## kits
Kits
92 published kits — audit tooling, starter kits, and runbooks. Every card below is a real link to the product page.
## flagships
Start here
UpdateKit
UpdateKit is a native macOS update manager that finds every app on your Mac via the LaunchServices API, checks for updates from Sparkle appcasts and GitHub Releases, and flags known security vulnerabilities using the NIST NVD CVE database — surfacing critical patches first. Installs are transactional: a privileged helper handles the destructive replace atomically, with rollback on failure and orphan recovery if anything crashes mid-update. Local-first SQLite database, no accounts, no telemetry. Free to download. Founders Edition Pro license ($19, lifetime) supports development and unlocks future Pro features as they ship — starting with Guardian Mode for managing updates on a family member's Mac (v1.1).
GitHub Copilot AI Credits Cost Calculator
A free web calculator that estimates your monthly GitHub Copilot cost under the new metered AI Credits billing model based on your actual usage patterns.
GitHub Actions Starter Kit for Sysadmins
10 annotated GitHub Actions workflow YAML files purpose-built for IT ops tasks — automated patch checks, server health pings, backup validation notifications, SSL cert expiry alerts, and dependency audits — with a setup guide for sysadmins who've never touched CI/CD.
Active Directory Security Audit Kit for Solo IT Teams
A fillable AD audit checklist covering privileged access, stale accounts, GPO hygiene, MFA gaps, and event log review — everything an auditor expects, packaged for the sysadmin who has no security team.
IT Manager's AI Request Deflection Toolkit
The IT manager's professional toolkit for evaluating and responding to AI-generated project proposals — with data, not drama.
IT Manager's AI Request Deflection Toolkit
The IT manager's professional toolkit for evaluating and responding to AI-generated project proposals — with data, not drama.
AI Prompt Engineering Cheat Sheet for Sysadmins & DevOps
50 AI prompts built for ops teams — bash scripts, K8s debugging, Terraform, CI/CD, incident triage, all tested, none generic
Cybersecurity Compliance Starter Kit (SOC 2 + NIST CSF)
Your SOC 2 audit prep doesn't need a $10,000 tool — it needs this spreadsheet and three policy stubs.
AI-Augmented IR Tabletop Exercise Kit
Run your first IR tabletop without hiring a red team.
Server Security Hardening Checklist Kit
Harden your servers in one afternoon — the Linux + Windows security checklist built for solo sysadmins who can't afford to get this wrong
Sysadmin Documentation Toolkit
The documentation starter pack every sysadmin wishes they'd had on Day 1.
Active Directory Security Audit Kit for Solo IT Teams
A fillable AD audit checklist covering privileged access, stale accounts, GPO hygiene, MFA gaps, and event log review — everything an auditor expects, packaged for the sysadmin who has no security team.
Agent Memory Architecture Part 2: Episodic vs Semantic vs Procedural Memory
The three agent memory types — episodic, semantic, and procedural — explained through the real production code of ClaudeClaw, a 24/7 multi-agent system, so your agents stop starting from scratch every session.
AI Chatbot Account Recovery: Security Audit Checklist for Developers
A developer's guide to designing safe AI chatbot account recovery flows, using the Meta/Instagram breach as a live case study.
AI for Everyday Life Micro-Ebook Bundle
For adults who want one clear, useful AI win — no tech background, no jargon, no wasted afternoon.
AI on Your Phone: A Plain-English Guide for Seniors
A plain-English walkthrough for adults 60+ who want to get real value out of their phone's built-in AI assistant — no apps, no jargon, no tech background required.
AI Homelab Energy Dashboard: Monitor GPU Power Costs in Real Time
A step-by-step guide to building a Prometheus + Grafana dashboard that tracks GPU wattage, token throughput, and cost-per-inference for local LLM rigs — so homelab operators know exactly what their AI stack costs to run.
AI Literacy Training for Experienced Professionals (50+)
For mid-to-late-career professionals who want practical AI skills that apply to their actual job — without starting over from scratch.
AI-Powered Acquisition Readiness Audit for SaaS Founders
Vibecoding is now a standard M&A due diligence step — Bain consultants are vibecoding acquisition targets to prove their code isn't defensible.
