Dear Diary (Homelab edition)

Dear Diary (Homelab edition)

7 Oct 2026

I wanted to do a dear diary post before too much more time goes past. I’ve been working on several projects that have been published, such as Activity Relay and Activity Relay Directory, and I have a couple WordPress plugins that about ready to be published as well.

With feedback from my parents, who are on a slower internet connection, I used AI to build a plugin that renders raw video into much more streaming friendly formats – the ArgentWolf Video Processor (AWVP) plugin. Version 1.0 does all of the rendering on server, so for if you are self hosted like myself, it’s nice to use your hardware to do the rendering and it doesn’t require any API tokens or subscriptions.

The next level, and continuing my efforts to explore the Fediverse (a term that refers to open, free, and distributed social media), is leveraging PeerTube. I set up a PeerTube instance at https://video.argentwolf.org, where you can check out recent videos that I’ve uploaded to the blog. PeerTube has a couple nice features, such as automatic captions, transcoding, better streaming options, and the ability to use ‘runners’ to do these jobs. Runners are clients on various computers that do a job and part of the processing, and now that we have a couple additional computers around for the kids, I’ve set up runners on their workstations, so when they are idle, which is most of the time, they can be useful for other things.

You will notice that the videos here recently are served up a bit differently. They are embedded from the PeerTube instance, and not WordPress’ native video interface. AWVP 2.0 allows me to do all my video uploads through WordPress, configure the metadata, and send it to the runners for transcoding without leaving WordPress’s editor interface. AWVP 2.0 is in the Release Candidate (RC) status right now, and as I get through my backlog of posts and test it a bit more, I expect to publish the new version soon, perhaps this weekend or next week.

Work continues on another plugin, Argent Wolf Post Notifier, which will fill a gap I have of properly notifying users of new posts, again in a proper self hosted manner without external services.

One of the annoying things about WordPress, and enabling user registration is the spam bots hammmering your site. So, time for another plugin! Argent Wolf Access Guard is designed to thwart these bot attempts. No captchas or other things necessary. So far, it has blocked nearly 1,000 attempts to create a spam account on the site. This protection also leverages my Argent Wolf Email Verification Plugin, which, if a spam account does register, it is prevented from fully activating the user until a verification email is clicked. And since they don’t use real email addresses, they never verify, and the accounts are deleted after seven days.

This will also tie into the over watch program, Argent Sentinel (not a WordPress Plugin), which can block the offending IPs at the firewall automatically on configured servers. This is a self learning and protecting methodology across all protected hosts to defend against malicious IPs/hosts.

The home network continues to grow and be refined. I have set the kids up with workstations on Ubuntu connected to a SAMBA domain controller, and leveraging ZFS, they can log into any computer and have their profile and home directory synchronized via ZFS snapshots. The practical effect is that they can go to any workstation, log in, and it is transparent to them which computer they are on, compared to my experience with Windows machines where the profiles didn’t truly roam and when you saved things on a computer, they didn’t necessarily follow you unless you saved it on your embarrassingly small network drive.

I’ve also gotten into the Minecraft hosting business. A client wanted a Minecraft server set up for their group, so I had some extra capacity on the server, and set that up for them. I also set up a family Minecraft server using Pterodactyl and Wings. Pterodactyl is the control plane and Wings are the ‘nodes’ that run the server. I put the family Minecraft server on one of the workstations, and that has been working out well. That way the kids can leverage what I set up for the infrastructure, without impacting the server. I bought the workstations bit higher spec just for this purpose.

With the software releases I’ve been doing, I make announcement posts. When the posts on the blog are reshared by my Friendica (https://friendica.argentwolf.org/profile/alan/conversations), the server gets a lot of traffic in a big burst. Friendica (and PHP) didn’t handle that so well, so yesterday I, with the help of my AI tech support, set up caching on Nginx which has greatly reduced that problem. We had to make sure that the caching only affected some of the Friendica endpoints, and not the other parts which should not be cached. This allowed me to unblock the GoToSocial clients which, for whatever reason, really liked to hammer the instance and previously caused PHP timeouts/overloads.

