Personally
The part that doesn't fit on a resume
A recruiter needs the other page. This one is for anyone who wants to know what I'm actually like: what I run at home, what I'm learning, and what I do when nobody is paying me to do it.
In my own words
Three things that explain most of the rest
I wanted to be a doctor. I didn't go for it because I've never trusted my memory for names, but the interest never left. My favourite book is Immune, which is 700 pages about the immune system, and I recommend it to people constantly.
I'm a nerd who has spent a lot of time with AI, and I've picked up scattered knowledge across a lot of unrelated fields as a result. It's why the projects on this site look like they belong to four different people.
I think everyone is the same underneath: gender, caste, religion, race. That isn't a position I argue about, it's just where I start.
Photos
Some of it, in pictures
Click any of them. Arrow keys work too.
The homelab
Everything I run, on one mini PC and a firewall box
One mini PC, a separate firewall box, and a wall of shelves with more cable than the wall deserves. Every service I run lives on it.

- Host
- ASUS PN52 mini PC
- CPU
- Ryzen 5 5600H, 12 threads
- Memory
- 16GB DDR4-3200
- Storage
- 512GB NVMe, plus external spinning disk on XFS
- Hypervisor
- Proxmox VE 8.4
- Firewall
- Separate pfSense box, 4 × 2.5GbE
One golden template, seventeen containers
Every service runs in its own LXC cut from a Debian template that already has Docker and the toolchains on it: git, Node, Python, Rust, Go. A new service is a clone away from running, and nothing gets installed twice. The media stack is the exception that proves it, since Jellyfin, Sonarr, Radarr, Prowlarr, qBittorrent and Jellyseerr all share one container because they only ever talk to each other.
Exposing a service is a DNS entry, not a config change
A Cloudflare tunnel runs as a container inside the lab. Publishing something means adding a hostname in the Cloudflare dashboard and nothing else: no port forward, no inbound firewall hole, no local file to edit and forget about. The tunnel dials out, so the network has no listening ports facing the internet at all.
Two ISPs, so the line does not drop
pfSense load balances across two providers and fails over between them. Gateway monitoring alerts through three independent layers, the first of which is pfSense talking to Telegram directly. That one exists precisely because it depends on nothing else I built: if my own automation is what broke, the dead-man path still reaches me.
Segmented by subnet, because the Wi-Fi cannot do VLANs
Quarantine, phones, cameras and the NVR, entertainment devices, the lab itself, IoT, and production each live on their own range with firewall rules between them. It is not as clean as proper VLANs, and it was the honest answer to hardware that does not support them. The doorbell does not get to talk to the NAS.
The projector sequence
favouriteForty-odd steps, every single time it turns on: power up, walk the settings menu, switch HDMI over to the Chromecast. The projector has no API and no memory of what I last chose, so the automation reproduces a human pressing buttons. It has not missed yet.
Power grid detection
An input boolean helper that works out whether the grid is up, so the rest of the house can behave differently during an outage. I wrote it up on Medium.
Read the write-upParty mode
uselessEvery light in the room cycling colours like a bad nightclub. Completely useless. Absolutely staying.
The house runs on solar
The house runs on solar. I documented the whole thing across three parts: what it cost, what it actually delivers, and what nobody tells you beforehand.
Read the seriesThe AI stack
Hermes, and the boundary around it
The part of the lab I would actually show someone. A personal assistant running on my own hardware, with a gateway in front of the models and a hard boundary around what any one of them can touch.
A gateway with five keys, not one
Every model call goes through a LiteLLM gateway holding five virtual keys, split by what the caller is for rather than who the caller is. Calendar, contacts, home automation, the assistant core, and general tooling each get their own. They share a user id so spend rolls up, and each one can be rate limited on its own.
Access fails closed, and the restriction lives in the right place
The gateway refuses any key that has not been explicitly granted a tool surface. Restriction is enforced where tools are registered, not on the key, which means a client cannot discover or call anything outside its envelope no matter what it sends. The MCP servers themselves only accept connections from the gateway address, so the firewall rule is a load-bearing control rather than a comfort.
