Kamis, 01 Oktober 2026

YT-DLP is Being Treated as a Piracy Tool By The IFPI

yt-dlp has over 195,000 stars on GitHub, supports thousands of platforms, and is actively maintained by a global developer community. Unfortunately, the IFPI would like to see it on the EU's piracy watchlist.

Just so you know, the International Federation of the Phonographic Industry (IFPI) represents around 8,000 music labels across 70 countries.

In its submission to the EU's Counterfeit and Piracy Watch List consultation, the group calls yt-dlp "a major problem for the music industry" and names four of its maintainers by their GitHub handles.

A Piracy Watch List?

eu's public consultation on the counterfeit and piracy watch list webpage showing some key details

Run by the European Commission's Directorate-General for Trade and Economic Security, the Watch List identifies online services and physical marketplaces outside the EU reported to engage in or facilitate copyright infringement.

While it sounds serious, the undertaking isn't meant to gather legal findings and does not mandate any form of direct action. It's closer to a naming exercise intended to pressure operators and governments outside the EU into addressing the identified services.

The 2027 edition is being compiled from submissions received through September 2026, with the final list expected in Q2 2027.

What does their submission say?

IFPI's submission covers a wide range of copyright enforcement concerns, from AI music generators and cyberlockers to streaming fraud services and domain registrars. yt-dlp appears under the "stream ripping" section, grouped with commercial websites like Y2mate and Savefrom.

They describe the tool as an application that retrieves content by parsing web page data and interacting with platform playback endpoints, with GitHub serving as the primary delivery method for its source code, pre-compiled binaries, and installation instructions.

IFPI names four of the project's maintainers by their GitHub handles: pukkandan, who founded the project and led it between 2021 and 2024, and some core maintainers mentioned in the project's Maintainers.md file, like coletdjnz, bashonly, and Grub4K.

The same submission also flags X, Discord, Telegram, and Vimeo as platforms facilitating copyright infringement at scale.

It's a tool, not a service

the yt-dlp github repo

The Watch List, as described by the European Commission, targets online service providers and physical marketplaces located outside the EU. yt-dlp fits neither description in any conventional sense.

IFPI acknowledges this by noting that the project's open source nature, its Unlicense licensing, and an extensive international developer community make it "difficult to contain and/or remove."

From their point of view, there's no central domain to block, no payment processor to cut off, and no hosting provider to strongarm into complying with a takedown request.

The source code is distributed globally and can be compiled by anyone with the skills to do so. But that doesn't mean yt-dlp is a piracy platform.

It's a command-line tool for downloading audio and video content, and categorizing it alongside dedicated ripping or piracy websites conflates a general-purpose downloader with services whose primary purpose is facilitating unauthorized copying.

Closing thoughts

The Watch List has been used in connection with enforcement against commercial stream-ripping platforms before.

Y2mate.com and eleven other stream-ripping sites were shut down in Vietnam in 2025, and Y2mate had previously appeared on the list.

Before that, in 2024, a German court held the host provider for youtube-dl.org liable in connection with facilitating circumvention. This shows that grouping an open source command-line tool with those commercial services in the same breath does not, by itself, make the tool one of those.

Via: TorrentFreak



from It's FOSS https://ift.tt/4dlrbqc
via IFTTT

FOSS Weekly #26.40: NixOS is European Choice, Firefox Nova and Features, Free Terminal Course, Homelab Improvements and More

FOSS Weekly

Canonical is moving Ubuntu's kernel update cycle from four weeks to two, with the expected result being a kernel release landing every week due to cycle overlap. They did this because AI-assisted vulnerability hunting is causing CVEs to land faster than the old timeline could respond to.

They have also enabled upgrades from Ubuntu 24.04 LTS to Ubuntu 26.04.1. And the delayed beta release of Ubuntu 26.10 should arrive today.

AlmaLinux now has software certification, which means publishers can list products and users can confirm what runs on their hardware, with everything going into a public catalog with a free read-only API facilitating bulk data export.

GhostBSD's lead developer is building a new desktop called Mocka to eventually replace MATE. It is built from scratch with no shared code from the MATE project, and the name comes from a typo.

postmarketOS is now Nura. The rename has been in the works since March 2025, drew over 300 community submissions, and went through a trademark review and a vote before it was finalized. On the same note, F-Droid has a major revamp. In case you did not know, F-Droid is the FOSS alternative to Google Play Store.

openSUSE is consolidating its distro lineup. Leap Micro, the separate immutable flavor for container and edge workloads, is going away, and Leap 16.1 absorbs its functionality via an optional installer mode.

This edition of FOSS Weekly is supported by Dawarich, an open source alternative to Google Timeline.

