Linux Homelab
Practical infrastructure guides — Ansible, Docker, Proxmox, self-hosted AI, monitoring, security, and backup. Everything tested on real hardware.
-
Linux Zswap Homelab Guide: Batched Writeback & Tuning
Optimize Linux Zswap in your homelab. Learn how the new batched writeback I/O patch works, zswap vs zram, and how to overcommit Proxmox RAM.
-
Let's Encrypt 64-Day Certificates: Homelab SSL Automation
Prepare your Caddy, Traefik cert renewal pipelines and homelab SSL automation for Let's Encrypt 64-day certificates before manual tasks break.
-
OpenSSH 10.6 Update: Homelab SSH Hardening
What OpenSSH 10.6 changes for a homelab, from LZ77 compression and post-quantum keys to WarnWeakCrypto, plus a hardened sshd_config and fail2ban setup.
-
Debian Rsync CVE: Upgrading to 3.5.0 in Your Homelab
rsync 3.5.0 fixes 33 security issues and Debian 13 shipped it as a security update. What changed, which behaviour can break backups, and how to update.
-
Linux 7.4 Steal Governor: What It Means for Proxmox VMs
The steal governor queued for Linux 7.4 steers guest tasks away from contended vCPUs. What it does, its status, how to measure steal time today, and Proxmox fixes.
-
Samba 4.25 SMB3 Persistent Handles: Homelab NAS Setup
Samba 4.25 adds experimental SMB3 persistent handles. What they do, the exact smb.conf settings, the locking and performance trade-offs, and client mounts.
-
Self-Hosting Behind CGNAT: Tunnels and Relays
Master self-hosting behind cgnat. Expose your cgnat homelab securely without public IPv4 using Cloudflare Tunnels, WireGuard VPS relays, and IPv6.
-
Ubuntu Rust Coreutils: Test Your Homelab Scripts
Since Ubuntu 25.10, and in 26.04 LTS, coreutils come from the Rust uutils project. What changed, a real bug it caused, how to test scripts and how to switch back.
-
X11 Clipboard Security: Sandbox Linux Zoom With Flatpak
Proprietary apps like the Linux Zoom client proactively snoop your clipboard data. Learn how to fix X11 clipboard security and Flatpak sandbox Zoom.
-
Forgejo RCE Vulnerability: Patch Your Homelab Server Now
Forgejo 16.0.4 and 15.0.8 fix a critical RCE through malicious template repositories. Who is exposed, how to update Docker and binary installs, and hardening.
-
ZFS vs Btrfs vs Stratis: Best Homelab NAS Filesystem?
Choosing a homelab NAS filesystem? This guide compares ZFS, Btrfs, and Stratis on RAID, snapshots, data integrity, and performance for backups.
-
Trusting Trust Attacks: Secure Your Linux Homelab
Learn to mitigate the 'Trusting Trust' supply chain attack on your Linux homelab. Practical steps for binary verification and secure build environments.
-
Proxmox VE on ARM64: What Works in a Homelab
Proxmox VE 9.2 officially supports ARM64 with its own ISO. Which hardware is supported, why Raspberry Pi and RK3588 boards are not, and what that means for a homelab.
-
Bor: Self-Hosted Linux Policy Management for Homelabs
Bor is a self-hosted policy manager for Linux desktops: Firefox, Chrome, KDE Plasma and Flatpak policies pushed over mTLS. Setup, enrollment and limits.
-
Fixing SQLite WAL Mode Reader Locks in Your Homelab
Why SQLite WAL files grow and 'database is locked' errors appear in self-hosted apps like Uptime Kuma, what really causes them, and safe fixes.
-
Self-Hosting on a Static IP: The No-Nonsense Homelab Guide
A practical guide to exposing homelab services. Learn to configure static IPs, dynamic DNS, and secure remote access with WireGuard or Tailscale.
-
Self-Host Your Email in 2026: A Practical Homelab Guide
A no-nonsense guide to setting up a self-hosted email server in your homelab. Learn to configure Postfix, Dovecot, and Rspamd for secure, reliable mail.
-
CVE-2026-64600: Patch Your Homelab XFS Before This LPE
A critical local privilege escalation vulnerability (CVE-2026-64600) affects Linux kernels using XFS. Here's how to check your homelab and patch it.
-
Mitigating 400+ Linux Kernel CVEs in Your Homelab
A deluge of Linux kernel CVEs hit the wire. Learn a practical strategy to assess, prioritize, and automate kernel security patching for your homelab.
-
MicroVMs in Proxmox: True Homelab Isolation, Simply
Running microVMs in Proxmox VE with the experimental pve-microvm package: QEMU microvm guests from OCI images, what it gives you over LXC, and the risks.
-
Train a Gen AI Model on an Old Linux Desktop (Low VRAM)
Stop just running models. Learn to train and fine-tune your own generative AI on a Linux desktop with limited VRAM. A practical guide for your homelab.
-
AWS S3 Homelab Backups: Automated and Under €5/Month
Back up your homelab to AWS S3 and Glacier (Proxmox VMs, Docker volumes, Nextcloud) using restic with automated scheduling and real cost numbers.
-
Linux Homelab Security Hardening: Complete Checklist (2026)
Harden any Ubuntu or Debian server in under an hour: SSH lockdown, UFW, fail2ban, CrowdSec, and automatic updates, every command tested, reason explained.
-
Coolify on Your Homelab: Ditch Vercel and Heroku for Good
Deploy Coolify on Proxmox or bare-metal Linux, set up push-to-deploy, and route traffic with Caddy or Traefik. Self-hosted PaaS that actually works.
