It must be a me-thing - but I am still learning OPNSense and it is forcing me to read and pay attention. You can't _just_ make a VLAN, you have to go through a couple of screens. This is far from done, but I am getting somewhere and I love it. :D
Still learning and progressing, still not ready to deploy it as my main and primary WAN - but, I am not far away from it either. :3

Also, IPv6 can suck. my. dick.
I see this in Primal's Trending column...

...and I wonder how many worlds apart we truely are.
I still can not buy a cheeseburger with bitcoin, heck, not even regular bread, coffee or my smokes.
Meanwhile, there's bitcoiners out there _apparently_ living this kinda world? Arite...
It's happened three times now: I heared weird noises that woke me up. Over this and the previous day, I have been falling alseep mid-day and waking up from distorded-sounding notification sounds on my headphones I was still wearing.
My breaking point aint too far off at this point... that was a haunting experience, seriously. Too much stress and all that is really, _really_ getting at me. x.x
I have spent so much time in Excel as of late...
Sanity check:
- 2 out of 3 Radxa Orion O6 32GB units
- OPNSense Firewall
- OpenBao-dedicated system - SpacemiT MUSE Pi Pro, in the mail
- Pi-esque rack mount + keystones - installed, ready to rock; missing the Pi boards, which will be MUSE Pi Pro + Radxa Dragon
- Milk-V Pioneer for CI/CD and NAS
- Secondary 8-bay NAS, OpenMediaVault, has NanoKVM for full power-down/-up backup scheduling
Missing:
- >8 Port 10G RJ45 + PoE switch (~450-650 €)
- WiFi 7 AP (~100 €)
- 3x 256GB NVMe Gen 4 SSD (Orion boot disk); Unknown, NAND prices...
- 3x 2TB NVMe Gen4 SSD (Orion shared data disk; k8s Longhorn); Unknown, NAND still
- 4x 2TB NVMe Gen3 SSD (NAS, "hot" tier, mergerFS+snapRAID); ...yes, NAND
- 2x 4/5TB SATA-III SSD 2.5" (NAS, "warm" tier, mergerFS+snapRAID)
- 2x 4TB SATA-III HDD 2.5" (NAS, "cold" tier); Unknown, havent checked yet
- 1x ICY DOCK PCIe NVMe to OcuLink adapter
- 1x 4x OcuLink to PCIe x16 adapter - ultra-low profile (HLHH)
- 1x ICY DOCK SATA carrier - literally enclosure only, goes straight to mobo
- 3x (Orion) + 1 (NAS) + 1 (Desktop) + 1 (AI Server) = 6 Sipeed NanoKVM (PoE option, ~100€)
- Oh yeah an entire fucking AI Server... Dual MaxSun B60 48GB Turbo, AMD Epyc, 265GB RAM - highly unknown, DRAM.
- 3x 1U short-depth Mini-ITX case (Orion); 50 € each
- 1x 1U long-depth Micro-ATX case (Pioneer); 90 €
- 1x Multi USB Type-C charger for Orions (at least 180W, 60W per socket)
- 1x PSU for Pioneer - wattate completely unknown. xD
Optional:
- Desktop PC upgrade from R9 3900X -> 9000-series (32GB RAM and board, rest stays)
Goal:
- Orions will build Kubernetes cluster (k0s, NLLB + CPLB) to run all selfhosted things, automate them through ArgoCD, connect to OpenBao with External Secrets / Cert-Manager to keep them off-cluster
- OPNSense acting as a whole-network VPN router to sink my entire traffic into a VPN bar exceptions - and also link with Tor and i2pd
- Home Assistant for inter-device / inter-service and (local) smart-home automation
- OpenBao for certs, secrets and sensitive data, HSM backed (NitroKey)
- Pioneer to automate building and testing of all the projects I find cool, act as a NAS and CI/CD into oblivion with Concourse CI, using QEMU to go between ISAs if needed too. It may become my new BTC/CLN node while I am at it, and may run solo miners in the time between jobs...because, why not. Also a big maybe. But, XMRing looks nice.
I am inching closer and closer and closer to replace every single cloud-service I need or want to use with a local option. It's basicaly my "Project: Good Bye Internet". I already prepared one of the pieces on the OPNSense within a BSD Jail and it will be glorious. =)
Also, I will be fucking broke for a bit, but thats fine, because after this, I have the exact lab I want, for good, for real, and it's mine. No shitty -aaS will ever take this away. :3
Heck I might some day build a solar powered, 4G modem backed device to help me reach my homelab even when WAN goes offline or something like that - and to send SMS lol.

I have a Milk-V Pioneer at my table, 1.400 €. My homelab has been costing me a multitude of nerves, arms, legs and whatever else I could find. My goal to become fully self-sovereign is almost here but now I get buttfucked with DRAM and NAND prices.
Brother. I am gonna be so happy when I can close my rack door, knowing that everything I wanted is inside now - for real, for good, and most definitively. XD
BROTHER I WANT TO SCREAM THAT AT RUST EVANGELISTS SO BAD HOLY SHIT
#TUNESTR
I successfuly:
- Flashed a FritzBox with OpenWrt
- Set up a bridge (actually a relay) between the WiFi and LAN
- Bought, installed, configured a Sipeed NanoKVM
- And stuffed the whole thing into my basement segment!

