Lexicanum
Notes and references on the stuff I actually run. Each entry is a deep-dive: implementation steps, real configs, the failure modes I hit along the way. Guides are task-sequenced how-tos; reference docs explain how a system works and which option to pick. / searches everything.
Supabase
Where tenants live, what they cost, and how to move them - the largest cluster here.
All Supabase docs (23)
- Build a public-record entity graph on managed Postgres
- Consolidating one Supabase project per customer onto a shared project
- Migrate a Supabase project to another region, end to end
- Migrating a static MongoDB archive into Postgres with the Supabase MongoDB wrapper
- Migrating PBKDF2 password hashes into Supabase Auth
- Monitor Supabase with Grafana: dashboards and alerting
- Moving Supabase projects under one organization
- Promoting a tenant to its own Supabase project
- Running many tenants on one Supabase project
- Set up AWS PrivateLink to Supabase with OpenTofu
- Supabase preview-branch compute sizing & a CI parity model
- Supabase resilience runbook: probes, TTL levers, edge cache, warm standby
- Trusted-device MFA and impersonation audit trails on Supabase Auth
- Upgrade a Supabase project to a new Postgres major version, end to end
- AWS PrivateLink to Supabase: an architecture reference (reference)
- Cloudflare Workers + Supabase: an architecture reference (reference)
- Entity graphs on managed Postgres (reference)
- Stripe Sync Engine: schema projection, version drift, and the FDW alternative (reference)
- Supabase data residency and sovereignty (reference)
- Supabase disaster recovery tiers: daily backups, PITR, warm standby - RPO, RTO, and cost (reference)
- Supabase incidents: what a client can actually do - a resilience reference (reference)
- What a Supabase platform operation costs a client (reference)
- Where should a tenant live: one Supabase project per tenant, or many (reference)
Cloudflare
Workers, caching, tunnels, and the WAN - the edge provider half of the estate.
All Cloudflare docs (6)
Kubernetes
k3s on ARM64: deployment, ingress, and observability.
All Kubernetes docs (3)
Networking and DNS
The self-hosted edge and the resolvers behind it.
All Networking and DNS docs (3)
Homelab and self-hosting
The services that run on the home network, and the network they run on.
All Homelab and self-hosting docs (10)
- Add Prometheus monitoring to a Compose Postgres stack
- AirGradient ONE on ESPHome, fully local
- Multi-site Vaultwarden: PostgreSQL, R2 sync, and Cloudflare load balancer failover
- Self-hosting Matrix + Element Call on k3s with Cloudflare and VyOS
- Singapore weather alerts and live maps with Home Assistant and Grafana
- Docker Servarr stack security: hardening media automation (reference)
- Home IoT: an ESPHome fleet on a Flint-bridged VLAN (reference)
- Media transformation architecture (reference)
- Monitoring a self-hosted stack behind a policy-drop edge (reference)
- Tailscale homelab reference: overlay as second path and management plane (reference)
Workstations and tooling
Hardware tuning and the tooling around the machines.
All Workstations and tooling docs (7)
- Creating QMK, VIA, and Vial keymaps
- Extending your Terraform configuration with the http provider
- Reclaiming disk space from WSL2 and Docker Desktop
- Setting up Steam Deck (Steam OS) with Nix
- Tuning a USB4 10GbE adapter on Windows
- A cross-client memory store for coding agents (reference)
- Benchmarking local models for agent work (reference)
Contributing
Section titled “Contributing”Every page has an Edit this page link in the right rail that opens the source on GitHub. PRs welcome.