1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
|
#+title: uses
#+slug: index
#+options: toc:nil
Tools powering this site and the infrastructure behind it. Each entry includes
a threat model justification and an exit strategy. ~TECHNICAL DEBT~ flags items
with no clean migration path or active sovereignty risk.
* Philosophy
- Own the hardware or you don't own the content.
- Zero tracking. No cookies. No analytics. No exceptions.
- Full rebuild from source on a fresh OS in under an hour.
- One tool per job. No dependencies that rot.
* Software
| Technology | What I Use | Threat Model | Exit Strategy |
|-----------------------+-----------------------+------------------------------------------------------------------------+--------------------------------------------------------------------------------------------------------------|
| Registrar | [[https://njal.la][Njalla]] | Registers domains on your behalf. No WHOIS identity exposure. | Any registrar accepting anonymous payment. Portable. |
| DNS | [[https://njal.la][Njalla]] | Same as above. DNS records are portable on day one. | Self-hosted BIND or any other provider. |
| Security | [[https://github.com/fail2ban/fail2ban][fail2ban]] | Automated auth-failure bans. No cloud WAF. No data leaving machine. | nftables rate limiting or self-hosted crowdsec. |
| Routing | [[https://ui.com/][UniFi]] | Local network segmentation. Controller must run self-hosted. | ~TECHNICAL DEBT~ - cloud dependencies by default. OpenWrt on compatible HW. |
| Server | [[https://cleberg.net/blog/server-build.html][Self-hosted]] | Physical control. No hypervisor escape vector. No subpoena to a DC. | N/A. This is the exit strategy. |
| Operating System | [[https://ubuntu.com][Ubuntu]] + [[https://www.apple.com/os/macos/][macOS]] | Ubuntu: telemetry off, LTS, stable. macOS: workstation only. | Ubuntu → Debian. macOS → ~TECHNICAL DEBT~. Target: NixOS/Fedora on ThinkPad or Framework. |
| Web Server | [[https://nginx.org][Nginx]] + [[https://community.torproject.org/onion-services/setup/][Tor]] | Static file serving. Tor layer for censored-network access. | Caddy or lighttpd. Tor is already the exit layer. |
| SSL | [[https://certbot.eff.org][Certbot]] | Free automated TLS. No commercial CA dependency. | acme.sh. Same protocol, no Python dependency. |
| Static Site Generator | [[https://github.com/emacs-love/weblorg][Weblorg]] + [[https://git.sr.ht/~ccleberg/cleberg.net/tree/main/item/build.py][build.py]] | Org-mode source compiles to plaintext HTML. No JS build chain. | Pandoc + shell script. Source files survive any generator change. |
| Terminal | [[https://iterm2.com/][iTerm2]] | Functional. Inherited from macOS. | ~TECHNICAL DEBT~ - macOS-only. Target: foot or Alacritty on Linux. |
| Shell | [[https://www.zsh.org/][Zsh]] | Portable, POSIX-adjacent, available on every target OS. | bash or fish. Config is plain text. |
| Editor | [[https://github.com/doomemacs/doomemacs][Doom Emacs]] | Editor and markup are the same tool. No proprietary format. | Vanilla Emacs + org-mode. Doom is a config layer only. |
| Markup Language | [[https://orgmode.org][org-mode]] | Plain text. Readable without any software. Version-control native. | N/A. Org files are the source of truth. |
| Image Processing | [[https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/w/webp.rb][webP (CLI)]] | CLI-only. No GUI, no cloud, no account. | ImageMagick or cwebp. Trivial swap. |
| Browser(s) | [[https://www.torproject.org/][Tor]] + [[https://librewolf.net/][LibreWolf]] | Tor for anonymity-critical use. LibreWolf for hardened daily use. | N/A. Safari dropped - proprietary and redundant. |
| Version Control | [[https://git-scm.com/][Git (CLI)]] | Decentralized. The repo is the backup. | N/A. Content is portable to any host. |
| Git Host | [[https://github.com/ccleberg][GitHub]] | Public mirror only. | ~TECHNICAL DEBT~ - Microsoft-owned. Target: self-hosted Forgejo. One-line remote URL change. |
| CI/CD | [[https://git.sr.ht/~ccleberg/cleberg.net/tree/main/item/build.py][build.py]] + [[https://www.openssh.org/][OpenSSH]] | A Python script and SSH. No CI runner, no stored secrets, no webhooks. | A shell script. Python is not load-bearing here. |
| Email Host | [[https://soverin.com/][Soverin]] | Privacy-focused provider. Better than Gmail. | ~TECHNICAL DEBT~ - not self-hosted. Target: Postfix + Dovecot + Rspamd, or maddy. MX records portable day one. |
| Search Engine | [[https://docs.searxng.org/][SearXNG]] (self-hosted) | Queries route through own instance. No third-party search profile. | Any other self-hosted SearXNG instance. |
| Backups | N/A | Nothing to back up. No user data. Source mirrored via Git. | Intentional. If this changes: restic to a local target. |
| Monitoring | N/A | Monitoring creates logs. Logs are a liability. | Intentional. |
| Analytics | N/A | No interest in visitor data. Content finds its way via RSS. | Intentional. |
| Social Media | N/A | — | Intentional. |
| Newsletter | RSS Only | No subscriber list. No email vendor. No data relationship. | N/A. |
* Hardware
Custom rack-mounted server. Physical control, no hypervisor, no vendor lock-in.
See: [[https://cleberg.net/blog/server-build.html][server build post]].
| Component | Spec | Threat Model / Notes |
|---------------+----------------------------------------------------+------------------------------------------------------------|
| Chassis | Rosewill RSV-R4100U 4U Rackmount | — |
| Motherboard | NZXT B550 | — |
| CPU | AMD Ryzen 7 5700G | Onboard GPU eliminates need for discrete card in the rack. |
| RAM | 64GB DDR4 (2x32GB) | — |
| Boot Drive | 500GB WD M.2 NVMe SSD | — |
| Storage (HDD) | 1x10TB WD White, 1x8TB WD White, 2x8TB WD Red Plus | — |
| PSU | Corsair RM850 | — |
| Cooling | Noctua (1x120mm front, 2x80mm rear) | — |
Physical hardware under personal control eliminates the hypervisor escape vector
and the cloud provider subpoena vector. Full recovery from a fresh OS install:
under one hour.
Secondary: Raspberry Pi 4 for miscellaneous self-hosted services.
|