<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Zero Trust on 万屋猫Labs</title><link>https://yn-labs.com/en/tags/zero-trust/</link><description>Recent content in Zero Trust on 万屋猫Labs</description><generator>Hugo</generator><language>en</language><lastBuildDate>Mon, 15 Jun 2026 10:00:00 +0900</lastBuildDate><atom:link href="https://yn-labs.com/en/tags/zero-trust/index.xml" rel="self" type="application/rss+xml"/><item><title>Codifying a Homelab with Ansible — Fail-Closed Defense-in-Depth Infrastructure</title><link>https://yn-labs.com/en/posts/ansible-homelab-iac/</link><pubDate>Mon, 15 Jun 2026 10:00:00 +0900</pubDate><guid>https://yn-labs.com/en/posts/ansible-homelab-iac/</guid><description>&lt;h2 id="turning-my-whole-home-server-into-code"&gt;Turning my whole home server into code&lt;/h2&gt;
&lt;p&gt;To run an AI-agent platform on my home server (homelab), I hand-built the entire stack: container runtime, network isolation, encrypted DNS, kernel hardening, and audit logging. It worked, but one thing kept nagging at me. If I ever reinstalled the OS, I wasn&amp;rsquo;t confident I could rebuild the same thing. Exactly what I had changed and where, and which security settings I might have forgotten to apply — in the end, it all lived only in my head.&lt;/p&gt;</description></item></channel></rss>