<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: SelfHost Pilot</title>
    <description>The latest articles on DEV Community by SelfHost Pilot (@selfhostpilot).</description>
    <link>https://dev.to/selfhostpilot</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4119270%2F355b2885-b548-4991-b2e9-f1174129a83f.png</url>
      <title>DEV Community: SelfHost Pilot</title>
      <link>https://dev.to/selfhostpilot</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/selfhostpilot"/>
    <language>en</language>
    <item>
      <title>WireGuard Split Tunneling on Blocked Networks (udp2raw)</title>
      <dc:creator>SelfHost Pilot</dc:creator>
      <pubDate>Wed, 30 Sep 2026 03:43:16 +0000</pubDate>
      <link>https://dev.to/selfhostpilot/wireguard-split-tunneling-on-blocked-networks-udp2raw-144p</link>
      <guid>https://dev.to/selfhostpilot/wireguard-split-tunneling-on-blocked-networks-udp2raw-144p</guid>
      <description>&lt;p&gt;Your WireGuard tunnel works fine at home, then dies the moment you join a hotel, campus, cafe or mobile-carrier network. Below I show how to prove the network is the problem, hide WireGuard inside traffic those networks allow, and use split tunneling so only the traffic that needs the tunnel goes through it. I assume you already have a server running from my &lt;a href="https://selfhostpilot.com/wireguard-vpn-server-linux-setup-guide/" rel="noopener noreferrer"&gt;WireGuard server setup guide&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  WireGuard split tunneling: what it actually does
&lt;/h2&gt;

&lt;p&gt;On Linux, AllowedIPs is not a filter on top of your routing. wg-quick turns every AllowedIPs entry into a route on the tunnel interface. It is an allow-list: put a network in AllowedIPs and only that network goes through the tunnel.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;WireGuard split tunneling means listing the networks that should go inside the tunnel in AllowedIPs; everything else stays on your normal connection. The AllowedIPs list &lt;em&gt;is&lt;/em&gt; the split tunnel.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;&lt;code&gt;AllowedIPs = 0.0.0.0/0&lt;/code&gt; is the full tunnel. The popular &lt;code&gt;0.0.0.0/1&lt;/code&gt; plus &lt;code&gt;128.0.0.0/1&lt;/code&gt; trick does not exclude anything, because those two halves still cover all of IPv4. To exclude a host or subnet, add a more specific route so longest-prefix match sends it through your normal gateway:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;PostUp = ip route add 198.51.100.0/24 via 192.168.1.1&lt;br&gt;
PreDown = ip route del 198.51.100.0/24 via 192.168.1.1&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Set &lt;code&gt;Table = off&lt;/code&gt; in [Interface] if you want to manage routing yourself. Only add a DNS line if you want the tunnel's resolver.&lt;/p&gt;

&lt;p&gt;Per-app splitting depends on the platform:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Platform&lt;/th&gt;
&lt;th&gt;Per-app split tunneling&lt;/th&gt;
&lt;th&gt;What to use&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Linux&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;AllowedIPs, extra routes, &lt;code&gt;Table = off&lt;/code&gt;, or the Amnezia client&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Android&lt;/td&gt;
&lt;td&gt;Yes, official app&lt;/td&gt;
&lt;td&gt;"Excluded Applications" (&lt;code&gt;ExcludedApplications&lt;/code&gt; in the config)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;iOS&lt;/td&gt;
&lt;td&gt;No&lt;/td&gt;
&lt;td&gt;On-Demand rules instead&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Windows / macOS&lt;/td&gt;
&lt;td&gt;Not in the official app&lt;/td&gt;
&lt;td&gt;Tunnel follows AllowedIPs; Amnezia client for per-app routing&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;h2&gt;
  
  
  Why WireGuard stops working on some networks
&lt;/h2&gt;

&lt;p&gt;WireGuard was built to be fast, not hidden. The handshake initiation is always exactly 148 bytes, the response 92 bytes and the cookie 64 bytes, and every packet starts with a fixed 4-byte message type. For deep packet inspection, that shape is trivial to fingerprint.&lt;/p&gt;

&lt;p&gt;Networks usually break it in one of three ways: they drop all UDP (common on hotel and campus Wi-Fi), throttle UDP until the tunnel crawls, or allow only TCP 80 and 443.&lt;/p&gt;

&lt;h2&gt;
  
  
  Before you change anything: three quick checks
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;First, run &lt;code&gt;sudo wg show&lt;/code&gt;.&lt;/strong&gt; If "latest handshake" is empty, your packets are not getting through, and it is not a key typo when the same config works at home.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Second, connect your laptop to your phone's hotspot.&lt;/strong&gt; If the tunnel comes up instantly, the server is fine and the network is at fault.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Third, test UDP and TCP 443 separately&lt;/strong&gt; while tcpdump watches the server:&lt;/p&gt;

&lt;h1&gt;
  
  
  on the server
&lt;/h1&gt;

&lt;p&gt;sudo tcpdump -ni any 'udp port 51820 or tcp port 443'&lt;/p&gt;

&lt;h1&gt;
  
  
  on the client, from the blocked network
&lt;/h1&gt;

&lt;p&gt;echo test | nc -u -w1 203.0.113.2 51820&lt;br&gt;
nc -vz -w3 203.0.113.2 443&lt;/p&gt;

&lt;p&gt;If nothing arrives on UDP but the TCP 443 attempt shows up, you are on a TCP-only network.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Then try the cheapest fix.&lt;/strong&gt; Many networks only filter UDP 51820 or unknown high ports. Set &lt;code&gt;ListenPort = 443&lt;/code&gt; in the server config from my &lt;a href="https://selfhostpilot.com/wireguard-vpn-server-linux-setup-guide/" rel="noopener noreferrer"&gt;WireGuard setup guide&lt;/a&gt;, open UDP 443 in the firewall and update the client Endpoint. No extra software.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Finally, rule out MTU.&lt;/strong&gt; If the handshake works but nothing loads, run &lt;code&gt;ping -M do -s 1400 &amp;amp;lt;server-ip&amp;amp;gt;&lt;/code&gt;. If it fails, reduce the size until it passes and lower the tunnel MTU to match.&lt;/p&gt;

&lt;h2&gt;
  
  
  Fix 1: udp2raw, WireGuard in a fake TCP connection
&lt;/h2&gt;

&lt;p&gt;udp2raw (MIT) uses raw sockets to wrap UDP in encrypted FakeTCP, UDP or ICMP. In faketcp mode on port 443, firewalls see an ordinary TCP connection. It adds AES-128-CBC encryption, HMAC-SHA1 authentication and anti-replay protection, and it survives Wi-Fi changes.&lt;/p&gt;

&lt;p&gt;Server:&lt;/p&gt;

&lt;p&gt;[Interface]&lt;br&gt;
Address = 10.8.0.1/24&lt;br&gt;
ListenPort = 51820&lt;br&gt;
PrivateKey = &amp;lt;server private key&amp;gt;&lt;br&gt;
MTU = 1342&lt;br&gt;
PreUp = udp2raw -s -l 203.0.113.2:443 -r 127.0.0.1:51820 -k "shared secret" -a &amp;gt;/var/log/udp2raw.log 2&amp;gt;&amp;amp;1 &amp;amp;&lt;br&gt;
PostDown = killall udp2raw || true&lt;/p&gt;

&lt;p&gt;[Peer]&lt;br&gt;
PublicKey = &amp;lt;client public key&amp;gt;&lt;br&gt;
AllowedIPs = 10.8.0.2/32&lt;/p&gt;

&lt;p&gt;Client:&lt;/p&gt;

&lt;p&gt;[Interface]&lt;br&gt;
Address = 10.8.0.2/24&lt;br&gt;
PrivateKey = &amp;lt;client private key&amp;gt;&lt;br&gt;
MTU = 1342&lt;br&gt;
PreUp = udp2raw -c -l 127.0.0.1:50001 -r 203.0.113.2:443 -k "shared secret" -a &amp;gt;/var/log/udp2raw.log 2&amp;gt;&amp;amp;1 &amp;amp;&lt;br&gt;
PostUp = ip route add 203.0.113.2 via 192.168.1.1&lt;br&gt;
PreDown = ip route del 203.0.113.2 via 192.168.1.1&lt;br&gt;
PostDown = killall udp2raw || true&lt;/p&gt;

&lt;p&gt;[Peer]&lt;br&gt;
PublicKey = &amp;lt;server public key&amp;gt;&lt;br&gt;
Endpoint = 127.0.0.1:50001&lt;br&gt;
AllowedIPs = 0.0.0.0/0&lt;/p&gt;

&lt;p&gt;Both ends drop to MTU 1342 because udp2raw cannot carry payloads as large as plain WireGuard; go lower if any link in the path is smaller. On the server, &lt;code&gt;-r 127.0.0.1:51820&lt;/code&gt; forwards into your real WireGuard listener. The &lt;code&gt;-a&lt;/code&gt; flag adds the iptables rules udp2raw needs, and forgetting it is the most common mistake.&lt;/p&gt;

&lt;p&gt;That PostUp route fixes a gotcha from the project wiki: with 0.0.0.0/0 in AllowedIPs the client needs an exception for the server's public IP, or the tunnel tries to carry its own traffic and loops. Replace 192.168.1.1 with your real gateway.&lt;/p&gt;

&lt;p&gt;Honest limits: it needs root, and the last tagged release is 20230206.0 (February 2023). The repo still gets commits but moves slowly, so build from source. Advanced DPI can fingerprint the FakeTCP handshake. ICMP mode is a last resort. Fake TCP has no congestion control, so expect a bit more latency and jitter.&lt;/p&gt;

