A practical Docker image security checklist: minimal bases, non-root users, read-only filesystems, capability dropping, pinning, and scanning.
Self-Hosting
How to run your own servers, Docker stacks, and self-hosted services without losing weekends to config files.
Manage your dev environment with Nix shells (no Docker required)
Use Nix flakes and direnv for project-scoped dev environments without Docker. Define toolchains in flake.nix, share them, switch projects instantly.
Production Docker with Traefik v3.6: auto TLS, 30K RPS
Run Traefik v3 as a reverse proxy with Docker Compose. Automatic Let's Encrypt certificates, label-based routing, and security middleware on one VPS.
tmux 3.6a: scripted sessions, plugins, and persistence
Master scripted tmux sessions with plugins and persistence. Automate layouts, survive reboots, and recreate complex terminal environments instantly.
Wildcard SSL certificates with Let's Encrypt and DNS-01
Wildcard SSL certs from Let's Encrypt use DNS-01 or the new DNS-PERSIST-01 challenge. Certbot and acme.sh automate it, systemd timers renew it.
Btrfs vs ZFS: which filesystem protects your data better?
Compare Btrfs and ZFS for data protection: checksumming, RAID, snapshots, compression, and speed. ZFS for NAS, Btrfs for single-disk desktops.
Botmonster Tech




