Topic
Security
Threat models that match how you actually work, not airline-grade compliance checklists. SSH the right way, firewalls that aren't theater, TLS without the foot-guns, secrets that don't end up in git, and authn/SSO patterns that scale from "me" to "the family WiFi." If your security plan starts with "it's behind WireGuard" — fair, but read these anyway.
183 articles in this topic.
Featured posts
-
Prompt Injection vs Your Coding Agent
Prompt-level defenses against injection are probabilistic and lose to a patient attacker. Here's the capability-level design that holds, with working configs.
14 min read -
Stop Handing CI Jobs Root on Your Box
Self-hosted GitHub Actions, Forgejo, and GitLab runners can hand a forked pull request root on your box. Here is the isolation ladder that actually stops it.
13 min read -
CrowdSec Across a Home Lab: One Brain
One central CrowdSec LAPI, remote log-parsing agents, and bouncers on every box, so an SSH brute-force on one server gets blocked everywhere else too.
12 min read -
Docker MCP Toolkit: Trust the Sandbox?
Docker MCP Toolkit sandboxes AI agent tools in containers. Here's exactly what that isolation stops, where it silently breaks, and how to configure it safely.
12 min read -
NetAlertX MCP: One Token, Twelve Tools
NetAlertX v26.9.0 ships a built-in MCP server with 12 tools. Learn how to wire it into Claude Code, what it exposes, and when to use Home Assistant instead.
13 min read -
Skeleton Key MCP vs One Token Per Box
Skeleton Key MCP swaps four narrow homelab tokens for one Vaultwarden vault and one OAuth consent flow. Here is what that buys you, and what it risks.
14 min read
All Security articles
- Prompt Injection vs Your Coding Agent
- Stop Handing CI Jobs Root on Your Box
- CrowdSec Across a Home Lab: One Brain
- Docker MCP Toolkit: Trust the Sandbox?
- NetAlertX MCP: One Token, Twelve Tools
- Skeleton Key MCP vs One Token Per Box
- Proxmox MCP: Read-Only Beats Root
- Komodo MCP vs the Docker Socket
- IPv6 Dual-Stack: The Hard Parts
- Tinyauth vs Pocket ID vs Authelia
- 20 Unix Users, 20 Rootless Dockers
- OsmAnd + Self-Hosted Tiles, Offline
- Self-Hosted HA Reverse Geocoding
- Photo Libraries Without Google Lookups
- Email Aliasing: SimpleLogin vs addy.io
- Discord Alternatives That Actually Work
- Tor Hidden Services for Self-Hosters
- Anubis: Anti-AI-Crawler Proof-of-Work
- GrapheneOS for the Curious
- Browser Hardening 2026: Brave vs LibreWolf vs Mullvad
- Matomo Self-Hosted: When You Need Funnels
- Falco + Trivy in k3s: Runtime Security on Small Clusters
- Garrul: The Audit Found My Rate Limiter
- Bots Ate 90% of My Worker Quota
- rclone Crypt: Encrypted Cloud Buckets That Stay Yours
- The Free Tier Rug Pull
- 3-2-1-1-0: The Backup Strategy That Survives Ransomware
- SSH Bastion & Jump Host Patterns That Don't Hurt
- systemd-homed: Portable Encrypted Home Directories
- Local Voice Assistant: Whisper + Piper + Home Assistant
- SOCKS5 Over SSH: Selective Routing Without a VPN
- Your Agent Doesn't Need a Shell
- Sandstorm: Self-Hosted Apps in a Sandbox, Not Just a Container
- Where Should Your Coding Agent Run?
- Go on Scratch: Docker With No OS at All
- DIY Perplexity: SearXNG + Local LLM = Private Web Search
- Mozilla Sync Server Self-Hosted: Still Viable?
