← Tags

#security

3 posts

Dotfiles, Part 6: Ephemeral and Declarative Edge Access

Two new modes for the cf CLI: throwaway tunnels that gate a local port behind a login and clean up after themselves, and a declarative reconciler that keeps self-hosted Cloudflare Access apps in sync from Nix.

nixcloudflaresecurityinfrastructure

Dotfiles, Part 4: Network-Aware Services — From Split Tunneling to Topology-Driven DNS

ProtonVPN with network namespace split tunneling, ad-blocking derived from VLAN topology, DHCP-to-DNS sync, and dynamic WireGuard peer onboarding — all as composable NixOS modules.

nixnetworkingsecurityinfrastructure

Dotfiles, Part 3: Secrets, Fleet Management, and the User Bridge

How I bootstrap 9 machines with sops-nix, clan-core, and a user module pattern that solves the secrets chicken-and-egg problem — plus service exposure via Caddy and Cloudflare Tunnel.

nixsecurityinfrastructure