Microsoft Security BlogsecurityTue, 29 Sep 2026 21:39:27 +0000
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog .
It's been a while since any new Spectre vulnerabilities have come to light but that's changing today. The embargo has now lifted on BTR, Branch Target Reuse as a new Spectre-V2 attack affecting just-in-time (JIT) compilers...
Building on the major release of Tempo 3.0 , Tempo 3.1 is here, delivering community-contributed Kafka client improvements, query-based trace redaction, sampling-aware TraceQL metrics, and more. Together, the updates in 3.1 make it easier to operate Tempo, get accurate insights from your trace data, and investigate issues more efficiently. You can continue reading and check out the video below to learn more about the latest features. The Tempo 3.1 release notes and changelog provide more in-dept
Microsoft Security BlogcveWed, 30 Sep 2026 14:00:00 +0000
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog .
A successful backup job seems like a different milestone from a usable restore. I’m interested in a small, repeatable check for self-hosted apps that doesn’t turn into a whole weekend project. My proposed minimum would be: restore into an isolated instance, restore the necessary configuration and secrets, sign in, open a known record and attachment, and check that user permissions still behave correctly. I would also keep outgoing email and webhooks disabled during the test so the restored insta
Taking over a production Java application from a SaaS provider and wondering how common this kind of transition is. We have the application running in our own environment, but the SaaS service expires at the end of the month and our instance needs to run in perpetuity thereafter. We haven't yet done a production database restore from backup, and we don't have the long-term backup/restore process fully in place. Some organizational constraints also mean that, for now, we can deploy only to the te
A useful troubleshooting habit I’ve picked up: Don’t change something simply because it looks suspicious. Establish the evidence first. A Windows Server issue can appear to be a service problem while the actual cause sits somewhere else — DNS, network connectivity, authentication, GPO, firewall, dependencies, or even the client. A structured approach helps: Observe → Isolate → Test → Verify → Remediate It takes a little longer at the beginning, but usually saves time when the problem isn’t where
I've been writing a series of articles about configuring postfix and dovecot to provide email services on a Debian Trixie VPS. This latest article is about how to configure SPF, DKIM and DMARC so your mail server won't be tagged as a spammer. You can find it at postfix: Asserting You’re Not a Spammer - Imperfect Computing Enjoy! And thanx again to the community here for helping me get started on this configuration. submitted by /u/MotorcycleMayor to r/selfhosted [link] [comments]
Hey folks! Absolute newbie here. My job recently upgraded computers across the board and I was able to walk away with 20 of these 600GB hard drives for free. I feel like I hit the jackpot, but now I need to figure out how to optimize this. I have a raspberry pi that's been collecting dust for awhile now. Would that be enough to run Jellyfin and Immich off of, or do I need a better mini computer? How do I even link the hard drives to the pi? What type of SAS bay should I get? Is that even the rig
So what are the best options for securing the nas and backing up to external drives? Seems like the native UGOS sync and backup tools are user friendly but nothing is encrypted. I worry about someone physically taking my nas and drives and all my data being accessible. Currently using the NAS with docker for Immich, jellyfin and nextcloud, as well as UGOS backups of photos from my phone. Any suggestions would be appreciated, thank you. submitted by /u/ctzn2000 to r/selfhosted [link] [comments]
I got tired of paying a company to read the questions. I wanted the model on my machine, the notes on my machine, and a chat that does not phone home. Simple. Local. Mine. You do not need a server, a graphics card, or an account. You need a normal computer, a free model app, and Docker. An 8 GB machine can run a small model. 16 GB is the comfortable one. The model download is about 5 GB. Mac, Windows, and Linux all work. If any of that is missing, it is a free download, not a project. No API key
Hi. I don't have much knowledge about cybersecurity/networks and I would like to improve the security of my home server. Currently, I have several services accessible from the Internet (the ones shown in the images) and right now I have them published through open ports on the router and a DuckDNS domain, but everything works over HTTP. I would like to move to HTTPS and, if possible, make the services accessible from outside without having to keep ports open on the router. What options would you
Hey everyone, I wanted to track all my money in one place (bank accounts, brokers, crypto, real estate) without handing my bank credentials to a cloud service, so I built Picsou. It syncs 2,000+ EU banks via PSD2, plus brokers like Trade Republic and crypto wallets, and tracks your net worth over time. Multi-arch images on GHCR: `docker compose up -d`, a setup wizard, done. Best suited for LAN use. Free for personal use: https://github.com/Cloeille/picsou-finance Would love feedback on the insta
I’m building a private alternative that runs completely on your own hardware. How it works: You hold a single button on your phone / or press a shortcut on your computer. You just say what you ate: "A bowl of chicken soup and two slices of whole wheat bread." The voice memo goes straight to your computer, which instantly processes the audio, calculates calories/macros, and updates your charts. I want to package this into a simple, easy-to-install app for your computer alongside a lightweight mob
I built Baloo because reviewing the code our coding agents produced was becoming a bottleneck. It runs as your own GitHub App. You choose which repositories it can access and provide the model credentials. Baloo reads the diff and surrounding code, checks repository conventions from AGENTS.md and CONTRIBUTING.md , and posts findings directly in GitHub. It tracks review threads across pushes so the same issue doesn’t keep appearing as a new comment. You can also give it specific checks in the PR
I would prefer not to deal with QNAP. They have too many security issues, and too much negative feedback from other posters here. Something simple with 2 spinny disks for raid-1. And quiet. I don't mind disk noise while it is being used, but want it to be quiet when idle. submitted by /u/caboy456 to r/homelab [link] [comments]
am a sysadmin, so I have no real coding experience. I have rebuilt networks and server rooms, worked with high-security networks, automated and set up IaC using Ansible and Terraform, and set up SSO. I have mostly worked with on-prem infrastructure, such as Proxmox and Ceph. I have worked with pipelines maintained by developers and also set up pipelines myself for internal IT. My question to you is: what should I focus on? I mean, when I did the Amazon interview, it was basic networking, trouble
If anyone uses CATO Networks they did maintenance on their backend and firewall behavior is broken. Essentially traffic is now being treated as stateless rather than stateful so our environment traffic flows are all broken. The issue is being tracked internally by CATO but wanted to pass along in case shit hit the fan for other orgs this morning/last night submitted by /u/Lopsided-Ad8680 to r/sysadmin [link] [comments]
As promised earlier today, here is an in-depth write-up of how I got postfix and dovecot to play together on a Debian Trixie VPS targeting both system and virtual users, and multiple domains. Thanx again to all the folks who helped me out in this reddit! postfix/dovecot Configurations - Imperfect Computing Enjoy! submitted by /u/MotorcycleMayor to r/selfhosted [link] [comments]
I’m trying to solve the mess around moving someone between departments: groups, Teams, SharePoint access and mailbox permissions. How do you confirm the old access is gone and the new access works—without manually checking everything? submitted by /u/Emergency_Recipe522 to r/sysadmin [link] [comments]
pfSense rules always seem to bamboozle me no matter how much research I do. I followed the online setup guide from Netgate. so I set up DNS over TLS and I am forwarding DNS requests to 53 back to the firewall, allowing 53, and blocking access to external 53 and 853 servers. Is this correct for DoT? Configs if needed: https://imgur.com/a/ZXHEiOL submitted by /u/amrogers3 to r/homelab [link] [comments]
Does anybody have experience with self-hosting a super-low-cost or no-cost landline service? It seems the only VoIP space these days are people trying to run home offices and need multiple lines. I just want something super cheap to run a an old-fashioned landline or two. My goal is to provide a phone service for my kids in lieu of getting them cell phones - as they are still pretty young and I'd like to insulate them as long as I can from smartphones. Basic google searching suggests various pro
Hi, everyone. I recently bought four 2 TB hard drives at a flea market, but when I got home, I realized they had a SAS interface, not SATA. I know I need to buy an IT-mode HBA controller with cables for them to work. Is it worth buying the controller and installing it in my home lab to use them for storage, or should I just resell them? (It’s worth noting that I have another SAS-compatible computer and that I’ve tested each of the drives: they all worked fine. The four drives have less than 5,00
