Heck IT logoHeck IT
  • Home
  • Projects
  • Contact

© 2026 Rex Heck. All rights reserved.

HomeProjectsContact[email protected]

Enterprise Homelab

In Progress

Enterprise-style lab for segmentation, identity architecture, Zero Trust access, observability, and automation.

ProxmoxMikroTikpfSenseFreeIPASamba ADAnsibleCloudflare Tunnel
  • Cross-forest trust architecture between FreeIPA and Samba AD
  • VLAN segmentation for WAN, infra, clients, IoT, management, and DMZ
  • Zero Trust access layers with Keycloak SSO and policy-driven administrative boundaries

FreeIPA + Samba AD Trust Architecture

In Progress

Attempting cross-forest identity federation between FreeIPA and Samba AD. Real progress made, real limitations hit at the Samba auth boundary. Windows Server is the next step.

FreeIPASamba ADKerberosLDAPAnsible
  • FreeIPA deployed as Kerberos + LDAP identity provider for Linux hosts
  • Samba AD DC stood up with Windows domain join and GPO capability
  • Ansible connector service built to pass identity attributes from IPA to AD
  • Cross-forest trust initiated; auth limitations reached at the Samba boundary
  • Next: Windows Server 180-day trial to validate full AD interop

pfSense Internal Policy Layer

In Progress

Dedicated inter-VLAN policy engine between segments with planned VPN termination and IDS/DNS filtering.

pfSenseVLAN RoutingPolicy EnforcementWireGuard (Planned)
  • Moves trust boundaries off edge-only routing
  • Designed to centralize East-West access controls

Proxmox + Cloudflare Zero Trust

In Progress

Secure remote Proxmox management via Cloudflare Tunnel (pve.heckit.dev) with Access MFA and Keycloak SSO.

ProxmoxCloudflare TunnelCloudflare AccessKeycloak
  • Per-app Access policy with identity challenge
  • Keycloak integrated for SSO-centric access flows

OpenRID Detection

In Progress

Low-cost receiver for FAA Remote ID using SDR with real-time map and alerts.

SDR (Software-Defined Radio)ESP32Python
  • Decode RID beacons; parse and display telemetry
  • Local alerting; optional privacy-respecting map