- Mullvad VPN Containers via Gluetun: Per-App VPN
- OPA & Rego: Policy as Code Beyond Kubernetes
- Vaultwarden Behind Authelia: 2FA That Holds
- Joplin Server vs Trilium vs Standard Notes
- Invidious, Piped, Redlib, Nitter: 2026 Status
- BTCPay Server: Self-Hosted Crypto Payments
- Tang & Clevis: LUKS Auto-Unlock Without a Typed Passphrase
- LibreSpeed: Hosting Your Own Speed Test
- LibreTranslate: Local Translation Without Google
- Collateral Freedom: Costly to Block
- SearXNG vs Whoogle: Private Search Frontends
- Meshtastic vs Reticulum
- Stirling-PDF: Stop Uploading Your Tax Returns to Sketchy Sites
- AdGuard DNS Sync Across Two Instances
- REALITY: Borrowing a TLS Handshake
- Self-Hosted Email Aliasing on Your Own Domain
- CryptPad vs EtherCalc: Privacy Collaboration
- nftables in 2026: Stop Pretending iptables Will Live Forever
- Why Your VPN Is Already Detected
- NextDNS vs Self-Hosted: When SaaS Wins
- Self-Hosted CAPTCHA Alternatives in 2026
- DNS-over-HTTPS at Home: cloudflared vs dnscrypt-proxy
- YubiKey + age: Hardware-Backed Encryption Without GPG
- Pangolin: Self-Hosted Cloudflare Tunnel Alternative
- Sigstore + Gitsign: Signed Commits Without GPG Pain
- Sealed Secrets vs External Secrets Operator
- Renovate vs Dependabot: Self-Hosted Dependency Bots
- Mesh VPN Showdown: Tailscale, Nebula, ZeroTier, NetBird
- Syncthing Through Untrusted VPS Relays
- Self-Hosted Email Gateways in 2026
- Assume Your App Gets Popped
- Kasm Workspaces: Browser Desktops
- Jitsi Meet Self-Hosted
- OPA & Gatekeeper: Policy as Code
- cert-manager: ACME at Scale
- Zeek for Home Lab Forensics
- ModSecurity vs Coraza WAF
- SOPS + age: Secrets in Git
- WebAuthn & Passkeys for Sysadmins
- Owntracks + Home Assistant: Private Location Tracking
- Claude Code + SearXNG: Private Web Search
- ZFS Encryption vs LUKS
- Syncthing vs Resilio vs Seafile
- OpenConnect vs AnyConnect
- Boundary vs Teleport
- stunnel vs spiped
- Container Escape: How to Stop It
- Cosign Keyless: Sign Without Keys
- age vs GPG: Modern File Encryption That Doesn't Make You Cry
- Sysbox vs gVisor vs Kata
- Trivy vs Grype vs Docker Scout
- Beyond Akismet: Spam Protection for 2026
- Sec-Fetch & UA Client Hints in 2026: What Actually Leaks
- Blog Comments: Self-Host or SaaS?
- CrowdSec Collections & Bouncers: fail2ban for 2026
- Distroless Images: When Minimal Goes Too Far
- Incident Response for Self-Hosters
- CVE-2026-31431: The 9-Year Linux Root Bug
- OpenCanary: Honeypots for Your Home Lab
- Pi-hole vs AdGuard Home: Block Ads for Your Whole Network
- nftables: Modern Linux Firewalling
- Suricata vs Snort: Network Intrusion Detection That Actually Works
- SBOMs and Supply Chain Security
- Authentik vs Authelia: SSO for Your Self-Hosted Stack
- Container Security: Scan and Sign Your Images Like You Mean It
- Falco: Catch Container Attacks at Runtime
- Cloudflare Tunnels: Beyond Port Forwarding
- Immich vs PhotoPrism: Escape Google Photos Without Losing Your Mind
- Trivy + Cosign: Scan and Sign Your Images
- Fail2ban vs CrowdSec: Blocking the Bots Actually Smartly
- 2FA for SSH and sudo via PAM
- WireGuard vs OpenVPN 2026: It's Not Even Close
- SSH CA: Finally Ditch authorized_keys
- Wazuh: Open Source SIEM for Your Home Lab
- LUKS Full Disk Encryption on Linux
- Rootless Docker: Run Without Root
- LinkedIn Is Searching Your Computer
- Linux Privilege Escalation: The Defensive Playbook
- De-Googling: Self-Hosted Replacements for Google Apps
- dotenv Files: The Mistakes That Leak Secrets
- Using AI to Find Security Bugs in Your Code
- Private Docker Registry with Harbor
