Docker
Container Security for Normal Homelabs
A normal-person Docker security guide for exposed ports, privileged containers, Docker socket risk, secrets, rootless mode, user namespaces, and backups.
Self-Hosted App Lifecycle: Updates, Rollbacks, and Release Notes
A self-hosted operations guide for updating containers safely, reading release notes, backing up state, automating carefully, and rolling back.
LXC vs VM vs Docker VM in Proxmox
A practical Proxmox placement guide for deciding when to use LXC containers, full VMs, or a dedicated Docker VM for home-lab workloads.
Recyclarr 8.7 Security Response: Treat Template Sources as a Write Boundary
A Recyclarr security-response guide for template-provider path traversal: upgrade, inventory providers, protect secrets, compare generated files, and test safely.
Bazarr 1.6.1 Security Response: Patch or Isolate, Rotate Keys, and Check for RCE
A practical Bazarr response plan for the 1.6.1 authentication bypass chain: isolate exposure, patch, rotate secrets, review logs, and decide when to rebuild.
Portainer 2.44 Security and Bootstrap Tokens: Secure First Run and Existing Installs
A Portainer security runbook for first-run exposure, setup tokens, agent trust, endpoint permissions, backups, and management-plane isolation.
Run Google Gemma Locally with Ollama, Open WebUI, and Codex CLI
Run Google Gemma locally with Ollama and Open WebUI, then connect Codex CLI for private coding workflows. Includes Docker setup, GPU sizing, Tdarr notes, and security guidance.
Nginx Proxy Manager vs Caddy vs Traefik: A Reverse Proxy Decision Tree
A reverse proxy decision tree for homelabs: when to pick Nginx Proxy Manager, Caddy, Traefik, or raw NGINX.
Orange Pi 6 vs Raspberry Pi 5 for Homelab: Powerful Hardware, Real Tradeoffs
Orange Pi 6 brings dual 2.5GbE, dual NVMe, LPDDR5, and serious AI claims to a tiny board, but software support and total cost decide whether it belongs in your homelab.
One UPS, Many Devices: NUT Shutdown for Proxmox, NAS, Router, and Docker Hosts
A practical NUT architecture for coordinating clean shutdown across Proxmox, NAS, Docker hosts, and network gear from one UPS.










