[{"content":"The astute may have noticed, this blog is on Hugo and PaperMod. A common choice. A sensible choice. A Just Works choice. It wasn\u0026rsquo;t hard. So why hasn\u0026rsquo;t this one before? Because, just like My Homelab. Hugo has been pretty nice to use actually. Same for PaperMod. It looks nice, it Just Works, and it gets this one started.\nBut there are many theme options to choose from, and the choice between Zola and Hugo. Writing this is making it look at Zola themes and fuck they\u0026rsquo;re looking pretty nice and making it want to switch. Maybe. Now that something exists to fall back to. It probably would have been fine just deciding to use Zola and- see this is the trap, and what? PaperMod, in this one\u0026rsquo;s mind, is the classic default-choice hugo theme that It ended up falling back on, but what is Zola\u0026rsquo;s and does It even like it?\nAnyway. So this one sucked it up and decided on something, and this is the result. But even then, this isnt exactly default hugo and papermod, you may have noticed this one\u0026rsquo;s posts have IDs in their URL. The first thing It did when deciding to use Hugo and PaperMod, with no prior experience with them and so concurrent with setting them up and learning enough to Get A Post Out:tm:, It was immediately fighting against the fact that titles are URLs.\nThis wasn\u0026rsquo;t actually too difficult to solve. The magic that makes this happen is 3 lines in the archetye.\n{{ $id := substr (now.UnixNano | sha1) 0 8 -}} url: \u0026#34;/{{.Section | urlize}}/{{ $id }}/{{ .Name | urlize }}/\u0026#34; aliases: [\u0026#34;/{{.Section | urlize}}/{{ $id }}\u0026#34;] This gives every post a canonical URL, with an automatic random ID because how many posts a nanosecond do you think are being made, independent of its title, which will html redirect to the SEO url with the title in it.\nThis one wanted this so It could potentially change titles with no breakage and without worry of title collisions. The title can always be changed and the previous one added as an alias, and even if it isnt, if you just try removing the title from the URL so its just the ID, it\u0026rsquo;ll work. It often has to do this for old or broken links, and it often works, so this one assumes others do too.\nThis causes hugo to create stub pages with redirects in \u0026lt;head\u0026gt;. Since this is a static site, this is the best they can do, which does have UX conseuqneces; Social cards dont work because those are only on the main page, browsers have to load and parse the html page to know to redirect it, and so such.\nThis is an acceptable trade-off for now. So are social cards. It could probably modify papermod to insert social card stuff into the stub pages so that It can social-post the stable ID link and have the canonical URL include the title text, keeping the nice cards on the stable id.\nIs this the \u0026ldquo;best\u0026rdquo; way to do this? The \u0026ldquo;right\u0026rdquo; way? It didnt ask and didnt care, It just did something. If this one wants to get anything out, and It does, then It has to learn when and how to make that trade off. This is blog post number two, so Progress has been made.\n","permalink":"https://catra.top/blog/d2042b1d/setting-up-hugo/","summary":"\u003cp\u003eThe astute may have noticed, this blog is on Hugo and PaperMod. A common choice. A sensible choice. A Just Works choice. It wasn\u0026rsquo;t hard. So why hasn\u0026rsquo;t this one before? Because, just like \u003ca href=\"/blog/2a74bf3f\"\u003eMy Homelab\u003c/a\u003e. Hugo has been pretty nice to use actually. Same for PaperMod. It looks nice, it Just Works, and it gets this one started.\u003c/p\u003e\n\u003cp\u003eBut there are many theme options to choose from, and the choice between Zola and Hugo. Writing this is making it look at Zola themes and fuck they\u0026rsquo;re looking pretty nice and making it want to switch. Maybe. Now that something exists to fall back to. It probably would have been fine just deciding to use Zola and- \u003cem\u003esee this is the trap, and what?\u003c/em\u003e PaperMod, in this one\u0026rsquo;s mind, is the classic default-choice hugo theme that It ended up falling back on, but what is Zola\u0026rsquo;s and does It even like it?\u003c/p\u003e","title":"My Experience (Setting Up Hugo)"},{"content":"I\u0026rsquo;ve been trying to \u0026ldquo;set up a homelab\u0026rdquo; for years. For me this really means, well, anything self hosted. Jellyfin, Nextcloud, Immich, a Bluesky PDS, so much as a static site for this blog post which is being written before any site exists, and will be hosted by the \u0026ldquo;homelab\u0026rdquo; this post will go on to create.\nI dont know if its me, other people, guides, but I\u0026rsquo;ve always struggled here. There are lots of guides and \u0026ldquo;steps\u0026rdquo;, but very little rationale, explanation, justification, \u0026ldquo;why this way and not that way\u0026rdquo;; I\u0026rsquo;ve always needed to know the rationale, the low-level details, how and why it works, and most of all: How and why its secure and private. I do not want my devices hacked, my data stolen, and so on, so I need what is sorely missing from most guides: The understanding of what i\u0026rsquo;m doing to be confident it is secure.\nThis means, for me, setting up a homelab requires as a first step much in-depth research and learning about networking, reading RFCs on what this shit means, best practice on security and cryptography, ipv4 and ipv6 and dual-mode sockets and NAT and legacy compatibility and firewalls and ports.