AI Sandbox Isolation: The Infrastructure Checklist Every Agentic AI Team Needs
Network segmentation for AI eval environments, egress allowlisting patterns, and a minimum viable sandbox spec — with steps to verify isolation before you run a capable model.
AI Shared-Chat Malware Detection Guide for IT Teams
A practical guide for IT teams to recognize and block malware distributed through AI shared-chat features, plus ready-to-use organizational AI usage-policy templates.
AI Tool Spend Optimization Guide for Engineering Teams
A practical framework for engineering teams and IT managers to audit, right-size, and optimize spending across Claude API, GitHub Copilot AI Credits, and other metered AI tools — with a cost-per-PR calculator and decision matrix included.
Claude Code Security Audit Tool for GitHub Repos
Build a pre-flight scanner that inspects a GitHub repo's setup scripts and CLAUDE.md before Claude Code runs them — flagging DNS-pulled payloads, suspicious eval patterns, and reverse-shell indicators.
Claude Enterprise Deployment Guide for IT Departments
A practical guide + reusable templates for IT teams inheriting Claude-powered workflows from consultants — covering security posture, data governance, API integration patterns, and shadow AI governance.
Cron & Scheduled Tasks Quick-Reference Kit for Linux Sysadmins
Master cron, systemd timers, and at jobs in one printable reference — syntax cards, real-world job examples, and a safety checklist so you never fat-finger a production schedule again.
DevOps Career Roadmap & Certification Guide 2026
For mid-level IT professionals with 3–7 years of operations experience who are ready to move into a DevOps or Cloud Engineer role — and want a clear, opinionated path to get there in 2026.
DevOps/SRE Interview Prep Cheat Sheet Bundle
Crack your DevOps/SRE interview in a weekend — scenario frameworks, K8s commands, CI/CD walkthroughs, and behavioral answers all in one cheat sheet bundle.
DevOps/SRE Career Track Bundle (Interview Prep + Resume Kit)
Land your next DevOps or SRE role faster — ATS-optimized resume templates, 2026 keyword lists, and scenario-based interview frameworks in one career bundle.
Microsoft Entra ID Migration Starter Kit for Sysadmins
A practical guide + checklist bundle for IT admins migrating on-premises Active Directory to Microsoft Entra ID in 2026 — covering Cloud Sync, legacy auth deprecation, Intune join strategy, and a phased migration checklist sysadmins can actually execute.
Entra ID Zero Trust Starter Kit for Sysadmins
A practical guide and policy template bundle for sysadmins implementing Microsoft Entra ID Zero Trust — Conditional Access policies, MFA rollout, Privileged Identity Management basics, and a 30-day activation roadmap.
Forward-Deployed Engineer Career Guide for Sysadmins
Show experienced sysadmins how their real-world deployment skills map directly to the fastest-growing AI-era role — Forward-Deployed Engineer — and give them a concrete path to land one at $200K+.
GitHub Copilot AI Credits Cost Calculator
A free web calculator that estimates your monthly GitHub Copilot cost under the new metered AI Credits billing model based on your actual usage patterns.
IT Offboarding & Knowledge Transfer Kit
Structured templates for capturing and handing off institutional IT knowledge when someone leaves — access deprovisioning checklist, system ownership matrix, undocumented-workaround interview guide, and a 30-day successor onboarding plan.
IT Vendor AI Contract Review Checklist
A structured checklist and scoring rubric for IT managers evaluating vendor AI clauses — data retention, model training rights, liability, and exit terms — before signing SaaS contracts that now bundle AI features by default.
IT Vendor Review Meeting Template Kit
A reusable template bundle — agenda, scoring rubric, TCO spreadsheet, and follow-up email pack — that gives IT managers a structured, repeatable process for evaluating and presenting vendor decisions to leadership.
Kubernetes Troubleshooting Runbook & Decision-Tree Kit
A printable PDF runbook with visual decision trees for the 15 most common Kubernetes failures — CrashLoopBackOff, ImagePullBackoff, pending pods, OOMKilled, and more — turning a 45-minute debug spiral into a 5-minute checklist.
Linux Command Line & Sysadmin Cheat Sheet Bundle
For junior-to-mid Linux sysadmins, cert studiers, and homelab operators who want organized command references — not another tab of man pages.
MAESTRO Security Framework for Claude Code Projects
Apply the MAESTRO 7-layer threat-modeling framework to any autonomous Claude Code / Agent SDK project — enumerate threats across the whole chain and fill in a reusable threat model for your own stack.
