
[{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/categories/","section":"Categories","summary":"","title":"Categories","type":"categories"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/categories/desktop/","section":"Categories","summary":"","title":"Desktop","type":"categories"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/desktop/","section":"Tags","summary":"","title":"Desktop","type":"tags"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/github/","section":"Tags","summary":"","title":"Github","type":"tags"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/linux/","section":"Tags","summary":"","title":"Linux","type":"tags"},{"content":" The Journey Before Settling # Niri paired with Noctalia Shell is my current desktop environment setup, but it certainly wasn\u0026rsquo;t my first. Having spent a good chunk of time experimenting with various DEs (Desktop Environments) and WMs (Window Managers), here is my experience with each along the way.\nGNOME GNOME felt like a bit too much. I prefer my desktop clean and minimalist, and GNOME lacked the out-of-the-box customization needed to strip away the clutter I didn't want. It definitely feels geared toward macOS refugees—my girlfriend uses macOS most of the time and felt instantly comfortable on GNOME compared to any other DE. Hyprland After GNOME, I jumped straight into total customization freedom: Hyprland. That was a major mistake. At the time, I didn't fully understand the difference between a standalone Window Manager and a full Desktop Environment. I tried running Hyprland without a shell, assuming I had to manually glue all the background services and daemons together myself... so I did. I ended up with a tangled spaghetti of intertwined config files and zero visual or functional coherence. Despite the chaos, Hyprland was a fun experiment. I skipped a lot of the learning curve by blindly copying someone else's dotfiles (bad idea). The tiling was fine, but I never really used it to its full potential because I rarely wanted a window smaller than half my screen (foreshadowing!). KDE Plasma Still somewhat confused by the DE vs. WM distinction, I assumed KDE Plasma was just a \"more complete\" desktop. KDE Plasma became my daily driver for the longest time before I eventually switched to Niri. As a Windows 11 refugee, it felt incredibly familiar while still granting me immense customization freedom. I loved that it \"just worked\" out of the box while providing a rich GUI for deep system settings. However, I still missed having a dedicated tiling layout. Niri (Without Noctalia Shell) To quench my thirst for tiling, I installed Niri alongside KDE Plasma as a separate session. Unsurprisingly, I *still* hadn't learned my lesson about standalone compositors. Running Niri without a desktop shell meant manually configuring my own daemons and services all over again. These background services started interfering with each other whenever I switched back to KDE Plasma, which kept me from using Niri consistently. On top of that, Niri's main config file gave me Hyprland flashbacks—everything was crammed into a single file, making on-the-fly tweaks a chore. Niri WITH Noctalia Shell After catching a random video reel showcasing Noctalia Shell, I knew I had to try it. I booted into my old Niri setup and installed it immediately. It wasn't smooth sailing at first—my system was still plagued by leftover, conflicting daemons from my previous attempts. It took a hot minute to sanitize my environment. Once the cleanup was done, everything clicked. This is the setup I finally settled on. The Current Setup # dotfiles below\nMy daily driver is Niri paired with Noctalia Shell. Niri\u0026rsquo;s infinite scrollable tiling manager fits my workflow effortlessly, and Noctalia Shell ties it all together into a sleek, unified desktop.\nHere is how each component is configured:\nNiri # By default, Niri uses a single monolithic configuration file. Since that gets cluttered fast, I adopted a modular config structure: (click the chart to see the code)\ngraph LR; inputs.kdl --\u003e config.kdl; outputs.kdl --\u003e config.kdl; noctalia.kdl --\u003e config.kdl; layout.kdl --\u003e config.kdl; window-rules.kdl --\u003e config.kdl; startup.kdl --\u003e config.kdl; binds.kdl --\u003e config.kdl; cursor.kdl --\u003e config.kdl; click config.kdl \"https://github.com/shen-nm/dotfiles/blob/main/niri/niri/config.kdl\" click inputs.kdl \"https://github.com/shen-nm/dotfiles/blob/main/niri/niri/inputs.kdl\" click outputs.kdl \"https://github.com/shen-nm/dotfiles/blob/main/niri/niri/outputs.kdl\" click noctalia.kdl \"https://github.com/shen-nm/dotfiles/blob/main/niri/niri/noctalia.kdl\" click layout.kdl \"https://github.com/shen-nm/dotfiles/blob/main/niri/niri/layout.kdl\" click window-rules.kdl \"https://github.com/shen-nm/dotfiles/blob/main/niri/niri/window-rules.kdl\" click startup.kdl \"https://github.com/shen-nm/dotfiles/blob/main/niri/niri/startup.kdl\" click binds.kdl \"https://github.com/shen-nm/dotfiles/blob/main/niri/niri/binds.kdl\" click cursor.kdl \"https://github.com/shen-nm/dotfiles/blob/main/niri/niri/cursor.kdl\" Splitting the .kdl files into dedicated modules makes quick adjustments infinitely easier. I highly recommend this approach if you\u0026rsquo;re building out a Niri setup!