GitHub had an outage on their runners a while back, so not to be deterred, I now have my own Forgejo instance (a self hosted GitHub replacement), which I am slowly migrating all of the projects over to it. One of the nice things, is that like PeerTube, it uses runners to do the jobs and can take advantage of the additional available workstations to quickly process jobs in parallel and much faster than what is provided by GitHub (for free, anyway) to do the various code actions and build the packages.

I’ve also taken to making a couple tweaked docker images for Jellyfin. Jellyfin is the media server software that allows us to stream our videos and music to devices. There are two issues that have come up. One is that with a relatively large library, the SQLite version of Jellyfin tends to crash and get hung up, which is inconvenient and it only does that when I’m away and the wife needs it to work so the kids will leave her alone. Switching to the experimental PostgreSQL edition, a much more robust database back end, fixed that problem. FFMPEG, which Jellyfin uses, recently had a security vulnerability, which while fixed in newer editions of Jellyfin is still present in the operational PostgreSQL editions. So I made some images that use a fixed (I’d say patched, but we just disabled the offending codec which caused the remote code execution CVE). Then there is a bug having to do with time precision, where PostgreSQL is more precise than the SQLite version, resulting in every library scan to reflect several thousand updates when nothing actually changed. This was fixed in later editions, 12.2, but that version isn’t ready yet with the PostgreSQL integration. So I backported that fix to 10.11.11 and built an image with all the fixes. Those can be found here: https://github.com/thystra/jellyfin-security-images The awsec2 images currently have those fixes in them.

I have a couple other projects in work – a maintenance tracking app for Nextcloud and a home school management program, but those are still early. Right now I’m focusing on finishing the infrastructure build out and protective measures for the spam bots and performance tuning.

So, the work continues and I’m now working through my backlog of posts while getting through these infrastructure updates, here at the homelab of Theseus. Between the homelab, homeschool, homesteading, sports, Scouts, and other activities, dull moments are rare around here!

That’s about it for now. My journaling time is done, and I have a bunch of chores and things to do! Until next time!

7 Sep 2026

I took advantage of a cool day to install a WiFi AP on the front of the house to provide coverage to the front yard. As I’ve been up in the attic a bunch, it was not much trouble to run the cable.

I also took some time to clean up the patch panel which had become a bit of a spaghetti mess over time. Unfortunately, there is still one cable run that had a problem, so I still need to troubleshoot that, but the rest of them were good!

Garrett and Randal being goobers in the kitchen!

Saryia and Rosalina are on clean up duty in the weed patch!

As it was a Monday, we also had all the usual fun with Music Lessons and Scouts!


Thanks for reading! Sign up here on the blog or on our Patreon to know when posts get published! I share these automagically to the Journey of the Wolf and Raven Facebook page if you prefer that. You can also follow me on the fediverse via @alan@www.wolfandraven.blog, or on Friendica at @alan

Popcorn Sunday

Back at it again with popcorn sales!

6 Sep 2026

Today was another sales day. We went to another Publix in northern Jacksonville. It was a bit of a different experience here, but the biggest issue was battling the attitude with the kids. Arya wasn’t doing herself any favors with being grumpy and pissy with things. She did a bit better after eating, but overall it wasn’t that great of a location for us; we sold about half of what we would have expected.

Back on the home front Garrett and Randal help make breakfast! They are great helpers and love to help cook!

A rare moment of brotherly love!


Thanks for reading! Sign up here on the blog or on our Patreon to know when posts get published! I share these automagically to the Journey of the Wolf and Raven Facebook page if you prefer that. You can also follow me on the fediverse via @alan@www.wolfandraven.blog, or on Friendica at @alan

Frightfully delightful!

Frightfully delightful!

5 Sep 2026

Up early in the morning to get chores done, I found this massive spider web in the yard. It was pretty impressive!

After chores, we were off to sell Popcorn for a Scout fundraiser. It started out a bit slow, and both Arya and her partner got a bit heat sick as we were getting blasted by the sun for the first hour, until it got high enough to shade us.