Anyone able to sanity check this (slightly vague) plan? I've got an old synology with a mirrored pair of 4TB disks in it. Mostly movies, music and photographs. Doesn't get new content very often. I stream music (minimserver) and movies (movies via a separate jellyfin server - but I'd rather it ran on the NAS but cant because synology). The photographs are mostly just archive via smb. It all totals about 2.6TB. I backup onto an external 2TB disk (and hence skip most of the movies to get it to fit
I've been trying to set up icloudpd on my Synology NAS via Container. I have it working and the logs show that it's downloading files from iCloud. However, when I go to the download folder location, there are no files shown. I've even looked at the download folder through File Station and I still don't see any files. I have even deleted the project folders and rebuilt the project, but no luck seeing any files. I removed user info since I've already verified all that information. I think the cont
I'm new to docker and I'm looking to learn/experiment with it. I want some advice regarding containers that will be used by other services like databases. I'm currently running two services which share a postgres container. For isolation, I created a migration which creates separate databases and users for each service before anything else starts. I'll eventually setup more services and I want it to be scalable, resource efficient, secure and easy to maintain. Is it better to create entirely sep
Curious if others are still seeing issues after deploying the Windows Server September 2026 out‑of‑band updates. In my environment, RDP is still failing, several servers need two or three reboots before they stabilize, and a few VMs are losing their assigned IP address at the hypervisor layer. How widespread is this, and has anyone found reliable workarounds? Patching has definitely not been good this month. submitted by /u/No_Solid68 to r/sysadmin [link] [comments]
I have a Ugreen dxp4800 plus running debian 13 with a 4TB 990 Pro and 4x20TB WD Pro drives. My four hdds are XFS individual filesystems no redundancy. I went this route primarily because my data is 99% movies and shows that I have cross seeded on multiple trackers so if a drive fails I can always just redownload. Right now I have four different folders for movies and shows across the drives. Should I just merge the four filesystems with mergerfs? And is there any downside with that approach like
Yep, a golden image. I still like having one on hand. That's my set up, and it's hard to argue with something that 'just works' most of the time. I've used clonezilla for applying that golden image. It's free. It's also works fairly well most of the time. So this might be a clonezilla question but I haven't found anything for a clonezilla setting yet. I was already resizing the Recovery partition. Then I found out Microsoft will want a larger System partition. So on a new image, I'll make a larg
I updated my main switch connecting my homelab from an Aruba CX with 1G+10G SFP+ to a Grandstream with 1G/2.5G/10G SFP+. While the CLI takes some time to getting used to, I'm pretty happy with the GWN7822P over all. I have a second switch installed in my fuse box connecting my living room and two other rooms using the pre installed cabling. A HPE/Aruba Instant On 1830 8G in local management is used at the moment. It's powered over PoE from the Grandstream as the power outlet is already taken by
Which is great, because if there was one unsolved problem in 2026, it was finding a way to run a Linux container on a developer's laptop. Microsoft has now given us wslc . I read the architecture deep dive expecting to understand why. I now understand the architecture. submitted by /u/Haunting_Ganache_850 to r/docker [link] [comments]
Broadcom 9400-16i On a new Broadcom 9400-16i I was able to update the firmware from version 16.00 to 22.00 and efibios with success in EFI mode. I used the instructions linked above which were very helpful. When I boot to Windows 11 the HBA controller has 3 line items. The top one is Avago Adapter Crusader Storport Version 2.61.29.80 Driver date 7/21/2017. According to Broadcom’s website the ITSAS35 P24 driver version is 8/9/2022 and version 2.61.48.00. I tried updating the driver from the ITSAS
Hello there! I've been in the selfhosting game for around 1 and a half year now. I would still consider myself a novice. But I have definitely leveled up. My "problem": I currently have a Truenas Scale system up and running with the following apps installed: Immich Plex Jellyfin Tailscale Mealie More or less just Storage things (except from Tailscale). BUT I want to level up. I want to host other things that are not storage things. Mainly Home assistant for example or *arr stacks (I know they ca
I stumbled upon HAVEN a few weeks ago while looking and testing various Discord alternatives. Haven looks and feels like discord, has PTT, soundboard, listen together, bots, and is light weight with an active team of devs behind it. I submitted an issue and the devs had it turned around in a week or so. Give it a crack, if you are looking for discord alternatives I can highly recommend! Haven, a chat server you run yourself ancsemi/Haven: Self-hosted private chat: no cloud, no telemetry, no Big
I posted this here a year ago and it went badly. The criticism was mostly fair. It was a bare link, there were no tests at all, and when I was asked twice how much of it was AI-written I didn't answer. So, answering first: The code is LLM-written and I direct it. Worth being precise about what "the code" is: kinc implements no Kubernetes, it's about 2,900 lines of shell and a handful of systemd units that assemble upstream components (kubeadm, kubelet, etcd, CRI-O, crun, Antrea, Fedora). What's
Hello to everyone. I hope this is the right sub to ask this. For at least 5 years I've been using both Google Photos and OneDrive to back up my photos. While OneDrive isn't perfect, it lays out all my photos in an understandable matter on my PC. All the exif data is contained in the photos and videos itself. When I use Google Takeout to download my entire G Photos library I've noticed that the exif data is separate and all my photos are in confusing folders and such. So i Have 2 problems: Gettin
Hey all, I’ve received notice that the DigitalOcean Open Source Credits Program is sunsetting and will no longer be accepting new applications or renewals. I’ve been fortunate enough to get credits for portchecker.io for many years now, and typically I’m a month away from requiring more credits. I’m currently using their App Platform with a static front end and their $5 container for the backend. I do get alerts for CPU so was looking at bumping to the next one (it gets a lot more traffic than I
This month includes 30+ Microsoft 365 major updates across new features, enhancements, retirements, and behavior changes that admins should review. In the spotlight: Pause all Teams notifications: Teams is introducing a new option to pause all notifications for a specific period , helping users reduce interruptions and stay focused. Prompt injection protection for email: Microsoft Defender for Office 365 is adding prompt injection protection to detect and block malicious email content designed t
My machines spend their nights running long jobs (agents, builds, backups) and I wanted one browser tab showing everything they're doing: every terminal session, what's running on each box, actual GUI windows from the Mac, and the admin panels that only ever listen on localhost. Without opening a single inbound port on anything. What pushed me to build it rather than rent it: every product in this space wants the work to happen on their computer. That's a non-starter for anything touching a priv
I work with Superlinked and we are looking for competitors in the market for some benchmarking exercise. We have designated three small encoders, each on its own pool, each provisioned for a peak that shows up maybe an hour a day. When I finally measured utilization it was in the low single digits, so I have been looking specifically for servers that keep more than one model on a single card. As I work with SIE (Superlinked), we know it keeps models hot on one GPU and evicts least-recently-used
I'm working on a project in my spare time that I've dubbed Lararium(naming follows the Roman theme). It's currently in build phase. It started as a simple AI assistant to replace Googles AI features that I lost when I switched to GrapheneOS(not so much for privacy, but simplicity and minimal bloat.) I host my own LLM and try not to depend on the cloud as much. I started playing around with Muse and then Instinct, and I liked the features, but they are cloud dependent. So I decided that I would t
Post approved by mods. Hey all, I make Cliparr, you might have seen me post updates once in a while. I woke up today and cliparr.dev had a few more stars on GitHub. After checking the insights tab, I noticed some traffic from a podcast, Linux Unplugged. They had insanely awesome things to say about Cliparr and I wanted to share this segment from their episode. I would have embedded the segment directly, but only pictures are allowed in the sub. Click the link for a short version, or skip to 1:17
I'm new to kubernetes so I apologize. I'm trying to design my homelab. This is what I initially came up with. Is this an OK configuration? Looking for feedback. submitted by /u/knlklabacka to r/homelab [link] [comments]
