Edy-Auth
Self-hosted authentication for every other service here. Pluggable providers, per-realm registries, client-side password derivation so credentials never cross the wire in the clear.
Edward Skarke · infrastructure & identity
A working estate of identity, provisioning, directory and virtualisation services — each one built to be run, inspected and handed over, not just demonstrated. The same engineering is available as consulting, including moving an estate off VMware.
Catalog
Eight things that run here.
Self-hosted authentication for every other service here. Pluggable providers, per-realm registries, client-side password derivation so credentials never cross the wire in the clear.
Reverse proxy and network services in Go — DHCP and DNS for the lab network, TFTP/iPXE chain for unattended Windows deployment, and ARP-change monitoring.
Unattended Windows 11 over PXE — UEFI Secure Boot, TPM 2.0 emulation, answer-file driven, with the iPXE chain that actually survives being loaded as a UEFI NBP.
A five-controller Active Directory domain with joined clients, for testing replication, group policy and cross-realm trust without touching anything that matters.
Two plugins: a System Tuner that reports and applies host tuning, and a Remote Desktop console that speaks the Guacamole protocol over a Cockpit channel — no Tomcat, no extra port.
KVM guests on an isolated NAT network with libvirt DHCP and DNS deliberately disabled, so the lab is served by Edy-Proxy instead and boots exactly the way a real deployment would.
Two independent podman scopes — a rootful estate for services that need real, routable addresses, and a rootless scope for everything that does not. Managed through Portainer.
The site you are reading. Server-rendered, signs you in through Edy-Auth, and hosts the collaboration workspace where projects are put out for proposal.
Open source
Cockpit plugins for WireGuard, Headscale, system tuning, password safes and remote desktop; a containerised Active Directory lab; and a long tail of PowerShell and Python tooling. Source, and the documentation that explains it.
Consulting
Headlined by VMware alternative consulting — assessment, pilot, migration and operation of KVM, Proxmox, oVirt, XCP-ng, Hyper-V and container platforms — alongside Linux host tooling, remote access, directory and identity, network services and automation.
About
Senior infrastructure and security engineer, with twenty-five years in IT and cybersecurity. The work is Linux and Windows platform engineering: host management tooling, directory and identity services, network services and remote access, and the automation and documentation that let somebody else operate the result.
Everything described on this site runs on the estate it describes — the catalog, the identity service in front of it and the network services behind it are the same stack the consulting is about.
Work history lives on LinkedIn; it is deliberately not reprinted here.
Collaboration
Register a piece of work, publish it when it is ready, and collect proposals from signed-in collaborators.