&lt;h2&gt;
  
  
  Fix 2: AmneziaWG, the obfuscated WireGuard fork
&lt;/h2&gt;

&lt;p&gt;If the handshake starts and then dies, or WireGuard stays blocked for weeks, the network is fingerprinting the protocol. AmneziaWG is a fork of WireGuard-Go (MIT, with a GPL-2.0 kernel module). It keeps the same ChaCha20-Poly1305 cryptography and speed but changes how the traffic looks.&lt;/p&gt;

&lt;p&gt;The padding values S1-S4 randomize packet sizes, so the fixed sizes of 148, 92 and 64 bytes disappear. Before each handshake it sends junk packets: Jc sets how many (4 to 12 is recommended), and each one gets a random size between Jmin and Jmax. Version 2.0 added dynamic headers (H1-H4) and signature packets (I1-I5) that can imitate a QUIC initial. Version 3.1 encrypts the low-entropy header fields with ChaCha20 and requires S1-S4 to be at least 12.&lt;/p&gt;

&lt;p&gt;The catch: both ends must run AmneziaWG, because it does not talk to stock WireGuard. Clients cover Windows, macOS, Linux, Android and iOS via the Amnezia VPN app (4.8.12.7+) or the native AmneziaWG clients. Expect it to run slightly slower than stock WireGuard, and keep Jmax below your MTU so junk packets do not fragment.&lt;/p&gt;

&lt;h2&gt;
  
  
  Fix 3: wstunnel, when only HTTPS gets out
&lt;/h2&gt;

&lt;p&gt;wstunnel (Rust, BSD-3-Clause, actively developed) wraps UDP inside WebSocket or HTTP2 traffic on port 443.&lt;/p&gt;

&lt;h1&gt;
  
  
  server
&lt;/h1&gt;

&lt;p&gt;wstunnel server wss://0.0.0.0:443 --restrict-to 127.0.0.1:51820&lt;/p&gt;

&lt;h1&gt;
  
  
  client
&lt;/h1&gt;

&lt;p&gt;wstunnel client -L "udp://51820:localhost:51820?timeout_sec=0" wss://203.0.113.2:443&lt;/p&gt;

&lt;p&gt;Point the WireGuard client Endpoint at 127.0.0.1:51820. If you run a full tunnel, add the same server-IP route exception. If Nginx already uses port 443, run wstunnel on a local port and proxy WebSocket traffic to it, the same pattern as in my &lt;a href="https://selfhostpilot.com/nginx-reverse-proxy-setup-guide/" rel="noopener noreferrer"&gt;Nginx reverse proxy guide&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;The tradeoff: TCP brings head-of-line blocking and the double-TCP problem, so under packet loss it is slower than udp2raw or AmneziaWG. That is another reason to split-tunnel instead of pushing everything through it.&lt;/p&gt;

&lt;h2&gt;
  
  
  Split tunneling while the tunnel is fragile
&lt;/h2&gt;

&lt;p&gt;An obfuscated tunnel is slower and more fragile than plain WireGuard, so push less through it. Most of my clients on hotel Wi-Fi only need their Nextcloud, Matrix server or office subnet, so I route just that:&lt;/p&gt;

&lt;p&gt;`[Peer]&lt;br&gt;
PublicKey = &amp;lt;server public key&amp;gt;&lt;br&gt;
Endpoint = 127.0.0.1:50001&lt;br&gt;
AllowedIPs = 10.8.0.0/24, 192.168.50.0/24&lt;/p&gt;

&lt;h1&gt;
  
  
  no DNS line in [Interface]: your local resolver keeps working`
&lt;/h1&gt;

&lt;p&gt;With WireGuard split tunneling like this, browsing and video calls use the normal connection. Only private traffic goes through udp2raw or wstunnel. The server's public IP is outside AllowedIPs here, so there is no routing loop.&lt;/p&gt;

&lt;p&gt;One honest note: respect your employer's network policy and your local law. These are your own tools for your own server, which is the whole point of &lt;a href="https://selfhostpilot.com/what-is-self-hosting-beginners-guide/" rel="noopener noreferrer"&gt;self-hosting&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Which fix should you use?
&lt;/h2&gt;

&lt;p&gt;Match your symptom to the fix:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Everything works except UDP 51820:&lt;/strong&gt; move WireGuard to UDP 443 first. No extra software.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;UDP is blocked entirely (hotel, campus, some carriers):&lt;/strong&gt; udp2raw in faketcp mode on TCP 443.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;The handshake starts and then dies, or WireGuard has been blocked for weeks:&lt;/strong&gt; the network is fingerprinting the protocol, so use AmneziaWG.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;Only TCP 443 gets out:&lt;/strong&gt; wstunnel.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;strong&gt;You only need one subnet or one service:&lt;/strong&gt; use WireGuard split tunneling and skip obfuscation entirely.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Does split tunneling break WireGuard's privacy?
&lt;/h3&gt;

&lt;p&gt;No. WireGuard split tunneling only decides which traffic enters the tunnel, and that traffic stays fully encrypted. Everything else travels normally.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I use udp2raw with the official WireGuard app on my phone?
&lt;/h3&gt;

&lt;p&gt;Not on a normal phone. udp2raw needs root and raw sockets, which regular phone apps do not get, so on mobile use the Amnezia app with AmneziaWG instead.&lt;/p&gt;

&lt;h3&gt;
  
  
  Is AmneziaWG safe and audited?
&lt;/h3&gt;

&lt;p&gt;Largely, yes. AmneziaWG keeps WireGuard's ChaCha20-Poly1305 cryptography and only changes how packets look, and the code is open source. Check the Amnezia repositories for the current audit status.&lt;/p&gt;

&lt;h3&gt;
  
  
  Will a VPN bypassing a blocked network get me banned?
&lt;/h3&gt;

&lt;p&gt;It can. On an employer or campus network, bypassing controls may breach an acceptable use policy, so read the rules before you tunnel around them.&lt;/p&gt;

&lt;p&gt;If you would rather not fight MTU values and iptables rules from a hotel lobby, I can do it for you. Since 2020 I have deployed 30+ self-hosted Nextcloud, Jitsi, Matrix and VPN setups for small clients. Take a look at my &lt;a href="https://selfhostpilot.com/services/" rel="noopener noreferrer"&gt;self-hosting and VPN setup services&lt;/a&gt; and send me your server details.&lt;/p&gt;

</description>
      <category>selfhosted</category>
      <category>opensource</category>
      <category>devops</category>
      <category>ai</category>
    </item>
    <item>
      <title>Portainer 3.0 Drops the Community Edition: What Self-Hosters Should Run Instead</title>
      <dc:creator>SelfHost Pilot</dc:creator>
      <pubDate>Mon, 28 Sep 2026 06:54:19 +0000</pubDate>
      <link>https://dev.to/selfhostpilot/portainer-30-drops-the-community-edition-what-self-hosters-should-run-instead-22h8</link>
      <guid>https://dev.to/selfhostpilot/portainer-30-drops-the-community-edition-what-self-hosters-should-run-instead-22h8</guid>
      <description>&lt;p&gt;Three clients messaged me this week asking some version of "did Portainer just&lt;br&gt;
kill Community Edition?" Not exactly, but if you run Portainer CE on a homelab&lt;br&gt;
box or a client's Docker host, your upgrade path just changed.&lt;/p&gt;

&lt;p&gt;Here's what happened with Portainer, why RustFS hitting 1.0 matters if you&lt;br&gt;
self-host S3 storage, and the Navidrome update you should back up before&lt;br&gt;
touching.&lt;/p&gt;

&lt;h2&gt;
  
  
  Portainer 3.0 drops the Community Edition
&lt;/h2&gt;

&lt;p&gt;On 11 September 2026, Portainer CEO Neil Cresswell published a post on the&lt;br&gt;
&lt;a href="https://www.portainer.io/blog/portainer-3-0-is-&lt;br&gt;%0Acoming" rel="noopener noreferrer"&gt;official Portainer blog&lt;/a&gt; titled "Portainer 3.0 is coming, and here's what it means for you." I&lt;br&gt;
read it twice, since I run Portainer for half my Docker clients, and the&lt;br&gt;
framing was blunt.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Portainer 2.45 LTS is the last release in the 2.x line, and Portainer 3.0&lt;br&gt;
ships as a Kubernetes-first STS release with no separate Community Edition&lt;br&gt;
build. CE stays on 2.x and does not get 3.x features. Free access continues&lt;br&gt;
through the existing 3 Nodes Free program, not as a community-built release.&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;A maintenance build, 2.45.1 LTS, shipped on 17 September 2026 with security&lt;br&gt;
fixes and no new features. Portainer 3.0.0 arrives as an STS (short-term&lt;br&gt;
support) release, with a new 3.x LTS line later. Docker, Swarm and Podman&lt;br&gt;
still work in 3.x, but Portainer calls them "secondarily ordered" in the UI,&lt;br&gt;
and they won't get new capabilities in the policy engine, GitOps engine or&lt;br&gt;
observability layer. Every new product in the family, including Portainer-Run,&lt;br&gt;
Portainer-IDP, the Portainer-Command MCP gateway, Portainer-Operations and&lt;br&gt;
Portainer-AiGrid, is Kubernetes-only. See &lt;a href="https://linuxiac.com/portainer-3-0-goes-kubernetes-first-leaving-&lt;br&gt;%0Adocker-secondary/" rel="noopener noreferrer"&gt;Linuxiac's&lt;br&gt;
writeup&lt;/a&gt; and &lt;a href="https://www.heise.de/news/Enterprise-Schwenk-Portainer-friert-&lt;br&gt;%0ACommunity-Edition-ein-11459273.html" rel="noopener noreferrer"&gt;heise online's&lt;br&gt;
coverage&lt;/a&gt; for outside takes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why Portainer made the call
&lt;/h2&gt;

