Topic
DevOps & Automation
DevOps without the buzzwords. Ansible roles that read clean six months later, Terraform you can hand to a teammate, CI pipelines that fail loudly and recover gracefully, and GitOps when it earns its keep. Aimed at small teams and home labs — most of what works at FAANG scale is overkill here, and most of what works here would survive a step up. Just don't pretend a Compose file isn't enough when it is.
164 articles in this topic.
Featured posts
-
Garrul: The Audit Found My Rate Limiter
A security audit of Garrul, my Cloudflare Workers comment system, found 2 critical bugs. Both had the same root cause as one I had already fixed in June.
14 min read -
Home Assistant Backups That Actually Restore
Home Assistant disaster recovery: off-site backups, secrets handling, Z2M coordinator, restore drills that catch missing pieces.
13 min read -
Bots Ate 90% of My Worker Quota
A WordPress login bot burned 90% of my Cloudflare Workers free tier in two hours attacking a site that has never run PHP. Here's what actually stopped it.
13 min read -
Kaniko & Buildah: Daemonless Container Builds
Daemonless OCI image builds in CI without Docker-in-Docker risks. Kaniko vs Buildah compared, when each fits, and which one suits your pipeline.
10 min read -
3-2-1-1-0: The Backup Strategy That Survives Ransomware
3-2-1 backups aren't enough anymore. The 3-2-1-1-0 rule adds immutable & offline copies plus verified restores, here's how to implement it.
9 min read -
regclient: Container Image Lifecycle Without a Daemon
regctl, regbot, and regsync give you tag retention policies, registry replication, and manifest surgery, no Docker daemon required.
9 min read
All DevOps & Automation articles
- Garrul: The Audit Found My Rate Limiter
- Home Assistant Backups That Actually Restore
- Bots Ate 90% of My Worker Quota
- Kaniko & Buildah: Daemonless Container Builds
- 3-2-1-1-0: The Backup Strategy That Survives Ransomware
- regclient: Container Image Lifecycle Without a Daemon
- dbt-core for Self-Hosters: SQL With Tests, Without dbt Cloud
- Agentic Browsers: Browser-Use & Skyvern Reviewed
- Your Agent Doesn't Need a Shell
- Durable Objects: Stateful Serverless
- ArgoCD ApplicationSets: One Manifest, Many Clusters
- Multi-Arch Docker Builds With QEMU & buildx
- OPA & Rego: Policy as Code Beyond Kubernetes
- Convoy: Self-Hosted Webhook Delivery That Doesn't Drop Events
- Forgejo Actions: Self-Hosted GitHub-Style CI Without GitHub
- Skopeo: Container Image Surgery Without a Daemon
- Beszel: Server Monitoring Without the Prometheus Tax
- Crossplane vs Terraform for Home Lab
- OpenTofu in 2026: Where the Terraform Fork Stands
- Sigstore + Gitsign: Signed Commits Without GPG Pain
- Dragonfly: P2P Container Image Distribution at Scale
- Renovate vs Dependabot: Self-Hosted Dependency Bots
- Gitea Actions vs Woodpecker CI
- Borgmatic: Borg Backup, Done Right
- ClickHouse for Self-Hosted Logs
- AI Swarm Audited My 840-Post Blog
- OPA & Gatekeeper: Policy as Code
- Claude Code in a Homelab Workflow
- Kustomize vs Jsonnet for K8s Manifests
- Argo Rollouts vs Flagger Progressive Delivery
- Argo Workflows vs Tekton
- k3sup vs kubeadm for Homelab Clusters
- Dead Container Took Down Prod
- etcd vs Consul vs ZooKeeper Coordination
- SOPS + age: Secrets in Git
- Boundary vs Teleport
- Dify: Visual Agent Workflows
- Function Calling in Local LLMs
- MCP Servers: Tools for LLMs
- Garden vs Tilt vs Skaffold
- Compose Watch: Faster Dev Loops
- ko vs Jib vs Buildpacks
- Cosign Keyless: Sign Without Keys
- Docker Bake vs Compose Build
- Nerdctl vs Docker CLI
- Trivy vs Grype vs Docker Scout
- OpenTelemetry for Self-Hosters: Traces, Metrics, Logs Without the Datadog Bill
- K3s vs K0s vs MicroK8s: Lightweight Kubernetes for Home Labs
- Hoist: Label-Driven Docker Updates
- Incident Response for Self-Hosters
- Bash One-Liners Worth Remembering
- Compiling on Linux With Low RAM
- Restic vs Borg vs Kopia: Backups That Actually Deduplicate
- SBOMs and Supply Chain Security
- Authentik vs Authelia: SSO for Your Self-Hosted Stack
- Container Security: Scan and Sign Your Images Like You Mean It
- Loki vs ELK: Centralized Logging Without the RAM Tax
- Cockpit vs Webmin: Web Admin Panels That Don't Make You Cry
- Trivy + Cosign: Scan and Sign Your Images
- Prometheus + Grafana: Monitoring That Doesn't Lie to You
- Systemd Timers vs Cron: Scheduling That Doesn't Suck
- Gitea vs Forgejo vs GitLab CE: Self-Hosted Git
- Docker Networking Demystified
- EmDash: WordPress Done Right, Finally
- When to Use Structured Output (JSON Mode) in LLMs
- dotenv Files: The Mistakes That Leak Secrets
- Using AI to Find Security Bugs in Your Code
- Private Docker Registry with Harbor
- Alert Fatigue: Why Your Alerts Are Meaningless
- Docker Manager Showdown: Pick One
- Cloudflare Workers: Edge Without the PhD
- Caddyfile Patterns That Actually Work
- Prometheus Scrape Intervals: The Hidden Tradeoff
