, stats, and library maintenance tooling

Security & Access

  • Traefik — reverse proxy, HTTP/3, Cloudflare TLS

  • Authentik — SSO / OIDC provider for all services

  • CrowdSec — collaborative IPS feeding threat intelligence into both a Traefik bouncer and a Cloudflare Worker bouncer, so malicious traffic is blocked at the CDN edge before it reaches the network

  • Cloudflare — WAF rules, firewall policies, and proxied DNS layered on top of CrowdSec blocklists for defence-in-depth at the perimeter

  • Self-hosted password manager with SSO, YubiKey & Duo MFA

  • Docker Socket Proxy — restricted docker.sock proxy deployed across select fleet hosts, limiting containers to only the Docker API access they need

Productivity

Monitoring & Management

  • Grafana · Prometheus · Telegraf
  • Dozzle — Docker log aggregation across multiple hosts
  • Uptime Kuma — uptime monitoring running on an external VPS for genuine outside-in visibility
  • Netdata — real-time performance monitoring on all VMs
  • Monocker — container state alerts via Telegram
  • Speedtest Tracker
  • PatchMon — patch management across all systems, tracking and reporting pending updates
  • PiAlert — network device tracking and new device detection across VLANs

Backup & CI/CD


🔥 My Stats

GitHub Trophies

GitHub StatsTop Languages

GitHub Streak

Github activity graph

AI Code Time

🐱 My GitHub Data

📦 2.6 MB Used in GitHub's Storage

🏆 1,159 Contributions in the Year 2026

🚫 Not Opted to Hire

📜 46 Public Repositories

🔑 10 Private Repositories

I'm a Night 🦉

🌞 Morning 2516 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 09.01 % 🌆 Daytime 7290 commits ███████░░░░░░░░░░░░░░░░░░ 26.11 % 🌃 Evening 9652 commits █████████░░░░░░░░░░░░░░░░ 34.57 % 🌙 Night 8465 commits ████████░░░░░░░░░░░░░░░░░ 30.32 % 

📅 I'm Most Productive on Wednesday

Monday 4645 commits ████░░░░░░░░░░░░░░░░░░░░░ 16.64 % Tuesday 4910 commits ████░░░░░░░░░░░░░░░░░░░░░ 17.58 % Wednesday 5387 commits █████░░░░░░░░░░░░░░░░░░░░ 19.29 % Thursday 3574 commits ███░░░░░░░░░░░░░░░░░░░░░░ 12.80 % Friday 4086 commits ████░░░░░░░░░░░░░░░░░░░░░ 14.63 % Saturday 2876 commits ███░░░░░░░░░░░░░░░░░░░░░░ 10.30 % Sunday 2445 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 08.76 % 

📊 This Week I Spent My Time On

🕑︎ Time Zone: Europe/London
💬 Programming Languages: No Activity Tracked This Week
🔥 Editors: No Activity Tracked This Week
🐱‍💻 Projects: No Activity Tracked This Week
💻 Operating System: No Activity Tracked This Week

🤖 AI Coding This Week

No AI Coding Activity Tracked This Week

I Mostly Code in Shell

Shell 22 repos ██████████░░░░░░░░░░░░░░░ 39.29 % Python 8 repos ████░░░░░░░░░░░░░░░░░░░░░ 14.29 % HTML 4 repos ██░░░░░░░░░░░░░░░░░░░░░░░ 07.14 % JavaScript 3 repos █░░░░░░░░░░░░░░░░░░░░░░░░ 05.36 % HCL 1 repo ░░░░░░░░░░░░░░░░░░░░░░░░░ 01.79 % 

Last Updated on 04/09/2026 05:36:06 UTC

🎮 Steam playtime leaderboard

⚔️ Dota 2 🕘 2309 hrs 19 mins
🎮 HELLDIVERS™ 2 🕘 1195 hrs 47 mins
🎮 Creeper World 4 🕘 889 hrs 58 mins
🎮 Overwatch® 🕘 270 hrs 19 mins
🌏 Sid Meier's Civilization V 🕘 226 hrs 21 mins

✍️ Latest Wiki Posts :

✍️ Personal Websites :

Pinned Loading

  1. docker-rickrolldocker-rickrollPublic

    Dockerised Rick Roll

    Shell 57 16

  2. docker-borgmaticdocker-borgmaticPublic

    Container to automate Borgbackups (https://github.com/borgbackup) using Borgmatic (https://github.com/witten/borgmatic)

    Shell 47 8

  3. public_scriptspublic_scriptsPublic

    Scripts for the general public

    Shell 92 18

  4. cibuildwheelcibuildwheelPublic

    CIBuildWheel

    Shell 1

  5. docker-devenvdocker-devenvPublic

    Docker Dev Environments

    Shell 5 1

  6. docker-starwarsdocker-starwarsPublic

    Self hosted, self contained Docker image of the classic www.asciimation.co.nz/Blinkenlights ASCII Star Wars animation.

    HTML 17 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View modem7's full-sized avatar

Organizations

@borgmatic-collective

Block or report modem7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
modem7/README.md

Header

GitHub FollowersOmegaWikiBuy Me A CoffeeProfile Views


👨‍💻 About Me

  • 🔭 I’m a Platform Engineer focused on building and managing CI/CD pipelines, internal tooling, and scalable infrastructure. Day to day that means everything from writing automation to bench-testing hardware and making sure software gets from dev to production reliably. Currently that includes ROS 2 pipeline infrastructure in the subsea/marine robotics space — Linux packaging with bloom and debhelper, Aptly-managed package repositories with GPG signing and environment promotion, and Fast-DDS discovery server configuration for distributed development teams.