&lt;p&gt;Cresswell's reasoning: keeping one codebase fully featured across&lt;br&gt;
Docker/Podman, Swarm and Kubernetes stopped being realistic. Policy&lt;br&gt;
management, the operations API and the internal auth model each had to be&lt;br&gt;
built three times, once per substrate. There's an AI-agent angle too.&lt;br&gt;
Portainer argues Docker and Swarm have no equivalent of Kubernetes network&lt;br&gt;
policies, pod security standards or admission controllers, the primitives&lt;br&gt;
you'd want to sandbox autonomous agents. That's why the new lineup only&lt;br&gt;
targets Kubernetes.&lt;/p&gt;

&lt;p&gt;After the backlash, Cresswell clarified: "We are not abandoning Docker," and&lt;br&gt;
"nothing that works today gets ripped out of 2.x or the Docker environments in&lt;br&gt;
3.x." He said that if Docker support ever reaches end of life, users will hear&lt;br&gt;
about it well in advance with a migration path. Worth stating plainly: the&lt;br&gt;
free tier going forward is a Portainer Business licence tied to an account,&lt;br&gt;
not a community-maintained build. The &lt;a href="https://docs.portainer.io/start/lifecycle" rel="noopener noreferrer"&gt;Portainer lifecycle&lt;br&gt;
docs&lt;/a&gt; track the support timeline.&lt;/p&gt;

&lt;h2&gt;
  
  
  What this means if you run Docker at home
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Option&lt;/th&gt;
&lt;th&gt;What you get&lt;/th&gt;
&lt;th&gt;Where it breaks down&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Stay on Portainer 2.45 CE&lt;/td&gt;
&lt;td&gt;Security patches and back-ports while the LTS line&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;is supported&lt;/td&gt;
&lt;td&gt;No new features, and no fixed end-of-life date has been&lt;/td&gt;
&lt;td&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;announced&lt;br&gt;&lt;br&gt;
Move to Portainer 3.x free tier| Kubernetes-first policy engine, GitOps and&lt;br&gt;
observability, free via 3 Nodes Free| Docker becomes second-class in the UI&lt;br&gt;
and stops getting new capabilities&lt;br&gt;&lt;br&gt;
Docker-first alternatives| Docker-only tools: Dockge, Komodo, Arcane, Coolify,&lt;br&gt;
Dokploy| You give up Portainer's Kubernetes option if you ever need it  &lt;/p&gt;

&lt;h2&gt;
  
  
  What I would actually run
&lt;/h2&gt;

&lt;p&gt;For a single box, I run &lt;a href="https://techfuelhq.com/homelab/komodo-vs-&lt;br&gt;%0Aportainer-vs-dockge-2026/" rel="noopener noreferrer"&gt;Dockge&lt;/a&gt;, the lightweight Compose stack manager from the&lt;br&gt;
Uptime Kuma author, holding a couple of stacks on a VM I built with my own&lt;br&gt;
&lt;a href="https://selfhostpilot.com/proxmox-beginners-guide/" rel="noopener noreferrer"&gt;Proxmox guide&lt;/a&gt;. It's MIT&lt;br&gt;
licensed, it edits compose files directly, and it starts in seconds on a&lt;br&gt;
Raspberry Pi. Mine sits behind my own &lt;a href="https://selfhostpilot.com/nginx-reverse-proxy-setup-guide/" rel="noopener noreferrer"&gt;reverse&lt;br&gt;
proxy&lt;/a&gt;, never&lt;br&gt;
exposed.&lt;/p&gt;

&lt;p&gt;When I manage several client boxes and want GitOps, I reach for Komodo&lt;br&gt;
instead. It's GPL-3.0, it handles multi-server Docker deployments, and Dockge&lt;br&gt;
compose files port to it unchanged. Once you're juggling stacks across hosts,&lt;br&gt;
networking is what bites, which is why I still hand clients my &lt;a href="https://selfhostpilot.com/docker-networking-guide/" rel="noopener noreferrer"&gt;Docker&lt;br&gt;
networking guide&lt;/a&gt; before&lt;br&gt;
they scale up. Arcane suits anyone wanting a modern Go-based UI, and Coolify&lt;br&gt;
or Dokploy cover git-push-to-deploy with automatic SSL.&lt;/p&gt;

&lt;p&gt;None of this is urgent: if your homelab runs Portainer 2.45 CE today, nothing&lt;br&gt;
breaks tomorrow.&lt;/p&gt;

&lt;h2&gt;
  
  
  RustFS 1.0 is out, and MinIO left a gap
&lt;/h2&gt;

&lt;p&gt;On 18 September 2026, &lt;a href="https://rustfs.com/blog/" rel="noopener noreferrer"&gt;RustFS announced 1.0.0&lt;/a&gt;, an&lt;br&gt;
Apache-2.0 licensed, Rust-based, S3-compatible object storage system pitched&lt;br&gt;
as a drop-in replacement for MinIO and Amazon S3. It reports around 32,000&lt;br&gt;
GitHub stars and 2.7 million instances deployed since February 2024, with the&lt;br&gt;
source opened in July 2025.&lt;/p&gt;

&lt;p&gt;1.0 covers erasure coding, tiering and S3 Tables with a built-in Iceberg REST&lt;br&gt;
catalog, speaks S3, WebDAV, Swift, FTP/FTPS and MCP, and ships IAM, OIDC, KMS,&lt;br&gt;
server-side encryption and mTLS, plus distributed deployment and self-healing&lt;br&gt;
nodes. RustFS claims it's 2.3x faster than MinIO for 4KB objects; I haven't&lt;br&gt;
verified that myself.&lt;/p&gt;

&lt;p&gt;When MinIO adopted AGPL for parts of its stack in 2025, plenty of self-hosters&lt;br&gt;
went looking for a permissively licensed alternative, and that's the gap&lt;br&gt;
RustFS is filling. If your files live in &lt;a href="https://selfhostpilot.com/nextcloud-vs-google-drive-2026/" rel="noopener noreferrer"&gt;Nextcloud instead of Google&lt;br&gt;
Drive&lt;/a&gt;, it's the&lt;br&gt;
sort of S3 endpoint your backup jobs would point at. My hard rule for anything&lt;br&gt;
storage-related at version 1.0: never point your only backup target at it.&lt;br&gt;
Test a full restore before you trust it with anything you can't afford to&lt;br&gt;
lose.&lt;/p&gt;

&lt;h2&gt;
  
  
  Quick note: Navidrome 0.64
&lt;/h2&gt;

&lt;p&gt;Navidrome 0.64.0 landed on 12 September 2026 with an experimental Jellyfin&lt;br&gt;
Music API, so Jellyfin-oriented clients like Finamp and Jellify can now talk&lt;br&gt;
to a Navidrome server. It also adds a new artwork pipeline with blurred&lt;br&gt;
placeholders and a diagnostic CLI. Full notes are on the &lt;a href="https://github.com/navidrome/navidrome/releases" rel="noopener noreferrer"&gt;Navidrome releases&lt;br&gt;
page&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Before you upgrade: every internal ID was re-encoded to a single canonical&lt;br&gt;
128-bit base62 format, and the migration touches every table, so back up your&lt;br&gt;
database first and expect clients that cache item IDs to re-sync. The release&lt;br&gt;
also fixes a SQL injection via the artist role sort and filter parameters, a&lt;br&gt;
share-ownership spoofing issue, and plugin SSRF guard bypasses, so it's worth&lt;br&gt;
doing despite the migration risk.&lt;/p&gt;

&lt;h2&gt;
  
  
  Check who is behind the repo
&lt;/h2&gt;

&lt;p&gt;The &lt;a href="https://selfh.st/weekly/2026-09-18/" rel="noopener noreferrer"&gt;selfh.st weekly newsletter&lt;/a&gt; reported&lt;br&gt;
on 18 September 2026 that BookOrbit, a suddenly popular self-hosted app,&lt;br&gt;
turned out to be run by the developer behind Booklore, an app that vanished&lt;br&gt;
earlier in 2026 after being called out over code quality, contributor&lt;br&gt;
treatment and licence issues. Before you hand a new project your data, check&lt;br&gt;
the maintainer's history and the licence, not just the feature list.&lt;/p&gt;

&lt;h2&gt;
  
  
  FAQ
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Is Portainer Community Edition being discontinued?&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
Not immediately. Portainer 2.45 LTS is the last release in the 2.x line, and&lt;br&gt;
Portainer 3.0 ships as a Kubernetes-first STS release with no separate CE&lt;br&gt;
build. The 2.45 LTS line keeps getting security fixes while it's supported,&lt;br&gt;
but no fixed end-of-life date has been announced.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Will Portainer 3.x work with Docker?&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
Yes. Docker, Swarm and Podman still work in 3.x, but Portainer places them as&lt;br&gt;
secondarily ordered in the UI and says they won't get new capabilities in the&lt;br&gt;
policy engine, GitOps engine or observability layer, since every new feature&lt;br&gt;
is built Kubernetes-first.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Is RustFS a safe MinIO replacement yet?&lt;/strong&gt;&lt;br&gt;&lt;br&gt;
RustFS 1.0 reached general availability on 18 September 2026 with erasure&lt;br&gt;
coding, tiering, site replication and an Apache-2.0 licence. It's promising,&lt;br&gt;
but after a fresh 1.0 I wouldn't move a sole backup target to it without&lt;br&gt;
testing a full restore first.&lt;/p&gt;

&lt;h2&gt;
  
  
  My take
&lt;/h2&gt;

