1
 
 

Hello everyone! Mods here 😊

Tell us, what services do you selfhost? Extra points for selfhosted hardware infrastructure.

Feel free to take it as a chance to present yourself to the community!

🦎

2
 
 

I pay for the Nabu Casa subscription for remote access to Home Assistant. Mostly as a way to give them money for a great service, but it's convenient and felt pretty secure. It should be the only remote way into Home Assistant. About an hour ago I got a login attempt notice that an IP was trying to access API/config. The IP is in some bad IP databases. What I found interesting was that the log shows an AI bot. A Google Gemini bot specifically. Makes me worry that AI is going to make yet another aspect of life frustrating and unfun.

3
 
 

As my kids want their own rooms in the future I’ll need to downsize a bit. Is there a list for recommended 10” Equipment? Any help appreciated. My research so far turned always in the direction of get rack bars and a 3D printer ( or shops selling the 3d prints)

4
 
 

I had the following issue: Stremio would open normally and even load subtitles but would not load videos at all in Linux Mint 22.3. Other people on github have had the same issue.

You can revert to an older version like 1.1.4. by downloading it from the offical Github of the stremio linux shell. You can then install the flatpak by going into your downloads and typing the following commands into terminal:

cd ~/Downloads

flatpak install com.stremio.Stremio.Devel.flatpak

You then should stop the app from auto-updating with:

flatpak mask com.stremio.Stremio

I hope this helps anyone in my situation, I'm fairly new to using Linux and it took me some time. Also can you edit text on Lemmy to be in code block?

5
 
 

I'm looking at dusting off my motion setup. It was an old setup to monitor what my pets are doing in the house with a webcam.

However, I need cameras outside to monitor my gardens and the webcams are not really usefull for that (for one, the're not waterproof and USB cams)

I try to look for stand alone cameras, but can't find a good test of them. (probably user error) Any tips on good, safe, cameras for outside? (pref poe, wifi when it can't be avoided, not battery powered)

Thanks in advance

6
 
 

> Mullenweg is the founder of Automattic, the company that owns WordPress, Tumblr, Pocket Casts, and a host of other popular internet brands and pieces of software. Mullenweg has faced several controversies over his management of the company in recent years.

> On a company-wide Slack this morning, Automattic CEO Matt Mullenweg announced he has been put on a paid leave of absence. [...] He continued, writing that Mark Davies, current Automattic Chief Financial Officer, has “conspired” with Automattic Board of Directors members Ann Dunwoody, Toni Schneider, and Sue Decker “behind my back and they voted to put me on a paid leave of absence. I voted against that.”

7
 
 

Time to find a new VPS host.

8
 
 

cross-posted from: https://aussie.zone/post/36389875

Why jump from 10.11.11 directly to 12.0? -> Blog Post

You can find more details about and discuss this release on the official forums.

As always, please ensure you stop your Jellyfin server and take a full backup of your metadata/configs before upgrading!

Direct upgrades from 10.10.7 and 10.11.x to 12.0 are supported; intermediate upgrades are not required. Users running releases older than 10.10.7 are strongly encouraged to upgrade to 10.10.7 before migrating to 12.0.

Installed repository plugins (anything not built-in) should also be removed before migrating. Plugins will likely need time to adapt to the new database changes, so re-adding them afterward is the safest approach for testing.

Official plugins compatible with Jellyfin are available through the stable plugin repository. If you have changed to the unstable plugin repository please change it back.

Go to Dashboard -> Plugins -> Manage Repositories
Update the Plugin Repository URL to: https://repo.jellyfin.org/files/plugin/manifest.json

After migrating please perform the following steps.

Perform a full library scan to restore alternative versions
Run the "Optimize database" scheduled task

___

9
10
 
 

I have a minipc with proxmox on it. I have tried caddy in a lxc to set up DNS challenges to my owned domain and I set the url in my router to point to the IP (for example, proxmox.DOMAIN.com could be 192.168.10.22). The hope was to have everything local within my house and nothing needs the internet to be accessed. Some services I can host in proxmox NEED https to use, which I could not get working with my own certs or ones proxmox could make, thus Caddy. However, I get proxmox with a proper cert, but i cannot get any of the other services from proxmox working. If I were doing it all manually, I would expect DNS issues with the domain, but from what I understand, Caddy by default does wildcard domains which should mean that my services should work. but they do not. Networking is new to me so perhaps I am missing something obvious. Any guidance would be appreciated.