  • 🔧 I work across the full stack of infrastructure — containers, virtualisation (ESXi, Proxmox, vSphere), IaC (Ansible, Terraform, Packer), and GitOps — with a strong lean towards automating anything that shouldn’t be done by hand. Prior to my current role I was a Linux Sysadmin, so I’m just as comfortable racking servers and hardening systems as I am writing pipelines.

  • 👥 I collaborate closely with software and engineering teams, and have worked across vendors, procurement, and SoC teams to keep projects moving. Happy switching between writing technical docs on Confluence, reviewing pipelines, or configuring switches and firewalls depending on what the day calls for. I also integrate AI tooling (Claude, GitLab Duo, Microsoft Copilot) into engineering workflows — pipeline automation, code review assistance, documentation, changelog generation, and infrastructure work. A force multiplier, not a substitute for understanding what's actually going on.

  • 🌍 I've worked my way up through infrastructure roles across high-stakes sectors like defence, energy, transport, and telecoms — picking up everything from large-scale VDI environments to Linux systems engineering along the way. I'm also a fluent Brazilian Portuguese speaker, which has come in handy supporting global and multilingual teams throughout.

  • ⚡ Outside of work I run a two-node Proxmox cluster (Samwise + Frodo) with 20+ VMs and LXC containers, ZFS storage, a dedicated Proxmox Backup Server, and a self-hosted GitHub Actions runner that ties it all into real CI/CD pipelines. IaC VMs for Packer, Ansible, and Terraform are spun up on demand from cloud-init templates I build and maintain myself. Ansible is my go-to for automating it all — I've also picked up both the Ansible Essential and Advanced Playbooks certifications to back that up.

  • 🧟 For nearly a decade I helped organise World Zombie Day — a global charity event that raised money for food banks through city-wide zombie walks. Coordinating sponsors, volunteers, routes, and day-of logistics across London, UK was genuinely great experience, and a lot of fun.

  • 🧑‍🤝‍🧑 I'm active in the open source community — opening PRs, contributing commits, reviewing code, and raising issues and bug reports across projects I use and care about. Not just a consumer.

  • ✍️ I write up what I learn over on OmegaWiki — mostly Linux, Docker, and homelab guides.

  • 📫 Reach me:LinkedIn


🛠️ Languages and Tools

Operating Systems

Shell

Editors
Containers & CI/CD

Robotics

Virtualisation

Source Control
Hardware & Other

Enterprise Systems

Project Management

AI Tooling

🚀 Featured Projects

ProjectDescriptionStars
public_scriptsA collection of practical scripts covering Proxmox automation, Docker management, server administration, and media processing — built for real use and shared publicly with sensitive values scrubbedStars
docker-borgmatic(co-maintainer)Multiarch Docker container packaging Borg, Borgmatic, and Apprise for automated backup orchestration with container stop/start hook support — part of the official borgmatic-collective. 7.2M+ pulls on Docker HubStars
docker-borgmatic(personal fork)Self-maintained fork of the above with custom builds and personal modifications running on S6 Overlay, supporting amd64 and arm64Stars
cibuildwheelCI pipeline that builds Python wheels for packages missing from PyPI, used to supply dependencies for the docker-borgmatic image — packages published to CloudsmithStars
crowdsec-troubleshooterUnprivileged, run-once Docker tool for diagnosing CrowdSec + Traefik setups — a wellness check, an IP block checker, and an optional live "does blocking actually work" test. No daemon, no docker.sock, no host networking, no capabilities requiredStars
docker-rickrollDockerised Rick RollStars

🏠 Home Lab

Two-node Proxmox cluster backed by a dedicated Proxmox Backup Server, ZFS on both nodes, and an Unraid NAS for secondary storage. The PBS doubles as a QDevice — third vote in the quorum, keeping the cluster clean in a node failure without split-brain.

Everything is managed as code. Cloud-init templates are built with a custom script (multi-backend storage detection, SHA256 image verification, reusable config profiles) and kept current by a template update pipeline that patches source VMs concurrently via QEMU Guest Agent, handles reboots, then clones and converts to templates automatically.

Network infrastructure managed with Terraform, services provisioned with Ansible.

Storage, by the drive count: 19 physical disks spread across the cluster, backup server, and NAS — 4 NVMe, 11 SATA SSD, 4 HDD.

Samwise(primary — 20c / 256GB / ~1TB ZFS | IPMI for out-of-band management)

ServiceTypeRole
DNS + NTP (primary)VMPihole + Unbound — full recursive DNS with DNSSEC validation, qname minimisation, DNS rebinding protection, and rate limiting. No upstream DNS dependency. Chrony NTP. HA primary — adlists synced to replica via Nebula-Sync
Home AutomationVMHome automation
Cloud StorageVMSelf-hosted cloud storage
Docker ServerVM50+ container Docker stack — media, productivity, security, and monitoring
NASVMNetwork attached storage
IaC ServerVMAnsible / Packer / Terraform (on-demand)
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
CI/CD RunnerLXCSelf-hosted GitHub Actions runner
Claude CodeVMSelf-hosted agent environment for AI-assisted infra work

Frodo(secondary — 4c / 32GB / ~100GB ZFS)

ServiceTypeRole
DNS + NTP (replica)VMPihole + Unbound + Chrony NTP — HA replica, gravity and adlists synced from primary
Transcoding NodeVMAutomated media transcoding
APT CacheLXCLocal APT package cache
BastionLXCSSH jump host
NetbootLXCPXE / network boot server
Patch ManagementLXCTracks and reports pending updates across all systems
IoT BuilderLXCESPHome firmware builds
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
Push NotificationsLXCSelf-hosted push notifications
Network MonitorLXCNetwork device tracking and new device detection

Network(because the lab doesn't stop at the hypervisor)

Managed via a UniFi stack — everything named after Lord of the Rings characters because of course it is.

