The Ops Stack
LearnLabsToolsProductsAbout
Newsletter

Labs Pillar

Network and DNS

Pi-hole, split DNS, DHCP, VLAN-aware services, network visibility, and practical edge services.

Published Guides7
Branches3
Open Gaps0
Local DNS

Pi-hole core deployments, Technitium DNS setups, split DNS for self-hosted services

4 guides
Remote Networking

WireGuard access patterns, Tailscale overlay networks, DNS over VPN

1 guide
Network Visibility

DHCP audit scripts, VLAN-aware monitoring, edge diagnostics utility boxes

2 guides
Local DNS

Create a WireGuard plus Split DNS Lab for Secure Remote Access to Self-Hosted Services

Build a two-client WireGuard lab with split DNS, explicit routing, resolver selection, firewall/NAT boundaries, and deterministic failover/teardown tests.

Network Visibility

Build a Small Office Network Monitoring Stack with LibreNMS, Syslog, and Alert Routing

Build a small-office monitoring path that proves one SNMP device, one syslog event, and one routed alert end to end instead of installing three disconnected products.

Local DNS

PowerShell Health-Check Pack for Active Directory, DNS, DHCP, and Certificate Expiration

Build a parameterized PowerShell health-check pack with testable AD, DNS, DHCP, and certificate functions, structured results, and controlled negative tests.

Network Visibility

Build a Home Network Visibility Dashboard with ntopng, Syslog, and VLAN Traffic Summaries

Build an ntopng visibility dashboard around one explicit traffic-observation topology, then prove traffic from the intended VLANs actually reaches the sensor and is attributed correctly.

Local DNS

Small Office DHCP and DNS Evidence Audit with PowerShell

Collect DHCP scopes/leases and DNS records read-only, then run explicit stale/conflict checks instead of changing execution policy or treating raw exports as an audit conclusion.

Local DNS

Create a Secondary Pi-hole DNS Node and Test Resolver Resilience

Build an independent secondary Pi-hole resolver, align the settings that should match the primary, and test both resolvers before advertising them together to clients.

Remote Networking

Creating a WireGuard Jump Host with MFA-Friendly Access Patterns

Build a WireGuard transport to a hardened jump host, then enforce MFA at the administrative login boundary instead of implying that WireGuard itself provides MFA.

Browse

All Labs

Back to the full library.

The Ops Stack

Practical infrastructure guidance, labs, tools, and software for real operational work.

Understand the problem. Validate the evidence. Choose the right next step.

Explore

LearnLabsToolsProductsAbout

Resources

NewsletterSearchTopicsRecent

Connect

ContactRSS
PrivacyDisclosure

© 2026 The Ops Stack