// INFRASTRUCTURE · CODE · AUTOMATION

The things that run, and the code that runs them.

Panda DevOps is a working technology practice — self-hosted infra, automation pipelines, and the experiments that come out of a real self-hosted environment. Everything here is deployed, building, or honestly labeled archived.

~/status · live
source-controlstablelive
edge-orchestratorstablelive
ingressdeploybuilding
ci-runnersmulti-nodelive
legacy-apparchived
// projects — what's running
source-control
live

Self-hosted source-control on dedicated compute. Zero-downtime upgrades, container registry, the lot.

Dockersource-controllinux
edge-orchestrator
live

The always-on edge orchestrator — DNS, ingress tunnels, and cron that never sleeps.

edgeCloudflaresystemd
ci-runners
live

CI runners on a mixed-architecture fleet. Tagged + autoscaled-ish, cross-arch builds out of the box.

GitLab CIDockermulti-arch
cloudflare-tunnels
live

Zero-trust ingress. No open ports on the platform. Config-as-code routing per service.

CloudflareCaddyDNS-01
phonebook
building

Value-free credential helper. Resolves rbw entries + injects credentials to subprocess stdin. Never leaks values to transcript.

PythonBitwardenCLI
secret-rotator
live

Manifest-driven secret rotation engine. Multi-provider (Cloudflare, Anthropic, GitLab, Render, Telegram, local generate). Audit-logged, idempotent.

PythonYAMLSOC-2
// stack — what it runs on

The infrastructure, honestly mapped

COMPUTE
compute // x86

Container host. Source-control, registry, runners.

ORCHESTRATION
orchestrator // edge

DNS, ingress tunnels, scheduled jobs, the always-on layer.

BUILD
build // macOS

CI runner + build node. macOS targets and heavier jobs.

STORAGE
storage // nas

Snapshots, backups, offsite sync, restore drills.

INGRESS
ingress

Zero-trust ingress. No open ports, config-as-code routing.

CI/CD
ci-runners

Runners across x86 + macOS nodes. Tagged, autoscaled-ish.

// notes — postmortems & walkthroughs
INFRA2026.06.02 · 9 min
Zero-downtime GitLab upgrades on a single host

Blue-green on one box with Docker, a reverse proxy, and a 90-second cutover window.

CLOUD2026.05.18 · 6 min
Cloudflare Tunnels beat port forwarding every time

Why I closed every inbound port on the platform and didn't look back.

CODE2026.04.27 · 5 min
Erlang C in 40 lines of Python

The staffing formula every WFM tool hides, written out plainly.

PLATFORM2026.04.10 · 7 min
What the leak-detection hook actually catches

A PostToolUse regex stack that flags BASE64/HEX/secret patterns before they reach git or chat.

// contact

Got something to build or break?

Panda DevOps is the technology practice of d8vee. The work is the brand — reach out by email or open an issue.

✉ soporte [at] pandaops [dot] dev ★ github.com/pandadevops