Skip to content
@IT-Kuny

IT-Kuny

IT-Kuny

Infrastructure, automation, and self-hosting with a strong bias towards privacy, control, and Linux-first solutions.

  • 🇨🇭 Located in Switzerland
  • Focus: AI Agent agnostic private (like-a-ISP & NOC) data center infrastructure, Proxmox, kernel hardening, hardware-aware tooling and more
  • Philosophy: sustainable, vendor-independent IT with re-use of existing hardware where it makes sense
  • Security: defense-in-depth, CVE tracking, SIEM, kernel-level mitigation — because "it works" isn't good enough

Website: https://it-kuny.ch Self-hosted Git: https://git.it-kuny.ch (currently not exposed to the public)


About IT-Kuny

IT-Kuny is primarily a one-person operation in cooperation with self trained AI agent called Jarvis.

The work sits somewhere between previously homelab, nowadays private data center engineering and NOC/ISP, (and maybe further...) and real-world support:

  • Fixing everyday issues for friends, family, and close contacts (smartphones, PCs, tablets, NAS, Gaming consoles, TVs, TV Box's, Router/Modem, Security cameras etc.)
  • Acting as a consultant and "second brain" for new systems, network redesigns, and infrastructure overhauls
  • Building tools and workflows when existing solutions are too heavy, opaque, or vendor-locked

Most tooling here started as "we have a real problem to solve right now" and was later cleaned up and published.


What you'll find here

This organization collects tools and configurations that help you:

  • Run self-hosted infrastructure (Proxmox, Linux, containers)
  • Automate repetitive operational tasks
  • Harden systems and reduce attack surface
  • Make hardware behaviour more predictable (IOMMU, iLO fans, kernel profiles)
  • Recover broken systems quickly (chroot, storage detection, bootfix)

Most of the daily-driver projects live on a self-hosted Forgejo instance on a private distributed server farm. GitHub is used for public tooling, kernels, and upstream collaboration (and sometimes for experiments that are useful to others).


Key repositories

Core tooling

Repository Description
chrooty Rescue and chroot utility that automates recovery workflows. Handles LVM, ZFS, Btrfs subvolumes, EFI mounts, logging, and a plugin-driven hook system for pre/post-chroot actions. Designed for "fix this system now" scenarios on modern Linux distributions.
Proxmox-Sync-Wildcard Bash automation to securely pull a wildcard TLS certificate from a remote CA / reverse proxy host and deploy it into a Proxmox VE cluster. Includes full store backup, atomic replacement, permission fixes, and minimal service impact (reloads only pveproxy).
dnf-pkgsync Helper script to export and restore package sets between DNF-based systems (migration/bootstrap use-cases).

These projects are designed to be dropped into real environments: rescue media, Proxmox clusters, and automation pipelines.


Infrastructure & Automation

Repository Description
PDC-stack Self-hosted DevOps monorepo for private data center operations. Bundles 9 services (n8n, Grafana + InfluxDB, Zabbix, Wazuh, nginx ECH, UPS Dashboard, WGDashboard, Falco, Akvorado + ClickHouse) with shared networks, volumes, and documentation. Designed for Proxmox/Debian hosts with ZFS storage.
ThinClient-For-Proxmox Thin client orchestration for Proxmox VE environments. Multi-user capable with OOBE, boot-wait phases, SPICE connect, and PAM-based SSO via the companion pam_proxmox module. Currently in active development. (private)
AISec AI-powered network guardian for firewalls — detects known threats, anomalous behaviour, and blocks attackers automatically. Four-layer defense: signature matching, ML anomaly detection, pattern recognition, automatic response. In active development, source code not yet published.

These projects target real virtualization environments — from single-host Proxmox to multi-node clusters with monitoring, SIEM, and automation pipelines.

Collaboration note: The community network backbone (LIXP fleet — FreeBSD/FRR routing, VyOS/IPSec) is designed and operated by a community partner. IT-Kuny hosts its own WireGuard overlay on top of it and the monitoring/NOC stack (Akvorado, Grafana, Zabbix) that runs on top. The fleet itself is not an IT-Kuny product.