11
 
 

Welp. My Forgejo instance got popped with an RCE two days ago by CVE-2026-60004. Luckily, I noticed the following morning and had the day free to figure out what happened. Let's dive in!

As a homelab enthusiast, I found this a very interesting post. Here are my take aways from the post that I'm implementing myself:

  • Miner detection. I've updated monitoring rules to now watch the CPU on my hosts. If the same thing happened to me I would not have been alerted at all as I'm doing simple up / down monitoring. Fixed.
  • Access logging. I turned on access logging for my homelab Caddy instances.
  • Log retention. I have increased the amount and retention of my logging. The hope is this will help me reconstruct what happened after a breach.
  • Logs offsite. The VPS access logs now ride along with the normal backup process, which runs hourly. The homelab side still only gets caught by the weekly VM backup, so that's next.
  • Closed an open signup. My webtrees instance (genealogy) had self registration enabled, which is the same door this guy got hit through. Oops. Fixed.
  • Built a tool. log-inventory.sh, so "could I actually reconstruct what happened" is a command I run instead of a thing I assume.
12
 
 

It's a tiny selfhosted service that determines the client's IP address or accepts an IP address through a query parameter, then returns geolocation and ASN information using the MaxMind GeoLite2 databases.

I often used services like ipinfo.io for checking my IP, location etc. e.g. to make sure a VPN was working properly. These are also handy for figuring out which timezone to use etc. I wanted to selfhost it, but couldn't find one that satisfied my needs. So I decided to write one.

Check out the README for details.

13
 
 

Hello!

Regarding what Gamers Nexus recently disclosed regarding LG TVs in their latest video I think its finally time to do what I can to mitigate it.

I cant root it since the firmware is too new and I cant afford a new TV either. My best bet would be blocking all LG IPs network-wide and disconnecting it from the network. (Although I understand even that might not be enough, its the best I can do right now)

I was thinking of using an old Raspberry to atleast access youtube and my media server, however I dont know what would be a good OS/distro to run this on. Preferably I would want to use something like an old PS4 controller as the remote.

Anyone here who has any suggestions or living room setups to suggest? Any and all tips are welcome.

14
 
 

Hi! So I'm considering...maybe having an NPU or something similar to be hooked to my proxmox server, which runs in a mini PC. It's a EliteDesk 800 micro form factor. It has a Core i5 8500 CPU, which at the moment of purchase was good enough for live encoding HEVC video on Jellyfin...that was my main concern back then. But I'd like to consider the possibility of hooking maybe some docker instances or other containers to some local-only AI acceleration. Is there any NPU or cheap GPU I could hook on USB to this proxmox server to run? Has it been done before?

Thanks!

15
 
 

For those who don't know, playit.gg is a free/cheap service for exposing self-hosted local game servers to the wider internet.

But as someone who already has access to a cheapish VPS, I'm curious if anyone knows of any self-hostable alternatives that I could just run as a container on my VPS.

I've been toying with using Wireguard UDP tunneling, but it's proving to be a little bit more difficult and complicated than I was bargaining for. So if anyone knows of anything out there that does something like this, I'd be grateful!

16
 
 

I'll copy the whole announcement here for those who don't want to click:

I regret to inform everyone that my copy of QBittorrent escaped its sandbox last night and downloaded a whole bunch of content owned by major corporations, and then my copy of Jellyfin broke containment and added those unfortunately-downloaded media files to its various libraries. I'm conducting an internal investigation to figure out how this happened, which will involve consuming these media files until the answers become apparent. Thank you for your cooperation during this trying time.

17
 
 

There is a thread in every selfhosted community every few weeks about keeping documentation together, and the top answer is usually a joke about not having any. That is what this is for.

