Zswap vs Zram Last year I blogged about using Zram for VMs [1]. That setup is still working well for VMs and for phones and laptops with no swap device. I have just read Chris Down’s insightf…| etbe - Russell Coker
USB-LTE4G-EU is Reliable 4G LTE USB Modem and delivers reliable, cost-effective, and energy-efficient cellular connectivity for IoT, M2M, industrial automation, telemetry, POS terminals, remote monitoring, and embedded systems. Key Features USB-LTE4G-EU is specifically designed for European LTE networks and offers: Built for Industrial and IoT Deployments The USB-LTE4G-EU is optimized for applications requiring dependable wireless […]| olimex
Occasionally, I will forget to link something from the mailing list in this post. To see my full mailing list activity (patches, reviews, and reports), you can view it on lore.kernel.org. Linux kernel patches Build errors: These are patches to fix various build errors that I found through testing different configurations with LLVM or were exposed by our continuous integration setup. The kernel needs to build in order to be run :)| Nathan Chancellor
Falco is an open-source runtime security tool for Linux systems, built for cloud-native environments. It monitors the system in real time to spot unusual| Help Net Security
We break down the primary attack vectors in containerized environments: exposed secrets, privilege misconfigurations, API compromise, and supply chain attacks.| Securelist
What are the main risks for container environments: vulnerabilities, supply chain attacks, configuration errors; how to improve container security and how Kaspersky Container Security with the KIRA AI assistant can help.| Securelist
When we first announced the transition to Plasma Wayland, one of Martin's slides from stated, "It's done when it's done!"| blog.davidedmundson.co.uk
José Marchesi and the GCC-BPF developers opened the BPF track at the 2026 Linux Storage, File [...]| LWN.net
Disclaimer: I will be using the name/term vim in this blog post, but I actually mean any command-line editor based on or inspired by vi, or "vi-style editors." This includes the original vi, nvi (which IIRC was the basis of the vi that comes with the various BSDs), elVIs …| R.L. Dane
When I was a kid, a new computer cost the equivalent of $3,000 in today's money, and a five year old computer was basically a dinosaur. Nowadays you can get a brand new computer for $200 or less, and a ten-year-old computer can still be a viable daily-driver. You …| R.L. Dane
... ... ... Because it's cool! But first, a brief history of writing in the digital age! Some History, or: I have ADHD and we're all aboard the unnecessary detail traaaaaainnnn!...... The very first computer I had at home was an Apple ][+ that my mom rented for a computer class in university. The …| R.L. Dane
In the last post, we introduced the relationship between the components in the Docker system, and in this post, we’ll discuss the attack surfaces.| Blog
For this year’s (2026) Pwn2Own Berlin, I tried to find vulnerabilities in Docekr but came up with nothing. This post simply documents my research on Docker’s system implmentation, since it is quite interesting.| Blog
We’ve always found strace useful but somewhat hard to work with. Its output is often inscrutable, it’s hard to follow subprocesses or threads, and if you wan...| Jane Street Blog
A new local privilege escalation vulnerability in Linux, dubbed CIFSwitch, has raised alerts among system administrators and security teams. The flaw affects the interaction between the kernel’s CIFS/SMB client and the cifs-utils user-space tools package, and can allow an unprivileged user to gain root execution on certain configurations. The case is relevant because this is […]| System Administration
Artificial intelligence has turned documents into everyday working fuel. PDFs with reports, Word contracts, spreadsheets, presentations, screenshots, audio files, web pages and even YouTube videos increasingly end up inside models such as Claude, ChatGPT, Gemini or Copilot. The problem is that many companies and users still upload them “as they are”, without thinking about a […]| System Administration
AlmaLinux has released AlmaLinux OS 9.8 “Olive Jaguar” and AlmaLinux OS 10.2 “Lavender Lion” at the same time, marking the first simultaneous stable release in the project’s history. The distribution, widely used in server environments and as a community-driven alternative within the Enterprise Linux ecosystem, uses this launch to reinforce its core message: stability, practical […]| System Administration
For more than two decades, running your own mail server has usually meant assembling the same familiar stack: Postfix for SMTP, Dovecot or Courier for IMAP and POP3, SpamAssassin or Rspamd for filtering, OpenDKIM for signing, certificate automation, monitoring scripts and plenty of operational patience. The result can be extremely reliable, but it becomes harder […]| System Administration