MCP Server Setup Guide for Sysadmins
A hands-on guide for sysadmins and IT pros to deploy, configure, and secure local MCP servers — covering tool selection, auth patterns, network exposure controls, and integration with Claude Code and local LLMs.
On-Call Survival Kit for Sysadmins & SREs
Survive and improve every on-call rotation — runbook templates, alert triage flowcharts, escalation scripts, and a post-incident review framework in one downloadable bundle.
OpenAI Codex Record & Replay: IT Automation Without Code
Learn to record your repetitive IT workflows once and let Codex replay them as reusable AI skills — the practical guide for sysadmins who want automation without writing a script.
Prompt Injection Defense Toolkit for Claude Code Users
Detect injected instructions in fetched content, audit tool call chains, and run agentic workflows safely — the prompt injection defense guide Anthropic hasn't written yet.
Proxmox VE Complete Setup & Migration Guide
Stop piecing together blog posts. Migrate from VMware and run Proxmox right.
Run Your Own LLM API Endpoint with HF Jobs + vLLM
Hugging Face Jobs now lets you spin up a private, OpenAI-compatible vLLM endpoint in a single command with pay-per-second billing.
SE Job Market 2026: AI Skills Transition Guide for Sysadmins
A practical pivot guide for sysadmins navigating the 42% AI-skills mandate and 28% entry-level SE decline — showing exactly which AI engineering skills convert fastest from an ops background.
SkillOpt for ClaudeClaw Agents
Implement Microsoft Research's SkillOpt concept for ClaudeClaw's war room agents: treat each agent's procedural memory file as trainable external state that self-improves across runs.
Slash Command System Deep Dive: Build Your Own Agent Dispatcher
Build a custom slash command dispatcher in TypeScript using ClaudeClaw as a live working example — bridging simple prompts and real agentic workflows.
Solo Sysadmin Salary & Career Navigation Bundle
A practical toolkit for mid-career sysadmins ready to stop accepting stagnant pay and start making data-backed decisions about their compensation and career.
The Real Economic Disruption Playbook — ASTGL Newsletter Series
For mid-career sysadmins and IT ops professionals who want a grounded, data-backed framework for navigating AI-era disruption — not reassurance, not doom.
VMware ESXi to Proxmox Migration Playbook
Step-by-step migration playbook for moving Windows and Linux VMs from ESXi to Proxmox VE — covering OVA/OVF export, storage migration, network reconfiguration, and post-migration validation checks.
Windows Server Patch Management Playbook
For solo sysadmins and small IT teams managing Windows Server patching at SMBs — a practical guide and checklist bundle that turns a monthly fire drill into a repeatable process.
Agentic AI Security Policy Template Pack
Downloadable Markdown + YAML policy templates giving IT teams the acceptable-use, blast-radius, approval-gate, and logging scaffolding to safely deploy agentic AI coding tools like Claude Code, Codex, and Grok Build.
Agentic Migration Playbook: API Endpoint Modernization
For DevOps and platform engineers with a real migration deadline — the complete Claude Code workflow you'd otherwise spend months reverse-engineering.
Ansible Automation Starter Kit for Linux Sysadmins
12 production Ansible playbooks for Linux sysadmins — annotated, tested, ready to run.
ASTGL PowerCLI Automation Cookbook v1.0
14 production-ready PowerShell 7 scripts for vSphere admins — built for Broadcom VCF.PowerCLI, ships-to-vCenter ready.
Bash Scripting for Sysadmins Reference Guide
The Linux sysadmin's go-to bash reference — patterns, variables, loops, and practical automation scripts in one printable guide.
CI/CD Governance Bottleneck Playbook for AI-Augmented Teams
A practical guide and checklist bundle for engineering teams whose human release-approval processes have become the rate-limiting step after AI floods their repos with code.
Claude Code Security Scan CI/CD Integration Template
Both Anthropic and OpenAI shipped AI vulnerability scanners this month — here's the copy-paste GitHub Actions workflow, per-PR cost math, and false-positive triage playbook that turns them into something you'd actually merge against.
Claude Mythos Vulnerability Scanner — Educational Demo
A teachable ASTGL guide + lightweight demo showing how to use Claude Code and the Claude API for AI-assisted vulnerability scanning on your own projects — bringing Mythos-level thinking to solo developers.