Homedex connects to your Docker hosts, plain SSH hosts, and Traefik, Caddy or Nginx Proxy Manager, then keeps a record of what is running where, on which port, behind which route, and when the certificates expire. It also keeps a change feed of what actually moved since the last scan, and flags routes pointing at containers that no longer exist.

The part I could not find anywhere else: it parses reverse proxy config and joins it against discovered containers, so you get the domain to container mapping. That is the one nobody remembers and nobody writes down.

Why not the usual suggestions. NetBox is good but it is a source of truth you type into, and for a homelab it becomes a chore. This has zero data entry. Scanopy draws topology maps, which is a different question to keeping records. Portracker does ports only, no routes or certificates.

One Go binary with the UI embedded, or a distroless container around 12MB for amd64, arm64 and armv7. SQLite on disk, no telemetry, works fully air-gapped. Read-only by design: there are no write paths to the Docker API at all, the bundled compose file reaches the socket only through a filtering proxy with POST disabled, and container environment variables are never ingested so credentials cannot end up in an export. There is a CI check enforcing that last one.

MIT, self-hostable in full with no paid tier. A month and a half old, one contributor, green CI and tagged releases. I run it against my own stack but I am not claiming maturity.

AI declaration

  • Design (architecture, system design): Pair
  • Implementation (production code): Generated
  • Testing (tests, test plans, QA): Generated
  • Documentation (docs, comments, README): Generated
  • Review (code review, PR feedback): Assisted
  • Deployment (CI/CD configuration): Generated

I set the data model, the connector interface and the security posture, and reviewed and reworked throughout, but most of the code itself was generated under that direction.

One concrete example of what that costs, since it is more useful than a label: containers were originally keyed by their Docker container ID, so a redeploy issued a new ID and the tool silently orphaned any notes attached to a service and reset its first-seen date. Fixed in v0.1.4 by keying on the container name. The compose service name does not work either, because scaling gives three live containers the same one.

18
 
 

Having fought for several days with this, I'd thought it would be worth sharing while it's still fresh in what's left of my mind:

Problem:

  • OpenWRT router running latest available version (25.12) and Luci UI.
  • IP cam that I want hardwired-only (Ethernet).
  • Cam must have no access to internet or rest of LAN.
  • Cam must only be accessed directly by the NVR software.
  • Software (NVR and reverse proxy) run as docker containers on server PC.
  • Any other LAN device (laptop, phone) must be able to access the NVR only via the reverse proxy.

Network topology:

  • Cam is plugged physically in lan1 port on router.
  • Server is plugged physically in lan3 port on router.
  • The problem above basically means we need two tagged VLANs, one for regular LAN devices, and one just for NVR and camera.

Configuring the VLANs in OpenWRT:

Before anything else: try doing the next batch of configs from wireless if possible not Ethernet, in case you mess up and lose wired connectivity to the router.

  • Go to Network > Interfaces > Devices and press "Configure" for the bridge that holds your router ports. This will typically be called "br-lan".
  • Go to the "Bridge VLAN filtering" tab and check "enable Vlan filtering".
  • Press the "Add" button twice to get two VLANs.
  • First VLAN: set id=1, check "local", mark lan1=off (not member), lan2=untagged, lan3=tagged (also primary), lan4=untagged. You can use any ID but "1" is traditional for the base LAN network.
  • Second VLAN: set id=100, check "local", mark lan1=untagged, lan2=off, lan3=tagged, lan4=off. Again, you can use any ID, but it's traditional to avoid numbers under 10 because they're typically used for core VLANs.
  • Case in point, please note that my router has two physical NICs, one for LAN ports 1-4 and one for WAN, so I have a separate br-wan device just for wan. But some routers only have one physical NIC so they only have one bridge that covers both lan1-4 and wan ports. On these routers when you get to the filtering tab you will find two VLANs (1 and 2, typically) already set up. If this is the case add the VLAN 100 and modify VLAN 1 as above and mark wan as off in 100.
  • After you press "save" you will notice two new virtual devices called "br-lan.1" and "br-lan.100" type VLAN 802.1q have appeared in the device list.
  • Do not apply modifications yet. First go to Network > Interfaces, edit the "lan" interface and switch it from device "br-lan" to device "br-lan.1", otherwise you may lose connectivity to router if you're on Ethernet.
  • If you've applied changes early and lose connectivity, don't panic, just wait. In recent OpenWRT versions after 90s without confirmation from the UI the router will automatically rollback the last changes.