Proxmox VE 9.2 is now available, and it arrives with the kind of update that is especially relevant for system administrators, platform teams and| System Administration
Having a second pathway to press the default mod / super key is a nice choice to have available.| From Development to Production on Nick Janetakis
This could happen if you've fat fingered your password too many times, we'll go over how to reset it and configure the limits.| Nick Janetakis
Arch Linux| archlinux.org
Heap buffer overflow in the iSCSI target CHAP authentication code: the BASE64 branch of chap_server_compute_hash() passes attacker-controlled input directly to chap_base64_decode() without a length check, overflowing the kzalloc(digest_size) destination buffer by up to 79 bytes before any password validation occurs.| ahossu.ro
This page is a stub.| Tao of Mac
SSH Labs| blog.compass-security.com
The Linux desktop in 2026 is more diverse than ever. Whether you’re a newcomer, a power user, a gamer, or […] The post Linux Mint vs Arch vs Ubuntu vs Bazzite vs Fedora – Best Distro for 2026 appeared first on Peq42.| Peq42
This post is an overview of the different tunneling options available in OpenSSH.| /dev/posts/
Using dm-crypt and auto-mounting a drive without storing the key on the local disk| With Blue Ink
Three effective tips to stop bots that won't harm you in the process| With Blue Ink
This is an article quite some time in the making. I’ve written 3 or 4 drafts of it over the last 4 months, looking for just the right thing to say. After I wrote the initial draft of this one, it sat in the drafts for another 2 months before I really finished it. In the end, I’ve decided that being straightforward is the best way to go, so here it is:| Insane Rambles About Technology
How eBPF-based rootkits evade traditional detection and what Volatility 3 can actually recover from a memory dump.| Andrea Fortuna
How the latest Volatility 3 plugins are finally breaking down the silos between memory analysis and encrypted network traffic decryption.| Andrea Fortuna
Hotspot is a standalone GUI designed to provide a user-friendly interface for analyzing performance data. It takes a perf.data file, parses and evaluates its contents, and presents the results in a visually appealing and easily understandable manner. Our goal with Hotspot is to offer a modern alternative to perf report, making performance analysis on Linux […]| KDAB
Dylan, useful idiot with commit access, pushed age verification PRs to systemd, Ubuntu & Arch, got 2 Microslop employees to merge it, called it 'hilariously pointless' in the PR itself, then watched Lennart personally block the revert. Unpaid compliance simp.| Sam Bent
Hardening Docker doesn’t have to be complex. Learn how to secure your home lab by limiting privileges, locking filesystems, and managing secrets properly.| The Unknown Universe
I updated my Framework 13 to Fedora 42 about two weeks ago, just before the final release. It has been pretty solid! This evening, I went to start up my VPN (I use NordVPN, FWIW). No luck. Just no …| The lost outpost
AlmaLinux ha publicado de forma simultánea AlmaLinux OS 9.8 “Olive Jaguar” y AlmaLinux OS 10.2 “Lavender Lion”, dos nuevas versiones estables que llegan el mismo día por primera vez en la historia del proyecto. La distribución, muy utilizada en entornos de servidor y como alternativa comunitaria dentro del universo Enterprise Linux, refuerza con este lanzamiento […]| Administración de Sistemas
Linux devices are heavily embraced across industries. This is due to their unparalleled flexibility, stability, and cost-effectiveness. Being an open-source system, Linux can be customized to fit any use case, from kiosk devices to dedicated operation machines. This adaptability meets scalability through Linux MDM enrollment, enabling organizations to deploy hundreds or thousands of devices. Each […] The post How to enroll Linux devices in MDM first appeared on Scalefusion.| Scalefusion
Yocto is powerful, but for many embedded Linux projects it's overkill. Here's when to use it, when to skip it, and what to use instead.| sigma star gmbh
We have updated Flathub's LLM policy to explicitly disallow AI usage for both the submission process and applications being submitted. https://github.com/flathub-infra/documentation/commit/992f57b30de98ddbd5e80959e9672998c83c8c97 I've had some reservations about it, so the wording before that commit was relatively milder. I know it's an unpopular opinion on the Fediverse, but I do think LLMs are inevitable, and the reality is that you can expect less organically grown code as time goes on. I ...| treehouse.systems
The NNN Stack: NixOS + Niri + Noctalia-shell. Declarative. Scrollable. Beautiful.| the-nnn-stack.github.io
