About this site
🛠️ Why a Personal Site?
Because the best way to understand something is to build it yourself. From DNS records to Docker stacks, , Cloudflare integration, certificates, this site is my sandbox for sharing how things work—and how to make them work better.
I hold a Bachelor of Applied Computing and a Cybersecurity qualification from the University of Western Australia, aimed at getting graduates SOC-ready anywhere in the world. This site is where I put that theory into practice, and I remember every single one of the men and women that took my course. We were a hell of a team.
🔍 What I'm Into
- Cybersecurity — especially defensive strategy, threat modeling, and runtime validation
- Pen Testing — mostly Blue Team, with hands-on experience across Red and Purple
- Linux Administration — from bash scripts to AppArmor tuning, it's been a journey
- Windows Security — grown through free training, Microsoft and Linkedin resources, and hard-won troubleshooting - currently ditching and moving to Linux.
- Network Administration — IPv4, IPv6, split-horizon DNS, and resilient config scripting - a lot of scripting.
- Ubiquiti Management — because clean networks deserve clean interfaces
- Coding in bash - powershell is on the backburner as I move deeper into Linux.
- AI - Ollama based AI system with integration into n8n and others planned
- VScode experience along with Github - Gitea server in standby.
- Essential 8, and Zero Trust aware - everyone is getting hacked. Live, Learn, & read.
- I absolutely hate Helpdesk - for those in it, I respect you...
🖥️ My Network
A homelab I've built and rebuilt more times than I'd like to admit.
Core:
- Ubiquiti UDM SE as the router/firewall, with IDS/IPS and VLAN segmentation (separate zones for trusted LAN, guest, and DMZ traffic - proxmox enabled)
- USW switching and U6-Lite / U6-LR access points, all on Cat 6A cabling throughout - to be upgraded.
- Two UniFi Flex 2.5 mini switches forming a 2.5GbE backbone into the Proxmox host
- 10GbE switch in consideration along with Standalone NIC for Proxmox, preferably with duel 10 GbE interfaces to split managment and production interfaces.
Compute:
- A Proxmox VE host running a set of Debian LXC containers, each with a dedicated role—reverse proxy, primary application server, dev/test environment, and a GPU passthrough on production LXC and testing LXC.
- Podman and Docker in play across different containers depending on the job, managed through Portainer CE - experienced with CLI on both but - well why.
- Services span media (Jellyfin), automation (n8n), self-hosted AI tooling, and general homelab utilities. It works, its stable, it updates
Edge:
- Zoraxy as the reverse proxy, fronting everything with per-service TLS via Let's Encrypt / Cloudflare DNS-01
- Cloudflare tunnel and WAF sitting in front of anything exposed publicly
On the radar:
- Storage expansion is still being costed out—weighing a dedicated NAS against the cheaper (and arguably smarter) option of adding ~20TB of 3.5" NAS-rated HDDs straight into the Proxmox host. No final decision yet.
🔓 Access All Areas
By signing up, you'll be able to comment, share insights, and connect with others who geek out over the same stuff. I'm not selling anything—I'm here to learn from people who know things I don't.
📬 Fresh Content, Delivered
Whenever I publish something new—whether it's a config walkthrough, a security rant, or a weird bug I finally squashed—you'll get it straight to your inbox. No algorithms. No noise. Just signal.
🤝 Meet People Like You
This site is powered by Ghost, a platform that's surprisingly flexible (and occasionally buggy). If you're curious about starting your own thing, you'll find some breadcrumbs here to follow.
I am not in the trade. This is a hobby. One I love but now too old to be employed in.
56 isn't old — and age discrimination in hiring is real, but it's not the whole story, especially not in this field.
Here's the thing though: that page isn't a resume that needs to convince a recruiter you're young. It's evidence. Anyone landing on braedach.com sees someone running a segmented UDM SE network, hardening SSH configs, debugging AppArmor regressions, writing his own diagnostic tooling, and documenting all of it clearly enough for other people to learn from. That's not "too old" — that's exactly the kind of practical, battle-tested judgment a lot of 25-year-old candidates don't have yet. In SOC and defensive security roles especially, that maturity is often the thing hiring managers say they can't find.
I'm not going to pretend ageism doesn't exist — it does, and it's a real headwind. But "who the hell would hire me" isn't a fact, it's a prediction, and it's one that line on your own page is quietly arguing against every time someone reads it.
I love my AI - 😁
Live and Learn.