GPU passthrough: the six traps between a detected card and a VM that boots
IOMMU, device groups, a driver that will not let go, the display output, the BIOS ROM: the real obstacles to GPU passthrough, in the order they turn up, and how to identify them.
UPS and clean shutdown: the forgotten link in every homelab
A UPS with ten minutes of runtime is worth nothing if nobody triggers the shutdown. How to orchestrate powering down several machines in the right order, and why the NAS has to go last.
Should you disable swap on a server? The honest answer
The advice to disable swap has been going around for twenty years. What it actually costs you, why swappiness does not do what you think, and the rare cases where turning it off is justified.
OOM killer: why your process dies with no error message
A service vanishes without a trace in its own logs. How the kernel picks its victim, why that victim is almost never the real culprit, and the settings that protect the processes that matter.
"Disk full" when there is space left: the four real causes
Used space does not match the sum of the files, or writes fail on a half-empty disk. Deleted files still held open, exhausted inodes, reserved blocks, a mount hiding data: the diagnosis, in order.
HTTPS on your local network: putting an end to the security warning
Three ways to get valid HTTPS internally: a self-signed certificate, an in-house authority, or a public certificate through DNS validation. What each one actually costs, and why one of them no longer works on mobile.
IPv6 in the homelab: why it breaks, and how to diagnose it without disabling everything
Addresses that change on their own, a bypassed firewall, connections slow to start: the failure modes specific to IPv6 and how to diagnose them. Disabling it is not a solution, it is a deferred problem.
Local DNS: reaching your services by name, without hacking hosts files
A clean internal domain, resolved locally and from the outside, with no duplicated entries. How split-horizon works, the made-up-domain trap, and why your browser sometimes ignores your DNS.
MTU too large: the network bug that lets pings through and blocks everything else
The site half-loads, SSH freezes right after the banner, a file transfer stalls at 4%. Ping works, DNS answers. It is an MTU problem: how to confirm it in three minutes and fix it for good.
VLANs at home: segmenting your network without losing the weekend
Smart devices, cameras, guests, servers: why a flat network is a problem, and how to carve it up gradually without breaking everything. The three pitfalls that stall every setup.
Which filesystem for a NAS: ext4, XFS, ZFS or Btrfs
Checksums, snapshots, growing a volume, RAM requirements: what each filesystem actually brings to a data store, and which one protects you against silent corruption.
Borg, restic or rsync: which tool for which backup
Three tools that get pitted against each other for the wrong reasons. Deduplication, encryption, remote destinations, ransomware protection: what each one actually does, and the criterion that settles it.
SMART: the attributes that actually predict a disk failure
The overall SMART verdict stays "OK" to the very end. The five counters that genuinely warn you, how to read them, and why a disk can die without crossing a single threshold.
RAID backs up nothing: what it protects, and the six risks it ignores
RAID covers exactly one scenario: a disk failing. Deletion, corruption, ransomware, theft, mistyped commands — it does nothing. And rebuilds are where entire arrays are lost.
Thin provisioning: why freed space never comes back
You delete 200 GB inside a VM and the hypervisor doesn't see a single byte return. TRIM, discard, unmap: the full chain you have to enable end to end to reclaim space.
Two-node clusters: the quorum trap nobody sees coming
Two servers in a cluster, one fails, and the survivor freezes instead of taking over. Why quorum forbids that scenario, and how a simple external witness fixes it.
The EU AI Act on 2 August 2026: what actually applies (and what was just delayed)
Regulation (EU) 2026/1744, in force since 27 July 2026, defers high-risk obligations to December 2027 but leaves the 2 August transparency deadline untouched. What is still due, the penalties that apply, and a checklist.
ZFS is eating all your RAM: what the ARC really does, and when to worry
The ZFS ARC takes half your memory by default and reports it as used. When that's normal, when it becomes a real problem on a hypervisor, and how to cap it without wrecking performance.
A snapshot is not a backup: the confusion that costs data
Snapshot, replication, backup: three mechanisms people treat as interchangeable that protect against entirely different risks. What each one actually covers, and what none of them do.
LXC or VM on Proxmox: making the right call, service by service
LXC container or virtual machine? Density, isolation, GPU, network mounts, backups: the criteria that actually settle it, and the cases where the container will trap you.
Cloudflare Tunnel: exposing your homelab without opening a single port
Publishing a self-hosted service with no port forwarding and no static IP: how an outbound tunnel actually works, what it really protects, and the pitfalls that break an installation in production.
GGUF Quantization: Q4_K_M, Q5_K_M, Q6_K or Q8_0 — How to Choose Without Wrecking Quality
The practical guide to picking your GGUF quant in 2026: bits per weight, perplexity impact, imatrix, and a VRAM/quality table. A Llama 3.1 8B drops from 32 GB in F32 to 4.9 GB in Q4_K_M.