Google CTF challenge with ebpf, kernels, linux-security-modules (LSMs), race-conditions and file descriptors. Some meditations on the Soham Parekh fiasco of 2025| Shiv After Dark
The post Linux, Unix, Windows, and OS/2: How Demand Beat Design appeared first on Planet Mainframe.| Planet Mainframe
The post Linux and the Mainframe: A Platform Relationship Coming Into Its Own appeared first on Planet Mainframe.| Planet Mainframe
When configuring a new device, achieving an acceptable Lynis hardening score is a challenge most practitioners are familiar with. Navigating its recommendations often requires significant background knowledge, leaving administrators without clear guidance on which settings are vulnerable and how to remediate them effectively. We believe that security hardening should be insightful and accessible, a philosophy […]| Insinuator.net
Hardening a Linux client system to an acceptable degree is a time-consuming process, one that demands familiarity with a broad set of configuration parameters, framework recommendations, and the reasoning behind each control.| Insinuator.net
The newly disclosed Linux LPE flaw “CIFSwitch” allows low-privileged users to gain root access via weaknesses in the kernel CIFS subsystem.| Cyber Security News
eBPF (extended Berkeley Packet Filter) is a technology that lets you run sandboxed programs in the Linux kernel without changing kernel source code or loading kernel modules. It powers tools like Cili...| linkconfig - Systems Administration and Networking
Linux bonding (NIC teaming) combines multiple physical NICs into a single logical interface. Different bonding modes provide active/standby failover, round-robin load balancing, or LACP 802.3ad dynami...| linkconfig - Systems Administration and Networking
nftables is the modern Linux firewall framework that replaces iptables, ip6tables, arptables, and ebtables with a single unified tool. It uses a cleaner syntax, supports sets and maps for efficient ma...| linkconfig - Systems Administration and Networking
Linux network namespaces provide complete network stack isolation: each namespace has its own interfaces, routing tables, firewall rules, and sockets. They are the foundation of Docker containers, Kub...| linkconfig - Systems Administration and Networking
SR-IOV (Single Root I/O Virtualization) allows a single physical NIC to present multiple virtual functions (VFs) to the hypervisor. Each VF is assigned directly to a VM or container, bypassing the sof...| linkconfig - Systems Administration and Networking
Multipath TCP (MPTCP) is an extension to TCP that allows a single TCP connection to use multiple network paths simultaneously. On Linux (kernel 5.6+), MPTCP enables bandwidth aggregation across multip...| linkconfig - Systems Administration and Networking
MACVLAN and IPVLAN are Linux kernel features that create virtual network interfaces on top of a physical NIC. Unlike a Docker bridge network (NAT), containers using MACVLAN/IPVLAN appear directly on t...| linkconfig - Systems Administration and Networking
Open vSwitch (OVS) is a production-quality multilayer virtual switch designed for use in hypervisors, containers, and network function virtualization. It supports VLAN trunking, bonding, LACP, OpenFlo...| linkconfig - Systems Administration and Networking
Linux tc (traffic control) with the HTB (Hierarchical Token Bucket) qdisc provides fine-grained bandwidth shaping and QoS on Linux routers and servers. You can guarantee bandwidth for VoIP and gaming,...| linkconfig - Systems Administration and Networking
Longhorn is an open-source distributed block storage system for Kubernetes, developed by Rancher/SUSE. It provides replicated persistent volumes across multiple nodes, snapshots, backups to S3/NFS, an...| linkconfig - Systems Administration and Networking
Cilium is a Kubernetes CNI plugin that uses eBPF (extended Berkeley Packet Filter) to implement networking, load balancing, and security policies entirely in the Linux kernel. It offers superior perfo...| linkconfig - Systems Administration and Networking
Cloud-Init is the industry standard for cross-platform cloud instance initialization. It runs at first boot to configure hostname, users, SSH keys, packages, files, and arbitrary scripts. All major cl...| linkconfig - Systems Administration and Networking
Flux is a GitOps operator for Kubernetes that keeps your cluster synchronized with configuration stored in Git. Unlike ArgoCD's UI-centric approach, Flux is purely Kubernetes-native (custom resources)...| linkconfig - Systems Administration and Networking
ArgoCD is a declarative GitOps continuous delivery tool for Kubernetes. It monitors your Git repository for changes to Kubernetes manifests and automatically syncs the cluster to match the desired sta...| linkconfig - Systems Administration and Networking
OPA Gatekeeper is a Kubernetes admission controller that enforces custom policies written in Rego (OPA's policy language). Every time a resource is created or updated in Kubernetes, Gatekeeper evaluat...| linkconfig - Systems Administration and Networking
