Infrastructure, automation, and self-hosting with a strong bias towards privacy, control, and Linux-first solutions.
- 🇨🇭 Located in Switzerland
- Focus: AI Agent agnostic private (like-a-ISP & NOC) data center infrastructure, Proxmox, kernel hardening, hardware-aware tooling and more
- Philosophy: sustainable, vendor-independent IT with re-use of existing hardware where it makes sense
- Security: defense-in-depth, CVE tracking, SIEM, kernel-level mitigation — because "it works" isn't good enough
Website: https://it-kuny.ch Self-hosted Git: https://git.it-kuny.ch (currently not exposed to the public)
IT-Kuny is primarily a one-person operation in cooperation with self trained AI agent called Jarvis.
The work sits somewhere between previously homelab, nowadays private data center engineering and NOC/ISP, (and maybe further...) and real-world support:
- Fixing everyday issues for friends, family, and close contacts (smartphones, PCs, tablets, NAS, Gaming consoles, TVs, TV Box's, Router/Modem, Security cameras etc.)
- Acting as a consultant and "second brain" for new systems, network redesigns, and infrastructure overhauls
- Building tools and workflows when existing solutions are too heavy, opaque, or vendor-locked
Most tooling here started as "we have a real problem to solve right now" and was later cleaned up and published.
This organization collects tools and configurations that help you:
- Run self-hosted infrastructure (Proxmox, Linux, containers)
- Automate repetitive operational tasks
- Harden systems and reduce attack surface
- Make hardware behaviour more predictable (IOMMU, iLO fans, kernel profiles)
- Recover broken systems quickly (chroot, storage detection, bootfix)
Most of the daily-driver projects live on a self-hosted Forgejo instance on a private distributed server farm. GitHub is used for public tooling, kernels, and upstream collaboration (and sometimes for experiments that are useful to others).
| Repository | Description |
|---|---|
chrooty |
Rescue and chroot utility that automates recovery workflows. Handles LVM, ZFS, Btrfs subvolumes, EFI mounts, logging, and a plugin-driven hook system for pre/post-chroot actions. Designed for "fix this system now" scenarios on modern Linux distributions. |
Proxmox-Sync-Wildcard |
Bash automation to securely pull a wildcard TLS certificate from a remote CA / reverse proxy host and deploy it into a Proxmox VE cluster. Includes full store backup, atomic replacement, permission fixes, and minimal service impact (reloads only pveproxy). |
dnf-pkgsync |
Helper script to export and restore package sets between DNF-based systems (migration/bootstrap use-cases). |
These projects are designed to be dropped into real environments: rescue media, Proxmox clusters, and automation pipelines.
| Repository | Description |
|---|---|
PDC-stack |
Self-hosted DevOps monorepo for private data center operations. Bundles 9 services (n8n, Grafana + InfluxDB, Zabbix, Wazuh, nginx ECH, UPS Dashboard, WGDashboard, Falco, Akvorado + ClickHouse) with shared networks, volumes, and documentation. Designed for Proxmox/Debian hosts with ZFS storage. |
ThinClient-For-Proxmox |
Thin client orchestration for Proxmox VE environments. Multi-user capable with OOBE, boot-wait phases, SPICE connect, and PAM-based SSO via the companion pam_proxmox module. Currently in active development. (private) |
AISec |
AI-powered network guardian for firewalls — detects known threats, anomalous behaviour, and blocks attackers automatically. Four-layer defense: signature matching, ML anomaly detection, pattern recognition, automatic response. In active development, source code not yet published. |
These projects target real virtualization environments — from single-host Proxmox to multi-node clusters with monitoring, SIEM, and automation pipelines.
Collaboration note: The community network backbone (LIXP fleet — FreeBSD/FRR routing, VyOS/IPSec) is designed and operated by a community partner. IT-Kuny hosts its own WireGuard overlay on top of it and the monitoring/NOC stack (Akvorado, Grafana, Zabbix) that runs on top. The fleet itself is not an IT-Kuny product.
| Repository | Scope | Focus |
|---|---|---|
Thinkpad-P16S-Kernel |
Opinionated Linux kernel profile for the Lenovo ThinkPad P16s Gen4. Keeps NVMe-only internal storage, USB BOT/UAS disks, USB4/TB4, graphics, audio, camera, LAN, WLAN, BT, and trims unused SATA/SAS/FC/iSCSI paths to reduce complexity and attack surface. | Hardware-specific kernel config, IOMMU, VFIO, modern workstation hardening. |
HPE-G8-G9-Fan-Controller |
Fan controller stack for modded iLO4 servers on HPE Gen8/Gen9 platforms. Vibeforked + enhanced. | Practical fan control UI/service for homelab ProLiant systems. |
HPE-Proliant-G8-G9-Autofan-Controller |
Standalone thermal controller for HPE ProLiant Gen8/Gen9 with per-sensor curves and adaptive cooling logic. Vibeforked + enhanced. | Autonomous thermal management for quiet but safe operation. |
UGREEN-DXP-FAN-NAS-Driver |
Kernel driver for the system fan controller on UGREEN DXP NAS devices. Enables proper fan speed management under Linux where no official driver exists. | Hardware driver, NAS platform support, Linux kernel integration. |
This is not a generic "one size fits all" kernel - it is a documented profile for a very specific platform and threat model.
| Repository | Origin | Purpose |
|---|---|---|
IOMMU-Report |
Fork of mkoreneff/iommu_info_generate |
Curses-based TUI to inspect local platform details and submit IOMMU topology data to iommu.info. Includes API health checks, vendor probes, board existence checks, chunked upload flow, and throttling that respects Retry-After. |
HPE-G8-G9-Fan-Controller |
Fork/continuation in the iLO4 fan-control ecosystem | Next.js UI and Dockerized service to control fan speeds on modded iLO4-based HPE Gen8/Gen9 servers. Talks to iLO4 over SSH, exposes presets and dynamic fan layouts, and is homelab-friendly when paired with an auth proxy. |
pvekclean |
Fork of jordanhillis/pvekclean |
Proxmox VE kernel cleanup tool. Consolidates community PRs and fixes 6 open upstream issues: ZFS /boot support, UEFI/systemd-boot detection, complete header removal, metapackage filtering, and stale dpkg state after purge. Added semantic version comparison for update checks (PR #2). v2.1.0. |
These forks are kept close to upstream while adding homelab-centric operational experience.