Compound Engineering Workflow Guide for Solo Builders
For solo Mac Studio developers who want a structured, repeatable Claude Code workflow — not another tutorial that resets every session.
Crontab Survival Kit
A read-only Bash toolkit + concise PDF runbook that produces a single Markdown report mapping every cron job on a Linux host — what runs, when, where it logs, and which schedules overlap. Translates cryptic cron expressions into plain English. No installs touched.
DeepSeek V4 vs Claude vs Local LLM Benchmark Kit
A standardized Python benchmark suite with a simple results dashboard that lets Mac Studio and local LLM users compare DeepSeek V4, Ollama models, and Claude API on real-world coding, reasoning, and agentic tasks.
DNS Drift Detector
For sysadmins and SREs managing 1–10 domains who need a nightly heads-up when a record quietly changes under them.
Docker Compose Production Hardening Kit
Transform your dev-grade Docker Compose stacks into production-ready deployments with security configs, resource limits, health checks, and secrets management — all annotated and ready to drop in.
GitHub Actions Starter Kit for Sysadmins
10 annotated GitHub Actions workflow YAML files purpose-built for IT ops tasks — automated patch checks, server health pings, backup validation notifications, SSL cert expiry alerts, and dependency audits — with a setup guide for sysadmins who've never touched CI/CD.
GitOps Workflow Starter Kit
For DevOps engineers and sysadmins who need to stand up a declarative GitOps pipeline without spending a week in documentation rabbit holes.
Grafana Loki Centralized Logging Starter Kit
Ship centralized log aggregation in an afternoon — a Docker Compose Loki + Promtail + Grafana stack, annotated configs, a LogQL cheat sheet, and a 15-page setup guide.
Hermes Blank Slate Starter Kit for Minimal Secure Agents
Build a starter template that uses Nous Research Hermes Agent's new Blank Slate mode to create minimal, security-hardened agents.
Homelab DR Kit v2 — Advanced Edition
Expand beyond the published v1 with automated backup validation scripts, tested restoration runbooks, and a DR drill scoring rubric for homelabs running Proxmox, TrueNAS, and containerized services.
Build 5 Real Infrastructure Projects from Zero
Escape tutorial hell for sysadmins — five hands-on homelab projects (monitoring, automation, DR, networking, security) with guided specs, code stubs, and a 30-day progress tracker.
k3s Homelab Kubernetes Starter Kit
Stand up a 3-node k3s cluster on your homelab hardware in an afternoon — annotated manifests, Helm quickstart, persistent storage config, and a troubleshooting cheat sheet for the ops engineer graduating from Docker Compose.
Kubernetes + Helm Starter Kit for Sysadmins
Annotated Helm chart templates and a kubectl cheat sheet that let a sysadmin deploy their first K8s workload without reading three docs sites.
Kubernetes & kubectl Command Toolkit
The kubectl + Helm reference kit every DevOps engineer bookmarks — annotated YAML starters, command cheat sheets, and troubleshooting flowcharts in one printable bundle.
Local Agent Memory Manager Using Claude Dreaming Pattern
A local-first CLI tool that consolidates and compresses agent memories between sessions using Ollama and SQLite — persistent cross-session memory with zero cloud dependencies.
macOS Sysadmin Field Manual
A concise PDF + Bash-toolkit field manual for sysadmins managing 5–50 Mac endpoints WITHOUT a full MDM (Jamf/Kandji/Mosyle). Read-only inventory scripts (hardware, OS, FileVault, Gatekeeper, XProtect, login items, software updates) plus a triage workflow that produces a single Markdown fleet-health report per host.
MCP Security Audit Tool for Local Agent Stacks
A CLI scanner that reads local MCP server configs and emits a Markdown + JSON audit report covering tool surface area, auth methods, and blast radius.
MCP Tunnel Explainer: Private Network MCP Without Public Endpoints
A hands-on tutorial and code walkthrough showing how to wire a local Ollama MCP server behind an outbound-only encrypted tunnel — no public IP, no inbound firewall rules, yet agents still reach private enterprise tools.
