Thai Acuna

System Administrator | Network & Home Lab Specialist

Resume (PDF)
Infrastructure Status: All core nodes online (THQlab, THAIA, TheOnePump) Domain: themagicalforest.net

Home Lab Infrastructure

THQlab Node

Docker Desktop & WSL2 Ubuntu host running Nginx Proxy Manager (80/443 ingress), Pi-hole DNS ad-blocking, and dedicated gaming containers (Palworld).

THAIA Rig (Main Workstation)

AMD Ryzen 7 5800X / 48GB DDR4 host running central Portainer UI and environment agents across private Twingate overlays.

TheOnePump Node

Entertainment & media node linked into Twingate zero-trust remote access overlay network.

Ingress & DNS Layer

Cloudflare DNS edge integration with Let's Encrypt wildcard SSL (*.themagicalforest.net) via Let's Encrypt DNS-01 verification challenges.

Network Architecture & Traffic Flow

                flowchart TD
                    SubGraph1[Remote / Mobile Traffic] -->|Twingate VPN Tunnel| Router[Netgear Orbi Mesh Router]
                    Internet([Public Internet]) -->|Edge Proxy| CF[Cloudflare Edge DNS]
                    
                    subgraph HomeLab [Home Lab Infrastructure]
                        Router --> Pihole[Pi-hole DNS Sinkhole]
                        Router --> NPM[Nginx Proxy Manager Ingress]
                        
                        NPM -->|HTTP/443 Wildcard SSL| PortainerUI[Portainer UI @ THAIA]
                        NPM -->|Internal Forward| PiholeUI[Pi-hole Admin Web UI]
                        
                        Router -->|Direct UDP Game Ports| Palworld[Palworld Server Container @ THQlab]
                    end
                

Project Case Study: Zero-Trust Remote Ingress & DNS Sinkholing

Problem Statement

Exposing home lab management web UIs (Portainer, Pi-hole) and custom game server instances directly to the public internet via port forwarding creates security vulnerabilities and exposes home IP addresses to scanning.

Solution & Implementation

Architected a hybrid ingress model combining Cloudflare API DNS-01 challenge automation in Nginx Proxy Manager for wildcard SSL termination (*.themagicalforest.net), combined with a network-wide Pi-hole DNS sinkhole and a Twingate zero-trust software overlay across all primary lab machines (THQlab, THAIA, TheOnePump).

Key Technical Takeaways

  • Eliminated exposed administration ports to the outside internet.
  • Automated trusted SSL certificate provisioning without open HTTP/80 validation ports.
  • Achieved network-wide ad and domain filtering across both desktop and mobile clients.

Infrastructure Code Snippets

Nginx Proxy Manager Stack (Portainer Compose)


version: '3.8'

services:
  app:
    image: 'jc21/nginx-proxy-manager:latest'
    container_name: nginx-proxy-manager
    restart: unless-stopped
    ports:
      - '80:80'     # HTTP Ingress
      - '81:81'     # Management Web UI
      - '443:443'   # HTTPS Ingress
    volumes:
      - npm_data:/data
      - npm_letsencrypt:/etc/letsencrypt

volumes:
  npm_data:
  npm_letsencrypt:
                

Cloudflare DNS Challenge Credentials Verification


# Test Cloudflare Scoped API Token for DNS-01 SSL Automated Issuance
curl -X GET "https://api.cloudflare.com/client/v4/user/tokens/verify" \
     -H "Authorization: Bearer YOUR_CLOUDFLARE_API_TOKEN" \
     -H "Content-Type: application/json"