Meanwhile, shenanigans are afoot! Little buddy is getting bigger all the time!

Meagan took the kids to a Spirit Halloween store. Garrett and Randal had a great time getting scared by the animatronics and checking out all the cool things!

Our little viking warriors were checking out the gear to ensure they were fully equipped!

Garrett and Randal have fun with the trash can monster at Spirit Halloween! They got over their fear of the displays and were having fun scaring themselves!

Garrett is having a great time learning about and playing with the candy bowl!

Time to get ready for Halloween!


Thanks for reading! Sign up here on the blog or on our Patreon to know when posts get published! I share these automagically to the Journey of the Wolf and Raven Facebook page if you prefer that. You can also follow me on the fediverse via @alan@www.wolfandraven.blog, or on Friendica at @alan

Fizzling Thursday

3 Sep 2026

Evan and Meagan got to practice early, and started doing some drills. Meagan made Evan a bet that if he blocked more shots than her, she would do his dishes(!). Sadly, he did not succeed.

Garret being a goober, as usual of course.

The other notable thing that happened today was our Ninja toaster oven started to go on the fritz. Which was rather disappointing and only then did we find out how much we really relied on it.

Drippy Friday

4 Sept 2026

Nothing quite like going out to the chickens and finding one randomly dead in the morning. No apparent signs of struggle or injuries.

Wildly crazy loud geese!

After animal chores, it was off to lunch with friends, then to the store. We were running low on our favorite peanut butter. Which, it turns out, was apparently also quite popular as there was none on the shelves when I got there.

Then it was time to change the oil on the truck. I was going to use my new oil extraction pump, but something wasn’t compatible with the setup – either too long of a hose or it couldn’t get down to the oil pan. I had to by a longer piece of tubing but it still didn’t reach.

Meanwhile, there was chess club. Garrett is learning to play, although he has a bit of trouble with losing.

The rest of the kids had a good time. Jarek and Evan can beat everyone there, however; so we need to find them some stiffer competiiton!

Fortunately, I had a Fumoto valve installed, which made it much less messy.

Normally, this results in a partial oil bath for me as 3 gallons of oil is liberated.

Of course, there is no time to change oil like when you are dodging rain showers!

I see a little person got a hold of my phone…


Thanks for reading! Sign up here on the blog or on our Patreon to know when posts get published! I share these automagically to the Journey of the Wolf and Raven Facebook page if you prefer that. You can also follow me on the fediverse via @alan@www.wolfandraven.blog, or on Friendica at @alan

Activity Relay 3.1.0 and Activity Relay Directory 1.3.0 are released!

Activity Relay 3.1.0 and Activity Relay Directory 1.3.0 are released!

Activity Relay 3.1.0 and Activity Relay Directory 1.3.0 are released. This synchronized release brings together some notable improvements in the heartbeat protocol. These enhancements allow a Relay operator to push stats and information to Directory servers automatically, keeping information up to date.

Live installations of the Relay and Directory may be found at:

https://directory.argentwolf.org

https://relay.argentwolf.org

On the Relay itself, the policy information will be presented on the default home page:

On the Directory, this information will be reflected as well with time stamps on when it was received and last checked for health by the Directory:

Other relays may be manually added to the Directory by the Directory operator/Admin. I have manually collected a list of Fediverse relays and populated my Directory installation with information about them. These sites are not automatically updated with regard to policy, but are verified as reachable by the Directory server.

Relays that are restricted (Approval Required) or closed to sign ups will appear as such on the Directory. Relays that go offline or are otherwise unreachable will appear in the offline list, eventually moving to the Graveyard after 30 days of offline time. Offline relays can be added the the Directory, but they will not become visible on the index until they pass an online check.

As always, if you want to make your own front facing website, you can disable the built in pages and use your own endpoints!

