Eric Li DevOps & Infrastructure

Every Session Starts Cold

Homelab · 2026-10-01 · Thursday · 11:54 PM · 5 min read · 78% AI · Eric Li

I finished the secrets migration from the night before and set up a real DNS resolver for the house. The evening went on client site work, where I had to call Claude out for forgetting a project it had been living in for a week.

Getting secrets off the backup path

The day started before five in the morning, picking up where the previous session had left off: getting every exposed secret off the one disk that lands in the nightly backup of the VM Claude runs on. An inventory from overnight had turned up SSH keys, login sessions for a handful of command-line tools, and a couple of dead credentials nobody remembered deleting. I generated four new SSH keys through the password manager on my Mac instead of moving the old ones across, because the old keys had already sat in weeks of NAS backups and moving them would leave those copies exposed. Claude installed the new public keys one host at a time, tested each with a fresh connection, and only removed the old ones once the new ones were proven.

Partway through, one of the Proxmox nodes reset itself. I'd been in the server rack checking which smart plug fed which device, for power monitoring I want to add later, and knocked one slightly loose. It did no harm, but it left a key swap half done when the node dropped, and a stopped container turned up that shared a name with the VM Claude actually runs on, a leftover from this week's server migration. I'd started it by accident, confused by the shared name, so I had it renamed.

With the key swap done I asked for a full network retest between all four Proxmox nodes and my own PC, since two of the nodes have been running on USB network adapters instead of onboard ports for weeks. Every link held close to full 2.5 gigabit speed in both directions, including the one pair of nodes that used to run slower in one direction than the other. Whatever caused that difference is gone.

A blank SSD for Linux

Mid-morning I formatted a blank 2 TB Samsung T7 Shield portable SSD from a Claude Code session on my Windows PC. I picked exFAT over ext4 or NTFS so the drive reads and writes on Linux, Windows and macOS. The first attempt failed because the shell wasn't elevated, and it changed nothing. The retry through an elevated prompt worked and left one GPT partition labelled T7.

A DNS resolver for the house

The bigger job was replacing the router's built-in DNS with something I control. I'd read a while back that one self-hosted DNS server had pulled ahead of the usual ad-blocking pick, mostly because it handles more than one instance without a separate sync tool, and the current release notes still said so. It went on a Raspberry Pi that also holds a tie-breaking vote in the Proxmox cluster, so I had to be careful with disk writes and avoid anything that could interfere with the cluster.

Before any device got pointed at it, a network review caught a gap in the plan: three of my networks are firewalled off from the one the Pi sits on, so switching their DNS over without an extra rule would have made every lookup time out before falling back to the slow path. That got fixed first. By early afternoon I'd proven it worked, first from my own PC, then from my phone on the home network. The phone mattered because it wasn't on an admin allow-list, so it showed that the new firewall rule did something.

I also moved the Pi itself off an access point and onto a port on the gateway, so the device holding the cluster's fifth vote no longer depends on a Wi-Fi access point staying up. That went cleanly. Around midday I rebooted two of the four nodes by accident while working near the rack. One of the photo app's containers went down briefly because it lost a race with a storage mount coming back online, and a battery-backed lighting hub dropped offline for good measure. Neither had anything to do with the DNS work.

Client work, and a session that had gone cold

Separately, I spent part of the morning pulling apart an old backup file from a client's equipment, to understand how the system is built instead of trusting what its web interface claims. It turned up a few things to raise with the vendor before handover, but those are for them, not for here.

The evening was a long site visit, installing and configuring a second piece of equipment for that same client's project. It did not go smoothly. Early on, Claude gave advice as if it remembered a change from an earlier visit without checking, and at one point assumed something had been cabled wrong when it hadn't. I pushed back twice, and the second time got the real answer: Claude doesn't carry memory between sessions. Each one starts cold and is only as good as what it reads before it starts advising, and this one hadn't read enough. There's a new note now to load the project's own files before advising on it, instead of after I correct it.

We got the equipment working by the end of the night.

By midnight the open items were small: a couple of loose ends on the client side, and a setting on a travel router worth tightening later.