Enterprise infrastructure, run out of a home rack.

A personal lab built to the same standard as production: identity, edge, containers, storage, and automation, wired together and actually monitored.

// rack status
What's running
U01ONLINE
AWS
Compute & IAM
Spot fleet compute, least-privilege IAM policies, and S3 lifecycle rules tuned for cold storage.
uptime214d
U02ONLINE
Azure
Hybrid identity
Entra ID sync, conditional access policies, and hybrid domain join across on-prem and cloud.
uptime190d
U03ONLINE
Cloudflare
Edge & DNS
Zero Trust tunnels, DNS failover, and Workers handling lightweight edge logic.
uptime231d
U04ONLINE
Docker
Containers
Compose stacks for internal tooling, images pinned and scanned before rollout.
uptime176d
U05ONLINE
Synology
Storage & backup
RAID6 array with Hyper Backup offsite replication and snapshot retention for rollback.
uptime340d
U06ONLINE
Monitoring
Observability
Uptime checks, log aggregation, and alert routing tuned to cut noise, not signal.
uptime301d
U07ONLINE
PowerShell
Automation
Scheduled runbooks for patching, backup verification, and configuration drift detection.
uptime264d
// live board
Monitoring
Uptime, 30d
99.97%
Nodes online
12 / 12
Backups verified
Daily
Alert routing
< 2 min
// field notes
Recent work
Networking

Automated failover for internal DNS

Secondary resolver takes over within seconds of a health check failure, with alerting wired straight into the monitoring stack.

Automation

Backup verification pipeline

PowerShell scripts that talk to the Synology API, confirm each snapshot restores cleanly, and log the result before anyone has to ask.

Security

Zero Trust access without a VPN client

Cloudflare Tunnel plus access policies replaced a legacy VPN, cutting client-side setup for every new device to zero.

// quick access
Lab links
LNK1LIVE
Status
Uptime Kuma
Real-time monitoring dashboard for all lab services.
publicopen →
LNK2GATED
Internal systems
NAS, admin panels
Storage and admin consoles sit behind Cloudflare Zero Trust — identity-gated, no public hostnames or open ports.
accessrequest only
// operator
About
Dwayne Kendall

Systems Engineer — Cloud & Hybrid Infrastructure

I design, build, and keep running the systems that businesses can't afford to have go down — identity, endpoints, networking, and now increasingly cloud and edge, all in one hybrid picture instead of siloed pieces.

Day to day that means Azure AD / Entra ID and hybrid identity, Intune-managed endpoints, Active Directory and Windows Server, and the automation (PowerShell, Infrastructure as Code) that keeps all of it consistent instead of hand-built. This lab is where I extend that into AWS, Cloudflare Zero Trust, Docker, and self-hosted observability — the same discipline applied to a stack I fully own end to end.

GitHub ↗    Contact ↗