&lt;p&gt;Nothing here means you need to touch your Docker setup today. If you're on&lt;br&gt;
Portainer 2.45 CE and it works, update to 2.45.1 LTS and move on. If you're&lt;br&gt;
starting fresh, or planning GitOps across multiple boxes, look at Dockge or&lt;br&gt;
Komodo before committing to Portainer 3.x, unless you're actually planning to&lt;br&gt;
run Kubernetes. RustFS gets the timing right, but the maturity isn't proven,&lt;br&gt;
so treat 1.0 as promising rather than trusted with your only copy of anything.&lt;br&gt;
This week's to-do list: update Portainer to 2.45.1 LTS, back up your Navidrome&lt;br&gt;
database before upgrading, and test a restore on anything you point at RustFS.&lt;/p&gt;

</description>
      <category>selfhosted</category>
      <category>opensource</category>
      <category>devops</category>
      <category>privacy</category>
    </item>
    <item>
      <title>ServerPilot Alternatives: CyberPanel, aaPanel, CloudPanel</title>
      <dc:creator>SelfHost Pilot</dc:creator>
      <pubDate>Wed, 23 Sep 2026 03:38:38 +0000</pubDate>
      <link>https://dev.to/selfhostpilot/serverpilot-alternatives-cyberpanel-aapanel-cloudpanel-3nl6</link>
      <guid>https://dev.to/selfhostpilot/serverpilot-alternatives-cyberpanel-aapanel-cloudpanel-3nl6</guid>
      <description>&lt;h2&gt;
  
  
  ServerPilot alternatives in 2026: the short answer
&lt;/h2&gt;

&lt;p&gt;The three ServerPilot alternatives worth using in 2026 are CyberPanel, aaPanel&lt;br&gt;
and CloudPanel. Each has a free edition you install on your own VPS.&lt;br&gt;
ServerPilot is still alive and still works well, but it charges per server and&lt;br&gt;
per app, so the bill grows every time you add a client site.&lt;/p&gt;

&lt;p&gt;A control panel is a web dashboard that installs and manages your web server,&lt;br&gt;
PHP, databases and SSL. I have moved client sites from ServerPilot to all&lt;br&gt;
three panels below. New to this? Start with &lt;a href="https://selfhostpilot.com/what-is-self-hosting-beginners-guide/" rel="noopener noreferrer"&gt;what self-hosting&lt;br&gt;
means&lt;/a&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  What ServerPilot actually costs in 2026 (and what it doesn't do)
&lt;/h2&gt;

&lt;p&gt;ServerPilot costs $5 to $20 per server plus $0.50 to $2 per app each month, on&lt;br&gt;
top of your cloud bill. It is a SaaS that manages a server you rent from&lt;br&gt;
DigitalOcean, AWS, Google Cloud, UpCloud or Linode.&lt;/p&gt;

&lt;p&gt;Plans are billed hourly, with a 14-day free trial and no card needed:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Economy:&lt;/strong&gt; $5/server + $0.50/app per month&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Business:&lt;/strong&gt; $10/server + $1/app per month&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;First Class:&lt;/strong&gt; $20/server + $2/app per month&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It installs Nginx in front of Apache (for &lt;code&gt;.htaccess&lt;/code&gt; rules), PHP-FPM, MySQL,&lt;br&gt;
multiple PHP versions, AutoSSL, automated security updates, an iptables&lt;br&gt;
firewall and one-click WordPress, with app isolation.&lt;/p&gt;

&lt;p&gt;It is a PHP-only tool: no email server, no DNS management and no one-click&lt;br&gt;
Node.js or Python. Economy has almost no monitoring. Logs and server metrics&lt;br&gt;
start at Business; per-app and MySQL metrics need First Class.&lt;/p&gt;

&lt;h2&gt;
  
  
  CyberPanel: free, full-featured and fast on OpenLiteSpeed
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; CyberPanel is the best free pick if you need email, DNS and a&lt;br&gt;
file manager in one panel for mostly WordPress sites.&lt;/p&gt;

&lt;p&gt;It is open source and built on OpenLiteSpeed, a free web server. The free tier&lt;br&gt;
includes unlimited domains, SSL, DNS, mail, FTP, a file manager, MySQL,&lt;br&gt;
backups, a Docker manager, a WordPress manager, a firewall and cron.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where CyberPanel wins
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Websites and client email live on one box for $0.&lt;/li&gt;
&lt;li&gt;Updates ship very often, so security fixes land fast — and you cannot safely skip them.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Where CyberPanel hurts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;OpenLiteSpeed is not a drop-in replacement for Apache. Some &lt;code&gt;.htaccess&lt;/code&gt; rewrite rules need hand-tuning.&lt;/li&gt;
&lt;li&gt;Paid LiteSpeed Enterprise is billed per server. The free Starter licence caps you at 1 domain and 2GB RAM. Site Owner is $11/month (5 domains) and Web Host Lite is $28/month (unlimited domains).&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  aaPanel: the most features for a one-time price
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; aaPanel is the right choice for a cPanel-style dashboard with&lt;br&gt;
multiple users, if a China-based project is acceptable.&lt;/p&gt;

&lt;p&gt;It is the international edition of BT Panel, with 200+ releases since 2017&lt;br&gt;
and, by its own site's claim, installs on 3,000,000+ servers. The free-for-&lt;br&gt;
life edition has no domain limit and includes mail, FTP, MySQL, a file manager&lt;br&gt;
with a code editor, cron and Docker.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where aaPanel wins
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Pro is a lifetime licence, not a subscription. 2026 promotions ran at about $399.&lt;/li&gt;
&lt;li&gt;Pro adds sub-accounts for shared-hosting setups, an Nginx WAF (web application firewall), file protection, bulk mail and the WP Toolkit.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Where aaPanel hurts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The free panel has an account and telemetry tie-in. Flag this if a client has data-residency or supply-chain rules.&lt;/li&gt;
&lt;li&gt;English docs lag behind the Chinese ones.&lt;/li&gt;
&lt;li&gt;Some Pro features are per-seat extras.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  CloudPanel: free, minimal and the lightest of the three
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;Verdict:&lt;/strong&gt; CloudPanel is the closest free replacement for ServerPilot,&lt;br&gt;
because it does hosting well and deliberately skips everything else.&lt;/p&gt;

&lt;p&gt;It has no paid tier, no email server, no DNS server and no web file manager.&lt;br&gt;
You upload files over SFTP instead.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where CloudPanel wins
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;The memory footprint is tiny. Its docs say a properly optimised 4GB RAM server can carry roughly 10–15 busy websites.&lt;/li&gt;
&lt;li&gt;You get PHP (many versions), Node.js and Python sites, per-site databases and users, auto-renewing Let's Encrypt, a reverse proxy and Varnish-style caching.&lt;/li&gt;
&lt;li&gt;It runs on Ubuntu, Debian, Rocky Linux 9 and AlmaLinux 9, on x86 or ARM64.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Where CloudPanel hurts
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;It refuses to install if Apache, Nginx or MySQL is already present, so you must start from a fresh OS.&lt;/li&gt;
&lt;li&gt;The minimum is 1 core, 2GB RAM and 10GB disk, but I would not go below 2 cores.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Before any panel install, I run two checks on the new VPS:&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;free -h
systemctl list-units --type=service | grep -E 'apache2|nginx|mysql'
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;The first shows RAM; the second should print nothing. If it lists a service,&lt;br&gt;
reinstall the OS. My &lt;a href="https://selfhostpilot.com/nginx-reverse-proxy-setup-guide/" rel="noopener noreferrer"&gt;NGINX reverse proxy&lt;br&gt;
guide&lt;/a&gt; covers&lt;br&gt;
custom proxy setups.&lt;/p&gt;

&lt;h2&gt;
  
  
  Side-by-side comparison
&lt;/h2&gt;

&lt;p&gt;ServerPilot is the only option here with no free tier; the other three cost&lt;br&gt;
nothing to start.&lt;/p&gt;

&lt;p&gt;Panel| Cost (2026)| Built-in email| File manager| Reverse proxy / caching|&lt;br&gt;
Best for&lt;br&gt;&lt;br&gt;
---|---|---|---|---|---&lt;br&gt;&lt;br&gt;
ServerPilot| $5/server + $0.50/app| No| No (SFTP only)| Nginx in front of&lt;br&gt;
Apache| Hands-off PHP and WordPress hosting&lt;br&gt;&lt;br&gt;
CyberPanel| Free (open source)| Yes| Yes| OpenLiteSpeed with LSCache|&lt;br&gt;
WordPress plus client email&lt;br&gt;&lt;br&gt;
aaPanel| Free; Pro lifetime about $399| Yes| Yes| Nginx; WAF on Pro| Multi-&lt;br&gt;
user hosting&lt;br&gt;&lt;br&gt;
CloudPanel| Free (no paid tier)| No| No (SFTP only)| Built-in reverse proxy&lt;br&gt;
and page caching| PHP, Node.js and Python apps  &lt;/p&gt;

&lt;h2&gt;
  
  
  $0 vs $38 a month: a real cost example
&lt;/h2&gt;

&lt;p&gt;Three client VPS with 8 apps cost $38 a month on ServerPilot Business and $0&lt;br&gt;
on CloudPanel.&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;(3 servers × $10) + (8 apps × $1) = $38/month
$38 × 12 = $456/year
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;CloudPanel handles a setup this size comfortably, and CyberPanel on&lt;br&gt;
OpenLiteSpeed is also $0. The 1-domain, 2GB RAM cap applies only to the free&lt;br&gt;
Starter LiteSpeed licence.&lt;/p&gt;