\nNoctalia Shell # Coming from having no shell whatsoever, Noctalia comes ridiculously feature-complete right out of the box. Instead of me having to stitch together half a dozen separate utilities (like Waybar for status, Dunst for notifications, and Swaylock for locking) and praying they don\u0026rsquo;t fight each other, Noctalia handles all of that in one sleek package.\nWhat really sold me on it was how painless it is to configure. It actually has its own built-in GUI settings menu, meaning I don\u0026rsquo;t have to hunt down raw config files or tinker with CSS just to change a theme, tweak a widget, or adjust my color palette on the fly. Plus, because it\u0026rsquo;s built on Quickshell, the whole UI feels super snappy and responsive.\nIt essentially bridges the gap for me: I get the scrolling tiling layout I love from Niri, but with the polished, hassle-free experience of a full desktop environment.\nDotfiles # GitHub Repo ","date":"4 August 2026","externalUrl":null,"permalink":"/projects/niri-noctalia-setup/","section":"Projects","summary":"An overview of my desktop running Niri and Noctalia Shell","title":"My Desktop: Niri with Noctalia Shell","type":"projects"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/categories/projects/","section":"Categories","summary":"","title":"Projects","type":"categories"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/projects/","section":"Projects","summary":"","title":"Projects","type":"projects"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/","section":"Shen Milan","summary":"","title":"Shen Milan","type":"page"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/","section":"Tags","summary":"","title":"Tags","type":"tags"},{"content":"","date":"4 August 2026","externalUrl":null,"permalink":"/tags/workflow/","section":"Tags","summary":"","title":"Workflow","type":"tags"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/tags/ci/cd/","section":"Tags","summary":"","title":"CI/CD","type":"tags"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/tags/cloudflare/","section":"Tags","summary":"","title":"Cloudflare","type":"tags"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/tags/cloudflare_pages/","section":"Tags","summary":"","title":"Cloudflare_pages","type":"tags"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/categories/engineering_logs/","section":"Categories","summary":"","title":"Engineering_logs","type":"categories"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/tags/github_actions/","section":"Tags","summary":"","title":"Github_actions","type":"tags"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/tags/homelab/","section":"Tags","summary":"","title":"Homelab","type":"tags"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/tags/hugo/","section":"Tags","summary":"","title":"Hugo","type":"tags"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/categories/infrastructure/","section":"Categories","summary":"","title":"Infrastructure","type":"categories"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/tags/networking/","section":"Tags","summary":"","title":"Networking","type":"tags"},{"content":" The Architecture # Most personal portfolios are treated like an afterthought—manually dragging files over SFTP or clicking around a clunky GUI. I wanted this space to treat infrastructure with the same discipline as a production enterprise cluster: immutable, tracked, and completely automated.\nThe Engine: Hugo running the Blowfish theme. It compiles raw markdown into lightweight static assets in milliseconds. The Edge: Hosted entirely on Cloudflare Pages. Traffic hits Cloudflare’s global edge network instantly, giving me zero server overhead to maintain. The Pipeline: A strict Git-driven CI/CD deployment loop. I don\u0026rsquo;t deploy files; I push code, and the cloud compiles the rest. Keeping the Workspace Clean # When building locally on my Arch laptop, running hugo server compiles thousands of temporary static files under public/ and resources/. Early on, I accidentally committed 16,000 lines of generated tracking junk into Git.