I maybe should have asked beforehand but oh well. Basically I was looking for a decent new switch to replace our current at capacity one. Requirements are 12-24 port gigabit, some SFP+ 10G ports for uplink and my HPC server, ideally rack mount, managed to have vLANs, not extreme power consumption and decent quality so netgear was just right. Yeah and a 100 euro budget which this one fit right in. Does anyone else have it and what are your experiences? Well I bought it already but still what shou
The CNCF ecosystem is pretty vast, gush out about your favourites! [ kubectl , curl , jq and yq go into 'well known' category] submitted by /u/segv to r/kubernetes [link] [comments]
I have been using openmediavault as my NAS os for a while and it has been working great. I have been using its smb/cifs or NFS share to give access to files across my home network. This network share is used as a persistence storage for my containers either run on docker or k8s nodes. (fx. glance dashboard config file, navidrome's music storage and config) But recently i needed a webdav server to do a sync for my super-productivity service. So, i have run a copyparty container on the openmediava
I want to self host my git repos. i have set up gitea and gotten https part working through cloudflare tunnels, but i cant figure out how to set up ssh. i would like to use that since when i try to push through https i need to enter my password which gets annoying. I am also not sold on gitea and might switch to just normal git repos with cgit, but i need to get ssh working for that. i live in an apartment so i dont have control over my router and such which is why i use cf tunnels. I also would
I've been spinning up my BookOrbit and I cannot get it to see the folders in my /mnt directory no matter what I do. I have tried a number of configurations for the BOOK_HOST_PATH in the docker compose file. This is what it currently looks like ${BOOKS_HOST_PATH:-/mnt/synology/BookOrbit/Books}:/mnt/synology/BookOrbit/Books I've been working my way through courses on docker and linux, but I'm just not sure why it won't find the /mnt directory. The drive is mounted on my Debian 13 VM correctly. I c
An ultra-lightweight, offline-first anime library manager for local collections. I built it because while media servers like Jellyfin or Plex are amazing for central home setups, I wanted something local-first for managing anime directly on desktop devices without requiring a running server, Docker containers, or an active internet connection. Offline-First Storage: All progress, metadata cache, and library indexes are stored locally using SQLite. No telemetry, no external accounts required. Aut
What are the best practices for storage when using docker containers. I’m running docker on Ubuntu using my NAS to store the photos for example, but the volume were the Immich database lives is directly on the servers(non-redundant) SSD. I tried putting these onto the nas using NFS I get permission’s errors. Perhaps I should try harder? :-) I’d like to have all of my Doctor containers protected by the same redundancy that my synology has a for all of my data files. Right now if I had a major SSD
I run a small mesh of devices writing to a shared receipt ledger on a 2TB exfat drive. Kept needing a way to prove the ledger had not been altered between snapshots. Wrote one. 447 KB tarball: - x86_64 (glibc) + aarch64 (static musl) - Three binaries: verify, sign, keygen - Signed 943-record sample ledger - Public key included - Zero network calls. Zero runtime deps. Exit 0 = intact, 1 = broken, 2 = usage error. Not a blockchain. Just a file with hash links that anyone can verify in one pass. Of
I have been using Mattermost for years, and I've always been an advocate of the software, as it's, IMO, a pretty good self-hosted chat software. Unfortunately, after a few disappointments at a previous company actually trying (and giving up) to buy a licence, and after their latest actions, which I could only call backstabs (paywalling previously available features, putting arbitrary limits that previously didn't exist, or recently adding nag screens to push people into either buying their licen
We're adopting github actions at work and... they look clunky, bloated and overcomplicated? I've used both Jenkins in the past and Gitlab CI/CD (and bare shell scripts in a past life). It seems to me that gitlab-ci was the pinnacle of code-driven ci/cd (despite having some sharp edges). Also, running github runners in kubernets is quite a fight. Gitlab's runner was so easy and simple to run. Am I missing something ? submitted by /u/znpy to r/devops [link] [comments]
Hello, I’ve often heard good things about the M920Q with 16GB of RAM—getting two or three of them, depending on the use case. I need to host several services, and my current mini PC is already maxed out on RAM (16GB). Thanks. submitted by /u/AnxietyIllustrious to r/selfhosted [link] [comments]
https://control-plane.io/posts/unauthed-to-rce-in-vault-and-openbao/ OpenBao engineers at ControlPlane have chained 4 vulnerabilities to show how under certain conditions, an OpenBao or Vault server can be completely compromised from an unauthenticated position. This is only the second RCE ever found in the Vault codebase. The exploit is highly plausible in real-world environments, requiring only an unauthenticated entry path and a defined Raft snapshot policy to trigger a complete server compro
I currently have my 3rd RMA on it's way back to Ubiquiti, and with that being sad I am considering moving away from them for good. Tired of the constant RMAs and having to setup my network over and over. Wanted to get some opinions of anyone who has made the switch from Ubiquiti to either opnsense or mikrotik. I know they have different UIs and there will be a learning curve to it all but if opnsense has an amazing community that helps new users learn and mikro doesn't, then I'd lean towards opn
Hello. I just set up OpenCloud with EuroOffice on my TrueNas server, using the community apps. I can upload and download files well, but the collaboration/document editing doesn't seem to work. Basically, when I open a document or a spreadsheet, EuroOffice opens the document normally and I can read, edit and save it. However, when I exit the file and the padlock icon dissapears after a few (~5) seconds, the file goes back to its original state and none of the changes I've made save. This happens
Not an expert in Kubernetes, need expert guidance inn two potential single points of failure during Kubernetes rolling updates Admin server: if the admin server unavailable, FEs cannot restart properly, even if available search does not function without the Admin server, any work around? Back-end Search: if one back-end server goes down the portion of index it hosts become inaccessible, resulting in search becoming completely unavailable.. Is this behaviour a limitation in single points of failu
I'm working on an open source mp3 player built on affordable hardware. * $50 - built on the m5 Core2 * has bluetooth, 3.5mm, and a built in speaker * supports SD cards up to 2TB * 500mAh battery, upgradeable to 2000mAh * plays mp3 and flac files * has BPM detection The project is currently a work in progress. The software is open source and available on github This is being built to work with mStream , a selfhosted music streaming server. mStream will be used to manage firmware upgrades and mana
Hello guys I made a drop-in Firebase replacement for an enterprise system I made, and now I'm working on generalising it, en route to open sourcing it. What SSO engines should I add, other than the ones already present in Firebase (Google, Facebook, GitHub, Microsoft)? I know there are many, I just want to know which ones are actually worth it and will be used. A bit about the tool for anyone interested: Without too much pre-release foreshadowing, the backend has a near-identical API reference t
We've been migrating a few AKS clusters from local (certificate-based) accounts to Microsoft Entra ID authentication with Kubernetes RBAC, group-bound via RoleBindings instead of individual users. It's gone smoothly on our internal/dev cluster — sign-in works, group-based access works as expected, and day-to-day operations (deployments, scaling, log analytics ingestion) are unaffected. We're now planning to roll the same change out to Production. Along the way we've hit a few gotchas worth men
For ending out the month of September the OpenMandriva Linux distribution crew released OpenMandriva ROME 26.0 as their long overdue release held up by various technical issues and a reported sabotage attempt to their platform. With OpenMandriva ROME 24.12 having been their last release, this is quite a big update...
Building on the major release of Tempo 3.0 , Tempo 3.1 is here, delivering community-contributed Kafka client improvements, query-based trace redaction, sampling-aware TraceQL metrics, and more. Together, the updates in 3.1 make it easier to operate Tempo, get accurate insights from your trace data, and investigate issues more efficiently. You can continue reading and check out the video below to learn more about the latest features. The Tempo 3.1 release notes and changelog provide more in-dept
This is Katriel, the architect of the tool APIaxess. I have been API pentesting for a good time now, and starting with API pentesting was a bit of a rough patch. Specially the setting up and having to know the intricacies of proxies, networking and other stuff. Then once i got through it, the next rough patch was the apk pentesting, where getting the traffic of any apk was more of a task then the pentesting itself. So i started by writing scripts that automates the process and then made sure tha
Microsoft Security BlogcveWed, 30 Sep 2026 14:00:00 +0000
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog .
Edison Design Group has open-sourced their EDG C/C++ front-end that has been known in the commercial world for its extensive dialect support and other features. The EDG C++ front-end has been used by the likes of Intel C++ Compiler classic, NVIDIA CUDA NVCC, and even Microsoft Visual Studio for IntelliSense...
You can now use built-in error monitoring in Cloudflare Workers to group production failures and send stack traces, logs, traces, and application context directly to a coding agent to investigate further and open a pull request.
Cloudflare Containers now start 6x faster, let your agent choose each sandbox's image and instance type at runtime, and support filesystem snapshots in public beta, all controlled from a Durable Object.
While the AMD Ryzen AI 400 series "Gorgon Halo" systems are nearing the marketplace, the NPU support for Linux was seemingly overlooked until now. But at least the simple enablement patch looks like it will arrive for the upcoming Linux 7.4 kernel...
A proposal was posted this week to the Linux kernel mailing list by a Google engineer to make it easier for ARM64 Linux to adjust the kernel stack size. The motivation for doing so to configure the kernel stack size during boot time is on reducing system memory consumption...
Kubernetes v1.37 brings important storage security features: emptyDir permission modes and bind mount options. They help application programmers and security professionals implement rigorous security policies, for example, prohibiting deletion of files across containers or execution of arbitrary binaries from writable volumes, directly in Kubernetes without any complicated circumvention. Linux storage and permission fundamentals Before diving into the new Kubernetes features, let us briefly revi
Microsoft Security BlogsecurityTue, 29 Sep 2026 21:39:27 +0000
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog .
Ahead of the October ISO refresh of the Arch Linux media, Archinstall 4.5 released today as the newest update to this convenient, text-based Arch Linux installer...
Microsoft Security BlogsecurityTue, 29 Sep 2026 16:00:00 +0000
Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. The post Beyond source code: A path to the keys to the kingdom appeared first on Microsoft Security Blog .
Microsoft Security BlogsecurityTue, 29 Sep 2026 15:00:00 +0000
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog .
One of the things that Windows really got right is WSL2. I drive an atomic Linux distro for daily use, but wanted a way to develop with multiple different distros with that same WSL UX. NSL is my answer. It is a faithful reproduction of the developer experience, powered by a single VM that hosts one or more systemd-nspawn containers with your development instances. Host file edits and port sharing come along for the ride, just like WSL. Take a look and tell me what you think... It's yet another
Following the public preview of Linux containers on WSL, Microsoft today announced the general availability of WSLC for supporting Linux containers on Windows...
A sophisticated attacker with a quantum computer can exploit a protocol design flaw to downgrade post-quantum IPsec tunnels to classical crypto. We helped the IETF develop a transcript authentication extension to prevent these attacks.
Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate and vary payloads.
Cloudflare has added visibility into post-quantum (PQ) encryption in TLS 1.3 directly into HTTP Analytics, Log Explorer, and Logpush. Learn how to make sure your domain is protected with PQ encryption.
We are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, extracts structured indicators, and connects threat context directly to your WAF rules.
It's been a while since any new Spectre vulnerabilities have come to light but that's changing today. The embargo has now lifted on BTR, Branch Target Reuse as a new Spectre-V2 attack affecting just-in-time (JIT) compilers...
Following the FUSE improvements in Linux 7.3 for file-systems in user-space, it looks like the upcoming Linux 7.4 kernel will be ready to enable the large folios feature...
As Kubernetes adoption has grown, the conversation has shifted beyond running containers to managing increasingly complex application lifecycles. Modern platforms support stateless web services, stateful databases, batch processing, AI workloads, and platform services. At the same time, they must remain reliable during upgrades, scaling events, and infrastructure failures. Every Kubernetes user relies on SIG Apps, whether they realize it or not. Deployments, StatefulSets, DaemonSets, Jobs, and C
With the release of Kubernetes v1.37, the Pod-Level Resource Managers feature has graduated to Beta status (disabled by default)! First introduced as an Alpha feature in Kubernetes v1.36 , this enhancement builds on Pod-Level Resources by equipping Kubelet's Topology Manager, CPU Manager, and Memory Manager to use Pod-level resource declarations ( .spec.resources ) directly when making hardware placement decisions. Bringing pod-level resources to node managers Before this feature, obtaining excl
Krebs on SecuritycveTue, 08 Sep 2026 21:44:22 +0000
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
AI/ML and complex batch workloads continue to push the boundaries of Kubernetes scheduling. Following the foundational workload-centric enhancements introduced in previous releases, Kubernetes v1.37 delivers the next major milestone in the Workload-Aware Scheduling (WAS) journey. In this release, the core Workload and PodGroup APIs—enabling gang scheduling—along with Workload-Aware Preemption (WAP) and shared DRA ResourceClaims for PodGroups, all graduate to Beta, solidifying their role in the K
Grafana BlogobservabilityThu, 27 Aug 2026 13:03:49
Modern engineering teams instrument everything, with metrics, logs, traces, and profiles flowing from hundreds of services at once. But full-stack observability isn’t really about collecting more telemetry; it's about having a single, unified picture of how your services connect to every layer beneath them, including their dependencies, the pods and nodes they run on, and the logs, traces, and profiles that explain their behavior. But there's often a quiet problem hiding underneath all that data
Kubernetes BlogkubernetesThu, 27 Aug 2026 10:30:00 -0800
Kubernetes v1.37 promotes the metrics.k8s.io API to stable ( v1 ). This API provides CPU and memory usage for nodes and Pods, and is the API behind commands such as kubectl top and resource-metrics-based autoscaling. For cluster operators and application developers, this graduation means that the API now has the stability guarantees associated with a Kubernetes stable API. The v1 API has the same resource types and fields as v1beta1 ; this is an API-version graduation, not a change to the metric
At Grafana Labs, observability is what we do. So as we started building AI agents, we naturally reached for the same instincts we bring to every system: measure it, set targets, and make reliability something you can reason about instead of hope for. That instinct led us somewhere unexpectedly useful. It turns out one of the oldest ideas in reliability engineering, the error budget, maps beautifully onto one of the newest problems in software: how do you know if an AI agent is actually any good?
Microsoft Security BlogsecurityThu, 24 Sep 2026 16:00:00 +0000
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog .
Run agents on your laptop, in the cloud, and move between them with one command, all safely. Earlier this year we launched Docker Sandboxes: microVM environments where coding agents can work autonomously in a safe way.
Hacker News (front page)open-sourceThu, 01 Oct 2026 20:32:18 +0000
I found that I'm not using even 1/3 of vim/vscode features anymore. That's wht I'm building rhun - a small code editor for Linux, Windows and Apple silicon Macs. It obviously has Vim mode, a terminal, Git diffs and a panel for Claude Code or Codex sessions. The editor and pixel renderer share an x86-64 assembly core. For Apple silicon, a build-time translator converts that core to AArch64, with separate platform adapters around it. The latest release can draft commit messages using a local Ollam
At WeAreDevelopers, Docker introduced Cloud Sandboxes, the open Sandbox Kit specification, and a commitment to bring Kits to the CNCF for neutral governance.
ServeTheHomekubernetesThu, 01 Oct 2026 18:14:30 +0000
We checked out the F5 lab getting over 3x the performance from the same GPU cluster using F5 BIG-IP NEXT for Kubernetes The post Touring the F5 BIG-IP Next for Kubernetes Lab to Make AI Clusters More Efficient appeared first on ServeTheHome .
While there have been a number of Ubuntu 26.10 development benchmarks in recent weeks and more on the way, some Phoronix readers have asked about the lack of any early Fedora 45 tests given its recent beta. For good reason, it's largely boring but here are some to illustrate.