&lt;p&gt;In rupees, $38 is over ₹3,000 a month, while many of my Indian clients pay&lt;br&gt;
₹400–₹800 for a Contabo or Hetzner box. Panel fees that cost more than the&lt;br&gt;
server itself are the biggest reason people leave ServerPilot.&lt;/p&gt;

&lt;p&gt;Count your hours too: the migration is a weekend if you do it yourself, or one&lt;br&gt;
to two days of paid work.&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;Pick the panel that fits the apps you actually run, not the one with the&lt;br&gt;
longest feature list.&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  Other ServerPilot-style tools worth knowing
&lt;/h2&gt;

&lt;p&gt;If you would rather pay for a hosted dashboard:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;RunCloud:&lt;/strong&gt; no free tier since 2024. Pricing runs about $8–9/month for single-server Basic, $15 for Pro and $45 for Business, and it feels the most like ServerPilot.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Ploi:&lt;/strong&gt; a genuinely usable free tier (1 server, 1 site, 5 deployments a month), then €8/$10 Basic, €13/$16 Pro and €30/$36 Unlimited. Its MCP server lets Claude, ChatGPT or Cursor drive your servers.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SpinupWP:&lt;/strong&gt; WordPress only. It costs $12/month (Essentials) or $19/month (Advanced) for one server with unlimited sites, plus about $1/month per extra server.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Laravel Forge:&lt;/strong&gt; roughly $12, $19 and $39 a month, billed per account rather than per server. It also handles Rails, Go, Node and Python.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Which one I would install for your case
&lt;/h2&gt;

&lt;p&gt;The right panel depends on email, app types and who needs a login:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;WordPress plus client email on one VPS:&lt;/strong&gt; CyberPanel.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reselling cheap hosting with a login per customer:&lt;/strong&gt; aaPanel Pro, if supply-chain rules allow it.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Mixed PHP, Node.js and Python apps on a 2–4GB box:&lt;/strong&gt; CloudPanel.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;You never want to SSH in and are happy to pay monthly:&lt;/strong&gt; Ploi or RunCloud.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;A Laravel or multi-language dev team:&lt;/strong&gt; Laravel Forge.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;My &lt;a href="https://selfhostpilot.com/proxmox-beginners-&lt;br&gt;%0Aguide/" rel="noopener noreferrer"&gt;Proxmox beginner guide&lt;/a&gt; covers spinning up a throwaway VM, and the &lt;a href="https://selfhostpilot.com/wireguard-vpn-server-linux-setup-guide/" rel="noopener noreferrer"&gt;WireGuard VPN&lt;br&gt;
guide&lt;/a&gt;&lt;br&gt;
keeps panel logins off the public internet.&lt;/p&gt;

&lt;h2&gt;
  
  
  Frequently asked questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Is CyberPanel really free?
&lt;/h3&gt;

&lt;p&gt;Yes. CyberPanel on OpenLiteSpeed is free and open source with unlimited&lt;br&gt;
domains. You only pay if you move to a paid LiteSpeed Enterprise licence,&lt;br&gt;
which starts at $11/month.&lt;/p&gt;

&lt;h3&gt;
  
  
  Do I need a control panel at all if I know Linux?
&lt;/h3&gt;

&lt;p&gt;No, but once you pass two or three sites a panel saves real time. It mostly&lt;br&gt;
automates SSL renewals, per-site users and safe client logins.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is the closest thing to ServerPilot?
&lt;/h3&gt;

&lt;p&gt;RunCloud is the closest paid replacement and CloudPanel the closest free one.&lt;br&gt;
CloudPanel sticks to hosting like ServerPilot, and it also runs Node.js and&lt;br&gt;
Python.&lt;/p&gt;

&lt;h3&gt;
  
  
  Can I migrate from ServerPilot without downtime?
&lt;/h3&gt;

&lt;p&gt;Yes, if you build the new server beside the old one. Copy files and databases,&lt;br&gt;
test through your hosts file, and lower the DNS TTL (how long resolvers cache&lt;br&gt;
records) a day early. Switch DNS, run a final database sync, then cancel&lt;br&gt;
ServerPilot.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;ServerPilot is still a good product, but charging per server and per app hurts&lt;br&gt;
small budgets. CloudPanel replaces it for most of my clients. If you need&lt;br&gt;
email, choose CyberPanel, and for multi-user hosting, choose aaPanel.&lt;/p&gt;

&lt;p&gt;If you want help setting up Nextcloud, Jitsi, Matrix or Moodle, or a careful&lt;br&gt;
panel migration off ServerPilot, &lt;a href="https://selfhostpilot.com/services/" rel="noopener noreferrer"&gt;get in touch&lt;br&gt;
here&lt;/a&gt;. Before any work starts, I will&lt;br&gt;
tell you honestly which panel fits.&lt;/p&gt;

</description>
      <category>selfhosted</category>
      <category>opensource</category>
      <category>devops</category>
      <category>privacy</category>
    </item>
    <item>
      <title>Docker Networking Explained: A Practical 2026 Guide</title>
      <dc:creator>SelfHost Pilot</dc:creator>
      <pubDate>Wed, 16 Sep 2026 03:43:16 +0000</pubDate>
      <link>https://dev.to/selfhostpilot/docker-networking-explained-a-practical-2026-guide-3ci9</link>
      <guid>https://dev.to/selfhostpilot/docker-networking-explained-a-practical-2026-guide-3ci9</guid>
      <description>&lt;p&gt;The first time I ran two containers on the same host and expected them to see&lt;br&gt;
each other, I got "connection refused" for an hour. Both were up, both worked&lt;br&gt;
alone, and pinging one by name from the other did nothing. In Docker, name&lt;br&gt;
resolution is not automatic. It depends on which network the containers are&lt;br&gt;
on.&lt;/p&gt;

&lt;p&gt;I have deployed 30-plus Nextcloud, Jitsi, Matrix, and Moodle stacks for&lt;br&gt;
clients, and almost every networking ticket traces back to four problems:&lt;br&gt;
containers in one project that cannot talk, a service that answers curl&lt;br&gt;
locally but not from a laptop, a database port open to the internet even&lt;br&gt;
though UFW blocks it, and host mode copied from a tutorial without knowing&lt;br&gt;
what it gives up.&lt;/p&gt;

&lt;h2&gt;
  
  
  How Docker Networking Actually Works
&lt;/h2&gt;

&lt;p&gt;Every container gets its own network namespace, Linux's way of giving a&lt;br&gt;
process its own interfaces, routes, and IP address. Docker links that&lt;br&gt;
namespace to the host with a virtual ethernet (veth) pair: one end inside the&lt;br&gt;
container, the other plugged into a bridge on the host, like a virtual switch.&lt;/p&gt;

&lt;p&gt;That bridge is &lt;code&gt;docker0&lt;/code&gt; by default. Outbound traffic is translated by NAT to&lt;br&gt;
the host's IP, the same trick your home router uses, and publishing a port&lt;br&gt;
with &lt;code&gt;-p&lt;/code&gt; sets up the reverse rule. That one mechanism explains most of the&lt;br&gt;
surprises below.&lt;/p&gt;

&lt;h2&gt;
  
  
  Docker's Network Drivers, Compared
&lt;/h2&gt;

&lt;p&gt;Docker Engine 29.x ships six network drivers; five matter in practice.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Driver&lt;/th&gt;
&lt;th&gt;What it does&lt;/th&gt;
&lt;th&gt;Use it when&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;bridge&lt;/td&gt;
&lt;td&gt;Private network on the host, NAT to reach outside&lt;/td&gt;
&lt;td&gt;Default choice for&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;almost every single-host setup&lt;br&gt;&lt;br&gt;
host| Container shares the host's namespace, no NAT| The app needs raw&lt;br&gt;
throughput or binds ports dynamically&lt;br&gt;&lt;br&gt;
overlay| VXLAN network spanning multiple hosts| You run Swarm across more than&lt;br&gt;
one server&lt;br&gt;&lt;br&gt;
macvlan| Own MAC address and a real IP on your LAN| The container must look&lt;br&gt;
like a physical device&lt;br&gt;&lt;br&gt;
ipvlan| Containers share the parent's MAC, separate IPs| Your switch limits&lt;br&gt;
MACs per port&lt;br&gt;&lt;br&gt;
none| No networking at all| Rare, for isolated batch jobs  &lt;/p&gt;

&lt;p&gt;New to containers? My &lt;a href="https://selfhostpilot.com/docker-for-beginners-first-container-&lt;br&gt;%0Amistakes/" rel="noopener noreferrer"&gt;Docker for beginners&lt;br&gt;
guide&lt;/a&gt; covers the earlier mistakes.&lt;/p&gt;

&lt;h2&gt;
  
  
  The Default Bridge Is Not Good Enough
&lt;/h2&gt;

&lt;p&gt;Installing Docker creates a default bridge called &lt;code&gt;docker0&lt;/code&gt; on subnet&lt;br&gt;
&lt;code&gt;172.17.0.0/16&lt;/code&gt; with gateway &lt;code&gt;172.17.0.1&lt;/code&gt;. Every container started without&lt;br&gt;
&lt;code&gt;--network&lt;/code&gt; lands there.&lt;/p&gt;

&lt;p&gt;The catch: it has no DNS between containers, so you cannot reach one by name.&lt;br&gt;
The old answer, the &lt;code&gt;--link&lt;/code&gt; flag, was deprecated years ago and should not&lt;br&gt;
appear in new work; Docker's docs now treat the default bridge as legacy.&lt;/p&gt;

