DevOps. Self-hosted. Security.
RSS FeedNotes on DevOps, infrastructure, self-hosting and cybersecurity — practical guides from real-world operations.
Read the posts below or head over to the About page.
Recent Posts

Wazuh: enrolling agents, turning on FIM and rootcheck for Linux and Windows (part 2/6)
Part 2 of the Wazuh series: enrolling agents on Ubuntu and Windows — automatically via authd or manually with keys — enabling syscheck FIM with realtime and whodata, plus rootcheck, a CIS SCA policy and agent groups. The real question: how to get signal instead of a stream of alerts about benign changes.

Wazuh from scratch: standing up an open-source SIEM/XDR in one evening (part 1/6)
Kicking off a series on Wazuh, the free open-source SIEM/XDR. Part one is installation only: manager, indexer and dashboard via Docker Compose, TLS certificates, first login, and an honest look at how single-node differs from production.

Cilium Tetragon: eBPF runtime security that blocks, not just logs
Falco and most eBPF security tools can only alert after the fact. Tetragon, Cilium's runtime security engine, can do more — kill a process synchronously in the kernel before the syscall even returns. We break down the TracingPolicy anatomy, enforcement risks, and the safe rollout pattern: audit first, Sigkill later.

containerd 1.x is done: what breaks moving to containerd 2.0 before Kubernetes 1.36
Kubernetes 1.35 is the last release that still supports containerd 1.x. We break down what actually changes in config.toml v3, the CRI plugin, and CDI for GPUs, and how to roll containerd 2.0 out node by node with zero downtime.