DeviceModelRole
GandalfUDM ProGateway / firewall — WireGuard VPN, SFP+ uplink to core switch
GimliUSW Pro Max 24 PoECore switch — 10GbE SFP+ backbone, SFP+ uplinks to gateway and NVR
DwalinUSW Flex 2.5G 52.5G distribution switch
DainUSW Lite 8 PoEAccess switch
BalinUSW Pro Max 16 PoEDistribution switch
Legolas / Galadriel / HaldirU6 Pro ×3Wi-Fi APs
SauronUNVRNetwork video recorder — SFP+ uplink to core switch
CategoryDetail
ProtectIP camera system — isolated on a dedicated camera VLAN
IoTSLZB-MR1u (PoE) — standalone Zigbee + Thread/Matter coordinator
VLANsDefault · IoT · Guest · VM · Camera
ClientsLarge number of devices spread across multiple VLANs

🖥️ Self-Hosted Services

The Docker server runs a 50+ container stack across three isolated networks — a main bridge, an outbound-only network, and a fully internal network with no external routing. All services sit behind Traefik (HTTP/3, dual internal/external entrypoints, Cloudflare wildcard TLS), with Authentik as the SSO layer and CrowdSec handling threat intelligence via both a Traefik bouncer and a Cloudflare Worker bouncer.

Media

  • Self-hosted media server with NVIDIA GPU passthrough for hardware transcoding
  • Automated media management and transcoding pipeline with multi-node remote transcoding
  • Request management, stats, and library maintenance tooling

Security & Access

  • Traefik — reverse proxy, HTTP/3, Cloudflare TLS

  • Authentik — SSO / OIDC provider for all services

  • CrowdSec — collaborative IPS feeding threat intelligence into both a Traefik bouncer and a Cloudflare Worker bouncer, so malicious traffic is blocked at the CDN edge before it reaches the network

  • Cloudflare — WAF rules, firewall policies, and proxied DNS layered on top of CrowdSec blocklists for defence-in-depth at the perimeter

  • Self-hosted password manager with SSO, YubiKey & Duo MFA

  • Docker Socket Proxy — restricted docker.sock proxy deployed across select fleet hosts, limiting containers to only the Docker API access they need

Productivity

Monitoring & Management

  • Grafana · Prometheus · Telegraf
  • Dozzle — Docker log aggregation across multiple hosts
  • Uptime Kuma — uptime monitoring running on an external VPS for genuine outside-in visibility
  • Netdata — real-time performance monitoring on all VMs
  • Monocker — container state alerts via Telegram
  • Speedtest Tracker
  • PatchMon — patch management across all systems, tracking and reporting pending updates
  • PiAlert — network device tracking and new device detection across VLANs

Backup & CI/CD


🔥 My Stats

GitHub Trophies

GitHub StatsTop Languages

GitHub Streak

Github activity graph

AI Code Time

🐱 My GitHub Data

📦 2.6 MB Used in GitHub's Storage

🏆 1,159 Contributions in the Year 2026

🚫 Not Opted to Hire

📜 46 Public Repositories

🔑 10 Private Repositories

I'm a Night 🦉

🌞 Morning 2516 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 09.01 % 🌆 Daytime 7290 commits ███████░░░░░░░░░░░░░░░░░░ 26.11 % 🌃 Evening 9652 commits █████████░░░░░░░░░░░░░░░░ 34.57 % 🌙 Night 8465 commits ████████░░░░░░░░░░░░░░░░░ 30.32 % 

📅 I'm Most Productive on Wednesday

Monday 4645 commits ████░░░░░░░░░░░░░░░░░░░░░ 16.64 % Tuesday 4910 commits ████░░░░░░░░░░░░░░░░░░░░░ 17.58 % Wednesday 5387 commits █████░░░░░░░░░░░░░░░░░░░░ 19.29 % Thursday 3574 commits ███░░░░░░░░░░░░░░░░░░░░░░ 12.80 % Friday 4086 commits ████░░░░░░░░░░░░░░░░░░░░░ 14.63 % Saturday 2876 commits ███░░░░░░░░░░░░░░░░░░░░░░ 10.30 % Sunday 2445 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 08.76 % 

📊 This Week I Spent My Time On

🕑︎ Time Zone: Europe/London
💬 Programming Languages: No Activity Tracked This Week
🔥 Editors: No Activity Tracked This Week
🐱‍💻 Projects: No Activity Tracked This Week
💻 Operating System: No Activity Tracked This Week

🤖 AI Coding This Week

No AI Coding Activity Tracked This Week

I Mostly Code in Shell

Shell 22 repos ██████████░░░░░░░░░░░░░░░ 39.29 % Python 8 repos ████░░░░░░░░░░░░░░░░░░░░░ 14.29 % HTML 4 repos ██░░░░░░░░░░░░░░░░░░░░░░░ 07.14 % JavaScript 3 repos █░░░░░░░░░░░░░░░░░░░░░░░░ 05.36 % HCL 1 repo ░░░░░░░░░░░░░░░░░░░░░░░░░ 01.79 % 