&lt;p&gt;Create your own instead:&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;docker network create --driver bridge --subnet 172.20.0.0/16 mynet
docker run -d --name app --network mynet nginx
docker run -d --name db --network mynet postgres:16
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;Any network you create is a user-defined network, and Docker runs an embedded&lt;br&gt;
DNS server at &lt;code&gt;127.0.0.11&lt;/code&gt; inside every container attached to it. It maps&lt;br&gt;
container names and aliases to their current IPs and forwards everything else&lt;br&gt;
upstream. That is the biggest reason to abandon the default bridge.&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;docker exec -it app ping -c2 db
docker exec -it app nslookup db 127.0.0.11
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;
&lt;h2&gt;
  
  
  Containers Talking to Containers (Compose)
&lt;/h2&gt;

&lt;p&gt;This is why Compose usually just works. &lt;code&gt;docker compose up&lt;/code&gt; creates a user-&lt;br&gt;
defined bridge per project named &lt;code&gt;&amp;lt;project&amp;gt;_default&lt;/code&gt;, so embedded DNS is live&lt;br&gt;
immediately and every service is reachable by its service name.&lt;/p&gt;

&lt;p&gt;If services cannot reach each other, check two things: they live in the same&lt;br&gt;
Compose file and start together, and they connect by service name rather than&lt;br&gt;
&lt;code&gt;localhost&lt;/code&gt;. A web app should talk to &lt;code&gt;db:5432&lt;/code&gt;, not &lt;code&gt;127.0.0.1:5432&lt;/code&gt;, because&lt;br&gt;
inside a container &lt;code&gt;localhost&lt;/code&gt; is the container itself.&lt;/p&gt;

&lt;p&gt;One pattern I use often: give the database a network with no way out.&lt;/p&gt;
&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;services:
  web:
    image: myapp:latest
    networks: [frontend, backend]
    ports:
      - "127.0.0.1:8080:80"
  db:
    image: postgres:16
    networks: [backend]

networks:
  frontend:
  backend:
    internal: true
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;&lt;code&gt;internal: true&lt;/code&gt; means containers on &lt;code&gt;backend&lt;/code&gt; cannot reach the internet and&lt;br&gt;
nothing outside can reach them. The database can talk to &lt;code&gt;web&lt;/code&gt;; nothing can&lt;br&gt;
talk to the database directly.&lt;/p&gt;

&lt;h2&gt;
  
  
  Ports, UFW, and the Security Mistake Everyone Makes
&lt;/h2&gt;

&lt;p&gt;This one surprises experienced admins. You configure UFW, block 5432 from&lt;br&gt;
outside, run &lt;code&gt;docker run -p 5432:5432 postgres&lt;/code&gt;, and Postgres is still&lt;br&gt;
reachable from the internet. UFW never saw the decision.&lt;/p&gt;

&lt;p&gt;Publishing a port is DNAT, and Docker writes its own rules into the &lt;code&gt;DOCKER&lt;/code&gt;&lt;br&gt;
and &lt;code&gt;DOCKER-USER&lt;/code&gt; iptables chains, ahead of your regular firewall rules. It is&lt;br&gt;
documented, expected behavior rather than a bug.&lt;/p&gt;

&lt;p&gt;Three fixes, simplest first:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Bind to localhost: &lt;code&gt;-p 127.0.0.1:5432:5432&lt;/code&gt;. Nothing outside the host can reach it. Put a reverse proxy in front for anything public; my &lt;a href="https://selfhostpilot.com/nginx-reverse-proxy-setup-guide/" rel="noopener noreferrer"&gt;NGINX reverse proxy guide&lt;/a&gt; covers that.&lt;/li&gt;
&lt;li&gt;Add rules to the &lt;code&gt;DOCKER-USER&lt;/code&gt; chain, evaluated before Docker's forwarding rules.&lt;/li&gt;
&lt;li&gt;Use the &lt;code&gt;ufw-docker&lt;/code&gt; tool if you want UFW to stay in charge.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;For anything holding real data I use option one on nearly every client server.&lt;/p&gt;

&lt;h2&gt;
  
  
  When to Use Host Mode (and When Not To)
&lt;/h2&gt;

&lt;p&gt;With &lt;code&gt;network_mode: host&lt;/code&gt; the container gives up its own network namespace and&lt;br&gt;
shares the host's. No veth pair, no NAT, lower latency. Fair for Home&lt;br&gt;
Assistant, some Pi-hole setups, and services where NAT overhead measurably&lt;br&gt;
matters.&lt;/p&gt;

&lt;p&gt;The cost: &lt;code&gt;ports:&lt;/code&gt; is ignored and the app binds host ports directly, so two&lt;br&gt;
host-mode containers cannot both want 8080, and you lose isolation. Default to&lt;br&gt;
bridge; use host mode only for a measured reason, such as multicast device&lt;br&gt;
discovery.&lt;/p&gt;

&lt;h2&gt;
  
  
  Giving a Container a Real LAN IP with Macvlan
&lt;/h2&gt;

&lt;p&gt;Macvlan gives a container its own MAC address and a real IP on your LAN, so&lt;br&gt;
your router sees it as a separate physical machine. That matters for Home&lt;br&gt;
Assistant when it must see Z-Wave or Zigbee devices over multicast, and for&lt;br&gt;
Pi-hole when every device should use it as their DNS server by IP.&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;docker network create -d macvlan \
  --subnet=192.168.1.0/24 --gateway=192.168.1.1 \
  -o parent=eth0 macnet

docker run -d --name pihole --network macnet --ip 192.168.1.50 pihole/pihole
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;

&lt;p&gt;The gotcha: the host cannot talk to its own macvlan containers by default,&lt;br&gt;
because traffic from the parent interface back to a macvlan child on the same&lt;br&gt;
interface is dropped by the kernel. The fix is a macvlan shim, a small host&lt;br&gt;
interface bridged into the same network, created with &lt;code&gt;ip link add&lt;/code&gt;. Skip it&lt;br&gt;
and the container works from every device except the one running Docker.&lt;/p&gt;

&lt;p&gt;IPvlan is similar, but containers share the parent's MAC, which helps where&lt;br&gt;
your switch limits MACs per port. Overlay is the multi-host option, tunneling&lt;br&gt;
traffic with VXLAN on UDP 4789, and rarely worth the complexity outside Swarm.&lt;br&gt;
IPv6 is off by default and must be enabled in &lt;code&gt;/etc/docker/daemon.json&lt;/code&gt;. And&lt;br&gt;
on rootless Docker in 2026, networking now defaults to &lt;code&gt;gvisor-tap-vsock&lt;/code&gt;&lt;br&gt;
instead of &lt;code&gt;slirp4netns&lt;/code&gt;, a slower path than rootful Docker.&lt;/p&gt;

&lt;h2&gt;
  
  
  Three Fixes for the Errors I See Most
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;A container name will not resolve.&lt;/strong&gt; Compare networks with &lt;code&gt;docker network inspect mynet&lt;/code&gt;. Containers on the default bridge, or split across two Compose projects, will never resolve each other. Test from inside: &lt;code&gt;docker exec -it app nslookup db 127.0.0.11&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Connection refused although the process is running.&lt;/strong&gt; Usually not a networking problem. Check the bind address inside the container with &lt;code&gt;netstat -tlnp&lt;/code&gt;. If the app listens on &lt;code&gt;127.0.0.1&lt;/code&gt; instead of &lt;code&gt;0.0.0.0&lt;/code&gt;, it only accepts connections from itself, and no port mapping can fix that.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;TLS handshakes hang over a VPN.&lt;/strong&gt; Usually an MTU mismatch. Containers default to 1500 while WireGuard tunnels typically run at 1420. Set &lt;code&gt;"mtu": 1420&lt;/code&gt; in &lt;code&gt;/etc/docker/daemon.json&lt;/code&gt; or per-network with &lt;code&gt;driver_opts&lt;/code&gt;, then restart the containers.&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Frequently Asked Questions
&lt;/h2&gt;

&lt;h3&gt;
  
  
  Do I need a custom Docker network?
&lt;/h3&gt;

&lt;p&gt;Yes, for anything beyond a standalone container. The default bridge has no DNS&lt;br&gt;
between containers, so a user-defined bridge is the standard fix for name-&lt;br&gt;
based service discovery.&lt;/p&gt;

&lt;h3&gt;
  
  
  What is 127.0.0.11 in Docker?
&lt;/h3&gt;

&lt;p&gt;It is the embedded DNS server Docker runs inside containers on a user-defined&lt;br&gt;
network. It resolves container names and aliases to their current IPs and&lt;br&gt;
forwards other lookups upstream.&lt;/p&gt;

&lt;h3&gt;
  
  
  How do I stop a container port from being public?
&lt;/h3&gt;

&lt;p&gt;Bind it to localhost, for example &lt;code&gt;-p 127.0.0.1:8080:80&lt;/code&gt;, and put a reverse&lt;br&gt;
proxy in front of anything that must be public. That avoids the trap where&lt;br&gt;
Docker's iptables rules bypass UFW.&lt;/p&gt;

&lt;h3&gt;
  
  
  Does host networking make Docker faster?
&lt;/h3&gt;

&lt;p&gt;It removes NAT and the veth pair, lowering latency and CPU overhead slightly,&lt;br&gt;
but the difference is rarely noticeable for typical self-hosted apps. It also&lt;br&gt;
disables port mapping and isolation, so it is a tradeoff, not a free upgrade.&lt;/p&gt;

&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;Most Docker networking problems come down to one root cause: not knowing which&lt;br&gt;
network a container is actually on, or assuming a port is private when Docker&lt;br&gt;
has quietly made it public. Create your own networks, check bind addresses,&lt;br&gt;
and most of this stops being mysterious.&lt;/p&gt;

