linuxcore.dev

Linux Infrastructure,
Built to Last

Practical guides on homelab automation, AWS hybrid setups, and building with Astro — written by a Linux infrastructure engineer who runs this stack in production every day.

AnsibleDockerProxmoxOllamaGrafanaTerraformAWSAstro

root@linuxcore:~# ls -lt articles/

coolify self-hosted-paas

Coolify on Your Homelab: Ditch Vercel and Heroku for Good

Step-by-step guide to deploying Coolify on Proxmox or bare-metal Linux, setting up push-to-deploy, and routing traffic with Caddy or Traefik. Self-hosted PaaS that actually works.

astro sveltekit

SvelteKit vs Astro: Which SSG Actually Performs Better in Production?

We benchmarked Astro vs SvelteKit across Cloudflare Pages, self-hosted nginx, and real blog workloads. Here's what the Lighthouse scores actually showed.

fragnesia linux-security

Fragnesia: How to Check and Patch the Linux Privilege Escalation Exploit on Your Homelab

Fragnesia is a Linux kernel LPE exploit hitting homelabs hard. Here's how to check your kernel, patch via apt/dnf/pacman, and apply stopgap mitigations on Proxmox, Ubuntu, and Debian.

docker docker-compose

Docker Compose Homelab Mega-Stack: 20 Self-Hosted Services, One File

Production-ready Docker Compose: AI, monitoring, security, media, and networking — 20 services configured, every port documented, ready to deploy.

dirty-frag-linux-vulnerability linux-privilege-escalation-no-patch

Dirty Frag: Linux Root Privilege Escalation With No Patch Yet — Homelab Mitigation Guide

Dirty Frag is an unpatched Linux LPE vulnerability. Learn which kernels are affected, why the broken embargo matters, and how to harden your homelab now.

dirtyfrag linux vulnerability linux local privilege escalation patch

Dirtyfrag: How the Universal Linux LPE Affects Your Homelab and How to Patch It

Learn how the Dirtyfrag Linux local privilege escalation vulnerability affects your homelab and follow this step-by-step guide to patch Proxmox, Ubuntu, and Debian.

[digital product]

Ansible Homelab Bundle

25 production-ready Ansible files across five roles: base hardening, Docker CE, SSH/kernel security with CrowdSec, Prometheus/Grafana monitoring, and Ollama with automatic GPU detection. Run one command and your server is configured — no copy-pasting from blog posts.

25Ansible files
5roles
5playbooks

Get new guides in your inbox

New articles and scripts when they publish — no spam, no digest noise. One email per release.

No spam. Unsubscribe any time.