Last Updated on 04/09/2026 05:36:06 UTC

🎮 Steam playtime leaderboard

⚔️ Dota 2 🕘 2309 hrs 19 mins
🎮 HELLDIVERS™ 2 🕘 1195 hrs 47 mins
🎮 Creeper World 4 🕘 889 hrs 58 mins
🎮 Overwatch® 🕘 270 hrs 19 mins
🌏 Sid Meier's Civilization V 🕘 226 hrs 21 mins

✍️ Latest Wiki Posts :

✍️ Personal Websites :

Pinned Loading

  1. docker-rickrolldocker-rickrollPublic

    Dockerised Rick Roll

    Shell 57 16

  2. docker-borgmaticdocker-borgmaticPublic

    Container to automate Borgbackups (https://github.com/borgbackup) using Borgmatic (https://github.com/witten/borgmatic)

    Shell 47 8

  3. public_scriptspublic_scriptsPublic

    Scripts for the general public

    Shell 92 18

  4. cibuildwheelcibuildwheelPublic

    CIBuildWheel

    Shell 1

  5. docker-devenvdocker-devenvPublic

    Docker Dev Environments

    Shell 5 1

  6. docker-starwarsdocker-starwarsPublic

    Self hosted, self contained Docker image of the classic www.asciimation.co.nz/Blinkenlights ASCII Star Wars animation.

    HTML 17 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content
View modem7's full-sized avatar

Organizations

@borgmatic-collective

Block or report modem7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
modem7/README.md

Header

GitHub FollowersOmegaWikiBuy Me A CoffeeProfile Views


👨‍💻 About Me

  • 🔭 I’m a Platform Engineer focused on building and managing CI/CD pipelines, internal tooling, and scalable infrastructure. Day to day that means everything from writing automation to bench-testing hardware and making sure software gets from dev to production reliably. Currently that includes ROS 2 pipeline infrastructure in the subsea/marine robotics space — Linux packaging with bloom and debhelper, Aptly-managed package repositories with GPG signing and environment promotion, and Fast-DDS discovery server configuration for distributed development teams.

  • 🔧 I work across the full stack of infrastructure — containers, virtualisation (ESXi, Proxmox, vSphere), IaC (Ansible, Terraform, Packer), and GitOps — with a strong lean towards automating anything that shouldn’t be done by hand. Prior to my current role I was a Linux Sysadmin, so I’m just as comfortable racking servers and hardening systems as I am writing pipelines.

  • 👥 I collaborate closely with software and engineering teams, and have worked across vendors, procurement, and SoC teams to keep projects moving. Happy switching between writing technical docs on Confluence, reviewing pipelines, or configuring switches and firewalls depending on what the day calls for. I also integrate AI tooling (Claude, GitLab Duo, Microsoft Copilot) into engineering workflows — pipeline automation, code review assistance, documentation, changelog generation, and infrastructure work. A force multiplier, not a substitute for understanding what's actually going on.

  • 🌍 I've worked my way up through infrastructure roles across high-stakes sectors like defence, energy, transport, and telecoms — picking up everything from large-scale VDI environments to Linux systems engineering along the way. I'm also a fluent Brazilian Portuguese speaker, which has come in handy supporting global and multilingual teams throughout.

  • ⚡ Outside of work I run a two-node Proxmox cluster (Samwise + Frodo) with 20+ VMs and LXC containers, ZFS storage, a dedicated Proxmox Backup Server, and a self-hosted GitHub Actions runner that ties it all into real CI/CD pipelines. IaC VMs for Packer, Ansible, and Terraform are spun up on demand from cloud-init templates I build and maintain myself. Ansible is my go-to for automating it all — I've also picked up both the Ansible Essential and Advanced Playbooks certifications to back that up.

  • 🧟 For nearly a decade I helped organise World Zombie Day — a global charity event that raised money for food banks through city-wide zombie walks. Coordinating sponsors, volunteers, routes, and day-of logistics across London, UK was genuinely great experience, and a lot of fun.

  • 🧑‍🤝‍🧑 I'm active in the open source community — opening PRs, contributing commits, reviewing code, and raising issues and bug reports across projects I use and care about. Not just a consumer.

  • ✍️ I write up what I learn over on OmegaWiki — mostly Linux, Docker, and homelab guides.

  • 📫 Reach me:LinkedIn


🛠️ Languages and Tools

Operating Systems

Shell

Editors
Containers & CI/CD

Robotics

Virtualisation

Source Control
Hardware & Other

Enterprise Systems

Project Management

AI Tooling

🚀 Featured Projects

ProjectDescriptionStars
public_scriptsA collection of practical scripts covering Proxmox automation, Docker management, server administration, and media processing — built for real use and shared publicly with sensitive values scrubbedStars
docker-borgmatic(co-maintainer)Multiarch Docker container packaging Borg, Borgmatic, and Apprise for automated backup orchestration with container stop/start hook support — part of the official borgmatic-collective. 7.2M+ pulls on Docker HubStars
docker-borgmatic(personal fork)Self-maintained fork of the above with custom builds and personal modifications running on S6 Overlay, supporting amd64 and arm64Stars
cibuildwheelCI pipeline that builds Python wheels for packages missing from PyPI, used to supply dependencies for the docker-borgmatic image — packages published to CloudsmithStars
crowdsec-troubleshooterUnprivileged, run-once Docker tool for diagnosing CrowdSec + Traefik setups — a wellness check, an IP block checker, and an optional live "does blocking actually work" test. No daemon, no docker.sock, no host networking, no capabilities requiredStars
docker-rickrollDockerised Rick RollStars

🏠 Home Lab

Two-node Proxmox cluster backed by a dedicated Proxmox Backup Server, ZFS on both nodes, and an Unraid NAS for secondary storage. The PBS doubles as a QDevice — third vote in the quorum, keeping the cluster clean in a node failure without split-brain.

