Wikispace¶
The Wikispace is a curated knowledge base covering systems administration, networking, security, AI tooling, 2026 technologies, and development workflows. Each section documents practical configurations, exact commands, and tested procedures.
Overview¶
What this page covers
This page serves as the master index for the Wikispace knowledge base:
- Systems Administration — Windows, iOS, WSL, applications, driver management
- Networking — DNS, iptables, IPv6, router firmware, WireGuard, ZeroTier
- AI and Development — Local LLM deployment, AI agent stack, modern technologies
- Security — 9-layer defense-in-depth model with specialized subsections
For the XML Project documentation, see XML Project. For individual projects, see Projects. For the curated external resource archive, see Deep Hole.
Wikispace Structure¶
flowchart TD
subgraph SysAdmin["Systems Administration"]
direction TB
S1["Windows Wiki"]
S2["Windows Advanced"]
S3["WSL Guide"]
S4["iOS"]
S5["Apps"]
S6["Portmaster Deep"]
end
subgraph Networking["Networking"]
direction TB
N1["DNS / iptables"]
N2["IPv6"]
N3["WireGuard"]
N4["ZeroTier"]
N5["Router Firmware"]
N6["Datacenters"]
end
subgraph AI["AI & Development"]
direction TB
A1["Local LLM"]
A2["AI Agent Stack"]
A3["Modern Objects 2026"]
end
subgraph Sec["Security"]
direction TB
SE1["9-Layer Model"]
SE2["Minimalism"]
SE3["Encryption"]
SE4["Hypervisors"]
end
style SysAdmin fill:#4a90d9
style Networking fill:#7ed321
style AI fill:#f5a623
style Sec fill:#9013fe
Systems Administration¶
- Windows Wiki — Windows setup walkthrough, system commands, registry, file operations
- Windows Advanced — Group Policy DNS hardening, dcomcnfg, sysdm.cpl, taskschd.msc, services.msc, forests/AD
- Microsoft Documentation — PowerShell, Windows commands, .NET, Azure, M365, security baselines
- Applications — Microsoft 365, VS Code workflows, driver management, package management
- Portmaster Deep — Advanced firewall rules, svchost analysis, Edge WebView2, IPv6 management
- iOS — Configuration profiles, Shortcuts automation, hidden settings, native apps guide
- WSL Guide — WSL2 installation, Kali Linux, Windows integration, Qubes comparison
Networking¶
- DNS / iptables + ip6tables / IANA / IPv6 — DNS resolution, firewall rules, port assignments
- iptables Deep — Low-level iptables rule construction, match extensions, NAT, complete rulesets
- IPv6 — Dedicated IPv6 addressing, ULA subnetting, ip6tables, Windows configuration
- IANA Internet Standards — Protocol registries at every OSI layer, port assignments, MIME types
- Router Firmware (OpenWRT / FreshTomato) — Third-party router firmware, DNS security, ad blocking
- FreshTomato Infrastructure — Full FreshTomato feature set, custom scripts, QoS
- GL.iNet / LuCI — VLAN configuration, MLO Wi-Fi, Qualcomm NSS, nftables
- OpenWRT LuCI — Web interface documentation, CBI, custom pages, API
- WireGuard Server — Windows WireGuard server setup, key management, NAT routing
- ZeroTier — SDN mesh networking, self-hosted controller, sovereignty implications
- Datacenters and Network Infrastructure — Colocation, WireGuard, GL.iNet, Cologix
- Hetzner Sovereign — ASN acquisition, NAT64/DNS64, ZeroTier controller hosting
AI and Development¶
- Local LLM Deployment — vLLM inference, quantization, torch.compile, hardware requirements
- Modeling — "Want to get into modeling?" — Ollama vs vLLM debate, AI agent stack, setup guides
- AI Agent Stack — Terminal agents, IDE agents, model serving, redirect proxies
- Modern Objects 2026 — 18650 batteries, powerwalls, atmospheric water, solar, gadgets
- DNN Analysis — Hybrid web architecture, DotNetNuke, Giraffe ViewEngine comparison
Security¶
- Security Overview — Defense in depth: 9-layer security model
- Minimalism — Attack surface reduction, service disabling
- Permissions — ACL management, least-privilege principles
- Encryption — AES, RSA, TLS/SSL, key management
- Steganography — LSB data hiding in images and audio
- Compression — Lossless and lossy compression algorithms
- Encoding — Base64, URL encoding, HTML entities
- Containerization — Docker, Podman, security constraints
- Hypervisors — Qubes OS, Proxmox, Xen vs KVM, VFIO passthrough
- Hosting — Web server hardening, TLS, DDoS mitigation
OSI Layer Security Mapping¶
Network security controls map to specific OSI model layers. Controls at each layer are independent and complementary.
flowchart TD
L7["Layer 7: Application<br/>HTTP, DNS, SMTP"] -->|"WAF, input validation"| L6
L6["Layer 6: Presentation<br/>TLS/SSL, encoding"] -->|"Certificate pinning<br/>Cipher selection"| L5
L5["Layer 5: Session<br/>Session management"] -->|"Token auth<br/>Session timeout"| L4
L4["Layer 4: Transport<br/>TCP/UDP, ports"] -->|"iptables, WireGuard"| L3
L3["Layer 3: Network<br/>IP, routing"] -->|"IPsec, ACLs, RPF"| L2
L2["Layer 2: Data Link<br/>Ethernet, Wi-Fi"] -->|"MAC filter, VLAN, WPA3"| L1
L1["Layer 1: Physical<br/>Cables, radio"] -->|"Physical locks<br/>Faraday cages"| END["Defense in Depth"]
style L7 fill:#d0021b
style L4 fill:#4a90d9
style L1 fill:#7ed321
style END fill:#f5a623
| Layer | Function | Security Controls |
|---|---|---|
| 7 — Application | HTTP, DNS, SMTP | WAF, input validation, secure coding |
| 6 — Presentation | TLS/SSL, encoding | Certificate pinning, cipher suite selection |
| 5 — Session | Session management | Token-based auth, session timeout |
| 4 — Transport | TCP/UDP, port numbers | iptables/ip6tables, port knocking, WireGuard |
| 3 — Network | IP, routing | IPsec, ACLs, reverse path filtering |
| 2 — Data Link | Ethernet, Wi-Fi | MAC filtering, VLAN segmentation, WPA3 |
| 1 — Physical | Cables, radio | Physical locks, Faraday cages |
For detailed firewall configuration, see the DNS and Firewall page or iptables Deep. For encryption and container security, see the Security section.