Docker

A Fully Local AI Assistant in One docker agent YAML

Point Docker Agent at a local OpenAI-compatible server, declare a few toolsets, and you have a private assistant that reads files, runs shell commands and calls your own scripts — no cloud API key required

docker agent is Docker’s agent runtime (the CLI plugin built on the open-source cagent project — you’ll see that name in ~/.config/cagent). Its whole contract is a single YAML file: one block describing agents, one describing models. Nothing stops you from pointing the model block at localhost, which is the interesting part — the same declarative agent, tools and all, running against a model on your own machine.

AI Docker docker ai llm

Serving a static site securely with static-web-server

Hardening a Hugo site behind Traefik with static-web-server: read-only rootfs, dropped capabilities, a non-root UID, and security headers

A Hugo build is a folder of files. Nothing executes, nothing talks to a database, nothing parses user input. The interesting attack surface isn’t the content — it’s the server you put in front of it, and for years that meant an nginx image carrying a config language, a module system, and a package manager I never used.

This blog now runs on static-web-server instead. Here’s the compose file that serves it, and what each hardening line actually buys.

Docker docker security traefik

http-echo: a verbose HTTP echo server for debugging anything

A small Go HTTP server that prints every detail of an incoming request — handy for proxies, webhooks, and Kubernetes networking puzzles

Every few months I find myself stuck on the same kind of question: what exactly is hitting my service? A reverse proxy is mangling a header, a Kubernetes ingress is rewriting a path, a webhook provider is sending a body in some shape I didn’t expect. The fastest way to answer is to point the traffic at something that will tell me, in painful detail, what arrived.

That’s why I wrote http-echo: a tiny Go server that responds to any HTTP request by dumping a structured, human-readable report of everything it saw.

Tools golang http debugging

httpfileserver: serve a directory over HTTP, the boring way

A tiny Go binary (and scratch Docker image) to expose a directory over HTTP, with optional basic auth and configurable timeouts

Once in a while I need to throw a directory online. Share a build artifact with a colleague, expose a folder of files inside a Kubernetes cluster, mount a release directory behind an internal nginx — the kind of task where a full web server is overkill and python3 -m http.server is too primitive.

That’s the niche httpfileserver fills: a single static Go binary (or a scratch-based Docker image) that serves a directory, with the few quality-of-life features I always end up wanting.

Tools golang http docker

gitlab-runner in a swarm

Launch a gitlab-runner in a Swarm

We are beginning to use Swarm at work and I wanted to make a complete CI/CD in the Swarm. So I have tried to run my own gitlab-runner in the Swarm (connected to https://gitlab.com).

Docker docker swarm gitlab