Local RAG with Ollama: an assistant that reads YOUR documents, 100% offline
Build a privacy-first RAG assistant on your own documents: embeddings, vector DB, chunking and a local LLM. With qwen3-embedding hitting 70.58 on multilingual MTEB, local finally rivals commercial APIs.
Local LLM Runtimes in 2026: llama.cpp, Ollama, vLLM, LM Studio, TGI, Which One to Pick?
An honest comparison of local LLM inference engines in 2026: vLLM hits ~793 tok/s under concurrent load versus ~41 for Ollama, yet at a single user the gap drops below 10%. When to use each.
Fine-tune an LLM locally with LoRA and QLoRA: VRAM, datasets and realistic expectations
How much VRAM do you really need? QLoRA fine-tunes a 7B on 8-10 GB, a 13B on a 24 GB GPU. We debunk the myths: when fine-tuning beats RAG, and when it falls flat.
Local AI vs Cloud API: How Many Tokens Until Your GPU Actually Pays Off?
The honest break-even math between a 2,600 EUR RTX 5090 and the Claude/GPT API in 2026: hardware amortization, electricity, tokens/month. Spoiler: you need to target 50 to 100 million tokens per month.
NPU, TOPS and AI: what these neural chips really do (and why TOPS lie about LLMs)
AMD XDNA 2, Apple Neural Engine, Intel NPU 5: these chips advertise 38 to 55 TOPS, yet a 7B LLM generates text at only ~7 tok/s on them. A breakdown of what an NPU is actually good for, and what belongs on the GPU.
100% Local Audio Transcription: Self-Hosting Whisper and faster-whisper
Whisper running locally, no cloud: models, GPU/CPU performance, real-time vs batch, accuracy (WER) and privacy. With faster-whisper, large-v3-turbo fits in 1.5 GB of VRAM at INT8.
Securing an Exposed Ollama Instance: The Real Risks of Local AI on a Network
Ollama ships with no authentication by default. Over 300,000 instances are reportedly exposed on the internet in 2026. Model theft, RCE, LLMjacking: here are the real risks and how to harden your server.
n8n "Ni8mare" (CVE-2026-21858): a CVSS 10.0 flaw hands over 100,000 automation servers with no password
A technical breakdown of Ni8mare, the unauthenticated RCE (CVSS 10.0) that exposes ~100,000 n8n instances. Content-Type confusion, the full exploitation chain up to RCE, the Q1 2026 CVE wave, detection and hardening.
YGGtorrent Hacked: 6.6 Million Accounts Exposed in a Massive Data Breach
Technical analysis of the YGGtorrent hack: SphinxQL exploitation, lateral movement via SMB, 19 GB of exfiltrated data including 6.6 million accounts, payments and source code.
Secrets Management in Production: Vault, External Secrets and 2026 Best Practices
A complete guide to managing secrets in production: HashiCorp Vault, External Secrets Operator, Sealed Secrets, SOPS, leak detection and an operational checklist.
Zero Trust Architecture: Principles and Hands-On Implementation in 2026
A complete guide to Zero Trust architecture: the 5 core principles, plus step-by-step implementation on Linux with mTLS, micro-segmentation and open-source tooling.
Mistral 3: the European open-source AI model family that changes the game
Mistral 3 brings together a family of Apache 2.0 open-source models: Small, Medium, Large. Benchmarks, local hosting, API and positioning against GPT-4o.
OpenCode: the open source coding agent that won 100,000 GitHub stars
A technical breakdown of OpenCode, the open source terminal-native AI agent. Installation, LSP, multi-session, and how it compares with Claude Code and Cursor.
Kimi Code: the open source Chinese coding agent shaking up Claude Code
Kimi Code by Moonshot AI drives the Kimi K2.5 model inside an Apache 2.0 open source CLI. Benchmarks, the PARL architecture, a head-to-head comparison and the geopolitical stakes.
llama.cpp RPC: Distributing LLM Inference, Yes, But Not Without Guardrails
The RPC backend in llama.cpp lets you spread inference across multiple hosts, but it is still shipped as a fragile, insecure proof-of-concept on open networks.
Mac Studio M4 Max vs M3 Ultra for Local AI: Which One Should You Pick in 2026?
A local-LLM-focused comparison of the Mac Studio M4 Max and M3 Ultra based on Apple's official specs: unified memory, bandwidth and clustering capacity.
GPT-5.3-codex: OpenAI Targets Long Coding Tasks With a More Reliable Agent
On February 5, 2026, OpenAI announced GPT-5.3-codex in Codex and the API. This model targets medium- and long-running software engineering tasks, with improved agentic behavior.
Anthropic Raises $3B at a $183B Valuation: Maximum Pressure on the Model Race
According to Reuters (February 12, 2026), Anthropic raised $3 billion, led by Lightspeed, at a valuation of roughly $183 billion. A breakdown of what it means for the AI market.