Routing by sensitivity, not by price alone
Tool-execution turns go to a cheaper hosted model that is good at them. Conversational turns go to a stronger one. Anything touching mail, calendar or the house goes to a direct provider rather than through a reseller, with a separate fallback on another provider entirely so one outage is not a blackout.
Tool surface compounds model weakness
This was the most useful thing I learned. One of the MCP servers exposes 87 tools and another 104. Handing all of them to a weaker model does not make it more capable, it makes it fail harder, because the choice gets harder faster than the capability grows. The fix is narrow per-use-case registrations against the same upstream server, so each caller sees only the handful it needs.
Prompt structure is a cost decision
Persona and profile are always loaded and capped, so they form a stable prefix that caches. Everything else loads on demand from a skills directory. The boundary between files is drawn by how often the content changes, not by what it is about, and that alone cut input spend substantially.
The MCP servers behind it
Indian Railways MCP
Built it myself. Live, behind the tunnel.
Google Workspace MCP
104 tools across 12 services, scoped down per key.
Home Assistant MCP
87 tools, which is exactly why the scoping matters.
Rules I run the place by
Five things I do not negotiate on
Fail closed
If access control is ambiguous, the answer is no. Firewall rules are controls, not decoration.
Life safety does not depend on my code
Smoke and gas alarms are never routed through Home Assistant, and at least one switch per room stays in normal mode so the house works when the automation does not.
Cost attribution from the start
Per-consumer keys and rolled-up spend, because "the AI bill went up" is not a debuggable sentence.
Network cable is not mains cable
Cat6 carries about 30V and is unsafe for a 230V switch drop, whatever the category on the jacket.
No custom conventions
Blue is already spoken for in Indian wiring. Use conduit colour and labels, never a private colour code the next person will not know.
Next
Wiring a house before the walls close
A new house is going up, and this time the network goes in while the walls are still open.
DIN-rail relay modules on Ethernet doing the actual switching, with PoE Zigbee coordinators segmented by floor for the battery sensors, wired recessed reed switches on doors and windows, and mmWave radar for presence rather than motion.
On the electrical side: a dedicated IoT sub-grid on its own conduit colour, in-wall DIN panels per room, star topology back to a central managed switch, surge protection at both the main board and the IoT sub-board, retractive switches, and a neutral at every switch box so nothing has to be bodged later.
Currently learning
Kubernetes, and why
I can deploy a container and wire the pipeline that ships it. What I want next is the layer above: scheduling, scaling, and self-healing across a cluster rather than one box. Seventeen containers on a single mini PC works right up until the mini PC is the problem, and the honest answer to that is an orchestrator rather than a bigger machine. The lab is the test bed, because breaking your own cluster at 1 AM teaches faster than a course does.
Alongside it
- IoT and Home Assistant
- Home networking and segmentation
- Self-hosting and backups that restore
Things I've been paid to do outside software
Networks, labs, and cable
Some of this started as a hobby and turned into work for people around me.
Home networking and IoT
Building or renovating? Get the network right while the walls are still open. Hardware selection, segmentation, mesh planning, and automation that survives a power cut, because mine has to.
Homelab setup
Proxmox, TrueNAS, Docker, media servers, and backups that actually restore. I run all of it at home.
CCTV and structured cabling
Surveillance and wiring done properly the first time. Installed and maintained for local factories: camera placement, recording, retention, and the cable runs underneath.
Writing
Things I worked out, then wrote down
Fifteen pieces on Medium, mostly written the evening after I got something working, while I still remembered what had gone wrong.
One more thing
The one video I am still fond of
गन वाली से कनेक्ट करो
Gun Wali Google, a conversational Google Action
Six years ago I built a Google Action on Actions Console and DialogFlow, wired up with intents and entities, and then recorded myself having a conversation with it. It was more of a joke than a tutorial and it is still the thing from that era I am fondest of.
Watch it on YouTubeOff duty
When nobody is paying me
Reading
Immune, cover to cover, more than once.
Films
In an actual theatre, and quite possibly one I have seen ten times.
Counter-Strike
The old-school kind.
Long walks
The main debugging tool.
Travel
Coorg, Dubai, and a long list of trains.