- TLS 1.3: Modern Encryption Without the Existential Dread
- Let's Encrypt Without Certbot
- The Zero-Trust Home Lab
- Cloudflare WAF: Free Tier Firewall Rules
- Distroless: How to Build Slim, Secure Containers
- Certificate Pinning: The Nuclear Option for TLS Security (Use With Caution)
- .gitignore Entries Every Project Actually Needs
- Vault vs Infisical: Secrets Management for Teams Who've Learned the Hard Way
- Open Source Licenses Explained: What You Can and Can't Do With Free Software
- mTLS Explained: When Regular TLS Isn't Paranoid Enough
- Port Knocking: Simple Obscurity for SSH Access
- Why Your VPN Isn't Routing What You Think
- Kernel Live Patching: Security Updates Without the 3am Reboot
- DNS Over HTTPS and TLS: Encrypt Your DNS Before Your ISP Sells It
- tcpdump Basics: Capture Traffic Without Wireshark
- AppArmor vs SELinux: Mandatory Access Control Without the Existential Dread
- Your Server Doesn't Know What Random Means (And That's a Problem)
- Caddy Advanced: Automatic HTTPS, Plugins, and Config That Doesn't Make You Cry
- Auditd & Audit Logging: Know Exactly Who Touched What on Your Server
- HashiCorp Vault: Stop Hardcoding Secrets Like It's 2012
- VPN Kill Switch and DNS Leak Prevention: Paranoia, Justified
- Suricata vs Snort: Intrusion Detection for the Paranoid Home Lab Owner
- Plausible vs Umami: Privacy-Friendly Analytics That Won't Creep Out Your Users
- nmap for Your Own Network: What You Should Be Scanning
- Vaultwarden Organization Sharing: Password Management for Your Whole Household (or Team)
- Reverse Proxy SSL: The Cert Chain Mistake Everyone Makes
- Linux Capabilities: Drop Root Without Breaking Everything
- Docker Security Hardening: 15 Things You're Doing Wrong Right Now
- UFW Advanced: Rate Limiting, Logging, and Rules That Actually Make Sense
- Open Source Security: Scanning Your Dependencies Before They Scan You
- DDoS Mitigation: Teaching Your Server to Say No Politely (Then Impolitely)
- SSH Hardening: Lock Down Remote Access Without Locking Yourself Out
- Vaultwarden vs Bitwarden: Own Your Passwords Before Someone Else Does
- Proxy Chains and Anonymization: What Actually Works and What's Just Theater
- Linux Audit Log: What's Really Happening on Your Server
- The sudoers Mistake Everyone Makes Once
- Why Your TLS Certificate Isn't Trusted
- Certificate Expiry: Monitor Before the 3 AM Call
- The Firewall Rule Order That's Breaking Your Setup
- Sticky Bit, Setuid, Setgid: Linux Special Permissions Explained
- Is fail2ban Actually Working? Here's How to Check
- SSHFS: Ditch SCP & Access Remote Files
- SSH Agent Forwarding: How It Works
- Why Your SSH Connection Keeps Dropping
- SSH Multiplexing: Stop Reconnecting Every Time
- Stop Putting Passwords in Docker ENV
- The SSH Config File: The Shortcut You're Not Using
- The umask You've Been Ignoring
- Running Docker Containers as Non-Root (And Why You Should)
- Disabling Discord’s Activity Tracking
- The Role of Antivirus and Endpoint Detection and Response Systems
- Certificate Pinning: A Secure Connection Guide
- Understanding the regreSSHion Vulnerability in OpenSSH
- How to securely deploy Cloudflare Tunnels
- Advanced UFW Techniques: Enhancing Firewall Security
- UFW Basics: Setting Up Your Linux Firewall
- SSH Tunneling: A Secure Conduit for Your Data
- User and Group Management in Linux
- Linux Home Lab Security: Planning for the Unexpected
- Wireguard VPN Server in Docker
- Ed25519 SSH Keys: Ditch RSA for Good
- Install Caddy reverse proxy via Docker
- Linux su with custom shell
- SSH keys and secure file copy