Comments, feedback, and bug reports are all welcome! Repo links below, available in both .deb and docker images. If you found these useful, please consider a tip to my Ko-fi to support further development! Thank you!

https://github.com/thystra/Activity-Relay

Activity-Relay 3.1.0

  • Added Activity-Relay Directory Protocol v2 profile synchronization and Protocol v3 participating-site telemetry.
  • Added automatic Directory reconciliation on relay startup, including an immediate heartbeat for already-registered relays.
  • Improved manual Directory register, heartbeat, and sync commands so they coordinate cleanly with the background scheduler.
  • Added richer relay profile metadata for registration status, topics, languages, regions, contact details, and related information.
  • Added --test-config validation with safer handling of optional profile errors.
  • Added optional SUPPORT information to the generated relay website, including links and plain-text values such as cryptocurrency addresses.
  • Hardened the outbound Directory client against malformed responses, unsafe redirects, oversized responses, and other hostile input.
  • Improved static-site tooling, operator documentation, and deterministic release packaging.
  • Preserves existing relay identity, Redis state, subscriptions, delivery behavior, and queue compatibility.
  • Published for linux/amd64 and linux/arm64 at ghcr.io/thystra/activity-relay:3.1.0.

https://github.com/thystra/activity-relay-directory

Activity-Relay Directory 1.3.0

  • Added source-aware relay profiles with per-field precedence: override > relay > csv.
  • Added bounded CSV import/export for relay metadata, including profile-change previews before applying updates.
  • Added support for updating metadata on already-known relays even when they are currently unreachable.
  • Added Activity-Relay lifecycle Protocol v2 profile synchronization and Protocol v3 participating-site telemetry while retaining Protocol v1 compatibility.
  • Treats successful authenticated registration as current relay-liveness evidence, improving restart and recovery behavior.
  • Expanded /v2/relays and the public Directory with profile information, site counts, and Open/Restricted/Closed registration status.
  • Preserves the existing four operational tiers: Heartbeat + Online, Online, Offline/Unreachable, and Graveyard.
  • Added configurable Directory title, banner, support information, and improved operator-facing presentation.
  • Keeps descriptive metadata separate from reachability, heartbeat health, moderation, pruning, and tier placement.
  • Upgrades existing databases in place to schema 12 while preserving the frozen /v1/relays compatibility API.
  • Published for linux/amd64 at ghcr.io/thystra/activity-relay-directory:1.3.0.

Activity Relay Directory 1.2.0 Released

Activity-Relay Directory 1.2 expands relay discovery, long-term availability tracking, and the public-facing Directory while preserving the authenticated V1 lifecycle protocol and the frozen /v1/relays compatibility API.

Highlights

  • More resilient relay discovery and bulk imports
  • Retention and automatic retry of unavailable relay candidates
  • ActivityStreams Group relay actor support
  • Four public operational relay tiers
  • 30-day transition to the Graveyard tier
  • Aggregate online, offline, and pending-verification counts on the public-facing Directory page
  • Local tier-scoped exports and public plain-text relay downloads
  • Automatic recovery of previously unavailable relays
  • Debian upgrade handling that reloads systemd definitions without automatically restarting an active Directory

Activity Relay Directory 1.2.0 can be downloaded from here: https://github.com/thystra/activity-relay-directory/releases/tag/v1.2.0

A working example of Activity Relay Directory may be found at https://directory.argentwolf.org

If you find this useful, please consider tipping me at my ko-fi! Thanks!

ARD 1.3 is mapped out and will be paired with a synchronized release of Activity Relay server. The 1.3 edition will allow for additional information, e.g. notes, state, and filtering, to be provided by Relay server operators rather than manually input by the Directory server operator/admin.

Activity Relay 3.0.1 maintenance release

30 Sep 2026

Activity Relay 3.0.1 has been released to fix a couple bugs caused by invalid follower states blocking relay operation.

https://github.com/thystra/Activity-Relay/releases/tag/v3.0.1

Activity-Relay 3.0.1 is a focused reliability release for follower-state handling and relay fan-out.

Fixed

  • Prevent stale mutual-follow responses from recreating incomplete Redis follower records.
  • Validate follower state before persistence.
  • Ignore malformed persisted follower records when loading relay state.
  • Isolate invalid or unplannable delivery targets so one bad receiver cannot abort healthy fan-out.
  • Keep queue reservations and remaining-delivery counts aligned with deliveries actually planned.
  • Harden manual follower acceptance ordering.
  • Update Forgejo container/release CI for Debian Trixie’s split Docker client packages.