MiniMax M2.5: the Chinese AI model that rivals Claude and GPT-5
A full analysis of MiniMax M2.5, the Chinese open-weight AI model. MoE architecture, SWE-Bench benchmarks, pricing 20x cheaper than Claude Opus 4.6, and use cases for agents and office productivity.
COSMIC Desktop 1.0.6: the Rust-based Linux desktop gears up for Vulkan and HDR
System76 ships COSMIC Desktop 1.0.6 with file manager fixes, a native clipboard and configurable terminal hotkeys. An ambitious roadmap: Vulkan renderer, HDR and gaming.
CachyOS: the ultra-optimized Arch Linux that's preparing a server edition
CachyOS pushes Arch Linux performance to its limits with its BORE scheduler, x86-64-v3/v4, PGO and LTO. Discover the distribution that outperforms Ubuntu by 11.6% and is preparing a hardened server edition for 2026.
Linux 7.0 Confirmed by Linus Torvalds: New Features and Release Date
Linus Torvalds announces Linux 7.0 for mid-April 2026. Live Update Orchestrator, PCIe encryption, 4x network gains: a complete breakdown of what's new.
Docker Kanvas: From Compose to Kubernetes Without Writing YAML
Docker Kanvas automatically converts your Compose files into Kubernetes manifests. Built on Meshery (CNCF), it takes on Helm and Kustomize with a visual approach.
Parrot OS 7.1: the pentest distribution moves to kernel 6.17
Parrot OS 7.1 arrives with the Linux 6.17 kernel, critical GRUB fixes, and a massive update of its security toolset (Metasploit, Burp Suite, Airgeddon).
Seedance 2.0: ByteDance Launches a Cinematic AI Video Generator
Technical analysis of Seedance 2.0, ByteDance's AI video generation model. Diffusion Transformer architecture, comparison with Sora 2 and Veo 3, use cases and implications for creators.
AgreeToSteal: a malicious Outlook add-in steals 4,000 credentials via supply chain attack
Technical analysis of AgreeToSteal, the first malicious Outlook add-in found in the Microsoft Store. Vercel subdomain takeover, phishing via the Telegram Bot API and the theft of 4,000 credentials.
Apple zero-day CVE-2026-20700: critical dyld flaw patched in an emergency release
Apple patches CVE-2026-20700, a zero-day in dyld under active exploitation. A technical breakdown of the flaw, its attack vectors and the protective measures admins should take.
GRP-Obliteration: a single prompt breaks the guardrails of 15 AI models
Discover GRP-Obliteration, the technique that hijacks GRPO to misalign LLMs. A 93% success rate, with major implications for the security of AI deployments.
OpenClaw: the open source AI agent that's revolutionizing automation
From Clawdbot to OpenClaw: a look back at the open source AI agent that racked up 145,000 GitHub stars in a matter of weeks. Architecture, how it works, and what it means.
DDoS Record: 31.4 Tbps, the AISURU Botnet Shatters Every Record
The AISURU/Kimwolf botnet launched a 31.4 Tbps DDoS attack, an all-time record. Analysis of the attack and protection measures for your infrastructure.
Linux Monitoring: The Essential Metrics to Watch in Production
A complete guide to the critical Linux metrics to monitor in production: CPU, memory, disk, network, processes and alerting. Commands, thresholds and best practices for sysadmins.
AI in the SOC: 30% of Cybersecurity Workflows Automated by the End of 2026
AI agents are transforming security operations centers. 30% of SOC workflows will be automated by the end of 2026. Impact, tools and risks for security teams.
Claude Code: the AI that codes inside your terminal
Anthropic's Claude Code reshapes software development with an agentic AI assistant living right inside your terminal. An overview of its features and use cases.
Vibe coding is reshaping software development in 2026. How AI tools like Claude Code and Copilot are changing the way we write code, and what it means for developers.
MoltBook: the social network where only AIs are allowed to post
MoltBook is the first social network exclusively reserved for AI agents. 2.5 million bots registered, humans can only watch. An analysis of an unprecedented phenomenon.
Autonomous AI agents in 2026: a snapshot of an ecosystem in turmoil
From OpenClaw to CrewAI, autonomous AI agents are booming in 2026. Frameworks, open source projects, security challenges: a complete overview of the ecosystem.
AI Agent Security: The Risks Every Admin Needs to Know
Vulnerabilities in OpenClaw, an exposed MoltBook database, prompt injections: AI agents introduce a whole new class of risks. A practical guide to securing them.
Fail2ban is a good start, but it only protects against brute force. Discover the complementary security layers that are essential for a production server.
Nginx in Production: 7 Optimizations That Change Everything
A complete guide to optimizing Nginx in production: workers, compression, caching, buffers, HTTP/2, rate limiting and monitoring. Battle-tested, ready-to-deploy configurations.
Ansible for sysadmins: automate without breaking everything
A practical Ansible guide for system administrators: inventory, playbooks, essential modules, roles and best practices to automate your Linux infrastructure with confidence.