Multi-LLM Orchestration Router for Mac Studio
Inspired by Sakana AI's Fugu (which matches Fable 5 benchmarks by dynamically routing tasks to the best model in a pool), build a local orchestration layer for the Mac Studio that routes agent tasks across Ollama models, Claude API, and local alternatives.
Port Drift Detector
A read-only Bash toolkit that inventories every listening TCP/UDP port on a Linux host, maps it to the owning process and unit, diffs against an expected baseline you declare once, and flags silent drift — new listeners, moved ports, processes that used to bind 127.0.0.1 but now bind 0.0.0.0, unit files whose ExecStart changed. Runs nightly, diffs visibly. Catches the 'who opened 8080?' question before the pen-tester does.
PowerShell Automation Starter Kit for Windows Sysadmins
20 production-ready PowerShell scripts for the Windows sysadmin who automates everything.
Prometheus + Grafana Monitoring Starter Kit
Deploy Prometheus + Grafana in 30 minutes — 5 import-ready dashboards, annotated configs, and a PromQL cheat sheet bundled together.
Secure Docker CI/CD Pipeline Checklist & Toolkit
Ship Docker containers with confidence — a checklist bundle covering image hardening, secrets management, registry scanning, and production rollback, all in PDF + Markdown + GitHub-ready templates.
SSH Key Hygiene Kit
Find every stale SSH key across your server fleet in under 10 minutes — read-only, agentless, Bash 3.2+ compatible.
Sudoers Audit Kit
A read-only Bash toolkit that maps every sudo privilege on a Linux host — who can run what, which NOPASSWD rules exist, which aliases resolve to root, and which include-files shadow the main sudoers. One Markdown report, zero writes. Finds the "we'll clean that up later" grants buried in /etc/sudoers.d/.
Terraform IaC Starter Kit for Sysadmins
10 annotated Terraform/OpenTofu configs for AWS and Azure — get from zero to running infrastructure in one afternoon.
Terraform + Kubernetes Homelab Career Kit
The homelab kit that gets you the job — working Terraform modules, a K8s cluster setup guide, and the interview narrative to prove you built it.
Terraform + GitHub Actions Homelab Career Kit
For mid-career sysadmins rebuilding cloud-relevant skills — a complete, working IaC project you can run today and talk about in interviews tomorrow.
TLS Cert Expiry Scanner
A read-only script that scans your fleet's listening TLS ports, extracts every cert in use, and produces a dated report ranking each by days-to-expiry, SANs, issuer, and chain health. Catches the self-signed cert your predecessor installed on the internal API three years ago before it breaks prod on a Sunday.
User Audit Kit
For Linux sysadmins and SREs who need a defensible account inventory before an audit, an offboarding sweep, or a compliance review — without touching a single file on the server.
Windows Event Log Analysis Field Guide for Sysadmins
A practical reference guide covering the 20 most critical Windows Event IDs every sysadmin must monitor — with detection logic, triage steps, and copy-paste PowerShell queries for each.
Substack Scheduler
Schedule and automate Substack Notes posts with a native desktop app — no browser required
UpdateKit
UpdateKit is a native macOS update manager that finds every app on your Mac via the LaunchServices API, checks for updates from Sparkle appcasts and GitHub Releases, and flags known security vulnerabilities using the NIST NVD CVE database — surfacing critical patches first. Installs are transactional: a privileged helper handles the destructive replace atomically, with rollback on failure and orphan recovery if anything crashes mid-update. Local-first SQLite database, no accounts, no telemetry. Free to download. Founders Edition Pro license ($19, lifetime) supports development and unlocks future Pro features as they ship — starting with Guardian Mode for managing updates on a family member's Mac (v1.1).
AI Employees: Build Your Own Autonomous Team
Stop prompting. Deploy agents that work while you sleep.
Homelab Beginner Starter Kit
Your first homelab in a weekend — no rabbit holes required.
Homelab Resilience & Disaster Recovery Kit
Plan, test, and document your homelab disaster recovery — so you're not rebuilding from scratch when your NAS fails at 2AM
Microsoft Intune Quick-Start Kit for Small IT Teams
Get your first 50 devices managed in Intune this week — policies, enrollment, and troubleshooting, without the Microsoft docs maze.
n8n IT Automation Starter Guide
Set up 5 real IT automation workflows in n8n — monitoring alerts, backup notifications, incident tickets, health checks, and report generation — all with downloadable JSON.