Everything is managed as code. Cloud-init templates are built with a custom script (multi-backend storage detection, SHA256 image verification, reusable config profiles) and kept current by a template update pipeline that patches source VMs concurrently via QEMU Guest Agent, handles reboots, then clones and converts to templates automatically.

Network infrastructure managed with Terraform, services provisioned with Ansible.

Storage, by the drive count: 19 physical disks spread across the cluster, backup server, and NAS — 4 NVMe, 11 SATA SSD, 4 HDD.

Samwise(primary — 20c / 256GB / ~1TB ZFS | IPMI for out-of-band management)

ServiceTypeRole
DNS + NTP (primary)VMPihole + Unbound — full recursive DNS with DNSSEC validation, qname minimisation, DNS rebinding protection, and rate limiting. No upstream DNS dependency. Chrony NTP. HA primary — adlists synced to replica via Nebula-Sync
Home AutomationVMHome automation
Cloud StorageVMSelf-hosted cloud storage
Docker ServerVM50+ container Docker stack — media, productivity, security, and monitoring
NASVMNetwork attached storage
IaC ServerVMAnsible / Packer / Terraform (on-demand)
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
CI/CD RunnerLXCSelf-hosted GitHub Actions runner
Claude CodeVMSelf-hosted agent environment for AI-assisted infra work

Frodo(secondary — 4c / 32GB / ~100GB ZFS)

ServiceTypeRole
DNS + NTP (replica)VMPihole + Unbound + Chrony NTP — HA replica, gravity and adlists synced from primary
Transcoding NodeVMAutomated media transcoding
APT CacheLXCLocal APT package cache
BastionLXCSSH jump host
NetbootLXCPXE / network boot server
Patch ManagementLXCTracks and reports pending updates across all systems
IoT BuilderLXCESPHome firmware builds
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
Push NotificationsLXCSelf-hosted push notifications
Network MonitorLXCNetwork device tracking and new device detection

Network(because the lab doesn't stop at the hypervisor)

Managed via a UniFi stack — everything named after Lord of the Rings characters because of course it is.

DeviceModelRole
GandalfUDM ProGateway / firewall — WireGuard VPN, SFP+ uplink to core switch
GimliUSW Pro Max 24 PoECore switch — 10GbE SFP+ backbone, SFP+ uplinks to gateway and NVR
DwalinUSW Flex 2.5G 52.5G distribution switch
DainUSW Lite 8 PoEAccess switch
BalinUSW Pro Max 16 PoEDistribution switch
Legolas / Galadriel / HaldirU6 Pro ×3Wi-Fi APs
SauronUNVRNetwork video recorder — SFP+ uplink to core switch
CategoryDetail
ProtectIP camera system — isolated on a dedicated camera VLAN
IoTSLZB-MR1u (PoE) — standalone Zigbee + Thread/Matter coordinator
VLANsDefault · IoT · Guest · VM · Camera
ClientsLarge number of devices spread across multiple VLANs

🖥️ Self-Hosted Services

The Docker server runs a 50+ container stack across three isolated networks — a main bridge, an outbound-only network, and a fully internal network with no external routing. All services sit behind Traefik (HTTP/3, dual internal/external entrypoints, Cloudflare wildcard TLS), with Authentik as the SSO layer and CrowdSec handling threat intelligence via both a Traefik bouncer and a Cloudflare Worker bouncer.

Media

  • Self-hosted media server with NVIDIA GPU passthrough for hardware transcoding
  • Automated media management and transcoding pipeline with multi-node remote transcoding
  • Request management, stats, and library maintenance tooling

Security & Access

  • Traefik — reverse proxy, HTTP/3, Cloudflare TLS

  • Authentik — SSO / OIDC provider for all services

  • CrowdSec — collaborative IPS feeding threat intelligence into both a Traefik bouncer and a Cloudflare Worker bouncer, so malicious traffic is blocked at the CDN edge before it reaches the network

  • Cloudflare — WAF rules, firewall policies, and proxied DNS layered on top of CrowdSec blocklists for defence-in-depth at the perimeter

  • Self-hosted password manager with SSO, YubiKey & Duo MFA

  • Docker Socket Proxy — restricted docker.sock proxy deployed across select fleet hosts, limiting containers to only the Docker API access they need

Productivity

Monitoring & Management

  • Grafana · Prometheus · Telegraf
  • Dozzle — Docker log aggregation across multiple hosts
  • Uptime Kuma — uptime monitoring running on an external VPS for genuine outside-in visibility
  • Netdata — real-time performance monitoring on all VMs
  • Monocker — container state alerts via Telegram
  • Speedtest Tracker
  • PatchMon — patch management across all systems, tracking and reporting pending updates
  • PiAlert — network device tracking and new device detection across VLANs