- Nosial (n64.cc) — Member, infrastructure contributor
- Neternels — Contributor to custom kernel builds for Kali NetHunter
- Private Security Research Group — knowledge sharing with industry practitioners, including Kali NetHunter Core Team members
IT-Kuny is not a large service provider. It is mainly:
- Best-effort support for friends, family, and close contacts and for those who want to get in touch with
- Help for small environments that share the same philosophy (primarly focused on privacy-focused, realistic budgets) and other environment obviously too
Typical support activities include:
-
End-user systems & apps Fixing issues with Apps (e.g. Google Play, Samsung Browser, iOS App sideloading via XCode, Wireguard), mail clients, office suites, and everyday desktop workflows on Windows, macOS, and Linux. And also for iOS/iPadOS and Android/HarmonyOS.
-
Client devices Troubleshooting and setting up smartphones and tablets (Android, iOS/iPadOS), including accounts, apps, backups, and security and privacy.
-
Storage & NAS systems Deploying and maintaining NAS devices (e.g. Synology, UGREEN and similar), ACL permissions, shared folders, remote access, and backup strategies.
-
Networks & small infra Designing or restructuring small networks (home and small office), including Wi-Fi, routing, VPN, DNS, remote access, and pragmatic security baselines.
-
Consulting & planning Acting as a sounding board for new systems, hardware refreshes, or complete infrastructure overhauls - from "What should I buy?" to "How do we migrate without losing data and while being live?".
Language-wise:
- 🇨🇭 Swissgerman - native
- 🇩🇪 German - native
- 🇬🇧 English - fluent
There is no 24/7 SLA and no marketing team. Expect honest answers, conservative designs, and solutions you can actually maintain yourself.
Typical stack and domains represented across these projects:
- Operating systems: Linux (Fedora, Debian, Proxmox), with a focus on server and workstation use-cases
- Infrastructure: Proxmox VE, containers, homelab automation, backup and recovery workflows
- Security & hardening: Kernel configuration, IOMMU/VFIO, TLS automation, reduced attack surface
- Scripting & tooling: Bash, Python, TypeScript/Next.js, plus packaging for Debian/RPM where useful
- Hardware: ThinkPad platforms, HPE ProLiant Gen8, 3× Synology NAS, 1× UGREEN NAS, IOMMU-capable boards and virtualization hosts
If you care about owning your infrastructure, keeping control over your data, and understanding what your hardware is actually doing, you are in the right place.
| Project | Stars | Contribution |
|---|---|---|
Lissy93/dashy |
⭐ 26k+ | Synology NAS deployment guide (PR #567) |
louislam/uptime-kuma |
⭐ 90k+ | Swiss German (de-CH) translation via Weblate |
Core-2-Extreme/Video_player_for_3DS |
— | German language support (PR #85) |
kaisenlinux/kaisen-menu |
— | German language string updates |
| Project | Contribution |
|---|---|
jordanhillis/pvekclean |
PR #23 — ZFS boot support, systemd-boot detection, header cleanup, metapackage filter (fixes 6 open issues) |
| Project | Contribution |
|---|---|
swiss/trustbroker.swiss |
Issue #1 — AGPL licensing report: missing project license header adaptation |
| Project | Description |
|---|---|
0n1cOn3/LinuxDOOM |
DOOM port for Linux using OSS audio — vibeported under Hx guidance |
0n1cOn3/mumble-iphoneos-swift |
Swift-based Mumble client for iOS — vibeported from upstream |
HPE Fan Controllers (
IT-Kuny/HPE-G8-G9-Fan-ControllerandIT-Kuny/HPE-Proliant-G8-G9-Autofan-Controller) are vibeforked and enhanced IT-Kuny projects — see Hardware section above.
@0n1cOn3 is the personal GitHub account (separate from IT-Kuny). Focus: security tools, spyware IOC blocklists, and vibeported projects.
Notable repos:
- Spyware IOC Blocklists (NSO/Pegasus, Intellexa/Predator, Paragon/Graphite, Candiru/DevilsTongue) — AI-Assisted Research, Owner-Published
- LinuxDOOM — DOOM port for Linux (OSS audio)
- mumble-iphoneos-swift — Swift Mumble client port
- HandyScripts — macOS/Windows/Linux utility scripts
- Adfilters — Web filter lists
- 401 followers, Arctic Code Vault Contributor (2020)
Additional internal tools, Ansible roles, and more live on the self-hosted Git:
- 🔗 Forgejo: https://git.it-kuny.ch (currently internal-only; public exposure under evaluation)
Issues and pull requests are welcome on the public repositories here on GitHub. For anything security-sensitive, please use a private contact channel instead of opening a public issue.
Tools and technologies I work with - some daily, some project-based:
🌐 Website:
💬 Telegram:
For project-specific bugs or feature requests, please use the respective GitHub issue tracker.