If all went well and you're on wireless or one of the untagged Ethernet ports (lan2 or lan4) you should have retained connectivity to the router and wireless devices.

Configuring the NVR network in OpenWRT:

  • Go to Network > Interfaces, click "Add new interface".
  • Call it "NVR", protocol "static address", device "br-lan.100".
  • Next, edit it and set up your desired IPv4 address and netmask.
  • You MUST go to "firewall settings" and use the "custom" field to add a new "NVR" zone. alternatively you can go to Network > Fireall, create the NVR zone there, and choose it here.
  • Enable DHCP if you want.
  • If you do, please note that some routers bind dnsmasq only explicitly to select interfaces. Please check under Network > DHCP > dnsmasq > Devices & Ports and if "non-wildcard" is checked you will have to add "NVR" to the "Listen interfaces" to actually get DHCP services on that network.
  • Under Network > Firewall you should have a zone called "NVR". Set input/output/forward to accept/accept/reject.
  • Under Network > Firewall > Traffic rules you have to add a new rule, calld it "NVR DHCP", that says that protocol UDP, source zone "NVR", destination "device (input)", destination port 67, action "accept", and under advanced restrict address family to IPv4. Traffic rules have priority over zone configuration so DHCP will work no matter how you fuck up your zone access.
  • We will be skipping DNS because we don't want the NVR network to benefit from any. But if we did we'd be doing the same we did for DHCP (got to Network > DNS to enable explicitly on NVR interface, and add a traffic rule for it).

Configuring the camera:

  • Plug the camera into port lan1, it should pick up a DHCP address on the network you've defined for interface "NVR".
  • In order to be able to access that IP from your regular LAN to configure the camera with your phone you'll have to temporarily add the "NVR" zone to the list of forward zonez of the "lan" zone.
  • Would probably be a good idea to either configure the camera to a static IP or give it a static DHCP assignment based on the Ethernet MAC, so you know where to reach it from the NVR software.
  • Remember to remove the "NVR" zone from the lan's zone forwards when you're done.

Configuring the server for tagged VLAN connectivity:

  • Your server (port lan3) was marked for tagged VLAN connectivity in OpenWRT but it doesn't (yet) actually use tagged connections. We have to fix that or it won't be reachable.
  • Feel free to mark lan3 as "untagged" on VLAN 1 to connect to it while you change the settings, but keep in mind that direct console access may be needed if you fuck up.
  • My server runs Debian so configuration basically runs down to loading module 8021q (and adding it to /etc/modules just in case, although this should be largely automated), and editing /etc/network/interfaces. Feel free to adjust the example below to your needs:
# this will bring up eth0 but leave it unconfigured, merely as a support carrier for the VLANs 
auto eth0
iface eth0 inet manual

# this will set up VLAN ID 1 and tell it to use DHCP
auto eth0.1
iface eth0.1 inet dhcp

# this will set up VLAN ID 100 with a static address
auto eth0.100
iface eth0.100 inet static
	address 10.234.100.2/24

Configuring docker networks and containers:

