The last pronouncable 3-letter domain on the .sh TLD (at time of purchase).
nag.sh · registered 2025-08-29 · served from the edge
This is the public side of a private, self-hosted cloud that one household runs for itself: identity, files, photos, mail, media and a small fleet of machines in a rack at home. The interesting parts are the plumbing — an identity-aware edge in front, an egress-only tunnel behind it, and nothing published that does not need to be.
Move around with the tmux bindings: C-b then n/p, 1…3, or ? for the key table. Members sign in from the status line.

I have always loved the idea of machines doing my job for me. Nothing sinister in it, I just wanted the toil gone. My motto was always "work hard now so I can be lazy later," which started as hyperfocus and scripts, then turned into CI/CD, GitOps, and platform engineering. Somewhere along the way I started describing my job as automating people. That line has a different kind of zing to it than it used to. 😅
It doesn't mean ending jobs. It means taking the boring junk off the plate: tickets, the same configuration update across a dozen repos, and work that eats a week without producing anything new. Engineers should spend their time designing solutions instead of implementing boilerplate.
As a platform and cloud infrastructure engineer, I don't just ship clusters. I ship the monitoring, alerting, and guardrails that decide which path is easiest to walk. I think about systems the way the FAA thinks about accidents: don't blame the pilot, fix the process. If someone breaks production, I don't ask who did it. I ask why anyone would prefer to do it that way. The answer is never to just block the path; it's to make a better path the one they'd rather take.
I have a real passion for deep debugging, taking problems apart into individual pieces until I understand exactly what happened, often late into the night purely out of curiosity. That same curiosity pulls me toward creative problem solving, like combining existing technologies into a stack that does something none of the pieces could do alone.
None of that stays at the office. I run a Terraform-built Kubernetes homelab, keep a 3D printer tuned for useful parts, and build tooling for the AI agent environment I work in. When I'm not engrossed in a terminal, I'm hiking or watching the Red Sox.
- focusself-hosting, identity, automation, quiet infrastructure
- toolsTalos, Kubernetes, Terraform, Authentik, Cloudflare Zero Trust, Go
- elsewherehiking, the Boston Red Sox, and a 3D printer tuned for parts nobody else needed
- nag.sha single-tenant cloud: identity-aware edge, WARP-only reachability, egress-only tunnel, and an exposure review that is allowed to say no. source
- homepagethe launcher behind this site — a permission-filtered card grid that reads the caller's groups and shows only the apps they were granted. source
- docsplain-language setup guides for the people who have to live with the thing I built. docs.nag.sh
hello@nag.sh |
|
| code | https://github.com/nag-sh |
| status | this page is static; the homelab is not |