- Semantic Versioning: The Part Everyone Gets Wrong
- Let's Encrypt Without Certbot
- Grafana Dashboard Variables: One Dashboard for All
- HAProxy: Load Balancing Done Right
- Stop Living Dangerously on :latest Docker
- Cloudflare WAF: Free Tier Firewall Rules
- Distroless: How to Build Slim, Secure Containers
- .gitignore Entries Every Project Actually Needs
- Multi-Stage Docker Builds: Stop Shipping Your node_modules to Production
- Cloudflare DNS: Beyond Pointing Records
- make for Project Automation (It's Not Just for C Code)
- Vault vs Infisical: Secrets Management for Teams Who've Learned the Hard Way
- Git Hooks You Should Be Using Locally Right Now
- Traefik: Docker Routing with Labels
- Docker BuildKit: Stop Waiting for Your Images to Build
- Terraform vs Pulumi: Infrastructure as Code Without the YAML Nightmares
- Nginx Proxy Manager for Normal Humans
- CI Pipeline Caching: Speed Up Every Build
- Apache in 2026: It's Time to Move On
- Self-Hoster's Disaster Recovery: When Everything Goes Wrong at Once
- mTLS Explained: When Regular TLS Isn't Paranoid Enough
- Nginx: The Config That Makes Sense
- Appwrite: Your Own Firebase, Minus the Google Surveillance Subscription
- n8n + LLM: Building Automations That Actually Think
- Your First Open Source Contribution: Less Scary Than You Think, More Useful Than You Know
- Watchtower vs Diun: Automating Docker Updates Without Burning Your Stack
- Chaos Engineering: Break Things on Purpose Before They Break Themselves
- ArgoCD vs Flux: GitOps, When Your Git Repo Is the Source of Truth
- Restic vs Borg vs Kopia: Backup Tools for People Who've Lost Data Before
- Docker Logging: From "Where Did My Logs Go?" to Centralized Bliss
- HashiCorp Vault: Stop Hardcoding Secrets Like It's 2012
- Woodpecker CI vs Drone CI: Lightweight Pipelines for People Who Hate Waiting
- Lazy Docker & Dive: CLI Tools That Make Docker Less Painful
- Docker Compose Environment Variable Precedence
- Podman Quadlets: Running Containers Without the Docker Daemon (or Your Sanity)
- Nextcloud Advanced: Federation, Backups, and Making It Actually Performant
- Docker Security Hardening: 15 Things You're Doing Wrong Right Now
- MinIO vs SeaweedFS: Self-Hosted S3 Storage Without AWS Bills
- Open Source Security: Scanning Your Dependencies Before They Scan You
- Portainer vs Dockge: Managing Containers Without the Terminal
- DDoS Mitigation: Teaching Your Server to Say No Politely (Then Impolitely)
- Home Assistant + Node-RED: Automate Your Home Without Losing Your Mind
- Traefik vs Nginx Proxy Manager: Reverse Proxies for Humans
- Wiki.js with GitSync: Documentation That Lives in Version Control Like It Should
- Docker Compose vs Docker Swarm: When "Good Enough" Beats "Enterprise"
- Docker Resource Limits: Stop Letting Containers Eat Your RAM
- n8n vs Node-RED: Automate Everything Without Learning to Code (Much)
- Docker Compose Profiles: Run Only What You Need
- Stop Putting Passwords in Docker ENV
- Why the `latest` Docker Tag Is Lying to You
- Multi-Platform Docker Builds with buildx
- Docker Healthcheck Patterns That Actually Work
- Docker Container Labels: The Metadata You're Ignoring
- Why Docker Builds Are Slow: Layer Cache Explained
- The .dockerignore File You're Not Writing
- Understanding and Optimizing Docker’s daemon.json File
- Techniques for Writing Robust, Reliable Bash Scripts
- Optimize Ubuntu Logs: btmp Log Rotation
- Ansible: Task and Role Inclusions for Efficient Automation
- Docker Networking Essential Guide for All Skill Levels
- Docker Volume Mounts: Essential Flags
- How to Transfer docker Images Without a Repository
- Understanding CMD and ENTRYPOINT in Dockerfiles
- Copying Files Between Docker Containers and Host Machines
- Dockerfile: Differences Between COPY and ADD
- Docker Strategies for Load Balancing and Failover
- Docker Networking: Connecting to the Host from a Container
- Understanding Docker vs. Full Virtual Machines (VMs)
- Multiple Actions with a Single docker exec Call
- Executing Commands with Asterisks in Docker
- Tmux for Streamlining Dev Workflow
- Ansible vs. Terraform: Cloud Infrastructure Management
- WordPress, Docker, NGINX, and MySQL via Ansible
- DevOps Tools: Ansible vs. Puppet vs. Salt vs. Chef
- Optimizing Ansible for Faster Playbook Execution
- Automating Docker via Ansible
- Observability and Monitoring for Containers
- Docker vs Podman: Key Differences
- Understanding PostgreSQL Connection URIs
- Supercharge Your Homelab Monitoring with Zabbix
- Talos OS: API-Driven, Kubernetes-First OS
- Linux System Monitoring: Tools and Techniques
- SumGuy’s Guide to Linux Log Analysis
- Docker Compose: Orchestrating Multi-Container Applications
- Install & use Doxygen via Docker
- Docker Compose useful commands
- Access Docker socket via TCP
- When systemd swallows your service logs
- Bulk rename files in bash
- Bash for loops sequential counting
- Logrotate & Compression