August 2026

Network Security
Jellyfin 10.11.10+ Security: Treat Media as Untrusted Input

Contain untrusted Jellyfin media, preserve evidence, patch to the current stable release, restrict writable paths, validate clients, and recover without returning to a vulnerable version.

Read more
Network Security
Patch Tailscale 1.98.9: Audit SSH, Serve, Funnel, And Services

A documentation-backed, testable runbook for Patch Tailscale 1.98.9: Audit SSH, Serve, Funnel, And Services, with safe defaults, validation evidence, failure modes, rollback, and publication-day checks.

Read more
AI
Adding RAG: Chat with Documents Locally

A beginner-friendly guide to local document chat, embeddings, vector databases, Open WebUI knowledge bases, privacy, and common RAG mistakes.

Read more
Homelab
Open WebUI Deep Dive: Users, Models, Documents, Prompts, and Safe Sharing

A noob-friendly tour of Open WebUI after installation: user accounts, model switching, documents, prompt shortcuts, admin settings, OpenAI-compatible endpoints, backups, updates, reverse proxy basics, and LAN/VPN security.

Read more
Network Security
OpenWrt 24.10.8 and 25.12 Migration Runbook: Patch, Backup, Sysupgrade, and Recovery

An OpenWrt router upgrade runbook for patching exposed services, preserving config, checking device support, testing DHCP, Wi-Fi, DNS, and keeping recovery ready.

Read more
Linux and Homelab
Keycloak 26.7.1 Security Response: Map the Fixes to the Features You Actually Use

Keycloak 26.7.1 includes many security fixes. This guide maps them to OIDC, SAML, FGAP, DCR, LDAP, metrics, and upgrade validation.

Read more
AI
Local AI Hardware Sizing: CPU, NPU, GPU, RAM, and VRAM

A local AI hardware sizing guide explaining model memory, quantization, KV cache, CPU-only use, NPUs, GPUs, RAM, VRAM, and upgrade tiers.

Read more
Homelab
Building the Right PC for Local AI

A plain-English guide to choosing the right CPU, RAM, GPU, VRAM, storage, power supply, and cooling for a local AI homelab PC.

Read more
Linux and Homelab
Bazarr 1.6.1 Security Response: Patch or Isolate, Rotate Keys, and Check for RCE

A practical Bazarr response plan for the 1.6.1 authentication bypass chain: isolate exposure, patch, rotate secrets, review logs, and decide when to rebuild.

Read more
Linux and Homelab
Portainer 2.44 Security and Bootstrap Tokens: Secure First Run and Existing Installs

A Portainer security runbook for first-run exposure, setup tokens, agent trust, endpoint permissions, backups, and management-plane isolation.

Read more