michael@post:~$
  • Writing
  • Projects
  • Bookshelf
  • About
Open source

Projects

Small tools shaped by real infrastructure problems, with an emphasis on understandable security boundaries and straightforward operations. Browse all repositories on GitHub.

01
gotls

tlsgate

A fingerprint-gating proxy for TLS services. It filters opportunistic scanner noise using JA3 or JA4 while leaving real authentication to the backend.

Source & documentation → Read the field note
02
gossh

sshgate

A companion fingerprint-gating proxy for SSH. It reads the plaintext key exchange and uses a HASSH-style fingerprint to reduce background noise.

Source & documentation → Read the field note
03
gosecurity

gatehub

The shared control plane for tlsgate and sshgate, with centralized fingerprint observations, approval policy, and narrowly scoped node synchronization.

Source & documentation → Read the field note
04
golibrary

gatekit

The reusable node-side spine of the fingerprint gates: SQLite state, control-plane sync, rate limits, connection caps, and graceful process lifecycle.

Source & documentation → Read the field note
05
gomonitoring

parallaxd

An availability monitor that corroborates failures from independent vantage points and alerts only when a quorum agrees that a service is down.

Source & documentation → Read the field note
06
godns

rilldns

A compact CoreDNS operations stack for authoritative zones, authenticated replication, managed blocking, APIs, an OIDC console, and monitoring.

Source & documentation → Read the field note
07
gonotifications

tintwire

A self-hosted inbox for rich operational notifications, with structured cards, actions, Web Push, and Mattermost and Slack compatibility.

Source & documentation → Read the field note
08
golibrary

tintwire-go

A small, standard-library Go client for publishing native Tintwire cards, with bounded retries and selective Mattermost delivery failover.

Source & documentation → Read the field note
09
gooidc

oidcrp

A focused OpenID Connect relying-party helper for Go web apps, covering the browser flow while leaving session ownership to the application.

Source & documentation → Read the field note
10
goai

wayminder

A self-hosted MCP memory service that gives AI coding agents durable, scoped recall using PostgreSQL, pgvector, and local Ollama embeddings.

Source & documentation → Read the field note
11
goai

rendercase

A self-hosted artifact plane for publishing, reviewing, versioning, and sharing interactive web output from AI agents, CI jobs, CLIs, and people.

Source & documentation → Read the field note

Practical field notes on Linux, infrastructure, and code.

Contact GitHub Mastodon GPG key Terms & Privacy