&lt;p&gt;Setting up Nextcloud, Jitsi, Matrix, or Moodle and want a second pair of eyes&lt;br&gt;
on the networking before go-live? Feel free to reach out. This is what I fix&lt;br&gt;
for clients every week.&lt;/p&gt;

</description>
      <category>selfhosted</category>
      <category>opensource</category>
      <category>devops</category>
      <category>privacy</category>
    </item>
    <item>
      <title>DeepSeek V4.1 Flash: MIT Open Weights, But Can You Self-Host It?</title>
      <dc:creator>SelfHost Pilot</dc:creator>
      <pubDate>Mon, 14 Sep 2026 03:35:04 +0000</pubDate>
      <link>https://dev.to/selfhostpilot/deepseek-v41-flash-mit-open-weights-but-can-you-self-host-it-4l37</link>
      <guid>https://dev.to/selfhostpilot/deepseek-v41-flash-mit-open-weights-but-can-you-self-host-it-4l37</guid>
      <description>&lt;p&gt;DeepSeek dropped a new model this week, and my inbox has three variations of&lt;br&gt;
the same question: "this is open weights, right, can I run it on my server?"&lt;br&gt;
Short answer: technically yes, practically no. Let me walk through why.&lt;/p&gt;

&lt;h2&gt;
  
  
  What is DeepSeek V4.1 Flash
&lt;/h2&gt;

&lt;p&gt;&lt;strong&gt;DeepSeek V4.1 Flash is a 552-billion-parameter, MIT-licensed mixture-of-&lt;br&gt;
experts model released on 10 September 2026, which DeepSeek says beats GPT-5.6&lt;br&gt;
Sol and Claude Opus-5.0 on several agentic coding benchmarks while activating&lt;br&gt;
only 8-16 billion parameters per token.&lt;/strong&gt; Weights are public on &lt;a href="https://huggingface.co/deepseek-ai/DeepSeek-V4.1-Flash" rel="noopener noreferrer"&gt;Hugging&lt;br&gt;
Face&lt;/a&gt;, and the&lt;br&gt;
official write-up is on &lt;a href="https://www.deepseek.com/en/news/deepseek-v4-1-flash/" rel="noopener noreferrer"&gt;DeepSeek's&lt;br&gt;
site&lt;/a&gt; and the &lt;a href="https://api-docs.deepseek.com/news/news260910/" rel="noopener noreferrer"&gt;API docs&lt;br&gt;
changelog&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Starting today, 14 September 2026, DeepSeek is also rerouting all&lt;br&gt;
&lt;code&gt;deepseek-v4-pro&lt;/code&gt; API traffic to V4.1-Flash, and phasing V4-Pro out entirely.&lt;br&gt;
If you were calling the Pro endpoint, you are already on this new model&lt;br&gt;
whether you asked for it or not.&lt;/p&gt;

&lt;h2&gt;
  
  
  The architecture, in plain words
&lt;/h2&gt;

&lt;p&gt;This is not just a bigger version of the old V4-Flash. DeepSeek rebuilt the&lt;br&gt;
internals. It uses a new "Causal Encoder-Decoder" (CED) design: a 40-layer&lt;br&gt;
transformer split into a 20-layer causal encoder and a 20-layer decoder. There&lt;br&gt;
are 384 routed experts plus 1 shared expert per MoE layer, and only 6 routed&lt;br&gt;
experts fire per token.&lt;/p&gt;

&lt;p&gt;It is natively multimodal, meaning it reads images directly without a bolted-&lt;br&gt;
on vision encoder. Context window is 1 million tokens, with output up to 384K&lt;br&gt;
tokens. Reasoning effort is a dial you can turn from 1 to 100, so you trade&lt;br&gt;
speed for depth on demand.&lt;/p&gt;

&lt;p&gt;The KV cache work is genuinely clever: about 890 bytes per token, roughly a&lt;br&gt;
quarter of the old V4-Flash and an eighth of the SSD storage, using Compressed&lt;br&gt;
Sparse Attention 2, FP4 (E2M1) KV caching, SWA Bounded Replay, and a&lt;br&gt;
196-billion-parameter "Engram" memory module accessed sparsely. DeepSeek&lt;br&gt;
claims a 437x cache reduction versus the original V1 model. It was trained&lt;br&gt;
from scratch on 45 trillion tokens, with context extended to 1M around the&lt;br&gt;
34T-token mark. If you've followed the &lt;a href="https://selfhostpilot.com/qwen3-8-flash-next-qwen4-architecture-&lt;br&gt;%0Apreview/" rel="noopener noreferrer"&gt;Qwen3 architecture&lt;br&gt;
previews&lt;/a&gt;, this is the same industry trend: shrink the active compute, keep&lt;br&gt;
the total knowledge huge.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where it actually wins (and where it doesn't)
&lt;/h2&gt;

&lt;p&gt;The benchmark numbers are real, but they are mixed, not a clean sweep. Here is&lt;br&gt;
the comparison that matters for coding and agent work, all at max reasoning&lt;br&gt;
effort.&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Benchmark&lt;/th&gt;
&lt;th&gt;DeepSeek V4.1 Flash&lt;/th&gt;
&lt;th&gt;GPT-5.6 Sol&lt;/th&gt;
&lt;th&gt;Claude Opus-5.0&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;DeepSWE v1.1&lt;/td&gt;
&lt;td&gt;74.2&lt;/td&gt;
&lt;td&gt;73.0&lt;/td&gt;
&lt;td&gt;74.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Terminal-Bench 2.1&lt;/td&gt;
&lt;td&gt;90.6&lt;/td&gt;
&lt;td&gt;88.8&lt;/td&gt;
&lt;td&gt;89.1&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;AutomationBench&lt;/td&gt;
&lt;td&gt;54.8&lt;/td&gt;
&lt;td&gt;45.8&lt;/td&gt;
&lt;td&gt;50.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Agent's Last Exam&lt;/td&gt;
&lt;td&gt;31.8&lt;/td&gt;
&lt;td&gt;26.7&lt;/td&gt;
&lt;td&gt;28.6&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Terminal-Bench 4.0&lt;/td&gt;
&lt;td&gt;31.2&lt;/td&gt;
&lt;td&gt;n/a&lt;/td&gt;
&lt;td&gt;51.8&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ProgramBench&lt;/td&gt;
&lt;td&gt;20.3&lt;/td&gt;
&lt;td&gt;n/a&lt;/td&gt;
&lt;td&gt;37.0&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;NL2Repo-Bench&lt;/td&gt;
&lt;td&gt;64.0&lt;/td&gt;
&lt;td&gt;n/a&lt;/td&gt;
&lt;td&gt;75.3&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;ExploitGym&lt;/td&gt;
&lt;td&gt;15.3&lt;/td&gt;
&lt;td&gt;33.7&lt;/td&gt;
&lt;td&gt;n/a&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;So it genuinely leads on Terminal-Bench 2.1, AutomationBench, Agent's Last&lt;br&gt;
Exam, CyberGym (88.1 vs Sol's 84.5), and coding contests (Codeforces rating&lt;br&gt;
3471, GPQA Diamond 90.9). But on the newer, harder Terminal-Bench 4.0 and&lt;br&gt;
ProgramBench, Opus-5.0 beats it by a wide margin, and on exploit-writing&lt;br&gt;
(ExploitGym) GPT-5.6 Sol is well ahead. Independent testers on&lt;br&gt;
&lt;a href="https://flowtivity.ai/blog/deepseek-v4-1-flash-benchmarks/" rel="noopener noreferrer"&gt;flowtivity.ai&lt;/a&gt;&lt;br&gt;
also found it failed a Rubik's Cube simulation stress test that other coding&lt;br&gt;
models handle fine. This is not a model that beats everyone at everything. It&lt;br&gt;
is strong on specific agentic tasks and weaker on longer, messier real-world&lt;br&gt;
repo work.&lt;/p&gt;

&lt;h2&gt;
  
  
  The self-hosting reality
&lt;/h2&gt;

&lt;p&gt;Here is the part that matters most for this blog. Yes, the weights are on&lt;br&gt;
Hugging Face under MIT licence. No, that does not mean you can run this on&lt;br&gt;
your homelab box.&lt;/p&gt;

&lt;p&gt;The checkpoint is around 510 GB. That alone rules out almost every consumer&lt;br&gt;
setup. But the bigger issue is something people misunderstand about sparse MoE&lt;br&gt;
models: even though only 8-16B parameters are &lt;em&gt;active&lt;/em&gt; per token, all 552B&lt;br&gt;
parameters still need to sit in memory (VRAM, ideally), because the router can&lt;br&gt;
send any token to any of the 384 experts. "Sparse" saves you compute, not&lt;br&gt;
memory. You cannot page experts in and out from disk fast enough to keep up&lt;br&gt;
with real inference speed.&lt;/p&gt;

&lt;p&gt;For comparison, the previous-generation V4-Flash was 304B total, about 13B&lt;br&gt;
active, a 166.9 GB download, and it fit on 2x H200 GPUs. This new model is&lt;br&gt;
bigger, not smaller. Industry estimates from &lt;a href="https://www.yottalabs.ai/post/deepseek-v4-flash-hardware-requirements-&lt;br&gt;%0Agpu-memory-2026" rel="noopener noreferrer"&gt;Yotta&lt;br&gt;
Labs&lt;/a&gt; put the practical floor at a full 8-GPU node, not the 2x H200&lt;br&gt;
that used to be enough. According to&lt;br&gt;
&lt;a href="https://www.mindstudio.ai/blog/deepseek-v4-1-flash-local" rel="noopener noreferrer"&gt;mindstudio.ai&lt;/a&gt;,&lt;br&gt;
DeepSeek has not published an official minimum-VRAM number, community GGUF and&lt;br&gt;
AWQ quantizations were still pending at launch, and the early local runs&lt;br&gt;
people reported were on multi-GPU servers or rented cloud GPUs, not gaming&lt;br&gt;
rigs or single-box homelabs. There's also a good technical rundown of the KV&lt;br&gt;
cache work on &lt;a href="https://rits.shanghai.nyu.edu/ai/deepseek-v4-1-flash-890-byte-kv-cache/" rel="noopener noreferrer"&gt;NYU Shanghai's&lt;br&gt;
blog&lt;/a&gt;&lt;br&gt;
if you want the deeper math.&lt;/p&gt;

