aboutsummaryrefslogtreecommitdiff
path: root/content/uses/index.org
blob: 7192c2d09f0d32e7f00121e6a58b5cdc01683c57 (plain) (blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
#+title: uses
#+slug: index
#+options: toc:nil

Tools powering this site and the infrastructure behind it. Each entry includes a
threat model justification.

* Philosophy

- Own the hardware or you don't own the content.
- Zero tracking. No cookies. No analytics. No exceptions.
- Full rebuild from source on a fresh OS in under an hour.
- One tool per job. No dependencies that rot.

* Software

| Technology            | What I Use              | Threat Model                                                                                        |
|-----------------------+-------------------------+-----------------------------------------------------------------------------------------------------|
| Registrar             | [[https://njal.la][Njalla]]                  | Registers domains on your behalf. No WHOIS identity exposure.                                       |
| DNS                   | [[https://cloudflare.com][Cloudflare]]              | Portable DNS, secure infrastructure, and acceptable privacy.                                        |
| Security              | [[https://cloudflare.com][Cloudflare]] + [[https://github.com/fail2ban/fail2ban][fail2ban]]   | Automated auth-failure bans. Minimal Cloudflare functionality enabled.                              |
| Routing               | [[https://ui.com/][UniFi]]                   | Local network segmentation.                                                                         |
| Server                | [[https://cleberg.net/blog/server-build.html][Self-hosted]]             | Physical control. No hypervisor escape vector. No subpoena to a DC.                                 |
| Operating System      | [[https://ubuntu.com][Ubuntu]] + [[https://www.apple.com/os/macos/][macOS]]          | Ubuntu: telemetry off, LTS, stable. macOS: workstation only.                                        |
| Web Server            | [[https://nginx.org][Nginx]] + [[https://community.torproject.org/onion-services/setup/][Tor]]             | Static file serving. Tor layer for censored-network access.                                         |
| SSL                   | [[https://certbot.eff.org][Certbot]]                 | Free automated TLS. No commercial CA dependency. Ensures Cloudflare can't view unencrypted traffic. |
| Static Site Generator | [[https://github.com/emacs-love/weblorg][Weblorg]] + [[https://git.sr.ht/~ccleberg/cleberg.net/tree/main/item/build.py][build.py]]      | Org-mode source compiles to plaintext HTML via native Lisp.                                         |
| Terminal              | [[https://iterm2.com/][iTerm2]]                  | Functional. Inherited from macOS.                                                                   |
| Shell                 | [[https://www.zsh.org/][Zsh]]                     | Portable, POSIX-adjacent, available on every target OS.                                             |
| Editor                | [[https://github.com/doomemacs/doomemacs][Doom Emacs]]              | Editor and markup are the same tool. No proprietary format.                                         |
| Markup Language       | [[https://orgmode.org][org-mode]]                | Plain text. Readable without any software. Version-control native.                                  |
| Image Processing      | [[https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/w/webp.rb][webP (CLI)]]              | CLI-only. No GUI, no cloud, no account.                                                             |
| Browser(s)            | [[https://www.torproject.org/][Tor]] + [[https://www.apple.com/safari/][Safari]]            | Tor for anonymity-critical use. Safari for hardened daily use.                                      |
| Version Control       | [[https://git-scm.com/][Git (CLI)]]               | Decentralized. The repo is the backup.                                                              |
| Git Host              | [[https://sr.ht][SourceHut]] + [[https://github.com/ccleberg][GitHub]]      | SourceHut is the primary and GitHub is the mirror.                                                  |
| CI/CD                 | [[https://git.sr.ht/~ccleberg/cleberg.net/tree/main/item/build.py][build.py]] + [[https://builds.sr.ht][builds.sr.ht]] | A Python script and SSH. builds.sr.ht for convenience, but not required.                            |
| Email Host            | [[https://soverin.com/][Soverin]]                 | Privacy-focused provider.                                                                           |
| Search Engine         | [[https://docs.searxng.org/][SearXNG]] (self-hosted)   | Queries route through my own instance. No third-party search profile.                               |
| Backups               | N/A                     | Nothing to back up. No user data. Source mirrored via Git.                                          |
| Monitoring            | N/A                     | Monitoring creates logs. Logs are a liability.                                                      |
| Analytics             | N/A                     | No interest in visitor data. Content finds its way via RSS.                                         |
| Social Media          | N/A                     | —                                                                                                   |
| Newsletter            | RSS Only                | No subscriber list. No email vendor. No data relationship.                                          |

* Hardware

Custom rack-mounted server. Physical control, no hypervisor, no vendor lock-in.
See: [[https://cleberg.net/blog/server-build.html][server build post]].

| Component     | Spec                                |
|---------------+-------------------------------------|
| Chassis       | Rosewill RSV-R4100U 4U Rackmount    |
| Motherboard   | NZXT B550                           |
| CPU           | AMD Ryzen 7 5700G                   |
| RAM           | 64GB DDR4 (2x32GB)                  |
| Boot Drive    | 500GB WD M.2 NVMe SSD               |
| Storage (HDD) | 6 x 8TB WD Red Plus                 |
| PSU           | Corsair RM850                       |
| Cooling       | Noctua (1x120mm front, 2x80mm rear) |

Physical hardware under personal control eliminates the hypervisor escape vector
and the cloud provider subpoena vector. Full recovery from a fresh OS install:
under one hour.

Secondary: Raspberry Pi 4 for miscellaneous self-hosted services.