Skip to main content

thomas

tier/10· Murk Beast· 684,932 pts· joined May 2026

Loading activity

OG SwamperI WAS HERE!
10XP 18.5%11
04Tier
10
of 20
Rank
Murk Beast
Score
684,932
Next
1,500,000
05Extensions9

Postgres Admin

@thomas/postgres-admin · v2026.06.01.1

Non-destructive PostgreSQL administration over a direct TCP connection (node-postgres). Read/audit of databases, roles, permissions, tables, connections, and extensions; plus data-safe admin DDL — create database/role, grant/revoke, rotate passwords, and an idempotent app_provision composite. Never reads or writes table rows; never DROP/TRUNCATE; no arbitrary-SQL passthrough.

upd 38 pullsB

Forgejo

@thomas/forgejo · v2026.09.04.2

Careful administration of a Forgejo (or Gitea) server over its /api/v1 REST API, authenticated with a scoped access token. Find-or-create organizations and repositories and converge their settings, run GitHub pull-mirrors (create via /repos/migrate, reconcile interval/visibility, queue immediate syncs), audit every mirror's sync health, drive pull requests (open, inspect with mergeability and head CI state, merge), and audit or repoint repository webhooks so a stale CI target is visible rather than silently undelivered. Mutations are find-or-create or reversible (archive/unarchive) apart from the guarded pr_merge; there are no delete methods — a failed migration's empty shell repo is detected and reported, never auto-deleted. Secrets are never emitted: mirror source credentials are write-only, and webhook operations neither read nor write the shared hook secret.

upd 28 pullsA

Technitium

@thomas/technitium · v2026.09.01.1

Management of a Technitium DNS Server via its HTTP API — built-in ad-blocking control (enable/disable, temporary disable, allow/block list URLs), authoritative zone + record lifecycle, allowed/blocked custom domains, dashboard stats, DNS client + query-log debugging, cache flush, settings backup/restore, and security settings (admin web-service TLS certificate + DNSSEC validation).

upd 26 pullsA

Zitadel

@thomas/zitadel · v2026.06.24.1

Careful, non-destructive administration of a Zitadel instance over its Management API (v1 REST), authenticated with a JWT private-key service account. Read/audit of orgs, projects, applications, users and managers; idempotent provisioning of OIDC/API applications and machine (service) users; project-role and user-grant authorization (roles, grants, and the role-assertion flag that surfaces roles in tokens); rotation of client secrets, PATs, machine keys and secrets; and reversible deactivate/reactivate. Machine identities only. The only hard delete is a single, verify-first project-role removal (roles have no deactivate state); secrets are emitted once and marked sensitive.

upd 19 pullsA

Woodpecker

@thomas/woodpecker · v2026.09.08.1

Careful administration of a Woodpecker CI server over its REST API, authenticated with a personal access token. Onboard and configure repositories (enable, mark trusted, set timeout/visibility/approval), promote shared CI credentials to org- or repo-scoped secrets idempotently, inspect recent pipelines, and trigger runs. Mutations are additive or reversible (disable/secret-delete undo by re-running enable/set); secret values are write-only — supplied via a vault reference, sent once, and never read back or emitted.

upd 17 pullsA
view all 9 →