&lt;p&gt;In my lab, the practical cutoff for "can I run this on hardware I own" has&lt;br&gt;
always been: does it fit on one or two consumer or prosumer GPUs after&lt;br&gt;
quantization. This model doesn't get close. Even a heavily quantized version&lt;br&gt;
would need well over 128 GB of fast memory just for weights, before you add KV&lt;br&gt;
cache for a 1M-token context. That is enterprise GPU cluster territory, not a&lt;br&gt;
Proxmox box in a spare room (my &lt;a href="https://selfhostpilot.com/proxmox-beginners-guide/" rel="noopener noreferrer"&gt;Proxmox&lt;br&gt;
guide&lt;/a&gt; assumes normal&lt;br&gt;
hardware, not 8-GPU nodes).&lt;/p&gt;

&lt;h2&gt;
  
  
  What I'd actually do
&lt;/h2&gt;

&lt;p&gt;If you want to use V4.1-Flash today, use DeepSeek's API. Pricing is genuinely&lt;br&gt;
cheap: roughly $0.15 per million input tokens off-peak (up to $0.30 at peak),&lt;br&gt;
$0.60 per million output tokens, and as low as $0.003 per million for cache-&lt;br&gt;
hit input. That is why they're killing V4-Pro, which cost about 4x more for&lt;br&gt;
less capability.&lt;/p&gt;

&lt;p&gt;For actual self-hosting on hardware a freelancer or small team can own, I'd&lt;br&gt;
still point people toward smaller open models that fit on 1-2 GPUs, the kind I&lt;br&gt;
covered in the &lt;a href="https://selfhostpilot.com/muse-glimmer-&lt;br&gt;%0Aopen-source-ai-model-self-hosting/" rel="noopener noreferrer"&gt;Muse Glimmer writeup&lt;/a&gt; or the monthly &lt;a href="https://selfhostpilot.com/open-source-repos-self-host-&lt;br&gt;%0Aseptember-2026/" rel="noopener noreferrer"&gt;open-source repos&lt;br&gt;
roundup&lt;/a&gt;. If you're routing API calls to a model like this from your&lt;br&gt;
own infrastructure, put it behind a private tunnel rather than exposing keys&lt;br&gt;
on a public box; my &lt;a href="https://selfhostpilot.com/wireguard-vpn-server-linux-setup-guide/" rel="noopener noreferrer"&gt;WireGuard setup&lt;br&gt;
guide&lt;/a&gt;&lt;br&gt;
covers that, and if you're storing outputs or logs, something like &lt;a href="https://selfhostpilot.com/nextcloud-vs-google-&lt;br&gt;%0Adrive-2026/" rel="noopener noreferrer"&gt;Nextcloud&lt;br&gt;
instead of Google Drive&lt;/a&gt; keeps that data under your control too.&lt;/p&gt;

&lt;h2&gt;
  
  
  My verdict
&lt;/h2&gt;

&lt;p&gt;DeepSeek V4.1 Flash is a real technical achievement and the licence is&lt;br&gt;
genuinely open. But "open weights" and "self-hostable" are two different&lt;br&gt;
promises, and this release only keeps the first one for most of us. Unless you&lt;br&gt;
have access to an 8-GPU enterprise node, you are using this model through&lt;br&gt;
DeepSeek's API like everyone else, cheap pricing and all. That's not a bad&lt;br&gt;
outcome, just don't let the word "open" fool you into thinking it belongs on&lt;br&gt;
your home server.&lt;/p&gt;

</description>
      <category>selfhosted</category>
      <category>opensource</category>
      <category>devops</category>
      <category>privacy</category>
    </item>
    <item>
      <title>Matrix vs Slack: Self-Hosted Team Chat in 2026</title>
      <dc:creator>SelfHost Pilot</dc:creator>
      <pubDate>Thu, 10 Sep 2026 12:03:27 +0000</pubDate>
      <link>https://dev.to/selfhostpilot/matrix-vs-slack-self-hosted-team-chat-in-2026-5af6</link>
      <guid>https://dev.to/selfhostpilot/matrix-vs-slack-self-hosted-team-chat-in-2026-5af6</guid>
      <description>&lt;p&gt;Your team needs chat. The question is: who should own the conversation — a&lt;br&gt;
company in San Francisco, or you?&lt;/p&gt;

&lt;p&gt;Slack is easy. Everyone knows Slack. But every year, more businesses are&lt;br&gt;
asking the same question: &lt;strong&gt;why are we paying forever for something we could&lt;br&gt;
run ourselves?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;Matrix is the answer for a growing crowd. Let's compare them honestly — no&lt;br&gt;
hype, no jargon walls.&lt;/p&gt;

&lt;h2&gt;
  
  
  What you actually pay
&lt;/h2&gt;

&lt;p&gt;Slack's pricing is simple and painful: the paid plans start around &lt;strong&gt;$8.75 per&lt;br&gt;
person per month&lt;/strong&gt;. A team of 20 people? That's about &lt;strong&gt;$175 a month, every&lt;br&gt;
month, forever&lt;/strong&gt;. The free plan exists, but it hides your history after 90&lt;br&gt;
days — which makes it useless for real work.&lt;/p&gt;

&lt;p&gt;Matrix is open source. The software costs nothing. You pay for a small server&lt;br&gt;
(a $5–10 VPS works fine for a small team) and a domain you probably already&lt;br&gt;
own. &lt;strong&gt;For a 20-person team, that's roughly $10 a month total — about 94%&lt;br&gt;
less.&lt;/strong&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  Who owns your data?
&lt;/h2&gt;

&lt;p&gt;With Slack, every message sits on Slack's servers. Your contracts, your plans,&lt;br&gt;
your honest internal conversations — all readable by a company you don't&lt;br&gt;
control, under laws you don't choose.&lt;/p&gt;

&lt;p&gt;With Matrix, the server is &lt;strong&gt;yours&lt;/strong&gt;. Your data lives on hardware you control,&lt;br&gt;
in a country you choose. If privacy matters to your clients — and it should —&lt;br&gt;
that's a difference you can sell.&lt;/p&gt;

&lt;h2&gt;
  
  
  What Matrix actually involves
&lt;/h2&gt;

&lt;p&gt;Let's be honest: self-hosting Matrix isn't a Saturday-afternoon project for a&lt;br&gt;
beginner. Here's what a real setup includes:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Installing &lt;strong&gt;Synapse&lt;/strong&gt; (the Matrix server) with Docker&lt;/li&gt;
&lt;li&gt;Setting up a domain and HTTPS certificates&lt;/li&gt;
&lt;li&gt;Turning on &lt;strong&gt;registration&lt;/strong&gt; the right way (so strangers can't join your server)&lt;/li&gt;
&lt;li&gt;Configuring &lt;strong&gt;backups&lt;/strong&gt; — a chat history you can't restore is a chat history you never had&lt;/li&gt;
&lt;li&gt;Updating it regularly (like every self-hosted thing, updates are homework)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of it is magic. It's the same work any serious IT setup needs — just done&lt;br&gt;
once, properly.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Slack still wins
&lt;/h2&gt;

&lt;p&gt;Fair is fair. Slack has polish Matrix is still catching up on:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;It &lt;strong&gt;just works&lt;/strong&gt; — zero setup, instant invites&lt;/li&gt;
&lt;li&gt;Better mobile apps in some areas&lt;/li&gt;
&lt;li&gt;A huge marketplace of integrations&lt;/li&gt;
&lt;li&gt;Your whole team already knows it&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;If you're a three-person startup shipping next week, Slack is fine. You're&lt;br&gt;
paying for speed and convenience — and that's a legitimate choice.&lt;/p&gt;

&lt;h2&gt;
  
  
  Where Matrix wins
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Cost&lt;/strong&gt; — near zero per user, forever&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Privacy&lt;/strong&gt; — your server, your rules, your jurisdiction&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Interoperability&lt;/strong&gt; — Matrix connects to other Matrix servers and even bridges to Slack, Teams, and WhatsApp&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;No vendor lock-in&lt;/strong&gt; — the protocol is open; nobody can switch your service off&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The honest verdict
&lt;/h2&gt;

&lt;p&gt;Pick Slack if you want zero effort and don't mind renting your conversation&lt;br&gt;
history.&lt;/p&gt;

&lt;p&gt;Pick Matrix if you're past 10–15 people, care about privacy, or simply hate&lt;br&gt;
the idea of a monthly bill that grows as your team grows.&lt;/p&gt;

&lt;p&gt;And if the setup part scares you — that's fair too. It's real work. The good&lt;br&gt;
news: it's exactly the kind of work I do for a living. I set up Matrix servers&lt;br&gt;
for businesses — properly, with backups, monitoring, and documentation in&lt;br&gt;
plain English. If you'd rather have it done right the first time, my inbox is&lt;br&gt;
open.&lt;/p&gt;

</description>
      <category>selfhosted</category>
      <category>opensource</category>
      <category>devops</category>
      <category>privacy</category>
    </item>
  </channel>
</rss>
