Briggs Bastian, Seattle, WA

Systems that hold
under pressure.

I'm a self-driven security analyst and engineer, happiest learning across the computer space, networking, infrastructure, wherever I'm needed. At work I run a security program. At home I run a NixOS homelab like it's production and build a souls-like game after hours.

years in security
04+
hosts, one flake
05
services on real certs
15
  • desktop 412
  • mgmt 188
  • media 203
  • playground 97
  • hacktop 154

Now building

Selected work

All projects

Operations

How I run things

The receipts
01

Infrastructure as Code

Five NixOS hosts described in one Nix flake and deployed with a single colmena apply. Any host can be rebuilt from scratch.

02

CI/CD & Release Engineering

A self-hosted Forgejo pipeline that builds every host, scans for secrets, and only mirrors to the public repo on green, including the site you are reading.

03

Cloud

The cloud leg is code: Terraform and nixos-anywhere stood up a Linode node in the same flake as the house, and tore it down just as cleanly — it is one apply from returning. Next is Azure at architect depth, AZ-104 under study now, AZ-305 behind it.

04

Secrets & Trust

sops-nix secrets keyed to each host’s own SSH identity, a private step-ca CA issuing real certs to internal services, and a deploy user that can ship a closure but never open a root shell.

05

Observability

A SIEM I tune at work; at home, a declarative Loki/Alloy stack that replaced Wazuh, every host shipping its journal, alert rules living in the same flake as the hosts they watch.

06

Security Engineering

Threat modeling, hardening baselines, and least-privilege design, plus a libvirt range to attack the lab and prove the detections fire.

07

Networking

An overall network guy: UniFi with VLAN segmentation across trusted, IoT, and guest, plus nftables host firewalls. At work, the same on Cisco, Meraki, SonicWall, Fortinet, and pfSense.

08

Declarative Recovery

Every NixOS host is a generation you can roll back to, and a compromised box is rebuilt to known-good with one command.

Thought garden

Recently tended

Enter the garden