\nTo permanently shield the repository source history from compilation bloat, my .gitignore is locked down tight:\npublic/ resources/ .hugo_build.lock Now, the source tree stays completely pristine, tracking only the structural configuration, custom styles, and raw markdown content:\n. ├── assets/ │ └── css/ │ └── custom.css # Where my background \u0026amp; blur overrides live ├── content/ # Obsidian markdown vault syncing posts └── config/_default/ # Core theme parameters \u0026amp; menus The \u0026ldquo;Don\u0026rsquo;t Break Prod\u0026rdquo; Workflow # To prevent a rogue syntax typo or broken theme layout from taking down shenmilan.com, I implemented an isolated staging sandbox. Every feature follows a strict promotion pipeline.\n1. The Sandbox Phase # No code or text is ever written directly on the live main branch. I switch over to an isolated staging workspace and fire up the local rendering engine to test changes:\ngit checkout staging hugo server -D 2. Isolated Edge Testing # When I push to the staging branch, GitHub alerts Cloudflare Pages. Cloudflare spins up an isolated build container, compiles the branch independently, and generates a private preview URL (https://staging.project.pages.dev).\ngit add . git commit -m \u0026#34;style: implement frosted card overlay and fixed background blur\u0026#34; git push origin staging If a layout script crashes or a parameter tag is malformed, the build fails safely in the container. The live production site remains completely untouched and online.\n3. Fast-Forwarding to Production # Once the staging preview URL is visually vetted and the build is solid green, I fast-forward those verified commits right into the production branch:\ngit checkout main git pull origin main git merge staging git push origin main Cloudflare handles the final switchover atomically. The edge network swaps the assets instantly, rolling out the new features to the world with zero downtime.\nInfrastructure Retrospective # Atomic Safety: Treat your portfolio like production infrastructure. If a deployment fails, nobody should ever see a 404 or a broken page.\nConventional Commits: Prefixing messages with labels like feat:, style:, or chore: might seem tedious at first, but it makes scanning git log --oneline incredibly clean and signals disciplined engineering.\n","date":"30 June 2026","externalUrl":null,"permalink":"/projects/portfolio-infrastructure/","section":"Projects","summary":"A rundown of the infrastructure of the page which runs on GitHub Actions and Cloudflare Pages","title":"Portfolio Infrastructure: Under The Hood Of This Web Page","type":"projects"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/posts/","section":"Posts","summary":"","title":"Posts","type":"posts"},{"content":" The Incident # A brief grid failure caused a hard reboot of my primary home-lab node. While the hardware physically survived the power cycle and booted back up cleanly, the public-facing portfolio went completely dark.\nInternal routing was functional, but the site was throwing a 502 Bad Gateway at the edge network.\nThe Root Cause: Systemd Dependency Race # Upon digging into the system logs via SSH, I discovered a classic race condition between my network mesh overlay and my reverse proxy tunnel.\nThe cloudflared daemon was configured to bind explicitly to an internal backend service routing over my private Tailscale interface. During the boot sequence, systemd initiated both services simultaneously.\nBecause cloudflared initialized milliseconds before tailscale could complete its handshakes and instantiate the virtual interface, the tunnel couldn\u0026rsquo;t resolve the route, panicked, and crashed.\nThe Fix (Enforcing Order) # To fix this permanently, I had to drop into the systemd configuration on the host and explicitly instruct the Linux kernel not to touch the Cloudflare tunnel until the Tailscale service is fully online and stable.\n1. Edit the Cloudflared service file overrides # sudo systemctl edit cloudflared 2. Inject the dependency constraints # Inside the systemd override configuration, I appended the explicit ordering rules under the Unit block:\n[Unit] Requires=tailscaled.service After=tailscaled.service network-online.target 3. Reload the systemd daemon and test the boot ordering # sudo systemctl daemon-reload sudo systemctl restart cloudflared Infrastructure Retrospective # Network Dependency: Never assume local network interfaces are instantly available on boot. If a service relies on an overlay network or a VPN mesh, the systemd unit file must explicitly state After=vpn-service.service.\nResilience Testing: A true high-availability system should be able to recover gracefully from a cold boot without human intervention. Fixing this race condition means the lab can now survive sudden blackouts completely hands-off.