Gadgets for fun.
Tradecraft for real.
OpsFox is a community of people who run their own metal — devops, opsec, sigint, anonymity, and a healthy distrust of anything that phones home. Everything gets built and broken in the open first. The commercial side exists to bring that same standard to organisations that need it, on infrastructure they own outright. Tinfoil hats welcome. So is a bin of dead thin clients.
It starts as a pile of Pi boards and e-waste.
Not a marketing hobby. The bench is where a technique gets tried, broken and rewritten before it goes anywhere near somebody’s production network.
Handshake-eating Tamagotchis, a pocketable assessment box, a real homelab out of corporate skip-diving. Here’s what’s on the bench — with the actual status on each one, because a build list that quietly over-promises is just a roadmap with better lighting.
- PWNAGOTCHIPlanned
A Tamagotchi that eats WiFi handshakes.
- RAGNARPlanned
A pocket assessment box that fits in a jacket.
- THIN CLIENT LABPlanned
A real homelab out of $25 corporate e-waste.
- OWN YOUR STACKPlanned
Replace the SaaS you're renting with things you run.
Planned means planned — there is no hidden guide behind it. The parts lists are already up.
Everything that leaves the bench leaves ungated.
No email wall, no “full version” upsell, no lead-magnet PDF. What’s already public: the single-node baseline stack and the audit tool that runs on your machine and reports to you. The weekly dispatch is queued, not running. Apache-2.0, all of it.
That’s not generosity, it’s the only honest way to sell infrastructure security. You can read the work, hand it to your own engineer, and have them tell you whether it’s any good — before any money changes hands.
The fun isn’t decoration. It’s the retention mechanism.
Security that feels like a chore doesn’t get done. Nobody patches out of duty for very long.
But giving a Pi Zero a face, racking thin clients out of a skip, watching your own dashboards light up for the first time — that keeps people coming back to the bench, and coming back is the entire discipline.
So tinfoil hats are welcome. Threat-model out loud. Being right about surveillance capitalism a decade early isn’t a personality disorder, and nobody here is going to tell you you’re overthinking it.
- DevOps
- OpSec
- SIGINT
- Anonymity
- Self-hosting
- Homelabs
- E-waste rescue
- Threat modelling
Broken in a basement first. Trusted in production later.
The loop that turns a weekend experiment into something worth running on a network that matters. Nothing skips a step.
- 01
Break it in a lab
Every technique gets proven on homelab gear first, where the blast radius is a ruined weekend instead of somebody's payroll system. That is where you find out the restore was never actually tested.
- 02
Write it down
The write-up is the artifact, not a courtesy afterwards. Parts lists, the configs, and the decisions that were wrong the first time — especially those. A guide that only documents the happy path has never been followed by a stranger.
- 03
Clear the gate
Nothing lands on your gear that hasn't already survived somebody's homelab. What clears the gate goes into the public baseline; what doesn't goes back to the bench and gets tried again.
Consultancies discover all of that on client time and bill for it. The homelab crowd has been doing the unglamorous version for free for twenty years; the only thing added here is being disciplined about writing down what happened.
Then it graduates onto hardware you own.
What survives the lab and the write-up goes into the public baseline — and what gets deployed for a paying client comes out of that same baseline. The free repo isn’t a teaser for the paid thing; it is the tested part.
- OpsFox tenancy
- None
- Nothing you run sits inside an account of ours. There is no shared plane to be a tenant of.
- Console to log into
- None
- No OpsFox pane of glass in the path between you and your own infrastructure.
- Telemetry pointed at us
- None
- Revoke access and you still have every config, runbook and dashboard, because they were never anywhere else.
Free is free. The fleet part is what costs money.
If you just want to build something: the baseline, the audit tool and the dispatch are free and ungated, and if you run them and never get in touch, that is a perfectly good outcome.
A fork gets you the files. What costs money is the fleet part — high availability, long retention, a restore that has actually been run, and somebody keeping up with upstream so you don’t spend your weekends on it.
Two doors. Neither one costs you a call.
If you run infrastructure for other people and there is nobody on the payroll doing this: thirty minutes, no pitch deck, no proposal.