Project portfolio

Current Technical Projects and Roadmap

A selection focused on real operations: infrastructure, monitoring, security, documentation, smart home and public services.

current

Production and Improvement Projects

Supervised personal Home Lab

In production

Personal infrastructure operated as a production-like environment.

  • Separate technical roles
  • Monitor availability and incidents
  • Document useful procedures
Proxmox VEDebianPBSUniFiGrafana

Grafana / Prometheus / Loki monitoring stack

In production

Operations-oriented observability with metrics, logs, alerts and dashboards.

  • Visualize global health
  • Detect degradation
  • Reduce alert noise
GrafanaPrometheusLokiBlackbox ExporterSNMP Exporterntfy

Redundant AdGuard Home + Unbound DNS

In production

Two redundant DNS servers based on AdGuard Home and Unbound provide DNS filtering, privacy, high availability and automatic configuration synchronization.

  • Keep two independent DNS servers
  • Synchronize AdGuard Home automatically
  • Keep local Unbound on each server
  • Filter and log requests cleanly
AdGuard HomeUnboundadguardhome-syncUniFiVLANDNS

Home Assistant Smart Home

In production / improving

Local smart home integrated into the home lab with Matter, Zigbee and monitoring.

  • Centralize devices
  • Reduce cloud dependency
  • Automate scenarios
  • Integrate metrics into Grafana
Home AssistantMatterZigbeeUniFi IoTPhilips TVIR

Self-hosted tools suite

In production

Useful web services published cleanly behind an NPMplus reverse proxy.

  • Publish without overexposure
  • Keep administration clear
  • Document services
  • Monitor public services
DockerNPMplusTLSDebianIT-ToolsStirling PDFVERTPingvin SharePassword PusherExcalidraw

Outline documentation

In production

Central knowledge base for procedures, runbooks, architecture and technical decisions.

  • Centralize runbooks
  • Document changes
  • Make recovery easier
  • Keep infrastructure explicit
OutlineDockerPostgreSQLRedisMarkdown

Apache Guacamole bastion

In production

Centralized administration bastion for SSH access to VMs, with documented connections and restricted access.

  • Centralize administration access
  • Avoid direct exposure
  • Keep SSH connections consistent
  • Keep sensitive interfaces internal
Apache GuacamoleSSHPostgreSQLMFABastion

NetAlertX network inventory

In production

Automated network inventory used to track assets, detect new devices and keep the lab map consistent.

  • Inventory assets
  • Detect new devices
  • Monitor network changes
  • Document the current state
NetAlertXUniFiInventoryVLANMonitoring

Cowrie honeypot in DMZ

Improving

Isolated SSH honeypot used to observe automated attacks.

  • Collect SSH attempts
  • Enrich events
  • Feed security analysis
  • Correlate logs
CowrieLokiGrafanaDMZGeoIP

Public portfolio + SEO

In production / improving

Public Next.js website with technical SEO, FR/EN versions and professional content.

  • Keep canonical URLs
  • Fix errors
  • Improve search visibility
  • Highlight projects
Next.jsSEOhreflangsitemapOpen Graph

NPMplus

In production

Production reverse proxy with TLS, controlled publication, retained rollback and CrowdSec integration.

  • Retained rollback
  • Full backup
  • Header validation
  • Rollback plan
  • Public service validation
NPMplusNginxTLSHTTP/3CrowdSec

planned

Priority and Planned Projects

These projects are presented as a roadmap, not as already deployed services.

Google Search Console + Grafana SEO dashboard

Priority project

SEO tracking dashboard for all public services via Google Search Console and Grafana.

  • Track clicks
  • Track impressions
  • Track CTR
  • Track positions
  • Compare public services
Google Search ConsoleAPIGrafanaPrometheus or intermediate database

Portainer / Docker administration

Priority project

Docker administration web interface for hosts and application stacks.

  • Manage stacks
  • Read logs
  • Restart services
  • Simplify administration
PortainerDocker ComposeDebianNPMplus

NAS Monitoring Website

Planned project

Dedicated interface to visualize Synology NAS and storage health.

  • Global NAS status
  • Volumes, disks and SMART
  • Temperatures and storage
  • SMB/NFS availability
SynologySNMPGrafanaPossible APIMonitoring

CrowdSec Manager

Planned project

Local web interface to visualize and administer CrowdSec.

  • View banned IPs
  • Follow alerts
  • Manage decisions
  • Simplify security administration
CrowdSecNPMplusDockerLocal reverse proxy

contact

Contact

Available to discuss a work-study opportunity, a project or a technical topic.

contact@morgan-mathis.com