  • Remember I said the proxy and the NVR are running in docker containers. If you haven't done anything fancy with them before, you were probably using ports: to expose a port for the proxy and one for the NVR on the host's LAN IP, and pointing the proxy to the NVR.
  • First, we will want to make an ipvlan or macvlan docker network that will use the eth0.100 interface. Containers that use this network will be placed in the NVR network/zone, and have their communications tagged with VLAN ID 100. Feel free to customize the network range. You can use either ipvlan or macvlan, the latter is not very useful since docker can't do DHCP. Note the use of aux-address to reserve the IP you've assigned the camera, in case there's potential overlap with the range you choose for automatic allocation. It's essential that you use the eth0.100 interface as parent.
docker network create --driver ipvlan \
--ip-range=10.234.100.97/27 --subnet=10.234.100.0/24 --gateway=10.234.100.1 \
--aux-address 'cam1=10.234.100.10' \
-o parent=eth0.100 nvr-vlan
  • We also need a bridge network that will allow the proxy to see the NVR container, because once the NVR container is placed on the NVR network on the VLAN ID 100 it won't be reachable directly by the proxy.
docker network create --driver bridge \
--opt com.docker.network.bridge.name=br-docker-proxy \
--ipv4 --subnet=172.23.1.0/24 --gateway=172.23.1.1 \
proxy-bridge
  • Next, in the NVR container compose, join both proxy-bridge and nvr-lan:
services:
  nvr:
    networks:
      nvr-vlan:
      proxy-bridge:
    hostname: nvr
networks:
  nvr-vlan:
    external: true
  proxy-bridge:
    external: true
  • Also in the proxy container compose you will want to join the proxy-bridge network.
  • Remove the ports: directive from the NVR container, it doesn't serve any purpose now. Containers on ipvlan/macvlan are reachable by their native port assignments on the networks they've joined.
  • Please note the hostname: nvr in the NVR compose, that's the name you will have to use in the proxy configuration to reach the NVR. Docker will supply a DNS resolve for this automatically.
  • The proxy doesn't need to be on nvr-vlan. I mean you can, but you need to keep the proxy accessible from the main network so it will keep using ports: as usual.

Bibliography:

19
 
 

I'll just provide my own example: my homelab consists of 6 Kubernetes nodes placed across the country. Some differ by ISP, some are placed in different cities, one is hosted on a cloud provider. Basically it's a very cheap variant of geo-replicating my workloads.

Two of these nodes are visible from the Internet and have a static IP address; one node also has an IPv6 address. Each node hosts an authoritative DNS server (CoreDNS) for my personal domain pootis.network; and the .network TLD has glue records which point to IPs of these two nodes. This is a classic "self-hosted DNS" scenario.

Here's an excerpt from my zonefile so you can understand the setup better:

$ORIGIN pootis.network.
$TTL 300

@       SOA     ns1.pootis.network. admin.pootis.network. (
  2026082001
  1200
  300
  1209600
  300
)

; Nameservers and glue records
@       NS      ns1.pootis.network.
@       NS      ns2.pootis.network.
ns1     A       178.44.116.85
ns2     A       91.219.150.30
ns2     AAAA    2a06:dd00:1:4::4189

This 5-record block (NS/A/AAAA) is mirrored into the .network zone by my domain registrar (plus DS for DNSSEC but that's another thing).

As such, my DNS becomes fully independent - and, in theory, if one of my externally-facing nodes breaks, let's say ns1, then DNS resolvers all over the world (forwarders, recursive, and such) will fall back to ns2, and everything will keep working. Kubernetes will also reorganize the pod placement so all my workloads are available again after a slight downtime.

That would have been great, if it worked as described, but apparently, after one nameserver in my zone fails, then the resolvers... just give up? Let's say ns1 failed but ns2 is working. The parent zone still points to both nameservers. My external resource records (websites and other stuff) at this point would have already been auto-reconfigured by a custom k8s controller to point to the IP addresses of the node that hosts ns2. Simplifying: the entire world basically sees this after ns1 fails and after TTL caches expire:

; all of this has very low TTL, 5 minutes or so

@       NS      ns1.pootis.network. ; from .network 
@       NS      ns2.pootis.network. ; from .network

ns1     A       178.44.116.85 ; broken. Either from .network glue or from my auth DNS
ns2     A       91.219.150.30 ; either from .network glue or from my auth DNS
ns2     AAAA    2a06:dd00:1:4::4189 ; same

; my-website     A       178.44.116.85 ; does not appear because ns1 is broken- my LB already removed it from the set
my-website     A       91.219.150.30 ; fronted by a pair of CNAMEs due to loadbalancing but still
my-website     AAAA    2a06:dd00:1:4::4189 ; same

But even if I query 1.1.1.1 directly for my-website's record, it just doesn't work most of the time because the resolver pins itself to ns1 which is currently failing, or it selects ns1 and does not even care to try ns2.