Hardware- and platform-specific work

Repository Scope Focus
Thinkpad-P16S-Kernel Opinionated Linux kernel profile for the Lenovo ThinkPad P16s Gen4. Keeps NVMe-only internal storage, USB BOT/UAS disks, USB4/TB4, graphics, audio, camera, LAN, WLAN, BT, and trims unused SATA/SAS/FC/iSCSI paths to reduce complexity and attack surface. Hardware-specific kernel config, IOMMU, VFIO, modern workstation hardening.
HPE-G8-G9-Fan-Controller Fan controller stack for modded iLO4 servers on HPE Gen8/Gen9 platforms. Vibeforked + enhanced. Practical fan control UI/service for homelab ProLiant systems.
HPE-Proliant-G8-G9-Autofan-Controller Standalone thermal controller for HPE ProLiant Gen8/Gen9 with per-sensor curves and adaptive cooling logic. Vibeforked + enhanced. Autonomous thermal management for quiet but safe operation.
UGREEN-DXP-FAN-NAS-Driver Kernel driver for the system fan controller on UGREEN DXP NAS devices. Enables proper fan speed management under Linux where no official driver exists. Hardware driver, NAS platform support, Linux kernel integration.

This is not a generic "one size fits all" kernel - it is a documented profile for a very specific platform and threat model.


Upstream collaboration & forks

Repository Origin Purpose
IOMMU-Report Fork of mkoreneff/iommu_info_generate Curses-based TUI to inspect local platform details and submit IOMMU topology data to iommu.info. Includes API health checks, vendor probes, board existence checks, chunked upload flow, and throttling that respects Retry-After.
HPE-G8-G9-Fan-Controller Fork/continuation in the iLO4 fan-control ecosystem Next.js UI and Dockerized service to control fan speeds on modded iLO4-based HPE Gen8/Gen9 servers. Talks to iLO4 over SSH, exposes presets and dynamic fan layouts, and is homelab-friendly when paired with an auth proxy.
pvekclean Fork of jordanhillis/pvekclean Proxmox VE kernel cleanup tool. Consolidates community PRs and fixes 6 open upstream issues: ZFS /boot support, UEFI/systemd-boot detection, complete header removal, metapackage filtering, and stale dpkg state after purge. Added semantic version comparison for update checks (PR #2). v2.1.0.

These forks are kept close to upstream while adding homelab-centric operational experience.


Communities

  • Nosial (n64.cc) — Member, infrastructure contributor
  • Neternels — Contributor to custom kernel builds for Kali NetHunter
  • Private Security Research Group — knowledge sharing with industry practitioners, including Kali NetHunter Core Team members

Scope & support model

IT-Kuny is not a large service provider. It is mainly:

  • Best-effort support for friends, family, and close contacts and for those who want to get in touch with
  • Help for small environments that share the same philosophy (primarly focused on privacy-focused, realistic budgets) and other environment obviously too

Typical support activities include:

  • End-user systems & apps Fixing issues with Apps (e.g. Google Play, Samsung Browser, iOS App sideloading via XCode, Wireguard), mail clients, office suites, and everyday desktop workflows on Windows, macOS, and Linux. And also for iOS/iPadOS and Android/HarmonyOS.

  • Client devices Troubleshooting and setting up smartphones and tablets (Android, iOS/iPadOS), including accounts, apps, backups, and security and privacy.

  • Storage & NAS systems Deploying and maintaining NAS devices (e.g. Synology, UGREEN and similar), ACL permissions, shared folders, remote access, and backup strategies.

  • Networks & small infra Designing or restructuring small networks (home and small office), including Wi-Fi, routing, VPN, DNS, remote access, and pragmatic security baselines.

  • Consulting & planning Acting as a sounding board for new systems, hardware refreshes, or complete infrastructure overhauls - from "What should I buy?" to "How do we migrate without losing data and while being live?".

Language-wise:

  • 🇨🇭 Swissgerman - native
  • 🇩🇪 German - native
  • 🇬🇧 English - fluent

There is no 24/7 SLA and no marketing team. Expect honest answers, conservative designs, and solutions you can actually maintain yourself.