Dawarich is a private alternative to Google Timeline.

Google killed browser Timeline and is limiting data retention. You can import your entire location history into Dawarich in minutes. It is private and encrypted. No ads. No data selling.

It is open source and can also be self-hosted. Or, you can opt for their encrypted service.

Try Dawarich Today

🧠 What We’re Thinking About

The Netherlands is building a NixOS-powered work environment after watching Microsoft cut off ICC access in 2025. Though it turns out France's digital agency had beat them to it, already running their own version of NixOS on internal workstations.

🐧 Tuxdle is rising

Last week I shared my weekend project, Tuxdle. It's a word game where you have to guess the Linux term within six attempts. The game has gained good popularity. We are getting more than 500 plays every day. A good number for a game that is less than a week old.

I have made some enhancements to the game. You can see your stats and you can also see stats on the day's puzzle. That tells you how many people played the game and how many people actually solved it. Streak badges have also been added.

Want more fun and challenges? On Linux Handbook, we have created a fun Capture the Flag game. You have 10 levels to solve. When you solve a level, the next level gets unlocked. The challenges run in custom docker containers. Everything on your system really. No sign up is needed.

🧮 Linux Tips, Tutorials, and Learnings

I am also enhancing the user experience on the It's FOSS website. One of the first things I did was organize the series/courses in a proper format.

If you visit the terminal course or bash scripting course, you will see the chapters in the series in the left sidebar. This will give you easier navigation.

There are many Linux distros that don't provide a dock by default, and if you want one, there's no dearth of options: Latte for KDE users, Cairo for old-school animations, and Dash to Dock for GNOME users; there's something for every taste and desktop setup.

You've seen "upstream" and "downstream" in patch notes, bug trackers, and forum replies without it ever being fully explained. We have already tackled what the terms actually mean, both for the kernel and for applications, and why it matters when you're deciding where to file a bug report.

👷 AI, Homelab and Hardware Corner

One of the biggest annoyances of homelab is accessing services by using IP address and port number. I fixed this by giving a custom domain name to every service I run. I used AdGuard as DNS and Nginx Proxy Manager for reverse proxy. And the end result is that I can use Jellyfin by typing jellyfin.internal instead of typing 192.168.0.23:8097.

Most SBC projects end with your drawer filling up with HATs for different use cases. Vicharak's Axon-Lite tries a different approach where it offers swappable interface modules for voice, vision, sensing, and AI data.

✨ Apps and Projects Highlights

Firefox's Nova redesign is finally here, and it looks good! There's also a neat toggle for anyone who doesn't prefer it's pill-shapedness.

📽️ Videos for You

And here's 21 useful Firefox features to give you a reminder why this browser keeps coming back, even after the wrong turns it has taken these past few years.

💡 Quick Handy Tip

0:00
/0:16

In KDE Plasma, you can copy a wide range of time/date formats to the clipboard by right-clicking on the Clock widget in the panel.

All you have to do is right-click on the digital clock in the panel, hover your mouse cursor over the "Copy to Clipboard" option, and click on the format you want copied.

Desktop Linux is mostly neglected by the industry but loved by the community. For the past 14 years, It's FOSS has been helping people use Linux on their personal computers. And we are now facing the existential threat from AI models stealing our content.

If you like what we do and would love to support our work, please become It's FOSS Plus member. It costs $49 a year (less than the cost of a McDonald's burger a month), and you get an ad-free reading experience with the satisfaction of helping the desktop Linux community. And there are also free Linux ebooks.

Join It's FOSS Plus

🎋 Fun in the FOSSverse

Sharpen your networking command knowledge by completing this crossword!

Linux is for power users. 💪

linux sudo meme

🗓️ Tech Trivia: On September 27, 1983, Richard Stallman announced the GNU Project, an effort to build a completely free Unix-compatible operating system. It helped spark the free software movement and popularize copyleft through the GPL, shaping how software is shared, modified, and built collaboratively.

🧑‍🤝‍🧑 From the Community: Neville is making the case for small, well-written programs; do you have an opposing view to present?



from It's FOSS https://ift.tt/YE2FRXz
via IFTTT

F-Droid's New App Shows it Isn't Going Anywhere

f-droid 2.0 release banner

Since 2010, F-Droid has been the go-to place for downloading free and open source apps for Android. Its client app is the one people interact with the most, and it has received many upgrades over the years.

But now it's time for a massive rewrite that has emerged from more than a year of development and numerous test releases.

A comprehensive redesign

Kotlin replaces the original Java codebase, and the interface has been rebuilt on Jetpack Compose. The result is an app that follows Material Design throughout, so that it looks and behaves like it belongs on a modern Android device.