With the vast array of wired and wireless networking drivers within the Linux kernel and range of protocols and other networking features, it's a big expanse of code for AI/LLM agents to analyze and critique. The Linux networking developers have acknowledged being "complete overwhelmed" by the AI/LLM-driven patch activity and bug reports as well as battling against AI slop patches. Even though Linux 7.3 stable won't be out for another three weeks, some networking fixes are already being diverted
In addition to the very nice AMDGPU IOMMU optimization for iGPUs set to debut in the Linux 7.4 kernel, over on the AMD EPYC server side for servers running SEV-SNP virtual machines is a separate, nice optimization also expected for this next kernel version...
Longtime ARM Linux maintainer Arnd Bergmann over the past year has been working to clear out a number of old ARM platforms from the mainline kernel tree. With Linux 7.3 many older 32-bit ARM platforms were deprecated and in turn hundreds of kernel drivers orphaned. Now it's on to removing that actual code, which given the amount of entangled code, is itself a challenge...
Rob Clark, who originally started working on the reverse-engineering Freedreno and MSM DRM graphics driver projects prior to even being employed by Qualcomm, presented this week at XDC 2026 Toronto around all the recent efforts they have been pursuing at Qualcomm for this upstream open-source graphics driver stack...
The Renesas SH7305 isn't a new processor and is well known for powering various Casio graphing calculators over the past decde and a half. But finally the mainline Linux kernel may end up seeing support for this 32-bit SH-4a RISC core...
SANS Internet Storm CentersecurityThu, 01 Oct 2026 05:32:13 GMT
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
Phoronixopen-sourceSun, 04 Oct 2026 13:51:01 -0400
This week was the surprising and unfortunate decision of Siemens shutting down the OpenRadioss project as the four year old open-source project started by Altair Engineering with their prominent Radioss finite element solver. Siemens didn't just end the project but they shutdown the GitHub repository that hosted the open-source code and removed other resources that had built around it. Fortunately, there's a new community fork of OpenRadioss as OpenCourant...
Linux's Multi-Gen LRU "MGLRU" has already achieved nice performance gains for Linux in recent years by optimizing page reclaims and improves performance under memory pressure. The new MGLRU-FG patches aim to take things further...
Last month Fujitsu formally announced their MONAKA CPU as a 144 core Arm-based server processor geared for AI infrastructure. This comes after two years of seeing various Monaka patches to the GCC compiler and other open-source components. Now that MONAKA is announced, we are seeing more patches surface for the Linux kernel with this week seeing several workarounds for MONAKA CPU bugs...
We are nearing the cut-off of new Direct Rendering Manager (DRM) subsystem material for the upcoming Linux 7.4 cycle. AMD this week sent in another feature pull to DRM-Next that is moving over to mostly bug fixing but does contain the enablement of some new GPU intellectual property blocks for upcoming graphics hardware...
OpenSUSE developers have announced they are making ZUPT available on their Linux distribution as a solution for providing post-quantum backups. ZUPT combines backup creation, compression, integrity verification, and encryption all via this single open-source utility...
Arm sent out an initial set of patches this week working on support in the Linux kernel for TLBI Domains. This "TLBID" feature is an upcoming Arm architecture capability designed to increase performance on high core count systems...
Kubernetes BlogkubernetesMon, 31 Aug 2026 10:30:00 -0800
I am excited that storage version migration (SVM) has graduated to General Availability (GA) in Kubernetes v1.37! After a number of releases of work and testing, the built-in StorageVersionMigration API ( storagemigration.k8s.io/v1 ) and control plane controller are now fully stable and enabled by default across all v1.37 Kubernetes clusters. The problem with stale storage versions In Kubernetes, stored API resources are written using a specific storage version (schema representation). The way K
Alert routing often starts simple. A team creates a few contact points, adds some label matchers, and builds a notification policy tree that sends each alert to the right destination. But alerting configurations rarely stay simple. As an organization grows, its notification policy tree must accommodate more teams, services, and routing requirements. Changes for one team still require editing a global configuration, making ownership less clear and independent provisioning harder. Over time, even
Kubernetes v1.37 promotes the PersistentVolumeClaimUnusedSinceTime feature gate to Beta (enabled by default). With this feature, the PersistentVolumeClaim (PVC) protection controller adds an Unused condition to each PVC, telling you whether any running pod currently references it — no custom tooling or cross-referencing required. For the API definition of PVC conditions, see the PersistentVolumeClaim API reference . Read on to learn how the Unused condition works and how to use it. Why track PVC
When something breaks in production, the questions that matter most are also the toughest to answer from metrics alone: who was affected, what did they actually see, and is this worth waking someone up for? Answering those questions requires a fuller picture of the issue and its impact on your users. That’s where Digital Experience Monitoring (DEM) in Grafana Cloud comes in. By combining Frontend Observability and Synthetic Monitoring , DEM connects real user experiences with proactive testing,
Memory QoS has graduated to Beta in Kubernetes v1.37 and is now enabled by default. On Linux nodes running cgroup v2, the feature uses the memory controller to give the kernel better guidance on how to treat container memory. It was first introduced as Alpha in v1.22, and expanded in v1.36 with tiered memory reservation. This post covers what changed in v1.37, what the Beta promotion means for cluster operators, and how to configure the feature. What changed in v1.37 Memory QoS is Beta and enabl
Changed Block Tracking (CBT) support for CSI drivers shipped as Alpha in September 2025. With the March 2026 v1.0.0 release of the external-snapshot-metadata project, the feature moved to Beta . If you aren't yet familiar with changed block tracking for storage in Kubernetes, the Alpha announcement covers the motivation, the three primary components (the CSI SnapshotMetadata gRPC service, the SnapshotMetadataService CRD, and the external-snapshot-metadata sidecar), and a walkthrough of how to us
Kubernetes BlogkubernetesMon, 05 Oct 2026 10:00:00 -0800
Memory is often the first hard limit a Kubernetes cluster hits. Nodes run out of RAM long before they run out of CPU, and the new wave of agentic AI workloads makes this worse. These workloads demand large memory footprints to start up and run untrusted code, then sit idle waiting for the next prompt. That idle but resident memory is expensive, and it caps how many pods a node can hold. This is where swap helps. Kubernetes support for running nodes with swap enabled reached General Availability
The Mold high speed linker alternative to the likes of GNU Gold/LD and LLVM LLD recently has been going through a rewrite from C++ to Rust as well as having high ambitions of eventually becoming the default linker on Linux systems. Today marks the release of Mold 3.0 for this Rust-based high performance linker...
Back in May we spotted a Linux patch adding "Panther Lake R" as a rugged version of Panther Lake intended for "use in harsh environments". Since Linux 7.2 we have seen some bits of Panther Lake R driver support added while for the upcoming Linux 7.4 cycle there is additional enablement happening for this Panther Lake derivative...
A new patch series sent out from Qualcomm that aims to help at least the Snapdragon X series laptops is hardware-binned trip point support. Some Qualcomm SoCs are available in different multiple thermal/package bins with different junction temperature limits but otherwise being the same silicon. The new Linux patches are working to properly convey that information around the thermal limits for a given piece of silicon...
With the upcoming Linux 7.4 kernel the necessary changes to the AMD P-State driver are set to land for properly supporting the upcoming AMD Ryzen client processors based on the Zen 6 cores...
Kubernetes BlogkubernetesFri, 28 Aug 2026 10:30:00 -0800
Kubernetes brings a wealth of features that make it easy to run your production workloads securely and reliably. While aspects like scheduling, health checks and resource limits are probably at the front of your mind, one other important feature of Kubernetes is production identity — how your workload can authenticate to other systems in order to do its job. Up until now, the primary production identity mechanism built into Kubernetes has been service account JWTs (JSON Web Tokens). These are cr
Krebs on SecuritysecurityFri, 25 Sep 2026 21:44:40 +0000
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
Microsoft Security BlogsecurityFri, 25 Sep 2026 15:35:08 +0000
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog .
