Cheap Phone Service and Whole-House Intercom with FreePBX + SignalWire
Business phone service — RingCentral and the like — runs $20–35 per seat per month, locks your desk phones to their firmware, and puts your dial tone at the mercy of someone else’s cloud. I replaced all of it with a self-hosted PBX that costs a few dollars a month in actual usage, keeps every phone on hardware I own, and adds something the commercial offerings either charge extra for or simply don’t do: push-to-talk intercom between rooms. Dial the kitchen, it answers itself on speaker, you talk.
The whole thing is four Docker containers on one host, one DNS record on another, and a single SIP trunk in the cloud. Everything else is a text file.
A note on the examples: this runs on my real network with real family phone numbers on it. Every phone number, personal name, and account identifier below is synthetic — invented for illustration and drawn from the
555-01xxrange reserved for fiction. The configuration is real and copied verbatim from the running system; only the personal data is swapped. If you build one of these, keep your own credentials and family numbers out of your blog. I’m practicing what I preach.
A Valid TLS Cert for a LAN-Only Home Assistant: Traefik, DNS-01, and Split-Horizon DNS
Here’s a puzzle that trips up a lot of homelabbers: you want a publicly-trusted TLS certificate for a service that is only ever reachable on your LAN. No port forwarding, no exposing the box to the internet — but also no browser warnings, no self-signed-cert clicking-through, and no private CA to install on every device.
The specific thing that forced my hand: I wanted to connect Claude.ai’s remote MCP connector to my Home Assistant instance, and that connector flatly refuses plain HTTP. It demands a valid https:// endpoint. My HA is a sealed Green appliance at 192.168.1.18:8123, LAN-only, and I had no intention of exposing it to the world.
The answer is a nice combination of three ideas — a Let’s Encrypt DNS-01 challenge, a wildcard certificate, and split-horizon DNS — wired together with Traefik. This post is the worked example.
Letting Claude Read My Firewall: an OPNsense MCP Server, and What It Found on My Network
I gave Claude a read-only window into my firewall. Not “pasted some logs into a chat” — an actual Model Context Protocol server wrapping the OPNsense API, so Claude Code could call leasesSearchLease, dnsReverseLookup, and dozens of other firewall functions on demand. Then I pointed it at a simple question — what is actually on my network, and where does it all phone home? — and got a genuinely uncomfortable answer.
This post is two things: how to stand up an OPNsense MCP server in Docker safely, and the little network-forensics session it enabled, which is the real reason to build one.