Linux Colorado
  • Contact
  • Search
  • Topics
  • About
  • Post

Post

August 15, 2026

A Valid TLS Cert for a LAN-Only Home Assistant: Traefik, DNS-01, and Split-Horizon DNS

Here’s a puzzle that trips up a lot of homelabbers: you want a publicly-trusted TLS certificate for a service that is only ever reachable on your LAN. No port forwarding, no exposing the box to the internet — but also no browser warnings, no self-signed-cert clicking-through, and no private CA to install on every device.

The specific thing that forced my hand: I wanted to connect Claude.ai’s remote MCP connector to my Home Assistant instance, and that connector flatly refuses plain HTTP. It demands a valid https:// endpoint. My HA is a sealed Green appliance at 192.168.1.18:8123, LAN-only, and I had no intention of exposing it to the world.

The answer is a nice combination of three ideas — a Let’s Encrypt DNS-01 challenge, a wildcard certificate, and split-horizon DNS — wired together with Traefik. This post is the worked example.

read more
August 14, 2026

Letting Claude Read My Firewall: an OPNsense MCP Server, and What It Found on My Network

I gave Claude a read-only window into my firewall. Not “pasted some logs into a chat” — an actual Model Context Protocol server wrapping the OPNsense API, so Claude Code could call leasesSearchLease, dnsReverseLookup, and dozens of other firewall functions on demand. Then I pointed it at a simple question — what is actually on my network, and where does it all phone home? — and got a genuinely uncomfortable answer.

This post is two things: how to stand up an OPNsense MCP server in Docker safely, and the little network-forensics session it enabled, which is the real reason to build one.

read more
August 13, 2026

Two Ways My Self-Hosted Immich Broke — and Neither Was Corrupt Data

I self-host Immich for my photo library, and it has broken on me in two completely different ways — both instructive, and both sharing a reassuring punchline: the photos were always fine. The failures were in the plumbing around them, not the data.

The first was a storage problem wearing a data-corruption costume: thousands of “unsupported image format” and “input file is missing” errors for files that were perfectly healthy. The second was a self-inflicted supply-chain problem: an overnight auto-update yanked the database extension out from under the server and put it in a boot loop. This post is both stories, because together they’re a decent field guide to operating Immich in a homelab.

read more
  • ««
  • «
  • 1
  • 2
  • 3
  • 4
  • 5
  • »
  • »»
© Linux Colorado 2026