I'm excited to announce that native histogram support for Kubernetes metrics is graduating to Beta and is enabled by default in Kubernetes v1.37! Native histograms (previously introduced as Alpha in Kubernetes v1.36 under KEP-5808 ) bring high-resolution, low-cardinality observability to Kubernetes metrics. By adopting Prometheus Native Histograms , Kubernetes components now expose latency and duration metrics with far greater accuracy while significantly reducing telemetry storage and scraping
Kubernetes v1.37 promotes the KubeletInUserNamespace feature gate to beta. With this feature enabled, all of the node components (kubelet, CRI and OCI runtimes, CNI plugins, and kube-proxy) can run as a non-root user on the host, using a Linux user namespace . This technique is also known as rootless mode . The work started as an experiment in 2018, and was merged into Kubernetes v1.22 (2021) as an alpha feature (Kubernetes Enhancement Proposal KEP-2033 ). This feature should not be confused wit
Asahi Linux developer Sven Peter today sent out the pull requests of the Apple SoC Device Tree changes they are ready to upstream for the Linux 7.4 merge window happening later this month. Most notable is the initial Device Tree for Apple systems using the base M4 SoC model as well as for the MacBook Neo with the A18 Pro SoC...
Cloudflare BlogdevopsFri, 02 Oct 2026 16:13:45 GMT
Streamline demonstrates how to build long-running, continuous video processing pipelines by pairing Cloudflare Workers and Durable Objects with a containerized media engine.
Sent out on Thursday was the last round of planned Intel Xe kernel driver improvements targeting the upcoming Linux 7.4 cycle. There is one big improvement that is set to benefit Intel discrete GPUs with at least Battlemage benefiting nicely...
Ubuntu developer Gianpiero Carpinelli at Canonical has been working on introducing SHA3-256 and SHA3-384 support for Debian's APT packaging tool in preparing for if/when that SHA2 is broken...
Cloudflare BlogdevopsFri, 02 Oct 2026 13:28:10 GMT
Cloudflare AI Gateway now supports native web search API integration in partnership with Ceramic.ai, Exa, and Linkup. Developers can now inject real-time web context into model inference calls via AI Gateway, REST APIs, or Workers bindings.
Cloudflare BlogdevopsFri, 02 Oct 2026 13:00:00 GMT
Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.
Cloudflare BlogsecurityFri, 02 Oct 2026 13:00:00 GMT
Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed User IDs to help teams investigate and block account abuse.
Cloudflare BlogsecurityFri, 02 Oct 2026 13:00:00 GMT
We’re announcing the closed beta of a self-serve Cloudflare OHTTP Gateway. We’re also renaming our Privacy Gateway to Cloudflare OHTTP Relay to better distinguish the two products.
Cloudflare BlogdevopsFri, 02 Oct 2026 13:00:00 GMT
A year after pledging to eliminate two-tier product access, Cloudflare has expanded Logpush, multi-account governance, and higher platform limits to all accounts. Here is an update on our progress, how we dogfood these tools internally, and what is coming next.
Cloudflare BlogdevopsFri, 02 Oct 2026 13:00:00 GMT
Cloudflare Traces shows how a request moves through security rules, transformations, cache, routing, Workers, and your origin, then follows it across services running anywhere in your stack.
Cloudflare BlogobservabilityFri, 02 Oct 2026 13:00:00 GMT
Cloudflare is launching eight major updates that bring logs, traces, analytics, alerts, dashboards, querying, and telemetry export into one observability platform, with simpler and more predictable pricing.
The newest systemd component being worked on and drafted for an initial pull request is systemd-appd as a new mechanism to centralizing the tracking of user's apps...
Phoronixopen-sourceFri, 02 Oct 2026 09:00:03 -0400
Imagination Tech was at XDC 2026 Toronto this week to talk up their ongoing work around their PowerVR Mesa Vulkan driver (and PVR upstream DRM kernel driver) with this driver continuing to improve, plans for supporting their new Volcanic GPU architecture, and other improvements...
As a follow-up to the news one month ago of Intel Nova Lake P's graphics introducing a new 64-bit GPU mode, the latest driver-side enablement has now landed for Intel's Iris Gallium3D OpenGL driver for supporting efficient 64-bit addressing...
Canonical engineer Richard Scott McNew published a status update surrounding the Rust programming language efforts in the upcoming Ubuntu 26.10 release. Sequoia PGP is being rolled out to Ubuntu Linux and in a future release may end up replacing OpenPGP...
Coreboot 26.09 released yesterday as the latest quarterly feature release to this open-source software for replacing proprietary BIOS and system firmware on a growing selection of devices...
KDE Linux developers have been experimenting with a build of their Linux distribution based on BuildStream to ship as an OS image rather than a set of Arch Linux packages. They are nearing a point soon where they will decide if they will officially ship this BuildStream-based KDE Linux image...
Hacker News (front page)homelabFri, 02 Oct 2026 19:10:38 +0000
pi pod runs sessions of the pi coding agent in isolated sandboxes ("pods") on a server you run, in composable environments. ---- Since moving my company towards AI-native work, I have been really frustrated by the state of "agentic engineering" environments. Products by the labs (claude code, codex) lock you into a single provider for your tokens. Agnostic solutions (factory, devin, arguably cursor) make you pay per-token costs. None of these products allow you to fully customize the harness, an
Hi everyone! A few hours ago I bought my very first server to get started with homelabbing: a Lenovo ThinkCentre M700 . I’d love to get your thoughts and recommendations on which OS to install and what other cool services I can run on it. Hardware Specs: System: Lenovo ThinkCentre M700 Tiny CPU: Intel Core i5-6500T (4 cores / 4 threads, 2.5 GHz base / 3.1 GHz boost) Power Consumption: 35W TDP (~7W-10W at idle) RAM: 8 GB DDR4 (planning to upgrade to 16 GB in the future) Main Question: Which OS sh
Hi everyone! A few hours ago I bought my very first server to get started with homelabbing: a Lenovo ThinkCentre M700 . I’d love to get your thoughts and recommendations on which OS to install and what other cool services I can run on it. Hardware Specs: System: Lenovo ThinkCentre M700 Tiny CPU: Intel Core i5-6500T (4 cores / 4 threads, 2.5 GHz base / 3.1 GHz boost) Power Consumption: 35W TDP (~7W-10W at idle) RAM: 8 GB DDR4 (planning to upgrade to 16 GB in the future) Main Question: Which OS sh
I'm trying to get into coding and electronics, so I want to learn how to do so by building my own router. I've always wanted to build my own things and code whatever I want. Could anyone let me know what I may need and how to set it up properly? I want to do this right and not buy the wrong things, build it wrong, code it wrong, or mess anything up in general. submitted by /u/VXGXE to r/homelab [link] [comments]
This is my first real homelab effort, still evolving. All starts with a Unify gateways and a couple Unify Pro 10 XG switches that distribute all around the house and feed two 10gb connections into this mini rack. I also have a Synology Nas as the main storage and a couple older NAS, one is off site, for backups. - Three Minisforum MS-A2 (8945HX, 64gb Ram, 2 TB SSDs as base, the first two nodes got ram upgrades to 96gb and all got an extra ssd for Ceph) - first two nodes are running 5070TIs via O
The idea is to create a NAS to use these drawers, it is already with the disk controller for hotswap SAS-743TQ to manage the disks, the idea is to print a case, some tips for creating this case? submitted by /u/Sabino08 to r/homelab [link] [comments]
I've been in IT for over 16 years, working across on-prem, datacenters, Azure and AWS. These days I'm an AWS cloud consultant. I've lurked here for a long time, and over the last few years I've torn down and rebuilt my homelab more times than I can count. I've finally landed on a setup I'm happy with and proud of. I run it for my family and me, but mostly for me. It's where I learn new things, and honestly, it's just my passion. A few highlights: Everything is infrastructure as code. No snowflak
TL;DR: Md files in a private GitHub repository I’m looking for the simplest documentation solution I can use for setting up and configuring my whole lab. One of the requirements is for this to be a simple as possible, with the least amount of dependencies, complexity, and it must be available when the environment goes down. This means that a self host solution is not practical because if my home lab goes down my services go down and I cannot access my documentation for restore procedures, as an