-
Debian 13.5 Trixie: What Homelab Admins Should Know
Debian 13.5 is out with CVE patches and updated packages. Here's the safe update workflow for homelab servers, plus whether Trixie beats Ubuntu LTS.
-
Fragnesia: Check and Patch This Linux LPE on Your Homelab
Fragnesia (CVE-2026-46300) is a Dirty Frag follow-up giving local root through ESP-in-TCP. Fixed kernels, patching Proxmox and Debian, and mitigations that work.
-
Docker Compose Homelab Stack: 20 Services, One File
Production-ready Docker Compose: AI, monitoring, security, media, and networking, 20 services configured, every port documented, ready to deploy.
-
Dirty Frag: Unpatched Linux LPE, Homelab Mitigations
Dirty Frag mitigation without a patched kernel: block the esp4, esp6 and rxrpc modules, why restricting user namespaces is not enough, and what the stopgap breaks.
-
Dirtyfrag: How the Universal Linux LPE Hits Your Homelab
Dirty Frag (CVE-2026-43284 and CVE-2026-43500) gives local root via the kernel ESP and RxRPC modules. Fixed versions, patching Proxmox, Debian and Ubuntu, and the stopgap.
-
Podman Rootless and the Copy Fail Exploit: What to Know
Copy Fail (CVE-2026-31431) is a kernel bug, not a Podman one. What it does inside rootless Podman containers, why it stops at container root, and how to limit it.
-
Proxmox VE Homelab Setup: Install and Configure (2026)
Install Proxmox VE 8 on a mini PC, configure storage, networking, and GPU passthrough, then deploy your first VMs and LXC containers, complete 2026 guide.
-
Your Container Is Not a Sandbox: Use MicroVMs Instead
Docker containers share the host kernel, learn why that matters, and how microVMs like Firecracker give your homelab real isolation without VM overhead.
-
AEAD Socket Flaw (Copy Fail): Patch Your Homelab Kernel
CVE-2026-31431 (Copy Fail) in the kernel's algif_aead: who is affected, fixed kernel versions, patching Debian, Ubuntu, Fedora, Arch and Proxmox, and the module mitigation.
-
CachyOS vs Ubuntu 26.04 vs Fedora 44 for Homelab Servers
Comparing CachyOS, Ubuntu 26.04 LTS, and Fedora 44 for homelab server use. Real trade-offs on stability, containers, and whether benchmark wins matter.
-
Linux Kernel CVE Disclosure Is Broken: What to Know
The Linux kernel CVE process has a critical gap. Learn how homelab admins can protect their servers with practical mitigations and smart update schedules.
-
Stratis on Linux: ZFS-Like Storage, Less Complexity
Practical guide to Stratis storage on Linux: compare Stratis vs ZFS vs Btrfs for homelab NAS and VM storage, plus Stratis 3.9 encryption setup.
-
Best Mini PC for a Homelab Server in 2026
Which mini PC runs Proxmox, Docker, Ollama, and a full homelab stack without killing your electricity bill? N100, N305, Ryzen 7, and MS-01, honestly compared.
-
Self-Hosting Forgejo: A GitHub-Free Git Server
Deploy a self-hosted Git server with Forgejo on Docker Compose, reverse proxy via Caddy, SSH access, and optional Cloudflare Tunnel for remote reach.
-
Ubuntu's AI Kill Switch: Disable Canonical AI Features
What Canonical actually announced about AI in Ubuntu (opt-in previews from 26.10, removal of snaps as the kill switch), what a server runs today, and how to audit it.
-
10GbE on a Budget: USB Adapters for Your Homelab
USB 10GbE for mini PC homelabs: the Realtek RTL8159, the 20 Gbps USB port it needs, Linux driver and firmware, Proxmox setup, and when PCIe or Thunderbolt is better.
-
WireGuard vs Tailscale for Homelab Remote Access (2026)
Secure remote access to your homelab without port forwarding. Set up WireGuard and Tailscale, understand when to use each, and lock down your Linux servers.
-
n8n + Ollama: An AI Automation Agent on Your Server
Connect local LLMs to real workflows: auto-summarise RSS feeds, analyse logs with AI, send Telegram alerts, all self-hosted, private, and free.
-
K3s on Your Homelab: Lightweight Kubernetes That Works
Deploy a K3s Kubernetes cluster on your homelab. Single node to multi-node with Traefik ingress, Longhorn storage, and real workloads running in minutes.
-
Grafana + Prometheus Homelab Monitoring in 30 Minutes
Set up Prometheus, Grafana, Node Exporter, cAdvisor, and Alertmanager with Docker Compose. Real dashboards, real alerts, zero cloud dependency.
-
Docker Compose for Homelab: What It Is and How to Use It
A practical guide to Docker and Docker Compose for self-hosters: what containers really are, how Compose orchestrates stacks, with Immich and Jellyfin examples.
-
Immich vs PhotoPrism: Self-Hosted Google Photos Compared
Immich vs PhotoPrism for self-hosters: resource requirements, features, Docker Compose examples, and honest recommendations based on your hardware tier.
-
Ansible for Homelabbers: Automate From One Playbook
Learn how to provision your entire homelab stack, Docker, Proxmox, monitoring, security, from a single Ansible playbook. Includes real working roles.
-
Run Local AI on Linux: Ollama + Open WebUI (2026)
Install Ollama on Debian/Ubuntu, configure GPU passthrough, add Open WebUI with Docker, and expose it via Tailscale. Tested on real homelab hardware.
[digital product]
Ansible Homelab Bundle
25 production-ready Ansible files — base hardening, Docker CE, SSH security with CrowdSec, Prometheus/Grafana monitoring, and Ollama with automatic GPU detection. Skip the setup hours.
Get the Bundle — €29 →