Docker
A Fully Local AI Assistant in One docker agent YAML
Point Docker Agent at a local OpenAI-compatible server, declare a few toolsets, and you have a private assistant that reads files, runs shell commands and calls your own scripts — no cloud API key required
docker agent is Docker’s agent runtime (the CLI plugin built on the open-source cagent project — you’ll
see that name in ~/.config/cagent). Its whole contract is a single YAML file: one block describing agents,
one describing models. Nothing stops you from pointing the model block at localhost, which is the
interesting part — the same declarative agent, tools and all, running against a model on your own machine.
Serving a static site securely with static-web-server
Hardening a Hugo site behind Traefik with static-web-server: read-only rootfs, dropped capabilities, a non-root UID, and security headers
A Hugo build is a folder of files. Nothing executes, nothing talks to a database, nothing parses user input. The interesting attack surface isn’t the content — it’s the server you put in front of it, and for years that meant an nginx image carrying a config language, a module system, and a package manager I never used.
This blog now runs on static-web-server instead. Here’s the compose file that serves it, and what each hardening line actually buys.
Launch a gitlab-runner in a Swarm
We are beginning to use Swarm at work and I wanted to make a complete CI/CD in the Swarm. So I have tried to run my own gitlab-runner in the Swarm (connected to https://gitlab.com).
Create a swarm cluster with vagrant
As for Kubernetes, I have done some code to build a swarm cluster with vagrant too :