$ ls -la ~/posts/
Notes, postmortems, and longer threads. Less marketing, more notebook. Notatki, postmortemy i dłuższe wątki. Mniej marketingu, więcej notatnika.
- A private CA at home: step-ca on a QNAP and no more "proceed anyway" How I set up Cygal-Home-CA with smallstep step-ca in Container Station, issue certificates for *.cygal.lan services, push the root CA to every machine in the house, and automate the whole thing with ACME and cert-renewer. With copy-paste snippets. Własne CA w domowym labie: step-ca na QNAP-ie i koniec z klikaniem "i tak przejdź" Jak postawiłem Cygal-Home-CA na smallstep step-ca w Container Station, wystawiam certy dla usług w *.cygal.lan, rozdaję root CA na wszystkie domowe maszyny i jak to wszystko zautomatyzować przez ACME i cert-renewer. Z gotowcami do copy-paste.
- Pinning a CI runner's egress IP with one curl A small pipeline pattern: detect a CI runner's public egress IP with ip.syschecks.com, check it against an allowlist, and fail fast when it drifts - just curl and jq, no extra dependencies. Przypinanie egress IP runnera CI jednym curl-em Maly wzorzec do pipeline: wykryj publiczne egress IP runnera przez ip.syschecks.com, sprawdz je wzgledem allowlisty i przerwij od razu, gdy sie zmieni - sam curl i jq, bez dodatkowych zaleznosci.
- mailops: SPF, DKIM, DMARC and the rest of mail, from one terminal A Go CLI that checks the whole mail posture of a domain in one pass: SPF, DKIM, DMARC, MTA-STS, BIMI, TLS-RPT, active SMTP and IMAP/POP probes, DNSBL reputation, and provider profiles. mailops: SPF, DKIM, DMARC i reszta poczty z jednego terminala CLI w Go, ktore sprawdza cala posture pocztowa domeny w jednym przebiegu: SPF, DKIM, DMARC, MTA-STS, BIMI, TLS-RPT, aktywne probe SMTP i IMAP/POP, reputacja DNSBL i profile providerow.
- SysTeam HealthChecks is now Syschecks SysTeam HealthChecks has been renamed to Syschecks and moved to syschecks.com. Same product, same data, same accounts - new name and its own domain. SysTeam HealthChecks to teraz Syschecks SysTeam HealthChecks zmienil nazwe na Syschecks i przeniosl sie na syschecks.com. Ten sam produkt, te same dane, te same konta - nowa nazwa i wlasna domena.
- certops: plan, drift, and trust stores for PKI A Go tool for checking CA providers, service certificates, and trust stores. It started as a TLS checker and turned into plan/drift/apply for internal PKI. certops: plan, drift i trust store dla PKI Narzędzie w Go do sprawdzania CA, certyfikatów usług i trust store'ów. Zaczęło się od TLS checkera, a skończyło na plan/drift/apply dla wewnętrznego PKI.
- sshmgr is out (and why I built it) Open source SSH connection manager: CLI + TUI, login chains with OS keyring, port forwarding, parallel exec across host fleets, native Ansible integration. Single Go binary. sshmgr poszedł w świat (i po co go w ogóle pisałem) Open source manager SSH: CLI + TUI, sekwencje logowania z OS keyring, port forwarding, parallel exec po flocie, integracja z Ansible. Jeden plik Go, zero demonów.
- Hello, world (and why this site exists) A short note about why I'm starting this site, what to expect, and what not to. Cześć. I po co ta strona Krótka notka o tym, czemu odpaliłem tę stronę, czego się tu spodziewać, a czego nie.