Docker

A Fully Local AI Assistant in One docker agent YAML

Point Docker Agent at a local OpenAI-compatible server, declare a few toolsets, and you have a private assistant that reads files, runs shell commands and calls your own scripts — no cloud API key required

docker agent is Docker’s agent runtime (the CLI plugin built on the open-source cagent project — you’ll see that name in ~/.config/cagent). Its whole contract is a single YAML file: one block describing agents, one describing models. Nothing stops you from pointing the model block at localhost, which is the interesting part — the same declarative agent, tools and all, running against a model on your own machine.

AI Docker docker ai llm

Serving a static site securely with static-web-server

Hardening a Hugo site behind Traefik with static-web-server: read-only rootfs, dropped capabilities, a non-root UID, and security headers

A Hugo build is a folder of files. Nothing executes, nothing talks to a database, nothing parses user input. The interesting attack surface isn’t the content — it’s the server you put in front of it, and for years that meant an nginx image carrying a config language, a module system, and a package manager I never used.

This blog now runs on static-web-server instead. Here’s the compose file that serves it, and what each hardening line actually buys.

Docker docker security traefik

gitlab-runner in a swarm

Launch a gitlab-runner in a Swarm

We are beginning to use Swarm at work and I wanted to make a complete CI/CD in the Swarm. So I have tried to run my own gitlab-runner in the Swarm (connected to https://gitlab.com).

Docker docker swarm gitlab

Swarm vagrant

Create a swarm cluster with vagrant

As for Kubernetes, I have done some code to build a swarm cluster with vagrant too :

Docker docker swarm vagrant