Rack A-01 Krux's home lab · somewhere in England, row 1
Temp 21.6°C Draw 142 W Uptime 0 d

Krux

IT, networking & cyber student. Absolutely in love with anything that has a power supply.

Hi, I'm Krux. I'm studying for a National Degree in IT / Networking & Cyber here in England, and I absolutely love IT. I'm the kind of person who reads the router's admin page for fun.

I'm aiming for a career in cybersecurity, and I'm aiming high. But I don't want to only know the security layer. I want to understand the whole stack: the cable, the switch, the hypervisor, the OS, the service, and the person about to click the link. So I build things at home, break them on purpose, and write down how I fixed them.

whoami · stor-01

/dev/sda · 1 TB · mounted at /origin

Where it started

It started with an old family PC that kept getting slower, and someone showing me Task Manager. Within a month I'd reinstalled Windows twice, once on purpose.

Since then I've been the unofficial IT department for my family, which turns out to be excellent training in incident response under pressure, with very demanding stakeholders.

/dev/sdb · 2 TB · mounted at /why-security

Why security

Security is the one field where you have to understand how everything works, because an attacker only needs the one thing you didn't. It rewards curiosity and punishes assumptions, and I like that.

I enjoy the defensive side as much as the offensive side. Finding a clever attack is fun; writing the detection that catches it the next time is better.

/dev/sdc · 2 TB · mounted at /how-i-learn

Build it, break it, write it down

I learn a protocol by capturing it in Wireshark, a service by misconfiguring it in my lab, and a concept by explaining it to someone who didn't ask.

My notes live in a private Git repo, and I try to turn the good ones into public write-ups at [Blog URL].

/dev/sdd · 500 GB · mounted at /off-hours

Off hours

Rescuing old hardware from e-waste piles before it gets shredded, reading post-mortems of famous outages, and playing CTFs most weekends, usually badly, occasionally brilliantly.

/dev/sde · read-only · mounted at /rules

Rules I follow

I only test systems I own or have written permission to test. I read the scope twice. I report what I find. That's not a disclaimer; it's the job.

/dev/sdf · unformatted · not mounted

Hot spare

This bay is empty on purpose. It's reserved for whatever I get obsessed with next. Suggestions welcome; the uplink is at the bottom of the rack.

Learning · ups-01

Charge level = how far along I am. Nothing is at 100%, and that's the point.

  • Networking (CCNA track)70%

    Subnetting is muscle memory now. Next: OSPF areas and getting comfortable in Cisco IOS, in Packet Tracer before I buy a real managed switch.

  • Linux administration65%

    Getting comfortable on the command line. Next: writing my own systemd units, running SELinux without disabling it, and using Ansible instead of SSH-ing into everything.

  • CompTIA Security+55%

    Exam booked. Flashcards on the bus, practice tests at night.

  • Python & Bash scripting50%

    Automating my own boring tasks: log parsing, backup checks, and a script that nags me when a VM's disk is filling up.

  • Windows Server & Active Directory40%

    Group Policy, DNS integration, and why AD sits at the centre of nearly every enterprise breach report I read.

  • Web application security35%

    Working through the PortSwigger Web Security Academy labs. Injection makes sense now; access control is this month's puzzle.

  • Cloud (AWS)25%

    Billing alarms first (other people's horror stories are great teachers), then IAM, which is where cloud security actually lives.

In the read buffer

  • The Cuckoo's EggClifford Stoll · re-reading
  • Practical Packet AnalysisChris Sanders
  • TCP/IP Illustrated, Vol. 1W. Richard Stevens · slowly
  • SandwormAndy Greenberg
  • The Phoenix ProjectGene Kim et al.

Everything runs on one machine: deimos, a second-hand HP Z640 running Proxmox VE. Each service is its own Proxmox guest with its own address, so I can rebuild, snapshot or break one without touching the rest. Everything marked planned is what I'm building next, starting with getting all of this off my flat home network.

deimosRUNNING

deimos: Proxmox VE on an HP Z640

The main (and so far only) node. An Intel Xeon E5-2690 v4 with 14 cores and 28 threads, plus 32 GB of DDR4 ECC registered memory, running Proxmox VE. I manage it from the Proxmox web UI on port 8006.

Learned: giving every service its own guest makes mistakes cheap. Snapshot first, experiment second.

  • Proxmox VE
  • Xeon E5-2690 v4
  • 14C / 28T
  • 32 GB ECC RDIMM
media stackRUNNING

An automated media stack

It manages and streams media I own. I self-host it to run my own services, not to pirate, and building it has taught me a lot. Several small services talk to each other over their APIs: Prowlarr manages indexers, Radarr organises the film library, qBittorrent handles downloads, and FlareSolverr helps Prowlarr get past browser challenges.

Media stack services on deimos
ServicePortStatus
Prowlarr9696up
Radarr7878up
qBittorrent8090up
FlareSolverr8191up
Gamarr5001inactive

Learned: how services discover and authenticate to each other with API keys, and why one misconfigured port breaks the whole chain.

  • Prowlarr
  • Radarr
  • qBittorrent
  • FlareSolverr
jellyfinRUNNING

Jellyfin media server

A self-hosted media server on port 8096 that streams my own library to devices around the house. The end of the media stack's pipeline, and the bit everyone else at home actually notices.

