Having my self hosted ZeroSentinel #privacy node DM me status updates on the decenteralized #nostr protocol is one of the nerdist things I've ever done. Would this be still be Notes or the "Other Stuff"?
Deep into upgrading the stack. Moving ZeroSentinel to a HP Mini EliteDesk for an Ultra version with more performance and headroom for more add ons. Pi Zero becomes isolated resolver and canary.
And as a bonus grabbed an old HP T630 to build a isolated tor access node. Blows the doors off any Pi and actually half the price.
Full write ups to follow.
The ZeroSentinel project has evolved multiple flavors. It has been fun to play with but guides aren’t written up yet. On the to do list but will probably be a month or so with everything else in front of it.
——————-
ZeroSentinel:
WireGuard on Pi 4 or Pi 5.
Unbound + Canary on Pi Zero.
The classic architecture:
• Remote access VPN
• Recursive DNS
• Canary alerts
• Clean separation of roles
• Best balance between performance and isolation
This is the “standard” ZeroSentinel build.
————————-
ZeroSentinel Lite:
Unbound + Canary on Pi Zero. No WireGuard.
For people who want:
• Fast local privacy
• Resolver isolation
• DNSSEC
• Health checks
• Simple maintenance
• No remote access component
This is the minimal, stable home setup.
————————
ZeroSentinel Pro:
Everything consolidated on Pi 5 (WG + Unbound + Canary).
AdGuard on the router.
For people who want:
• Highest speed
• Single node management
• Cleaner physical stack
• Simplicity over isolation
• Maximum throughput
This is the premium, all on one Pi 5 build for performance first users.
———————————
ZeroSentinel Full Stack:
ZeroSentinel WG (Pi 4/5 + Zero)
+
Dedicated Tor lane running on a second Pi 4/5 (“Onion Pi”).
The full privacy architecture:
• WireGuard server
• Local recursive DNS
• Canary monitoring
• Tor only WiFi network on a dedicated Pi
• Clean physical separation of Tor vs LAN
• Entire home privacy ecosystem
Flagship tier for the ballers with multiple pi’s.
I finally upgraded my hosting tier for more RAM and CPU. My site had gotten too big and was choked by the limits. I had to jump two whole tiers.
The site should load a lot faster now and have snappier response times.