\n","date":"30 June 2026","externalUrl":null,"permalink":"/posts/power-outage-postmortem/","section":"Posts","summary":"","title":"Power Outage Post-Mortem \u0026 Tailscale/Cloudflared Race Condition","type":"posts"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/tags/systemd/","section":"Tags","summary":"","title":"Systemd","type":"tags"},{"content":"","date":"30 June 2026","externalUrl":null,"permalink":"/tags/tailscale/","section":"Tags","summary":"","title":"Tailscale","type":"tags"},{"content":" Hello, I\u0026rsquo;m Jhenrick Shen Milan # Download PDF Version I am a highly independent Systems Engineer and IT Specialist with an engineering background and a proven track record of maintaining high-availability, 24/7 production networks. I specialize in enterprise identity governance, cloud administration, automated telemetry tracking, and low-latency broadcast infrastructure.\nWhether it\u0026rsquo;s independently resolving high-stakes production incidents during critical night shifts or designing zero-trust overlay networks from scratch, I focus on building reliable, secure, and observable systems.\nTechnical Arsenal # Enterprise Infrastructure \u0026amp; Security # Cloud Governance: Google Workspace (Super Admin), Microsoft 365, Azure Active Directory Identity \u0026amp; Access: Identity \u0026amp; Access Management (IAM), User \u0026amp; Group Governance, strict ACL policies Network Security: Enterprise Firewalls (Configuration \u0026amp; Migration), Checkpoint Firewalls, VPN tunnels, Managed Switches, Network Redundancy Systems, Virtualization \u0026amp; Automation # Operating Systems: Linux (Daily Driver), Alpine Linux, Debian, Arch Linux, Windows, MacOS Virtualization/DevOps: Proxmox VE, Docker, Docker Compose, Unprivileged LXC Containers, Virtual Machines Scripting \u0026amp; Data: Bash, Python, SQL Maintenance, Automated Backups \u0026amp; Cron Automation Hardware \u0026amp; Edge: Raspberry Pi deployments, low-latency Live Video/Audio Encoding, Broadcast Infrastructure Monitoring \u0026amp; SRE # Telemetry \u0026amp; Observability: Grafana, Zabbix, Automated Alerts \u0026amp; Metrics, System Health Dashboards Professional Experience # IT Systems Engineer / Infrastructure Specialist # Studioworks OÜ | Tallinn, Estonia | Feb 2025 – Present\nEnterprise Cloud Governance: Serve as Global Administrator for enterprise Google Workspace, managing identities, groups, access controls, and organization-wide security permissions for a highly distributed workforce. High-Availability Operations: Serve as the sole infrastructure anchor during critical night shifts, independently diagnosing, logging, and troubleshooting mission-critical network failures, link degradations, and ISP connectivity issues under intense SLA constraints. End-to-End Infrastructure Deployment: Designed, wired, and deployed complete low-latency video streaming infrastructures from scratch, configuring system connectivity, hardware encoders, and low-level system telemetry for 24/7 production environments. Proactive System Monitoring: Architected and monitored Grafana and Zabbix dashboards to track production system health, proactively remediating network bottlenecks to drastically improve infrastructure uptime. Incident Management: Provided expert 24/7 on-call tier-3 support via remote management tools, rapidly debugging server faults and restoring operations under intense pressure. Technical Documentation: Author of internal training guides, standard operating procedures (SOPs), and automated system manuals to streamline incident resolution and expedite engineering onboarding. Education \u0026amp; Background # BSc Integrated Engineering # Tallinn University of Technology (TalTech) | 2021 – 2024\nFoundational expertise in industrial systems, hardware design, electrical schematic analysis, AutoCAD, and SolidWorks. Languages # English: Professional Proficiency (C1) Filipino: Native Proficiency (C2) Estonian: Elementary (A1) Key Highlights \u0026amp; Homelab Philosophy # Outside of my professional engineering commitments, I maintain an active DevOps Home Lab. I treat my private server matrix (powered by Proxmox hypervisors, segmented Docker microservices, and automated backup routines) as an R\u0026amp;D sandbox to safely stress-test enterprise configurations before deploying them to live production networks.\n","date":"29 June 2026","externalUrl":null,"permalink":"/about/","section":"Shen Milan","summary":"","title":"About Me","type":"page"},{"content":"","externalUrl":null,"permalink":"/authors/","section":"Authors","summary":"","title":"Authors","type":"authors"},{"content":"","externalUrl":null,"permalink":"/series/","section":"Series","summary":"","title":"Series","type":"series"},{"content":"","externalUrl":null,"permalink":"/templates/","section":"Templates","summary":"","title":"Templates","type":"templates"}]