The headless OMEN laptop (lid closed) is the always-on node. It runs the vector DB, a Matrix server and a small local LLM. The tower under the printer has 2× Arc Pro B70 (64 GB VRAM) for big models. Everything talks over Tailscale, with LAN fallback. The topology is on the laptop screen; the full diagram is in the second image. Next up is pH, dissolved-oxygen and conductivity sensors in the fish tank, which will feed the same system. AMA. submitted by /u/PopulateThePlanets to r/homelab [link] [c
Currently have a server put together inside of an old Antec 300. Nine 3.5" SATA drives are in it, but I have a couple extra that I would like to put inside. So I'm hoping to get a very basic chassis that can hold 11-14 drives but can also use my existing hardware (motherboard, Intel 10500t, CPU cooler, PSU). I see a few different options on Newegg but they're almost all Rosewill. Wanting to know some model names of other options I could possibly find used from Facebook or eBay for cheaper. I fou
Hey all, I'm Spencer, a homelabber and IT pro (technical support by day). For 15+ years I've wanted a dead-simple off-site backup that doesn't mean handing my data to a cloud provider: you and someone else each give up some disk, and your machines back each other up, encrypted so neither of you can read the other's files. I finally had the time, tools and resources to build it. It's called **Backup Buddies**, and it's live. https://app.filegarden.net ## How it works - Run a small Docker client o
I want to find a reason to use Proxmox, but I am not finding anything that I really would benefit using Proxmox over Docker. When I got into homelabbing, I watched a ton of videos and they all said they installed Proxmox, but had no explanation of what they used it for. I want to use it, so I figured I could ask the fine folks here and see what you guys run in Proxmox and why so that I might find a couple reasons to use it. Right now I have plex and plex adjacent apps, an ark server, a couple Mi
I'm on an early journey into home labbing and looking for a computer to get started. I have 0 experience in this, I don't even own a personal computer. The goal at the moment is just Jellyfin and a music streaming service but It may very likely go further with some self hosting (photos, documents) raspberry pie hole etc or it may be a disaster and I'm just not that technically minded, lets see. Is 16GB a necessity or will I get away with 8GB and if so, for how long? I have a 1TB SSD that will ho
Thanks for all you comments on my previous post. Now I understand that homelab and self hosting never complete and always involve. Added 4g+ router for backup and I diy an exhaust window with two 140mm fans that send the hot air out of the room for keep the attic cool. Very pleased with the outcome so far. Every new idea is appreciated. My hardware right now is: -OpnSense Dec2700 series for firewall -TP-Link Jetstream SG3428 switch (not PoE) -Custom PC from spare parts with i7-7700, 32GB ram, 2
Hello everyone, I recently set up an HP G4 800 as an always on box. After some initial crashes from the i915 driver in debian things seem to work fine. There is a power on quirk that i've noticed. After I shut down the machine: I leave the machine plugged in, starts on with a single push of the power button I unplug the machine, and it won't power on until the third press, OR, a single 2 to 3 second press. Trying to figureout if this is a quirk of my machine, or a normal behaviour. I've done qui
Hey all! I have a Lenovo Thinkcentre Tiny (intel cpu) running headless debian 13 with docker and a bunch of services. I bought an mini pc with better specs (also intel cpu, if it matters) and would love to know if there's an easy way to migrate everything, be it disk cloning or whatnot. When googling I keep finding ways that would need both PCs to be hooked up to a monitor and keyboard and I don't have that many at home (and would like to avoid even hooking them up to the same keyboard video and
Hey guys, I have a Linux server in my home running jellyfin (with tailscale). I never had any issue with it, but recently tried to set it up in my grandmother's house as she is ill and watching movies she used to love hopefully helps her distract her mind of the pain. My issue is that my server is old and weak and it doesn't have enough capacity to transcode the videos well. I got a firestick and found out that it doesn't even let me install jellyfin (nor tailscale for that matter). What are my
So I am looking at home servers because 1. I don't trust apps now and 2. I'm sick of subs for everything. So I've got the pc stuff sorted, but what I don't get is how to host my own movies/series, and how I host music etc. Is there apps and a correct way of doing it, or is there an easy way? submitted by /u/Alarmed-Lock-5776 to r/homelab [link] [comments]
https://preview.redd.it/xh90vl8clbth1.jpg?width=768&format=pjpg&auto=webp&s=7897a57e815775851d7c1e141d05b6ce189e2bb5 https://preview.redd.it/9byofm8clbth1.jpg?width=768&format=pjpg&auto=webp&s=e26f8e398abfa4c00d83b507edb8309d51cace85 Thought I’d share my homelab as its grown quite a bit over the last few years. Started off with a NAS and a couple of VM’s and somehow ended up with this 😂 Most of it is retired enterprise kit that I’ve picked up, reused or saved from becoming e-waste. Its probably
I just wanted to pop in and thank the community for your inspiration and help. This is my home server set up currently. It serves all of my needs. Immich, Emby, qBittorrent/qui, *Arrs, and Audiobookshelf. Running Ubuntu 26.04 LTS. submitted by /u/Xielle to r/selfhosted [link] [comments]
Some of you told me that the three servers I was originally looking at were pretty bad, so I went back to eBay and searched again. I found this Dell PowerEdge R610 for €90 + €20 shipping: - 1U rack server - Intel Xeon E5530 (4C/8T, 2.4 GHz) - 24 GB ECC DDR3 RAM - PERC RAID controller - iDRAC 6 - 2× hot-swap PSUs - 2.5" front bays - Caddies/blanks according to the photos - Used/refurbished, tested and working - Business seller My budget is now €100 max for the server itself (shipping can be a lit
I’m thinking about creating an auth layer using my domain and a low cost VPS that will whitelist any ip address I authenticate from for x hours so that I can cast Jellyfin to a tv on the same WiFi/IP without needing to set up tailscale. I expect the front end of the domain would open a tunnel for said IP so that I wouldn’t have to forward any ports. Is this a dumb idea? How difficult would it be for an attacker to 1. Detect an ip is whitelisted on my server and 2. Spoof an IP? My goal is to enab
Helllooo everyone! I figured I would join all the other posts and show what I run. My homelab is a bit of a mix of running services for my family and a testing ground for learning new technology. My entire homelab is Proxmox as the hypervisor, debian VMs to run Docker and Komodo. Forgejo (git) deploys my containers on Komodo. Docker labels control Traefik and exposure. Jupiter My main server, pretty much what I would consider "production" in my house. I pretty much throw everything on this wheth
I have come very far in getting this relic setup but have run into a odd issue. I cannot for the life of me get the server to recognize/not fail loading these drives. Keep failing and refer to then as seagates. Not sure what i am doing wrong or what updates i need to install to the bios to get it to recognize/load them to add to VD. Only thing i have researched and found is to update the PERC controller but no idea how to do that. Any help would be insanely appreciated! You all rock in advance!
Still in the process of setting everything up (which may take some time based on my schedule) but I've got the hardware pretty much set. Top down: Giada F103D running OPNsence (not currently in use and bypassed for now). Networking for the rack that handles the rack itself as well as networking for my house. 12th gen Dell 3000, i5 12500T, 24GB DDR4, running Windows. Two 7th Gen Dell 3050, i5 7600t, 8GB DDR4, one currently running ZimaOS as a file server and the other is sitting idle for now wait
I recently purchased a Network / AV Rack from an individual for a kind of different project. I plan to put 2 PC’s, a NAS, a UPS and a DAC, along with some hard drives in the enclosed rack. The odd thing is there is absolute nothing to identify the rack manufacturer anywhere. I realize I could use parts from another company but it came with 5 - 2U vented shelves that I wish to use, if they are sturdy enough. But, not knowing the manufacturer & model, I do know know what their weight limits are. I
I have a Dell T320 Poweredge server that I’m using to run Jellyfin. It has 32gb of DDR3 ram and an E5-2470v2 processor. Apparently you can use a GPU to allow the server to run higher quality video. How powerful of a GPU do I need to encode 4K (or at minimum 1080p) video? Most in-depth reviews discuss a GPU in terms of either work or gaming, but few of them specifically discuss video encoding alone. Does anyone have any recommendations for GPUs that can do simple encoding for my setup? Thank you!