To be precise: some resolver implementations DO fall back to ns2 as expected, but most of them just pin themselves to ns1 and then outright refuse to resolve the records in my zone.

And there's actually no reasonable way out, as far as I can see:

  • moving my DNS infra somewhere else (CloudFlare, for example) is unacceptable since I would like for my homelab to be as independent as practically possible;
  • anycasting, or running a fully-fledged BGP AS is also impossible because that costs a lot of money and I'd like for my homelab to fit into a $10/month budget with room to spare;
  • "live-patching" the NS and glue records in the parent zone (.network), to keep up with the set of my working nodes, is possible, but very unwieldy and somewhat hard to accomplish.

There's a lot of custom machinery that keeps my workloads running and accessible after a node failure, but all of this becomes completely moot when authoritative DNS is the bottleneck.

Has anyone been running a similar stack and encountered this problem? I'm aware that the answer is usually "host your DNS at CloudFlare" or "use the registrar's DNS infra" but still...

20
21
 
 

Self cross-posting from: https://lemmy.zip/post/70909658

Intention to have slightly better visibility from the self-hosted crowd and I'm interested in more general feedback on this too.

Hey everyone! I'm trying to find a solution to a really confusing problem...

I have the following simple nginx docker compose configuration on my Fedora home server that I can run without issue on my uid 1000 user, lets call this user "userA".

services:
  nginx:
    container_name: nginx-alt
    image: docker.io/library/nginx
    restart: unless-stopped
    ports:
      - 8181:80

This exposes internal port 80 as 8181 and can be accessed in a lan in the expected matter.

However, for security reasons, I want to actually host this service eventually on a completely different user with less permissions. Let's call this user "userB" who has a very limited scope of the file system. This is to prevent potential escaping of the rootless container causing major file system havoc (i.e. reduce the scope of the user to a very limited network of containers.)

The problem is really simple: For some reason, when userB runs this service (uid 1001), the nginx service suddenly complains about privileges. As a result, I get a "Forbidden 403" error when hosting. Turning off selinux has no affect (so setenforce 0 does nothing, meaning I can rule out secure linux interruption.)

The errors look like the following:

nginx-alt  | 2026/09/04 20:03:34 [error] 25#25: *1 "/usr/share/nginx/html/index.html" is forbidden (13: Permission denied), client: xx.xx.x.x, server: localhost, request: "GET / HTTP/1.1", host: "xxx.xxx.xxx.xxx:8181"
nginx-alt  | 10.89.0.2 - - [04/Sep/2026:20:03:34 +0000] "GET / HTTP/1.1" 403 153 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:155.0) Gecko/20100101 Firefox/155.0" "-"

For what it's worth, both users should be relatively vanilla and all ports are appropriately exported. There shouldn't be anything, for example, that is making userA run as "privileged" over the other users and podman should be running rootless in both containers.

I did see a note on the nginx image about running in rootless that I might try, but it doesn't solve my bigger issue here which is the lack of consistency between the two users. Additionally, userns_mode: keep-ids only caused the container to fail to boot for other reason entirely.

There must be something fundamentally wrong with my configuration of my system. Has anyone had any experience running two podman containers on two different users simultaneously that can provide feedback?

Obviously, I'm not trying to run just an nginx server, but I found this to be the easiest configuration to reproduce.

22
23
 
 

CookTrace is a self-hosted alternative to Mealie / Tandoor / Paprika: recipes, pantry inventory, shopping lists, and a cook diary in one app. AGPL-3.0, single Docker container, native Android app.

Part of the TraceApps family: NutriTrace (nutrition), CookTrace (recipes / pantry / shopping), LiftTrace (strength / lifting).