Backup & CI/CD


🔥 My Stats

GitHub Trophies

GitHub StatsTop Languages

GitHub Streak

Github activity graph

AI Code Time

🐱 My GitHub Data

📦 2.6 MB Used in GitHub's Storage

🏆 1,159 Contributions in the Year 2026

🚫 Not Opted to Hire

📜 46 Public Repositories

🔑 10 Private Repositories

I'm a Night 🦉

🌞 Morning 2516 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 09.01 % 🌆 Daytime 7290 commits ███████░░░░░░░░░░░░░░░░░░ 26.11 % 🌃 Evening 9652 commits █████████░░░░░░░░░░░░░░░░ 34.57 % 🌙 Night 8465 commits ████████░░░░░░░░░░░░░░░░░ 30.32 % 

📅 I'm Most Productive on Wednesday

Monday 4645 commits ████░░░░░░░░░░░░░░░░░░░░░ 16.64 % Tuesday 4910 commits ████░░░░░░░░░░░░░░░░░░░░░ 17.58 % Wednesday 5387 commits █████░░░░░░░░░░░░░░░░░░░░ 19.29 % Thursday 3574 commits ███░░░░░░░░░░░░░░░░░░░░░░ 12.80 % Friday 4086 commits ████░░░░░░░░░░░░░░░░░░░░░ 14.63 % Saturday 2876 commits ███░░░░░░░░░░░░░░░░░░░░░░ 10.30 % Sunday 2445 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 08.76 % 

📊 This Week I Spent My Time On

🕑︎ Time Zone: Europe/London
💬 Programming Languages: No Activity Tracked This Week
🔥 Editors: No Activity Tracked This Week
🐱‍💻 Projects: No Activity Tracked This Week
💻 Operating System: No Activity Tracked This Week

🤖 AI Coding This Week

No AI Coding Activity Tracked This Week

I Mostly Code in Shell

Shell 22 repos ██████████░░░░░░░░░░░░░░░ 39.29 % Python 8 repos ████░░░░░░░░░░░░░░░░░░░░░ 14.29 % HTML 4 repos ██░░░░░░░░░░░░░░░░░░░░░░░ 07.14 % JavaScript 3 repos █░░░░░░░░░░░░░░░░░░░░░░░░ 05.36 % HCL 1 repo ░░░░░░░░░░░░░░░░░░░░░░░░░ 01.79 % 

Last Updated on 04/09/2026 05:36:06 UTC

🎮 Steam playtime leaderboard

⚔️ Dota 2 🕘 2309 hrs 19 mins
🎮 HELLDIVERS™ 2 🕘 1195 hrs 47 mins
🎮 Creeper World 4 🕘 889 hrs 58 mins
🎮 Overwatch® 🕘 270 hrs 19 mins
🌏 Sid Meier's Civilization V 🕘 226 hrs 21 mins

✍️ Latest Wiki Posts :

✍️ Personal Websites :

Pinned Loading

  1. docker-rickrolldocker-rickrollPublic

    Dockerised Rick Roll

    Shell 57 16

  2. docker-borgmaticdocker-borgmaticPublic

    Container to automate Borgbackups (https://github.com/borgbackup) using Borgmatic (https://github.com/witten/borgmatic)

    Shell 47 8

  3. public_scriptspublic_scriptsPublic

    Scripts for the general public

    Shell 92 18

  4. cibuildwheelcibuildwheelPublic

    CIBuildWheel

    Shell 1

  5. docker-devenvdocker-devenvPublic

    Docker Dev Environments

    Shell 5 1

  6. docker-starwarsdocker-starwarsPublic

    Self hosted, self contained Docker image of the classic www.asciimation.co.nz/Blinkenlights ASCII Star Wars animation.

    HTML 17 1

, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content
View modem7's full-sized avatar

Organizations

@borgmatic-collective

Block or report modem7

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Content in all repositories owned by your account will be closed.
Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
modem7/README.md

Header

GitHub FollowersOmegaWikiBuy Me A CoffeeProfile Views


👨‍💻 About Me

  • 🔭 I’m a Platform Engineer focused on building and managing CI/CD pipelines, internal tooling, and scalable infrastructure. Day to day that means everything from writing automation to bench-testing hardware and making sure software gets from dev to production reliably. Currently that includes ROS 2 pipeline infrastructure in the subsea/marine robotics space — Linux packaging with bloom and debhelper, Aptly-managed package repositories with GPG signing and environment promotion, and Fast-DDS discovery server configuration for distributed development teams.

  • 🔧 I work across the full stack of infrastructure — containers, virtualisation (ESXi, Proxmox, vSphere), IaC (Ansible, Terraform, Packer), and GitOps — with a strong lean towards automating anything that shouldn’t be done by hand. Prior to my current role I was a Linux Sysadmin, so I’m just as comfortable racking servers and hardening systems as I am writing pipelines.

  • 👥 I collaborate closely with software and engineering teams, and have worked across vendors, procurement, and SoC teams to keep projects moving. Happy switching between writing technical docs on Confluence, reviewing pipelines, or configuring switches and firewalls depending on what the day calls for. I also integrate AI tooling (Claude, GitLab Duo, Microsoft Copilot) into engineering workflows — pipeline automation, code review assistance, documentation, changelog generation, and infrastructure work. A force multiplier, not a substitute for understanding what's actually going on.

  • 🌍 I've worked my way up through infrastructure roles across high-stakes sectors like defence, energy, transport, and telecoms — picking up everything from large-scale VDI environments to Linux systems engineering along the way. I'm also a fluent Brazilian Portuguese speaker, which has come in handy supporting global and multilingual teams throughout.

  • ⚡ Outside of work I run a two-node Proxmox cluster (Samwise + Frodo) with 20+ VMs and LXC containers, ZFS storage, a dedicated Proxmox Backup Server, and a self-hosted GitHub Actions runner that ties it all into real CI/CD pipelines. IaC VMs for Packer, Ansible, and Terraform are spun up on demand from cloud-init templates I build and maintain myself. Ansible is my go-to for automating it all — I've also picked up both the Ansible Essential and Advanced Playbooks certifications to back that up.