No configuration or data migration is required.

The 3.0.1 candidate was production-tested on relay.argentwolf.org, including real WordPress fan-out to healthy Friendica and Mastodon receivers while an independently failing receiver continued through its isolated retry path.

Container: ghcr.io/thystra/activity-relay:3.0.1

See docs/releases/v3.0.1.md and CHANGELOG.md for complete details.

The attached files are the exact canonical artifacts produced and accepted by the Forgejo release workflow.

If you find this useful, please consider leaving a tip on my Ko-Fi – https://ko-fi.com/thewolfandtheraven

Jellyfin Hotcache & Hardened Jellyfin Docker Images

I’m pleased to announce the release of Jellyfin Hotcache. This is a helper for Jellyfin that I built to address a fairly simple problem: my kids love to watch the same media over and over, but I’d rather they not spin up the NAS drives every time they want to watch the same episode again.

Jellyfin Hotcache identifies frequently and recently played media and stages a copy on a specified cache drive—ideally an SSD or NVMe device. It preserves the original media on the slower storage, renames that copy for safekeeping, and replaces Jellyfin’s original media path with a symlink pointing to the cached copy.

This helps reduce unnecessary spin-ups of the media drives and can improve playback startup and access times for frequently watched content.

https://github.com/thystra/hotcache-for-jellyfin

Version 1.0.3 has now been released, including several reporting and operator-visibility improvements:

https://github.com/thystra/hotcache-for-jellyfin/releases/tag/v1.0.3

Hotcache is packaged for Debian/Ubuntu-compatible Linux systems. It supports Jellyfin playback history stored in both SQLite and PostgreSQL, and works with both bare-metal and containerized Jellyfin installations. Container installations require the cache directory to be mounted into Jellyfin at the same absolute path so that Jellyfin can follow the cache symlinks.

Hardened Jellyfin Docker Images

Along with Hotcache, I’ve also put together some updated and hardened Jellyfin 10.11.11 Docker images.

These images address CVE-2026-8461, an FFmpeg MagicYUV decoder vulnerability that can result in an out-of-bounds write and potentially remote code execution when a malicious media file is processed.

https://nvd.nist.gov/vuln/detail/cve-2026-8461

The hardened Jellyfin 10.11.11 images use a custom Jellyfin FFmpeg 7.1.4 build with the affected MagicYUV decoder disabled. This mitigates CVE-2026-8461 while retaining Jellyfin’s expected hardware-acceleration support.

I’ve also repackaged the Jellyfin PostgreSQL images with separate PostgreSQL 17 and PostgreSQL 18 client-tool variants. Jellyfin’s PostgreSQL backup functionality relies on tools such as pg_dump, and pg_dump cannot back up a PostgreSQL server running a newer major version than the client itself. After I upgraded my database server to PostgreSQL 18, the older client tools in the Jellyfin image could no longer perform the backup.

The resulting images provide explicit PG17 and PG18 variants and are available for both amd64 and arm64:

https://github.com/thystra/jellyfin-security-images

Jellyfin 12.0 and later currently use Jellyfin FFmpeg 8.1.2 or newer, which contains the upstream fix for CVE-2026-8461, so these hardened FFmpeg images are primarily intended for users remaining on Jellyfin 10.11.11.

If you find any of this useful, I appreciate any tips at my Ko-fi!!

https://ko-fi.com/thewolfandtheraven

Wacky Wednesday

2 Sep 2026

We tried a little experiment, well two actually. One was cutting back the feed for the chickens, and two was using the Tractor Supply delivery service.

Cutting the feed back wasn’t that great. It caused a slow down in their eggs, and I’m not sure if it is related or not, but seemed to trigger a molt. Egg production pretty much stopped (writing this a couple weeks in the future..) and took a while to recover.

Tractor Supply also took their time delivering, missing the original promise date and stretched out the delivery over a few days. That was a little annoying as well.

Read more