Learned: transcoding is hard work for a CPU. 28 threads finally have something to do.

  • Jellyfin
  • port 8096
  • self-hosted
deimos · next guestsPLANNED

Self-hosting roadmap

What's going on deimos next. Each one is useful day to day, and each teaches a different part of running services securely.

Planned self-hosted services
ServiceWhat it's forWhat it teachesStatus
GiteaMy own Git server for lab configs, scripts and notesAuth, SSH keys, backupsplanned
VaultwardenA Bitwarden-compatible password managerSecrets, TLS, 2FAplanned
Nginx Proxy ManagerOne front door with HTTPS for every serviceCertificates, reverse proxiesplanned
WireGuardVPN access from outside, with no open portsRemote access done safelyplanned
AuthentikSingle sign-on in front of the web UIsIdentity, MFAplanned
Uptime KumaAlerts when a service goes downMonitoring, alertingplanned
ImmichSelf-hosted photo backupStorage, 3-2-1 backupsplanned
HomepageA dashboard linking every serviceKeeping things tidyplanned

Rule for every new service: its own guest, a snapshot before changes, no default passwords, and never port-forwarded to the internet.

  • Gitea
  • Vaultwarden
  • reverse proxy
  • WireGuard
  • SSO
pi-clusterPLANNED

Raspberry Pi cluster

A small stack of Raspberry Pis for always-on services and for learning lightweight Kubernetes, so not everything depends on deimos being up.

Goal: learn how distributed systems fail, on hardware that's cheap to break.

  • Raspberry Pi
  • k3s
  • Ansible
fw-01PLANNED

Firewall and segmented networks

Right now deimos and every service sit on the same flat network as the rest of the house. The next big project is a firewall VM and VLANs, so the lab, home devices and guests are kept apart.

Rule one: write the firewall rule down before applying it.

  • OPNsense
  • VLANs
  • 802.1Q
dns-01PLANNED

Pi-hole + Unbound, the Pi cluster's first job

Network-wide ad blocking and my own recursive DNS resolver, so I can see exactly what every device on the network asks for.

Because when something breaks, it's always DNS.

  • Raspberry Pi
  • Pi-hole
  • Unbound
siem-01PLANNED

Wazuh SIEM watching the lab

A Proxmox guest on deimos collecting logs from every service, so I can practise writing detection rules, starting with alerts for failed logins to the Proxmox and service web UIs.

Goal: test every detection I write. An untested one is just a guess.

  • Wazuh
  • Sysmon
ad-labPLANNED

An isolated Active Directory lab

Windows Server evaluation VMs on deimos, a small domain and a few deliberately weak settings, fully offline, so I can see attacks like Kerberoasting from both sides and then fix them.

Good news: 14 cores and 32 GB leave room for a domain controller, a client and an attacker VM next to the media stack.

  • Windows Server
  • AD DS
  • Group Policy

Configs and write-ups are on GitHub (secrets scrubbed, I promise).

Write-ups · lto-01 tape library

Only retired boxes, public challenges and my own lab. No live-event spoilers.

Fascinations · sw-01 · 24 ports, all up

SFP1 → uplink

Toolbox · drw-01

Every tool has its own cut-out. Put it back when you're done.

  • Wiresharka microscope for networks
  • Nmappointed only at my own lab
  • Burp Suite CEfor PortSwigger labs
  • Ghidrastaring at binaries, learning slowly
  • CyberChefdecode all the things
  • Proxmox VEruns everything on deimos
  • Packet Tracernetworks before hardware
  • Dockerthrowaway environments
  • Ansibleso I stop clicking things twice
  • gitconfig history, and my notes
  • tmux + vimyes, I know how to quit
  • KeePassXCunique passwords, every time
  • Obsidiana second brain in Markdown

Maintenance log · log-01

  1. Switched Gamarr off for now. Fewer running services means less to patch and less to go wrong.

  2. Sketched the Raspberry Pi cluster on paper: how many Pis, how to power them, and what runs where. DNS goes first.

  3. Jellyfin is up. Radarr, Prowlarr, qBittorrent and FlareSolverr are all talking to each other. The media stack works end to end.

  4. First guests running on deimos, one service per guest.

  5. Note to self, so I don't forget: ZmxhZ3tiYXNlNjRfaXNfbm90X2VuY3J5cHRpb259

  6. Installed Proxmox VE on the Z640 and named the node deimos.

  7. Brought home a second-hand HP Z640 with a Xeon E5-2690 v4. 14 cores, 28 threads. The first node officially exists.

Console · kvm-01

A toy shell that runs entirely in your browser. Try help.

Hidden CTF · ctf-01

0/6 captured

Six flags are hidden in and around this site

They look like flag{...}. Everything is harmless and client-side: no scanning, no brute forcing, nothing to break. You only need a browser, curiosity, and maybe CyberChef. Progress is saved in your browser only.

    © 2026 Krux · 0 trackers · 0 external requests · check my headers · press ? for shortcuts

    Keyboard shortcuts

    ?
    show this panel
    r
    turn the rack around (rear view)
    l
    room lights on / off
    m
    maintenance: slide every unit out / in
    `
    open the console
    s
    sound on / off
    p
    print the CV spec sheet
    Esc
    close this panel