  • 🧟 For nearly a decade I helped organise World Zombie Day — a global charity event that raised money for food banks through city-wide zombie walks. Coordinating sponsors, volunteers, routes, and day-of logistics across London, UK was genuinely great experience, and a lot of fun.

  • 🧑‍🤝‍🧑 I'm active in the open source community — opening PRs, contributing commits, reviewing code, and raising issues and bug reports across projects I use and care about. Not just a consumer.

  • ✍️ I write up what I learn over on OmegaWiki — mostly Linux, Docker, and homelab guides.

  • 📫 Reach me:LinkedIn


🛠️ Languages and Tools

Operating Systems

Shell

Editors
Containers & CI/CD

Robotics

Virtualisation

Source Control
Hardware & Other

Enterprise Systems

Project Management

AI Tooling

🚀 Featured Projects

ProjectDescriptionStars
public_scriptsA collection of practical scripts covering Proxmox automation, Docker management, server administration, and media processing — built for real use and shared publicly with sensitive values scrubbedStars
docker-borgmatic(co-maintainer)Multiarch Docker container packaging Borg, Borgmatic, and Apprise for automated backup orchestration with container stop/start hook support — part of the official borgmatic-collective. 7.2M+ pulls on Docker HubStars
docker-borgmatic(personal fork)Self-maintained fork of the above with custom builds and personal modifications running on S6 Overlay, supporting amd64 and arm64Stars
cibuildwheelCI pipeline that builds Python wheels for packages missing from PyPI, used to supply dependencies for the docker-borgmatic image — packages published to CloudsmithStars
crowdsec-troubleshooterUnprivileged, run-once Docker tool for diagnosing CrowdSec + Traefik setups — a wellness check, an IP block checker, and an optional live "does blocking actually work" test. No daemon, no docker.sock, no host networking, no capabilities requiredStars
docker-rickrollDockerised Rick RollStars

🏠 Home Lab

Two-node Proxmox cluster backed by a dedicated Proxmox Backup Server, ZFS on both nodes, and an Unraid NAS for secondary storage. The PBS doubles as a QDevice — third vote in the quorum, keeping the cluster clean in a node failure without split-brain.

Everything is managed as code. Cloud-init templates are built with a custom script (multi-backend storage detection, SHA256 image verification, reusable config profiles) and kept current by a template update pipeline that patches source VMs concurrently via QEMU Guest Agent, handles reboots, then clones and converts to templates automatically.

Network infrastructure managed with Terraform, services provisioned with Ansible.

Storage, by the drive count: 19 physical disks spread across the cluster, backup server, and NAS — 4 NVMe, 11 SATA SSD, 4 HDD.

Samwise(primary — 20c / 256GB / ~1TB ZFS | IPMI for out-of-band management)

ServiceTypeRole
DNS + NTP (primary)VMPihole + Unbound — full recursive DNS with DNSSEC validation, qname minimisation, DNS rebinding protection, and rate limiting. No upstream DNS dependency. Chrony NTP. HA primary — adlists synced to replica via Nebula-Sync
Home AutomationVMHome automation
Cloud StorageVMSelf-hosted cloud storage
Docker ServerVM50+ container Docker stack — media, productivity, security, and monitoring
NASVMNetwork attached storage
IaC ServerVMAnsible / Packer / Terraform (on-demand)
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
CI/CD RunnerLXCSelf-hosted GitHub Actions runner
Claude CodeVMSelf-hosted agent environment for AI-assisted infra work

Frodo(secondary — 4c / 32GB / ~100GB ZFS)

ServiceTypeRole
DNS + NTP (replica)VMPihole + Unbound + Chrony NTP — HA replica, gravity and adlists synced from primary
Transcoding NodeVMAutomated media transcoding
APT CacheLXCLocal APT package cache
BastionLXCSSH jump host
NetbootLXCPXE / network boot server
Patch ManagementLXCTracks and reports pending updates across all systems
IoT BuilderLXCESPHome firmware builds
HA-ProxyLXCSNI-based TCP routing to Proxmox UI + SPICE console proxy
Push NotificationsLXCSelf-hosted push notifications
Network MonitorLXCNetwork device tracking and new device detection

Network(because the lab doesn't stop at the hypervisor)

Managed via a UniFi stack — everything named after Lord of the Rings characters because of course it is.

DeviceModelRole
GandalfUDM ProGateway / firewall — WireGuard VPN, SFP+ uplink to core switch
GimliUSW Pro Max 24 PoECore switch — 10GbE SFP+ backbone, SFP+ uplinks to gateway and NVR
DwalinUSW Flex 2.5G 52.5G distribution switch
DainUSW Lite 8 PoEAccess switch
BalinUSW Pro Max 16 PoEDistribution switch
Legolas / Galadriel / HaldirU6 Pro ×3Wi-Fi APs
SauronUNVRNetwork video recorder — SFP+ uplink to core switch
CategoryDetail
ProtectIP camera system — isolated on a dedicated camera VLAN
IoTSLZB-MR1u (PoE) — standalone Zigbee + Thread/Matter coordinator
VLANsDefault · IoT · Guest · VM · Camera
ClientsLarge number of devices spread across multiple VLANs

🖥️ Self-Hosted Services

The Docker server runs a 50+ container stack across three isolated networks — a main bridge, an outbound-only network, and a fully internal network with no external routing. All services sit behind Traefik (HTTP/3, dual internal/external entrypoints, Cloudflare wildcard TLS), with Authentik as the SSO layer and CrowdSec handling threat intelligence via both a Traefik bouncer and a Cloudflare Worker bouncer.

