Building a Bulletproof Home Media Server: Solving Internet Outages, Transcoding, and Apple's Backup Paradox

When your child is two episodes away from the Puppy Dog Pals finale and Cox decides to take a 20-hour vacation, you realize it’s time to stop depending on internet uptime for family entertainment. This week, I solved three problems at once: unreliable ISP service, Plex transcoding performance, and Apple’s contradictory stance on iCloud Photos backups. The Problem: When Everything Depends on Internet That Isn’t There Cox has been down 20 hours this week. Not a typo. Twenty hours of “connection refused” while trying to stream media my family was actively watching. This isn’t normal, Cox is typically unreliable every couple months (still not great), not every couple hours, but it highlighted a dependency I could eliminate. ...

January 20, 2026 · 8 min · Zac Lohrenz

AWS Lambda Cleanup: When CloudWatch Metrics Lie

When you inherit a legacy AWS environment with dozens of Lambda functions and a mandate to clean up unused resources, the obvious first step is checking CloudWatch metrics. Invocation counts, error rates, duration stats - all there in neat graphs. But what happens when those metrics tell you a function has zero errors, yet it’s failing on every single execution? This week I investigated 45 Lambda functions to determine which could be safely deleted. What started as a simple metrics review turned into a forensic investigation revealing broken functions masked by misleading CloudWatch data, API Gateway routes pointing to deleted Lambdas, and scheduled jobs silently failing for months. ...

January 14, 2026 · 8 min · Zac Lohrenz

AWS EC2 Forensic Investigation: Analyzing a RegreSSHion Compromise

When an AWS abuse report lands in your inbox about an EC2 instance running cryptocurrency mining malware, you know you’re in for an interesting investigation. This week, I conducted a complete forensic analysis of a compromised production server, and the findings highlight critical lessons about patch management, monitoring, and security hygiene. Initial Discovery The timeline started simple: AWS abuse report in December, 2025, about suspicious network activity. The client had already rebuilt a clean instance, but the compromised server remained running for forensic analysis. My task was to determine what happened, how it happened, and ensure the replacement was truly clean. ...

January 3, 2026 · 5 min · Me

Azure SQL Private Endpoints: Why Your VPN Users Can't Connect (And What Actually Works)

We deployed an Azure VPN Gateway to give remote users secure access to Azure SQL databases through private endpoints. The setup looked textbook perfect: private endpoints approved and connected, VNet peering configured, routes in place, TCP connectivity verified. Everything worked except the one thing that mattered—users couldn’t authenticate. Here’s what we learned fighting Azure’s DNS architecture. The Setup That Should Have Worked Standard Azure private endpoint architecture for SQL Server: ...

December 12, 2025 · 7 min · Zac Lohrenz

Migrating Azure Container Apps from Docker Hub to Azure Container Registry

The Challenge When managing containerized applications in Azure Container Apps, you eventually face the question: should you continue using Docker Hub, or migrate to Azure Container Registry (ACR)? For enterprise workloads, ACR offers significant advantages: integrated security, managed identities for authentication, reduced egress costs, and better integration with Azure RBAC. This post documents a complete migration from Docker Hub to ACR across multiple Container Apps in different Azure subscriptions, including the critical managed identity configuration that enables seamless authentication without storing credentials. ...

December 5, 2025 · 7 min · Me