a field inventory of

the machine room

small systems, kept alive

self-hosted · private by default · public on purpose

field note // 01

Systems with a public story and a private edge.

Some things I build are meant to be read about. Others have to survive reboots, expiring tokens, full disks, and my own bad decisions. This is the small stack running behind the workshop: public experiments, private media, and the machinery that keeps both alive.

01 //

built here

02 entries
  1. StalkMarket

    A Raspberry Pi trading assistant for NSE positions. It polls broker feeds, trails stops, and sends a message when a rule matters.

    TypeScript · Node.js · SQLite · Docker · Raspberry Pi

    public
    read the buildopen public demo
  2. Sentinel

    A self-hosted multi-camera dashboard with live streams, motion-triggered recordings, and automatic RTSP recovery.

    Python · Flask · OpenCV · Raspberry Pi

    case study
    read case study
02 //

hosted here

02 entries
  1. Personal Media Cloud

    A private photo archive and personal media library, kept close to home and available across trusted devices.

    Immich · Jellyfin · Docker · Local storage

    private
  2. Automated Media Pipeline

    A coordinated set of services that organizes incoming libraries, sources metadata, handles transfers, and closes subtitle gaps.

    Sonarr · Radarr · Prowlarr · Bazarr · qBittorrent

    restricted
03 //

control plane

01 entry
  1. Operations Layer

    Metrics, container management, and secured maintenance access for the systems running behind the workshop.

    Grafana · Portainer · Docker · Cloudflare Tunnel

    restricted
field diagram // 02

How traffic reaches the machine room

not to scale
01public visitorpublic route
02trusted deviceidentity gate
edgeCloudflare edgepolicy and routing
secure tunnel
nodehome node / Dockerprivate network boundary
  • 01built
  • 02media
  • 03automation
  • 04operations
A deliberately incomplete map: enough to explain the trust boundary, not enough to inventory the network.