Media

  • Self-hosted media server with NVIDIA GPU passthrough for hardware transcoding
  • Automated media management and transcoding pipeline with multi-node remote transcoding
  • Request management, stats, and library maintenance tooling

Security & Access

  • Traefik — reverse proxy, HTTP/3, Cloudflare TLS

  • Authentik — SSO / OIDC provider for all services

  • CrowdSec — collaborative IPS feeding threat intelligence into both a Traefik bouncer and a Cloudflare Worker bouncer, so malicious traffic is blocked at the CDN edge before it reaches the network

  • Cloudflare — WAF rules, firewall policies, and proxied DNS layered on top of CrowdSec blocklists for defence-in-depth at the perimeter

  • Self-hosted password manager with SSO, YubiKey & Duo MFA

  • Docker Socket Proxy — restricted docker.sock proxy deployed across select fleet hosts, limiting containers to only the Docker API access they need

Productivity

Monitoring & Management

  • Grafana · Prometheus · Telegraf
  • Dozzle — Docker log aggregation across multiple hosts
  • Uptime Kuma — uptime monitoring running on an external VPS for genuine outside-in visibility
  • Netdata — real-time performance monitoring on all VMs
  • Monocker — container state alerts via Telegram
  • Speedtest Tracker
  • PatchMon — patch management across all systems, tracking and reporting pending updates
  • PiAlert — network device tracking and new device detection across VLANs

Backup & CI/CD


🔥 My Stats

GitHub Trophies

GitHub StatsTop Languages

GitHub Streak

Github activity graph

AI Code Time

🐱 My GitHub Data

📦 2.6 MB Used in GitHub's Storage

🏆 1,159 Contributions in the Year 2026

🚫 Not Opted to Hire

📜 46 Public Repositories

🔑 10 Private Repositories

I'm a Night 🦉

🌞 Morning 2516 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 09.01 % 🌆 Daytime 7290 commits ███████░░░░░░░░░░░░░░░░░░ 26.11 % 🌃 Evening 9652 commits █████████░░░░░░░░░░░░░░░░ 34.57 % 🌙 Night 8465 commits ████████░░░░░░░░░░░░░░░░░ 30.32 % 

📅 I'm Most Productive on Wednesday

Monday 4645 commits ████░░░░░░░░░░░░░░░░░░░░░ 16.64 % Tuesday 4910 commits ████░░░░░░░░░░░░░░░░░░░░░ 17.58 % Wednesday 5387 commits █████░░░░░░░░░░░░░░░░░░░░ 19.29 % Thursday 3574 commits ███░░░░░░░░░░░░░░░░░░░░░░ 12.80 % Friday 4086 commits ████░░░░░░░░░░░░░░░░░░░░░ 14.63 % Saturday 2876 commits ███░░░░░░░░░░░░░░░░░░░░░░ 10.30 % Sunday 2445 commits ██░░░░░░░░░░░░░░░░░░░░░░░ 08.76 % 

📊 This Week I Spent My Time On

🕑︎ Time Zone: Europe/London
💬 Programming Languages: No Activity Tracked This Week
🔥 Editors: No Activity Tracked This Week
🐱‍💻 Projects: No Activity Tracked This Week
💻 Operating System: No Activity Tracked This Week

🤖 AI Coding This Week

No AI Coding Activity Tracked This Week

I Mostly Code in Shell

Shell 22 repos ██████████░░░░░░░░░░░░░░░ 39.29 % Python 8 repos ████░░░░░░░░░░░░░░░░░░░░░ 14.29 % HTML 4 repos ██░░░░░░░░░░░░░░░░░░░░░░░ 07.14 % JavaScript 3 repos █░░░░░░░░░░░░░░░░░░░░░░░░ 05.36 % HCL 1 repo ░░░░░░░░░░░░░░░░░░░░░░░░░ 01.79 % 

Last Updated on 04/09/2026 05:36:06 UTC

🎮 Steam playtime leaderboard

⚔️ Dota 2 🕘 2309 hrs 19 mins
🎮 HELLDIVERS™ 2 🕘 1195 hrs 47 mins
🎮 Creeper World 4 🕘 889 hrs 58 mins
🎮 Overwatch® 🕘 270 hrs 19 mins
🌏 Sid Meier's Civilization V 🕘 226 hrs 21 mins

✍️ Latest Wiki Posts :

✍️ Personal Websites :

Pinned Loading

  1. docker-rickrolldocker-rickrollPublic

    Dockerised Rick Roll

    Shell 57 16

  2. docker-borgmaticdocker-borgmaticPublic

    Container to automate Borgbackups (https://github.com/borgbackup) using Borgmatic (https://github.com/witten/borgmatic)

    Shell 47 8

  3. public_scriptspublic_scriptsPublic

    Scripts for the general public

    Shell 92 18

  4. cibuildwheelcibuildwheelPublic

    CIBuildWheel

    Shell 1

  5. docker-devenvdocker-devenvPublic

    Docker Dev Environments

    Shell 5 1

  6. docker-starwarsdocker-starwarsPublic

    Self hosted, self contained Docker image of the classic www.asciimation.co.nz/Blinkenlights ASCII Star Wars animation.

    HTML 17 1