Hi! I recently got my hands on a reasonably cheap fibre channel LTO 6 drive made by HP. I have a small home server running ESXi and OpenMediaVault on top of that with 20TB of storage... around 8TB of which I need to back up. I am now looking for a piece of software that will ease my backup adventures. The data that I need to back up are mostly videos, pictures and some documents. I want them backed up with the assumption that nothing of this will change. If I have a folder with pictures from 202
I'm trying to buy an old PC to make my first home server. I'm looking for an OptiPlex or something similar, and I've found this HP ProDesk 400 G6 : i5-8500, 16gb of ram and a 256 Go SSD. I'll add a 12To HDD to it. Oh, and it's a micro tower. My question is : is it enough to run my server with Debian as an OS, CasaOS, Jellyfin, Immich, and overall NAS? It's at 120€ and I feel it'll sell fast. Is it a good price? Thanks! Edit : typo submitted by /u/nono-shap to r/homelab [link] [comments]
Everything started with an old laptop... And then it snowballed into this masterpiece! The 3D model is the KWS v.2 Rack Using my old MSI gf63 8rd laptop as my main Docker host and an Optiplex 7010 with a 12500T for my game servers Also the DAS at the bottom for my Jellyfin media submitted by /u/ThatWasEsyGG to r/homelab [link] [comments]
Hii, im thinking to change my beestation 4tb due to the slow machine to load picture and video to my iPhone. Im so done with this beestastion... After brainstorming with chatgpt and looking secondhand hardware locally i got this spec: Cpu: intel12500 Motherboard: gigabyte h610k Ram 16gb ddr5 Ssd 256gb for boot 2hhd 12gb Exos Psu 500watt 1.So my question is this hardware good enough or any contradiction? 2.Do i need to change the Ram for dedicated server PC? Need ECC? 3.If i want to use Jellyfin
Hello guys. I'm planning to purchase an old laptop to practice, learn and host some non long-term services (on Linux) which I don't expect to be a heavy workload. I found this Thinkpad laptop for around 49 USD, is it recommended or should I wait for a better one? Installed RAM: 4.00 GB (DDR3) Processor: Intel(R) Celeron(R) CPU N2930 @ 1.83GHz (1.83 GHz) Graphics Card: 64 MB (Intel(R) HD Graphics) Storage: 112 GB SSD ADATA SU650 Thanks for your help! submitted by /u/OddSweet5915 to r/homelab [lin
I wanted to know how people like onedr0p, bjw-s and buroa organize their home-ops repos, so I went through them. A few patterns stood out: 1. Almost everyone uses the same skeleton home-ops ├── bootstrap # one-time setup before Flux takes over ├── kubernetes │ ├── apps # one folder per namespace, then per app │ ├── components # reusable Kustomize components │ └── flux # Flux's own config ├── talos # node machine configs └── .renovaterc.json5 A lot of this comes from onedr0p's cluster-template, s
Most self-hosting lists are sorted by app category, which is great for deciding what to run. I kept wanting the other thing: how do people like onedr0p, bjw-s and buroa actually structure the repo, and where in their tree do secrets, storage and Renovate live? So I mapped it. Each section of the list is a layer of a typical home-ops repo. Here's what one layer looks like: 04 Secrets ( .sops.yaml ) Tools: SOPS, age, External Secrets Operator In the wild: szinn's and xunholy's .sops.yaml , onedr0p
Hi guys, I'm running a small VXL Q2 thin client with an Intel N3350 CPU and dual Gigabit NICs, powered by Debian and Incus . I bought this machine from a nice guy for just $25, and it has turned out to be a great little homelab server. It runs pfSense along with two LXCs hosting WireGuard, Gotify, Tinyauth, and a few other services. I haven't shut down this machine since last month, and honestly, keeping it running continuously feels like an achievement. I'm attaching its uptime and power consum
My jank home lab! I am running 25tb of space Intel i7 7700 16 Gig ram.. I would love to run a AI but sadly... not GPU... submitted by /u/Impress-Worldly to r/homelab [link] [comments]
I'm building a compact server around the ASRock Rack W880D4U and want to connect an LSI 9400-16i HBA through the MCIO1 port using MCIO to PCIe adapters (linked below). According to the manual, MCIO1 shares lanes with SLOT6 (x16) through a PS7101 PCIe redriver mux. A BIOS setting should split SLOT6 into two exclusive x8 links, one for SLOT6 and one for MCIO1. Problem is nothing connected to MCIO1 is detected, either in the BIOS or in Ubuntu Server. So far I've tried the following: Changing the BI
I have few servers, storage and bla bla If I want to do a gaming server what config should I do ? What I was thinking was : dell r730xd (256gb ram, 14x8tb sas ssd (raidz2), 6x4tb sata (raidz2), 4x2tb nvme) hot sto for running gaming server A hp dl380 gen 9 (256gb ram, 24x 1.2tb hdd) cold sto For a gaming server I know iops are the key for a fast server. I my suggestion is that vm are running on thoses nvme (and others nvme), the game file on 8tb ssd, when it’s been a week not used it’s going int
Repo: https://github.com/libredb/libredb-studio Demo: https://app.libredb.org Youtube : https://www.youtube.com/watch?v=rWANKEDszs4 Deploy it next to your database with Docker or Helm and open it in the browser. No SSH tunnels, no desktop client on every laptop. Postgres, MySQL, Oracle, SQL Server, MongoDB, Redis, ClickHouse, DuckDB, Cassandra and more. MIT licensed, SSO and the AI assistant included. submitted by /u/cevheribozoglan to r/selfhosted [link] [comments]
Hey everyone! At the moment I have a i7-9700k, 64GB of ram, running truenas. It has all my services on it, stuff like arrstack, tailscale, plex, and a few game servers that are currently inactive. I also have another rig with a Intel Xeon D-2141I and 256Gb of ECC ram that I managed to score for a steal. The thing is, my xeon rig is just sitting idle and basically doing nothing right now. I had proxmox on it at some point but even then I didnt install much on it since I'm still super new to this
First photo is where this thing lived when it started: a Dell 1U on a wooden table, monitor balanced on the lid, cables running past the shower door. I'd like to say there was a plan... Second photo is now. **What's in there** - Dual-socket Dell r610 1U, 128GB ECC, ZFS mirrors, Proxmox. Does all the real work. - An older Dell r710 2U that stays powered off six days a week and wakes up over IPMI only to take backups. - A small form factor desktop running the firewall on bare metal. - 8-port manag
I am looking for a Dashboard that has all major info in one spot. I would of course do work from the actual VM Dashboard. I am leaning towards Homarr but I dont see where you can view your VMs logs. does it offer that? do any Dashboards offer that? submitted by /u/Low_Money_633 to r/homelab [link] [comments]
Hello everyone! A few months ago I got into homelabbing, build up my first small homeserver with an old laptop and Debian, and now somehow got hold of an NetApp NAF 1701 system (for details see below). I'm quite clueless on how I should proceed. I have the feeling starting up the NetApp system with another OS would be a bit too much for me right now, as I also do not have a rack or anything. What's the best I can do with it? I would love to build a bigger homelab with a NAS, more RAM (currently
Thoughts - it seems like the VM names should be app agnostic in this case because they're just hosting docker. But at the same time, I don't know if naming them compute001, compute002 and so on would be a good idea. One idea I had was to work in the VLAN they'll be on. I'm curious to hear how you do it. submitted by /u/MostBasic3425 to r/homelab [link] [comments]