Helmfile lets you declare all your Helm chart releases in a single YAML file, manage them across multiple environments, and apply them all with a single command. It adds missing features to Helm: envi...| linkconfig - Systems Administration and Networking
Kustomize is a Kubernetes-native configuration management tool built into kubectl. Instead of templating YAML (like Helm), Kustomize works by layering patches and overlays on top of base YAML files —...| linkconfig - Systems Administration and Networking
PiKVM is an open-source KVM (Keyboard/Video/Mouse) over IP solution built on a Raspberry Pi. It gives you BIOS-level access to a server from any browser — before the OS loads, during crashes, and for...| linkconfig - Systems Administration and Networking
TrueNAS SCALE is a free, open-source NAS operating system based on Debian Linux with ZFS storage, Kubernetes-based app deployment, Active Directory integration, and enterprise-grade data protection fe...| linkconfig - Systems Administration and Networking
PCIe passthrough in Proxmox VE allows a virtual machine to use a real GPU directly, bypassing the hypervisor for near-native graphics performance. This is commonly used for gaming VMs, ML workloads, a...| linkconfig - Systems Administration and Networking
Home Assistant is an open-source home automation platform that keeps your smart home local — no cloud dependency. Combined with Zigbee2MQTT and a USB Zigbee coordinator (SONOFF Zigbee 3.0, ConBee II),...| linkconfig - Systems Administration and Networking
Proxmox Backup Server (PBS) is a dedicated, open-source backup solution for Proxmox VE environments. It stores VM and LXC backups with client-side deduplication and compression, supports incremental b...| linkconfig - Systems Administration and Networking
A Raspberry Pi cluster is an affordable, low-power platform for learning Kubernetes, Ansible, distributed storage, and HA patterns. Pi 4B (4GB) or Pi 5 nodes consume 3-8W each, run real Linux, and sup...| linkconfig - Systems Administration and Networking
10 Gigabit Ethernet dramatically improves homelab performance for NFS, iSCSI, VM live migration, and backup jobs. Used enterprise hardware makes 10GbE accessible at low cost — SFP+ DAC cables, second-...| linkconfig - Systems Administration and Networking
Wake-on-LAN (WoL) lets you power on a machine that is turned off by sending a "magic packet" to its network interface. This is invaluable for homelabs where you want servers available on demand withou...| linkconfig - Systems Administration and Networking
IPMI (Intelligent Platform Management Interface) and vendor implementations like Dell iDRAC, HP iLO, and Supermicro IPMI provide out-of-band server management. You can power on/off, access the console...| linkconfig - Systems Administration and Networking
Network UPS Tools (NUT) is an open-source framework for monitoring UPS (Uninterruptible Power Supply) devices over USB, serial, or SNMP. It notifies your servers of power events and triggers safe shut...| linkconfig - Systems Administration and Networking
Remote Desktop Services (RDS) is the Windows Server platform for delivering virtual desktops, RemoteApp programs, and session-based desktops to users. A basic RDS deployment uses three roles: RD Sessi...| linkconfig - Systems Administration and Networking
Windows Server Storage Spaces is a software-defined storage feature that pools physical disks into resilient virtual disks. It supports mirroring, parity, and three-way mirror layouts, hot spares, and...| linkconfig - Systems Administration and Networking
Windows Admin Center (WAC) is a free, browser-based management tool for Windows Server, Windows 10/11, and clusters. It replaces the need to RDP into servers for routine tasks like storage management,...| linkconfig - Systems Administration and Networking
Windows Server Data Deduplication identifies and removes duplicate chunks of data across files on a volume. For file servers with many similar files, VM stores, or backup targets, deduplication often...| linkconfig - Systems Administration and Networking
Fine-Grained Password Policies (FGPP) let you apply different password policies to different user groups in Active Directory. Service accounts can have 60-character non-expiring passwords, administrat...| linkconfig - Systems Administration and Networking
FRRouting (FRR) is an open-source routing software suite for Linux that supports BGP, OSPF, IS-IS, RIP, PIM, and MPLS. It provides a Cisco/Juniper-like CLI (vtysh) and is used in production by Cloudfl...| linkconfig - Systems Administration and Networking
NetBox is the industry-standard open-source IPAM (IP Address Management) and DCIM (Data Center Infrastructure Management) tool. It models your physical and virtual infrastructure: racks, devices, inte...| linkconfig - Systems Administration and Networking
