Categories

Jacar mascot — a curious laptop A friendly laptop whose eyes follow your cursor.

Madrid · ES/EN · async-first

DevOps &

Honest infrastructure for small teams. No theatre, no slides, with code that stays with you.

LEARNING PATHS

From first step to mastery, in order

Guided journeys through the best of the archive — without getting lost among hundreds of articles.

Explore all paths

How to migrate from MinIO to Garage with Docker

MinIO images no longer pull from Docker Hub, and the quay.io copy is frozen in 2025. To migrate from MinIO to Garage with Docker, run Garage v2.4.1 next to MinIO, copy the buckets with rclone sync, verify them with rclone check, and switch endpoint, keys and region in your clients.

How to install Portainer with Docker Compose v2

You install Portainer with Docker Compose by writing a single compose.yaml file and running two commands. Portainer CE 2.40 STS supports Docker Compose v2 natively, enables HTTPS on port 9443 out of the box, and manages Docker Engine, Swarm, Kubernetes and ACI from one panel. It runs on Ubuntu 24.04 or Debian 13.

How to use DeepSeek Harness with a local model

DeepSeek Harness (dsh) is the open-source agent harness DeepSeek released in August 2026. It works with a local model if you declare an openai-completions provider in settings.yaml that points at llama-server, with a placeholder key and the real context size. With Qwen3.5-4B on CPU it left the tests green in 4 of 5 attempts, but slowly.

How to install llama.cpp on Linux, macOS and Docker

There are four ways to install llama.cpp: the llama.app script, which drops a 15 MB llama binary into ~/.local/bin; Homebrew; the server-v0.4.1 Docker image; or CMake. I tested them on 14 September 2026 on Linux arm64 with Gemma 4 E2B, in the terminal with llama cli and as an OpenAI-compatible API.

Migrating SSH to post-quantum cryptography: a practical guide

OpenSSH added hybrid post-quantum key exchange with ML-KEM in version 9.9 and made it the default algorithm in 10.0. The question is no longer whether to migrate SSH to post-quantum, but how to do it without breaking old clients: enable the hybrid mode, keep a classical fallback, and verify with ssh -v that the active algorithm is the right one.

LATEST POSTS Just out

Fresh from the oven

  1. Tools

    How to fix pull access denied for minio/minio in Docker

    The pull access denied for minio/minio error appears because MinIO removed its Docker Hub images in September 2026, and quay.io has required an account since the 24th. Point your compose file at cgr.dev/chainguard/minio, at the pgsty/silo fork or at an image built from source: your existing data keeps working.

  2. Tools

    How to install Open WebUI with Docker and Ollama, slim image included

    Open WebUI 0.11.4 installs from a two-service docker-compose.yml: Ollama runs the models and the slim Open WebUI image, which on arm64 downloads 176 MB against 1.49 GB for the full one, serves the interface. This guide creates the admin account, chats with a local model and turns on tool approval.

  3. Technology

    CVE-2026-80521 container escape: check your Docker and k3s hosts and mitigate it

    CVE-2026-80521 is a use-after-free in the Linux kernel's AF_UNIX socket garbage collector, with a public container escape exploit since 22 September 2026. You are affected if your kernel is 6.10 or later without the fix, or a 6.1 or 6.6 branch that received the backport. Patch and reboot; until then, isolate untrusted workloads with gVisor.

  4. Tools

    How to migrate from MinIO to RustFS 1.0 with Docker

    To migrate from MinIO to RustFS 1.0 with Docker, run RustFS next to MinIO, import the users with mc admin cluster iam, copy the buckets with rclone sync --metadata and compare them with rclone check --download. In my test 4,012 objects arrived identical; versions, tags and public access had to be redone by hand.

  5. Artificial Intelligence

    How to fix “typical_p is no longer supported” in Ollama

    Ollama 0.34.1 through 0.34.4 reject with HTTP 400 any request to /api/chat or /api/generate that carries typical_p in options, even at 1.0. The fix is to drop the field in the client, go back to 0.34.0, use the /v1 endpoint, or move to 0.40.0, which only logs a warning.

  6. AI Agents

    How to use Shieldstral as a local guardrail for your agent

    Shieldstral is the 3B safety classifier Mistral released in August 2026: it answers yes or no to a policy written in plain language. Converted to GGUF Q8_0 with llama.cpp and served on a CPU, it blocked no legitimate one among the 100 Spanish and English prompts I prepared, but let 8 of 17 injections through.

  7. Tools

    RabbitMQ 4.3 streams vs quorum queues, measured

    A RabbitMQ quorum queue deletes each message once it is acknowledged and fsyncs before accepting it; a stream keeps it for rereading. On RabbitMQ 4.3.6, with 1 KB messages, the quorum queue moved 45,156 msg/s and the stream, over its own protocol, 281,330 msg/s, using 9 KB of memory per million messages against 20.5 MB.

  8. AI Agents

    How to use OpenCode with local models on llama.cpp and Ollama

    OpenCode uses a local model when you declare an @ai-sdk/openai-compatible provider in opencode.json with the llama-server or Ollama URL and the model's context limit. Version 1.18.31 sends 7,516 tokens on its first turn, so the 4k context Ollama assigns by default without a large GPU is not enough: reserve 32k.

  9. How to Install

    How to install OpenBao with Docker and Raft storage

    To install OpenBao with Docker, run the openbao/openbao:2.6.2 image with Raft storage on a volume, initialise it with bao operator init and unseal it with three of the five keys. OpenBao is the MPL 2.0 fork of HashiCorp Vault and keeps its API, so your applications read secrets the same way.

  10. Tools

    How to use init containers in Docker Compose with pre_start

    Docker Compose 5.3.0, released on 2 July 2026, adds init containers through the pre_start key: steps that run in ephemeral containers, in order, before the service starts. Use them for migrations, volume permissions and generated configuration. Compose 2.40.3 rejects the whole file, and every step must be idempotent because it runs again.

THE NEWSROOM

Most read, by category and trending

Most read

  1. Artificial Intelligence How to install and tune oMLX on M5 Max 128 GB 3.6K
  2. Technology NIST PQC: The Post-Quantum Cryptography Standards 3.5K
  3. Technology Next-generation NPUs: the hardware moving AI in 2026 2.5K
  4. Mac Essential Software for Your New M5 Mac (2026 guide) 2.2K

Most voted