The homelab has no change control board.1
I explain enterprise infrastructure for a living. At home, the same instincts operate without oversight. This is where I document the results — and, when necessary, defend the decisions.
The blog does not exist yet. This sentence will be quietly removed the day that changes.
About
I'm a Portfolio Solutions Engineer at Cisco Systems, working at the intersection of enterprise networking and security — which mostly means explaining, in various rooms, why the network is doing that.2 My background covers data center infrastructure — virtualization, storage, networking, and security — with a persistent interest in making complex systems legible to the humans who actually have to run them at 2am.
Outside of work, I build things that don't strictly need to be built. Currently that's a self-hosted AI platform wrapped in a full Cisco security stack, running across four physical machines in what I optimistically call a lab. It's part learning environment, part portfolio project, and part earnest attempt to answer a specific question: what actually happens when you put enterprise-grade security controls around a local LLM? So far, the answer involves a great deal of YAML.
This site is where I write about that project, and whatever else I'm currently overcomplicating.
Projects
planet-express
A self-hosted AI homelab — the name, like the hardware, is a Futurama reference3 — built as a Cisco Solutions Engineer learning platform: four physical servers, a full Cisco security architecture, and — eventually — an on-premises pre-sales intelligence tool called the SE Prep Assistant4 that's designed to never let customer data leave the building. It's early. How early is the point of the next two paragraphs.
Running now
Two GPU nodes — an RTX 5060 Ti and an RTX 3070 Ti — serving multiple local models through Ollama and Open WebUI. A Proxmox hypervisor coordinating all of it on a dual-Xeon workstation with more RAM than any homelab strictly requires. Internal DNS and NTP via CoreDNS and chrony, because guessing IP addresses gets old fast. A seven-VLAN network, segmented by an actual Cisco switching fabric rather than good intentions.
Not yet, but planned
HashiCorp Vault for secrets and internal certificates. A Cisco Firepower and Secure Firewall pair doing real east-west segmentation. Duo and ISE for identity, eventually with TrustSec tags doing the classifying instead of IP addresses. A Kubernetes cluster running Cilium, because apparently the CNI you choose says something about you. And, at the center of it, the SE Prep Assistant itself — a tool that's supposed to turn a company name into a customer brief, a competitive assessment, and a slide, in under two minutes, without a single byte of customer data leaving the network. Currently it turns a company name into nothing, on account of not existing yet.5
Notes
- This is not a metaphor. There is, in fact, no board of any kind. There is a spreadsheet, and it is aspirational. ↩
- It is usually DNS. ↩
- The four physical servers are named fry, bender, professor, and hermes. I regret nothing. ↩
- Or whatever other uninspired idea I've come up with by then. ↩
- Ask again in a few months. ↩