Unbound is a validating, recursive, caching DNS resolver. Unlike Pi-hole (which just blocks) or Technitium (which can do both), Unbound focuses on doing one thing perfectly: resolving DNS queries secu...| linkconfig - Systems Administration and Networking
PowerDNS Authoritative Server stores DNS zones in a relational database (MySQL, PostgreSQL, SQLite) instead of flat files. This enables programmatic zone management via the REST API, dynamic DNS updat...| linkconfig - Systems Administration and Networking
Response Policy Zones (RPZ) are a DNS mechanism for blocking or redirecting DNS queries at the resolver level. Unlike Pi-hole which modifies a hosts file, RPZ is a standard DNS zone format that any co...| linkconfig - Systems Administration and Networking
Knot DNS is a high-performance authoritative DNS server developed by CZ.NIC, the Czech internet registry. It is optimized for serving large numbers of zones with minimal latency, supports DNSSEC signi...| linkconfig - Systems Administration and Networking
SPF, DKIM, and DMARC are three complementary email authentication standards that protect your domain from email spoofing and phishing. Together they tell receiving mail servers which IPs are authorize...| linkconfig - Systems Administration and Networking
DNSSEC (DNS Security Extensions) adds cryptographic signatures to DNS records, allowing resolvers to verify that responses are authentic and have not been tampered with. This guide covers signing auth...| linkconfig - Systems Administration and Networking
Semaphore UI is a lightweight, self-hosted alternative to AWX for running Ansible playbooks, Terraform, and OpenTofu through a web interface. It is significantly easier to deploy than AWX (single bina...| linkconfig - Systems Administration and Networking
Pulumi is an infrastructure-as-code platform that lets you define cloud and on-premises infrastructure using TypeScript, Python, Go, C#, or Java instead of domain-specific languages like HCL. Your inf...| linkconfig - Systems Administration and Networking
Ansible AWX is the open-source upstream project for Red Hat Ansible Automation Platform. It provides a web UI, REST API, and RBAC system for managing Ansible playbooks, inventories, credentials, and s...| linkconfig - Systems Administration and Networking
Terragrunt is a thin wrapper around Terraform that adds features for keeping your Terraform code DRY (Don't Repeat Yourself), managing remote state automatically, and orchestrating dependencies betwee...| linkconfig - Systems Administration and Networking
Concourse CI is a container-native CI/CD system where everything is a pipeline, everything runs in containers, and configuration is fully declarative YAML. It has no plugins — every interaction with e...| linkconfig - Systems Administration and Networking
Act is an open-source tool that runs your GitHub Actions workflows locally using Docker. Instead of pushing commits and waiting for GitHub Actions to run, you test your CI workflows instantly on your...| linkconfig - Systems Administration and Networking
HashiCorp Vault is an open-source secrets management platform that stores and controls access to tokens, passwords, certificates, API keys, and encryption keys. It provides dynamic secrets, encryption...| linkconfig - Systems Administration and Networking
Earthly is a build tool that merges Makefile-style targets with Dockerfile-style layers. Builds run in containers, making them reproducible across developer machines and CI environments. Earthly integ...| linkconfig - Systems Administration and Networking
Dagger is a programmable CI/CD engine that lets you write pipelines in Go, Python, or TypeScript using a type-safe SDK. Pipelines run in containers and are fully portable — the same code runs locally...| linkconfig - Systems Administration and Networking
Tekton is a Kubernetes-native CI/CD framework that defines pipelines as custom Kubernetes resources. Tasks, pipelines, and triggers are all CRDs, making Tekton infrastructure-as-code by default. It is...| linkconfig - Systems Administration and Networking
Forgejo is a soft-fork of Gitea, created after concerns about Gitea's governance model. It is fully compatible with Gitea and provides the same features — Git hosting, issue tracking, pull requests, G...| linkconfig - Systems Administration and Networking
Portainer is a web-based container management UI for Docker, Docker Swarm, and Kubernetes. The free Community Edition covers most homelab needs, while Portainer Business Edition (free for up to 3 node...| linkconfig - Systems Administration and Networking
Woodpecker CI is a community-maintained fork of Drone CI that integrates seamlessly with Gitea, Forgejo, GitHub, and GitLab. It uses a simple YAML pipeline format and runs every build step in Docker c...| linkconfig - Systems Administration and Networking