I can now turn this NAS on and off as I need. It's an Athlon 3000G, I intend to use it as my secondary NAS down the line (3-2-1).
THIS IS SO COOL 0.0 I can turn it on, off, get into bios, everything! aaaaaa <3 SUCCESS
This goes so hard for no reason... xD
#tunestr
Compiled the zsbl, compiled edk2 - both with the properly pinned DTB.
Now I just need _a linux_... xD That should be fun.
"zsbl" means "Zero Stage Bootloader" and is the very, very first piece of the puzzle to boot the Milk-V Pioneer - which I now own.
user@BIGBOI:/opt/zsbl$ du -h zsbl.*
132K zsbl.bin
944K zsbl.dis
772K zsbl.elf
240K zsbl.map
It feels stupidly weird to just... compile your bootloader. This is literally the first thing that gets invoked after the CPU; it is what bootstraps the initial hardware and eventually goes to EDK2 / u-boot. o.o
This is probably as close to an IPL as Ill ever get. xD
Most people: Oh no, my Facebook got hacked! PANIC!
This lad: Oh no, my Facebook got hacked! Welp, I'll make it a song instead.
I SWEAR THIS GUY JUST FUCKING RULES HOLY SHIT
#tunestr
Hey
@GrapheneOS - quick question!
Have you patched CVE-2025-48561?
Thanks. =)
TIL: There are FreeBSD NVIDIA drivers. o.o
Index of /XFree86/FreeBSD-x86_64/580.105.08
... I was not ready for that.
Also, Wayland and KDE work there too. Holy shit, I feel like I've been living under a rock - although I really haven't. Dude this BSD rabbithole goes fucking deep O.O
So while looking through proxy tools like clash-rs, sing-box and friends, I came across Mihomo. The repo says it's 100% python, the README is about Honkai Star Rail.
...but check the branches, and you'll see something odd. Within there hides a Go application that is the _actual_ project. xD Pretty cheeky hiding, yeah, but the kind of software I am looking at is for evading censorship and alike - so... weird meassures are to be expected.
Slightly shady and I am still intrigued. This stuff is mainly targeted at China users but... hey, who says I can't deploy that here, and make some good use of my ProtonVPN connection? =) This'll be fun to explore.
One day, my whole network will have gone underground. Will take me quite a while to get there tho...
I have a new reason to have "an issue" with Rust. Not really, but see:
- OPNSense is an appliance based on FreeBSD,
- it disables the FreeBSD repos for stability,
- it provides source-ports to add some individual packages when needed,
- among those is fish,
- fish is written in Rust,
- Rust is based on LLVM,
- LLVM is fucking gigantic.

So this source port literally went from LLVM into Rust into Fish and took THREE FUCKING HOURS XD. Let alone the disk usage; easily 15GB for the entire build tree. @.@
I hope I never have to update this... because otherwise I am just gonna cry. Really, if elvish didn't have it's flickery odd behaviour in the Windows Terminal, which IS my primary terminal, I'd just use that...
Getting to know the ins and outs of FreeBSD under OPNSense. It's rather easy to tell it's ment as an appliance; ports have to be built from source - but their Makefile based system is stupidly good. I really like it. It reminds me of the MacPorts package ... oh, wait ... x)
The last "BSD" I ever did _was_ on Mac OS X - first with Macports (I remember exploding /sw multiple times...) and later with Homebrew. Those things were mad fun.
But, I intend to very carefuly pick and choose the packages I put here; the firewall is ment to be a firewall.
Long-term goal is to use it to put the whole network on a VPN, grant access to tor and i2p, and use DNS proxying/cloaking. I still have to figure out a good way to whitelist things though. For example, for Genshin, any of the *.hoyoverse.com domains need to be routed directly. Clash-rs _can_ do that, and I bet sing-box also. But it'll take time to find workflows from finding the edge cases, isolating them in the log, formulating rules, and then setting them.
... Have I mentioned that I am "done" with the clearnet? xD May sound like a stereotypical braindead imbicile but FUCK DEM CORPOS \m/
That Sophos is now running OPNSens. Time to learn a new thing!

This lad's story sure aged like milk... Meta, OpenAI, Microsoft and basically any "big tech" could not even remotely care less.
I doubt today's Reddit would do what it did back then - heck, not even WordPress...
Have I mentioned that I love japanese sillyness? x)
#tunestr

Spotify
Anonymous M
PinocchioP · META · Song · 2023
I finally found an editor to replace nano:

GitHub
GitHub - neurocyte/flow: Flow Control: a programmer's text editor
Flow Control: a programmer's text editor. Contribute to neurocyte/flow development by creating an account on GitHub.
This thing RULES. It doesnt even feel like a TUI - with mouse support and all. Thats so fucking cool O.O
Zig is also a language I really havent looked into all that much. In fact, Zig, D and Swift. I want to give all three of them a shot at some point. Swift in particular, because it can build standalone GUI apps with C interop - and thus, technically with Go interop. xD
I have very, very cursed ideas...