Posts
Creating a Custom Systemd Service
Your application needs to start on boot, restart on crash, and log output. Shell scripts in /etc/rc.local give you none of that. Systemd solves all three with a …
cockpit-ufw-module: Uncomplicated Firewall in Cockpit
UFW on a home or small server is usually configured over SSH: ufw status numbered, then ufw allow 443/tcp. cockpit-ufw-module covers the same cycle in the …
CasaOS: Web Dashboard for Home Lab
CasaOS is a lightweight web dashboard for managing Docker containers on a single host. If you’re currently accessing each container through its own port, this …
systemd-timer: scheduling instead of cron
cron works, but its logs are flat text files with no structure, and service dependencies require workarounds like embedding Requires= logic inside shell …
SSH certificates instead of authorized_keys
authorized_keys works fine for a handful of servers. Once you hit a dozen, it becomes a liability. Onboarding a new developer means manually distributing their …
Squid: Internet Forwarding to Remote VM
Your VM in the cloud has no public IP or internet access is blocked via NAT, but the deployment needs wget/curl from inside. Squid on an intermediate host with …
MkDocs: Project Documentation from Markdown
Documentation in a repository ages faster than anyone reads it: README links lead nowhere, sections are scattered across docs/, wiki/, and Confluence, and site …
dig: DNS Query Debugging in CLI
DNS resolvers return the wrong address, clients don’t see updates, or it’s unclear which server is handling requests. dig (Domain Information Groper) is the …
cockpit-modules: web panels for day-to-day operations
Cockpit covers basic Linux administration in the browser: services, logs, networking, accounts. Firewall, fail2ban, cron, and Let’s Encrypt sit outside that set …
Trusting a custom CA: system store, browsers, and CLI
A TLS error that says the certificate is untrusted almost never means the certificate is “broken”. The trust anchor is in the wrong store. curl, openssl, Git, …
Too many authentication failures: SSH ran out of tries
Received disconnect from 10.0.0.5 port 22:2: Too many authentication failures followed by Permission denied (publickey) is not a broken server, and it is not …
kind: Local Kubernetes in Docker
kind creates a Kubernetes cluster from Docker containers: control-plane and worker nodes are kindest/node images. Primary use cases are local development and …