procomm5 of 12 ports live

A network lab, built in the open.

procomm.uk is where I put networking, edge and self-hosting skills into practice. Every port on this panel is a real service, and it lights up when it goes live.

Live 5

  • DNS DNSSEC, strict TLS, SPF and DMARC on the zone.
  • Workers This page, rendered per visitor at the edge.
  • KV Stores the changelog below.
  • Email Inbound mail routed by Cloudflare. No mail server.
  • whoami Shows what the edge sees about your connection.

Being built 5

  • Tunnel Lab services published from a Raspberry Pi with no open ports.
  • Access Zero Trust login in front of admin tools.
  • Pi-hole Network-wide DNS filtering for the house.
  • UniFi Cloud Key controller, VLANs and Wi-Fi design.
  • Guest Test guest Wi-Fi with a QR join card and portal.

Planned 2

  • Grafana Prometheus and Grafana dashboards for the lab.
  • Rack A rack server for VMs and containers.

Your route to this page

That's a real trace of how you got here, built from your own request. The last hop is my home lab. It answers once the tunnel from the Raspberry Pi is up.

See everything the edge knows about your connection

$ traceroute procomm.uk 1 you ok Anthropic, PBC, Columbus, US 2 cloudflare-cmh ok 2 ms HTTP/2 TLS 1.3 3 procomm-worker ok rendered this page for you 4 home-lab * * * no reply yet, the tunnel is still being built

Changelog

Everything shipped to the lab, newest first. Things break here so they don't break anywhere that matters.

  1. Patch panel redesign

    New homepage: every lab service is a port on a patch panel, lit when it goes live. Plus a live traceroute and this changelog in Workers KV.

  2. whoami

    A page that shows visitors what the edge learned about their connection: IP, ISP, data centre, TLS and round-trip time.

  3. Email routing

    Inbound mail for the domain handled by Cloudflare Email Routing, with DKIM and SPF. No mail server to run.

  4. First page on a Worker

    procomm.uk and www live, served from a Cloudflare Worker with no origin server.

  5. Domain locked down

    Zone on Cloudflare with DNSSEC, TLS 1.2 minimum, Full (strict) SSL, Always HTTPS and strict DMARC.