Skip to content
View nopoz's full-sized avatar

Block or report nopoz

Block user

Prevent this user from interacting with your repositories and sending you notifications. Learn more about blocking users.

You must be logged in to block users.

Maximum 250 characters. Please don’t include any personal information such as legal names or email addresses. Markdown is supported. This note will only be visible to you.
Report abuse

Contact GitHub support about this user’s behavior. Learn more about reporting abuse.

Report abuse
nopoz/README.md

I build operations tooling for containerized infrastructure, networking, and DNS, designed to run anywhere from a homelab to production.

Projects

release CI

Monitors container images across one or many hosts and drives controlled, health-aware updates: semver-aware classification, one-click upgrades with live console output, and notifications via Slack, Discord, Telegram, SMTP, and webhooks. The middle ground between risky auto-updates and manual patching.

release CI

Brings encrypted DNS (DNSCrypt, DoH, Oblivious DoH, Anonymized DNS) to pfSense firewalls with a full management GUI. Signature-verified builds with SLSA provenance for supply-chain assurance.

release CI

Backs up, restores, and migrates Portainer stacks as plain, version-controllable Docker Compose files. Supports GitOps workflows, disaster recovery, and environment migration without all-or-nothing database snapshots.

Security & CI/CD

I treat the pipeline as part of the product. Practices I apply across my projects and contributions:

  • Default-deny GitHub Actions permissions (permissions: {}), with each job opting back into the least scope it needs.
  • Third-party actions pinned to commit SHAs rather than mutable tags, to close supply-chain gaps.
  • Layered scanning: secret detection (gitleaks), workflow auditing (actionlint, zizmor), dependency review, Dockerfile and image scanning (hadolint, Trivy), and CodeQL static analysis.
  • Signed, attested release artifacts (SLSA provenance) so downstream users can verify what they install.

Also contribute to

Home Assistant · odysseus

Focus areas

Container operations · Encrypted DNS · Network security · Backup & migration · CI/CD supply-chain security

Pinned Loading

  1. hosaka hosaka Public

    Docker image update monitor with notifications and one-click updates.

    JavaScript 3 1

  2. portrieve portrieve Public

    Back up, restore, and migrate Portainer stacks as plain Docker Compose files.

    Shell 5 1

  3. pfsense-dnscrypt-proxy pfsense-dnscrypt-proxy Public

    pfSense package for DNSCrypt Proxy - encrypted DNS with full GUI support

    PHP 16

  4. pewdiepie-archdaemon/odysseus pewdiepie-archdaemon/odysseus Public

    Self-hosted AI workspace.

    Python 74.1k 9.5k

  5. DNSCrypt/dnscrypt-proxy DNSCrypt/dnscrypt-proxy Public

    dnscrypt-proxy 2 - A flexible DNS proxy, with support for encrypted DNS protocols.

    Go 13.4k 1.1k

  6. home-assistant/core home-assistant/core Public

    🏡 Open source home automation that puts local control and privacy first.

    Python 87.8k 37.7k