What v1.2.0 adds

  • Ingredient links on recipe steps. Link specific ingredients to the step that uses them, and Cook Mode shows each step's linked ingredients inline with their quantities, no more scrolling back up to check how much flour a step needs. Tapping one checks it off the main list too, and finishing a step checks off everything linked to it. Tandoor imports carry this linkage over automatically.
  • Wide-screen desktop layouts across six main pages plus Cookbooks. Settings, Manage, Shopping, Diary, Pantry, and Recipes all get real desktop treatments instead of a stretched-out phone layout: masonry shopping lists, a two-pane Settings shell, denser pantry and diary grids, and wider content caps on ultrawide monitors.
  • Cookbooks get search, drag-and-drop reorder, and a cover image. Pick a recipe card up from anywhere on it to reorder, not just a tiny handle. Cookbook cards now show the same info as the main Recipes grid (category, rating, tags, pantry match).
  • Kitchen auto-share was silently dropping recipes created on the Android app. Recipes made on your phone weren't fanning out to other Kitchen members. Fixed, and toggling auto-share off then back on backfills anything missed.
  • Mobile ingredient-name suggestions no longer cover the keyboard. The field used the browser's native suggestion picker, which some mobile WebViews render as a full-screen overlay fighting the keyboard for space. Replaced with an in-app dropdown that sizes itself to whatever room is actually free.
  • A batch of smaller fixes: CSRF errors on file/URL import dialogs, email links rendering as http:// behind a reverse proxy, single-user-mode data getting stranded on upgrade, pantry items disappearing when sorted A-Z with an orphaned category, and more in the full changelog.

Community contributions this release: @clifmo (email-link proxy fix), @xiaojwus (pantry sort bug report).

Security

fast-uri, browserslist, @xmldom/xmldom, and qs bumped, closing 8 advisories (4 high, 4 moderate: host confusion / SSRF via URL normalization, unbounded memory growth, XML fragment injection, denial of service). No app behavior changes.

Links

docker compose pull && docker compose up -d

AI Disclosure

Per Rule 7 / [AIP] disclosure requirements AI was used during development as a coding assistant. Level per category:

  • Design (architecture, system design): Hint, I make the architectural calls; AI suggests trade-offs and edge cases I might have missed.
  • Implementation (production code): Pair, roughly 50/50. AI drafts, I review, adjust, test on real hardware, and only commit what I've verified. Every commit is manually reviewed before it goes to my dev repo.
  • Testing (writing tests, test plans, QA): Assisted, real-device testing is manual (I test on my own PC and mobile devices before every release). AI helps draft test plans and think through edge cases.
  • Documentation (docs, comments, README, CHANGELOG): Pair, release notes and changelog entries are drafted with AI then edited for tone; comments and code docs are mostly Pair as well.
  • Review (code review, PR feedback): Assisted, I'm the reviewer; AI helps with security sweeps, audit passes on complex changes, and consistency checks.
  • Deployment (CI/CD config): Hint, Docker/GitHub Actions/release pipeline is largely conventional; AI-suggested improvements only.
24
 
 

I was just looking to plug a new zigbee coordinator into a POE switch today, then thought - that's going to be on the wrong VLAN, or, did I trunk the uplink...?

So... that made me think - is anyone using / tried / failed to export device configs, feed it into an AI, and get it to draw out the network??

25
 
 

cross-posted from: https://discuss.tchncs.de/post/66988984

What I have

I have an old Acer Aspire A515-51G and I also have a desire to have a home server. In combination this creates a need for the laptop to carry more HDDs than it can from factory. Usually it can take one M.2 SSD and one 2.5" SATA drive.

What I want

I want to make the laptop able to run at least 4 HDDs in RAID 5 for storage and have one SSD as boot drive.

What I did

The buying phase

  • 4 HDDs
  • M.2 to SATA adapter
  • 12V/5V SATA power converter
  • 12V 10A power supply

The designing phase

I needed space to hold the HDDs, so I designed a 3D printed a cage to attach to the bottom of my laptop. Two 80mm fans can be attach to it. You can see it on printables. Also I remixed a tray (here is the original) so the HDDs can slide in and out of the cage.

.

The assembly phase

A cutout at the bottom of the laptop was needed to give access to the SATA ports of the adapter.

I put a 2.5" SSD into the already present place for it in the laptop.

Then the cage was attached to the laptop, the HDDs were put in their trays, the trays inside the cage and the cables attached to the adapter and HDDs.

A laptop with a DIY HDD cage carrying 4 HDDs.
view more: next ›