\nThis is why I do not yet have a homelab, do not have anything self hosted. My threat model includes other devices on my home\u0026rsquo;s LAN, it includes \u0026ldquo;evil parent attacks\u0026rdquo;, commonly referred to in industry as \u0026ldquo;evil maid\u0026rdquo; attacks, which underscores how common and realistic a threat it is. If you\u0026rsquo;re reading this, you\u0026rsquo;re probably in tech, so you should understand how realistic a threat abusive parents, friends, and partners are, and the kind of damage they can do to unsecured devices on a LAN; For this reason I prefer the term \u0026ldquo;evil parent\u0026rdquo;.\nThis led me to my interest in UEFI and Secure Boot, since the state of linux distribution security is abysmal, in particularly fully measured/integrity protected boot, something which is possible and Android has done for years, the kernel can do it, but no distribution does.\nTo build a homelab I now need to first make a secure linux distribution to run it on. This has spiraled out of control. This is my white whale, a project that many of my other projects and goals ultimate boil down to: Create a secure linux distro. It slightly predates my desire to self host things. When I was young, I used Linux off and on, driven back to windows mostly for games. I briefly used BackTrack linux(fucking lol)(now known as Kali Linux), I daily drove Gentoo off and on over many years before settling down on Arch. My interest in Linux and self-hosting came together at around the same times, intertwined. The specifics of what more secure means, of what best practice is, of what hardware features exist, have evolved over time.\nThis is even more out of control and over-whelming, and obviously does not get done. But still, I can\u0026rsquo;t give up security, so I need to research best practice for development, and today that means Containers. It means Docker, it means Podman, it means figuring out that podman needs to be treated as an entirely separate container platform rather than a rootless/more secure docker alternative because podman has more spec bugs than it does compatibility, and outright missing important features; It means learning why all those projects say they dont support podman and wont take questions about it, they have good reason to, podman is not up to par, i wasted so much time fighting its many bugs that contradict the specs they implement as well as their own direct documentation. Many of them had been reported years ago, so this demoralized me on the idea of podman. Maybe in a few years.\nANYWAY, Containers. Well containers are annoying, and what the fuck is a kubernetes and a k3s and a minikube? Everything is YAML and Go now, and supply chain attacks on package registries are ramping up so i really start caring about security of my environment and pulling packages somewhere that isnt even nominally secured, so what the fuck are Dev Containers? I should be developing in containers, but theyre all so fucking insecure and open by default that theres no point security wise- UH OH now i want to make my own sandbox framework or at least my own more secure Dev Container than the default\nBut testing and working on that is.. oops, development, chicken and egg, so i dont work on it obviously. I still do not host so much as a static website.\nI need to give up. I need to scope down. I need to focus. I need to figure out how to be okay with existing imperfect solutions, and figure out how they can be adapted or isolated or made more secure in a simpler manner, more containers, reverse proxies, go back to networking, just use docker and stop fighting podman, build more dev-tooling and ad-hoc scripts instead of giving up there or deciding they\u0026rsquo;re \u0026ldquo;unprincipled\u0026rdquo; and trying to do it some \u0026ldquo;right way\u0026rdquo;\nThe timeline on all the above is probably(definitely) pretty fucky, this is a bad blog post, and doesn\u0026rsquo;t do what it said at the start, and I will not go back to fix that. But it is a blog post. The first and only one I\u0026rsquo;ve written. If you are reading this, I got over it enough to host a static site, over embarrassment and fear and shame to put something this bad out, and maybe.. maybe more will come. Part 2: My Experience (Actually) Setting Up A Homelab (maybe) to come.\nWhy? I decided while writing the last two paragraphs to just finish it instead of trying to write it as I go on implementing the homelab, which would mean it would never get done. This post is a statement of intent as much as anything else.\nPostscript I gave up on self hosting a static blog post and put it on github pages. Minimum viable. self host later, blog now. This is the only edit.\n","permalink":"https://catra.top/posts/2a74bf3f/my-experience-trying-for-setting-up-a-homelab/","summary":"\u003cp\u003eI\u0026rsquo;ve been trying to \u0026ldquo;set up a homelab\u0026rdquo; for years. For me this really means, well, anything self hosted. Jellyfin, Nextcloud, Immich, a Bluesky PDS, so much as a static site for this blog post which is being written before any site exists, and will be hosted by the \u0026ldquo;homelab\u0026rdquo; this post will go on to create.\u003c/p\u003e\n\u003cp\u003eI dont know if its me, other people, guides, but I\u0026rsquo;ve always struggled here. There are lots of guides and \u0026ldquo;steps\u0026rdquo;, but very little rationale, explanation, justification, \u0026ldquo;why this way and not that way\u0026rdquo;; I\u0026rsquo;ve always needed to know the rationale, the low-level details, how and why it works, and most of all: How and why its \u003cem\u003esecure\u003c/em\u003e and \u003cem\u003eprivate\u003c/em\u003e. I do not want my devices hacked, my data stolen, and so on, so I need what is sorely missing from most guides: The understanding of what i\u0026rsquo;m doing to be confident it is secure.\u003c/p\u003e","title":"My Experience (Trying For) Setting Up A Homelab"},{"content":"","permalink":"https://catra.top/about/","summary":"about","title":"About Me"}]