TechBlog
A technical blog about Docker, Kubernetes, DevOps, and Cloud technologies
Recent Posts
A Fully Local AI Assistant in One docker agent YAML
Point Docker Agent at a local OpenAI-compatible server, declare a few toolsets, and you have a private assistant that reads files, runs shell commands and calls your own scripts — no cloud API key required
docker agent is Docker’s agent runtime (the CLI plugin built on the open-source cagent project — you’ll
see that name in ~/.config/cagent). Its whole contract is a single YAML file: one block describing agents,
one describing models. Nothing stops you from pointing the model block at localhost, which is the
interesting part — the same declarative agent, tools and all, running against a model on your own machine.
opencode.json: Wiring a Terminal Coding Agent to a Local Model
One JSON file turns opencode into a fully local assistant — declare an OpenAI-compatible provider, describe your models, and check the resolved config before you trust it
opencode is a terminal coding agent, and it has no opinion about where its tokens
come from. Providers are declared in an opencode.json file, so pointing it at a model running on your own
machine — LM Studio, an MLX server, llama.cpp, vLLM — is a matter of a baseURL and a couple of lines of
metadata. Here’s a config with three providers side by side: a LAN box, a hosted API, and a local server.
Serving a static site securely with static-web-server
Hardening a Hugo site behind Traefik with static-web-server: read-only rootfs, dropped capabilities, a non-root UID, and security headers
A Hugo build is a folder of files. Nothing executes, nothing talks to a database, nothing parses user input. The interesting attack surface isn’t the content — it’s the server you put in front of it, and for years that meant an nginx image carrying a config language, a module system, and a package manager I never used.
This blog now runs on static-web-server instead. Here’s the compose file that serves it, and what each hardening line actually buys.
Advanced Go Concurrency Patterns
Master goroutines, channels, and concurrency patterns for building high-performance Go applications
Go’s concurrency model is one of its most powerful features. This guide explores goroutines, channels, and advanced patterns for writing efficient concurrent code.
3 Ways to Add a --version Flag to a Go CLI
Inject build metadata with -ldflags, read it back with debug.ReadBuildInfo, or grab a tiny helper package — three approaches to a --version flag, with the trade-offs of each
Every CLI eventually grows a --version flag. Users need it to file useful bug reports, scripts need it to gate behavior, and you need it when an issue lands and you want to know what binary the reporter is actually running. Go gives you a few ways to wire this up — none of them long, but each with different ergonomics. Here are the three I reach for.