August 2026
Jellyfin 10.11.10+ Security: Treat Media as Untrusted Input
Contain untrusted Jellyfin media, preserve evidence, patch to the current stable release, restrict writable paths, validate clients, and recover without returning to a vulnerable version.
Patch Tailscale 1.98.9: Audit SSH, Serve, Funnel, And Services
A documentation-backed, testable runbook for Patch Tailscale 1.98.9: Audit SSH, Serve, Funnel, And Services, with safe defaults, validation evidence, failure modes, rollback, and publication-day checks.
Adding RAG: Chat with Documents Locally
A beginner-friendly guide to local document chat, embeddings, vector databases, Open WebUI knowledge bases, privacy, and common RAG mistakes.
Open WebUI Deep Dive: Users, Models, Documents, Prompts, and Safe Sharing
A noob-friendly tour of Open WebUI after installation: user accounts, model switching, documents, prompt shortcuts, admin settings, OpenAI-compatible endpoints, backups, updates, reverse proxy basics, and LAN/VPN security.
OpenWrt 24.10.8 and 25.12 Migration Runbook: Patch, Backup, Sysupgrade, and Recovery
An OpenWrt router upgrade runbook for patching exposed services, preserving config, checking device support, testing DHCP, Wi-Fi, DNS, and keeping recovery ready.
Keycloak 26.7.1 Security Response: Map the Fixes to the Features You Actually Use
Keycloak 26.7.1 includes many security fixes. This guide maps them to OIDC, SAML, FGAP, DCR, LDAP, metrics, and upgrade validation.
Local AI Hardware Sizing: CPU, NPU, GPU, RAM, and VRAM
A local AI hardware sizing guide explaining model memory, quantization, KV cache, CPU-only use, NPUs, GPUs, RAM, VRAM, and upgrade tiers.
Building the Right PC for Local AI
A plain-English guide to choosing the right CPU, RAM, GPU, VRAM, storage, power supply, and cooling for a local AI homelab PC.
Bazarr 1.6.1 Security Response: Patch or Isolate, Rotate Keys, and Check for RCE
A practical Bazarr response plan for the 1.6.1 authentication bypass chain: isolate exposure, patch, rotate secrets, review logs, and decide when to rebuild.
Portainer 2.44 Security and Bootstrap Tokens: Secure First Run and Existing Installs
A Portainer security runbook for first-run exposure, setup tokens, agent trust, endpoint permissions, backups, and management-plane isolation.