Technology focus

Typical stack and domains represented across these projects:

  • Operating systems: Linux (Fedora, Debian, Proxmox), with a focus on server and workstation use-cases
  • Infrastructure: Proxmox VE, containers, homelab automation, backup and recovery workflows
  • Security & hardening: Kernel configuration, IOMMU/VFIO, TLS automation, reduced attack surface
  • Scripting & tooling: Bash, Python, TypeScript/Next.js, plus packaging for Debian/RPM where useful
  • Hardware: ThinkPad platforms, HPE ProLiant Gen8, 3× Synology NAS, 1× UGREEN NAS, IOMMU-capable boards and virtualization hosts

If you care about owning your infrastructure, keeping control over your data, and understanding what your hardware is actually doing, you are in the right place.


Contributions & upstream work

Merged upstream contributions

Project Stars Contribution
Lissy93/dashy ⭐ 26k+ Synology NAS deployment guide (PR #567)
louislam/uptime-kuma ⭐ 90k+ Swiss German (de-CH) translation via Weblate
Core-2-Extreme/Video_player_for_3DS German language support (PR #85)
kaisenlinux/kaisen-menu German language string updates

Open upstream contributions

Project Contribution
jordanhillis/pvekclean PR #23 — ZFS boot support, systemd-boot detection, header cleanup, metapackage filter (fixes 6 open issues)

Compliance & security reports

Project Contribution
swiss/trustbroker.swiss Issue #1 — AGPL licensing report: missing project license header adaptation

Original projects — 0n1cOn3 (personal, AI-Assisted)

Project Description
0n1cOn3/LinuxDOOM DOOM port for Linux using OSS audio — vibeported under Hx guidance
0n1cOn3/mumble-iphoneos-swift Swift-based Mumble client for iOS — vibeported from upstream

HPE Fan Controllers (IT-Kuny/HPE-G8-G9-Fan-Controller and IT-Kuny/HPE-Proliant-G8-G9-Autofan-Controller) are vibeforked and enhanced IT-Kuny projects — see Hardware section above.


Personal GitHub — 0n1cOn3

@0n1cOn3 is the personal GitHub account (separate from IT-Kuny). Focus: security tools, spyware IOC blocklists, and vibeported projects.

Notable repos:

  • Spyware IOC Blocklists (NSO/Pegasus, Intellexa/Predator, Paragon/Graphite, Candiru/DevilsTongue) — AI-Assisted Research, Owner-Published
  • LinuxDOOM — DOOM port for Linux (OSS audio)
  • mumble-iphoneos-swift — Swift Mumble client port
  • HandyScripts — macOS/Windows/Linux utility scripts
  • Adfilters — Web filter lists
  • 401 followers, Arctic Code Vault Contributor (2020)

Additional internal tools, Ansible roles, and more live on the self-hosted Git:

Issues and pull requests are welcome on the public repositories here on GitHub. For anything security-sensitive, please use a private contact channel instead of opening a public issue.


Tools, platforms & ecosystem

Tools and technologies I work with - some daily, some project-based:


fedora logo centos logo debian logo ubuntu logo docker logo github logo gitlab logo markdown logo podman logo nginx logo filezilla logo


cloudflare logo bash logo git logo powershell logo python logo cmake logo cplusplus logo ruby logo rust logo swift logo perl logo gradle logo java logo mysql logo postgresql logo html5 logo css logo javascript logo php logo electron logo redis logo nodejs logo ansible logo vscode logo wordpress logo

linux logo windows logo apple logo android logo

Contact

🌐 Website:

https://it-kuny.ch

💬 Telegram:


For project-specific bugs or feature requests, please use the respective GitHub issue tracker.

Pinned Loading

  1. chrooty chrooty Public

    Linux rescue & chroot utility — automated recovery for LVM, ZFS, Btrfs and EFI systems with plugin architecture

    Shell 1

  2. IOMMU-Report IOMMU-Report Public

    Forked from mkoreneff/iommu_info_generate

    TUI Script to import data in the http://iommu.info database

    Python

  3. Thinkpad-P16S-Kernel Thinkpad-P16S-Kernel Public

    A trimmed down Linux Kernel for the Lenovo Thinkpad P16S Gen4

Repositories

Showing 10 of 13 repositories

People

This organization has no public members. You must be a member to see who’s a part of this organization.

Top languages

Loading…

Most used topics

Loading…