Engineering papers on self-hosted infrastructure, security, operations, and applied AI.
Each paper is a directory. The paper itself is that directory's README.md,
so the directory link renders it, and diagrams or other assets can sit next
to it without a restructure.
| Category | Paper | Summary | Updated |
|---|---|---|---|
| ai | Bounded Autonomy: A Language Model as a Validated Adjudicator over Live Data | Deterministic code finds, retrieves, and validates; the model only selects; oversight watches convergence instead of approving writes. | 2026-07 |
| operations | A Control Plane That Must Heal Itself | Self-hosted mesh-VPN coordination: deterministic on-host repair, fault-injection-proven rollback, and coexistence contracts on a shared host. | 2026-07 |
| operations | A Watchdog with a Power Switch | Safe physical actuation: a modem power-cycler that can never leave the power off, and the notify-only monitor that earned no autonomy. | 2026-07 |
| security | Layered Ingress and Egress Security for Self-Hosted Infrastructure | An ordered ingress path, a default-deny egress path, and the verification discipline that keeps both honest. | 2026-07 |
The engineering in every paper — the systems, the measurements, the incidents, the decisions — is the author's. The prose is written by AI models and adversarially reviewed by an independent model; each paper names the exact models in its own Provenance section. The author verifies every claim and every review finding against the implementation, approves the final text, and answers for the content. No AI system is an author here, because authorship means accountability.
All content is licensed under CC BY 4.0: share and adapt it freely, with attribution.
Use GitHub's "Cite this repository" button, or reference a paper by its directory URL. Each paper carries a version and date in its header.
This is a personal publication archive. Contributions are not accepted, and pull requests will be closed. Errata are welcome by any channel listed on the owner's profile.