The app's bottom bar now has three sections: Discover for browsing, Search for queries and quick access to categories, and My Apps for tracking installed apps, updates, and issues.

You will also find that the Settings menu has moved to the top-right, being placed alongside the new Repositories menu.

Coming back to the Discover page, it has been configured to highlight newly added apps, recently updated ones, and the most downloaded ones in the repository. Related categories are grouped together, making it easier to browse the full catalog without getting lost in a long list.

Search now handles categories, app descriptions, and translated content in addition to app names, and results for Chinese, Japanese, and Korean queries have improved. Your search history is also saved for future queries.

Filtering has been reworked too; results can be narrowed by anti-features, device compatibility, and category all at once.

What else's changed?

The app now checks for updates in the background by default, removing the need for the pull-to-refresh gesture that used to trigger repository scans. Of course the manual check is still available from the My Apps page once you go into the three-dot menu.

Similarly, the app hiding feature for changing F-Droid's logo to a calculator app has been moved into the Settings menu under "App Icon," and the Nearby app sharing tool has been temporarily removed.

Concluding their announcement, F-Droid stated that:

F-Droid 2.0 represents a major milestone, but it is not the end of the story. Rebuilding the app has given us a stronger foundation, yet there is still plenty of work ahead.

As the rollout reaches more users, we expect to learn a great deal from real-world usage. Community feedback has shaped F-Droid 2.0 from its earliest design discussions through many alpha and RC releases, and it will continue to guide future improvements.

A looming threat

Last year in August, Google announced that starting 2027, every Android app developer would need to register with the company, providing government-issued ID, signing key evidence, and a fee.

This way, apps from unregistered developers would be blocked from running on certified Android devices.

Of course F-Droid didn't sit by idly; one of their board members, Marc Prud'hommeaux, launched the Keep Android Open campaign in response, which has since brought together over 70 organizations from 20+ countries.

Its signatories include big names like the Electronic Frontier Foundation, the Free Software Foundation, KDE, Proton, Codeberg, VideoLAN, LineageOS, CryptPad and the Tor Project.

Seeing that we are shy of the 90-day mark for this absurd lockdown to occur, F-Droid introducing such a major update only strengthens their stance of not backing down to Google's strongarming tactics.

Get F-Droid 2.0

This revamp is rolling out gradually over the coming weeks, so if you haven't received this on your existing installation, just wait. For new installations, it is a similar situation, as the latest stable release is still v1.23.2.

On the other hand, if you can't be bothered with practicing the virtue of patience, then you could download the latest 2.0 beta build from the packages portal.



from It's FOSS https://ift.tt/FCTPvEj
via IFTTT

How I Fixed the Biggest Annoyance of My Homelab

Internal domain name setup in homelab

My homelab started small, and so did the annoyance.

To open Jellyfin, I typed 192.168.0.x:8097. For Home Assistant, it was another IP and :8123. For Karakeep, Ollama and the rest, even more IP and port combinations to either remember or bookmark.

The bookmarks weren't reliable either. My ZimaCube got its IP address from the router like any other device. Swap a cable or let it reconnect, and it mostly came back with a different IP, breaking every bookmark and config pointing to it. That's worse for Jellyfin because typing a full combination IP address and port number with a TV remote will give you a taste of medieval torture.

So, one weekend I decided to fix it. I started with assigning dedicated IP address to my Zima devices (ZimaBoard and ZimaCube) but ended up with a full network clean up.

Now my setup is smooth with all the regular services running with a .internal domain. Now I just type jellyfin.internal in the browser. No IP, no port number. Saved me a midlife crisis.

My setup, before and after

Here's what my network looked like before the cleanup. The router from my ISP feeds a TP-Link router, which runs the homelab network, with a OneMesh node extending the Wi-Fi.

ZimaBoard consumes less power and runs services like Jellyfin that need to be on all the time. ZimaCube is a powerful device, and with Nvidia Ada RTX on it, I use it for local AI exploration. To cut down on my electricity bill, I only turn it on when I need it.

My original homelab setup before the DNS changes

And here's what it looks like now. Both Zima devices have fixed IPs, the ZimaBoard handles DNS and the reverse proxy, and every service has a proper name.

my homelab setup after dns and reverse proxy manager

The idea in a nutshell: AdGuard as DNS and Nginx Proxy Manager

The whole setup rests on two pieces working together. AdGuard Home, running as the network's DNS server, turns a name like jellyfin.internal into an IP address.

Nginx Proxy Manager then looks at which name you asked for and forwards the request to the right port. Because AdGuard can only work on the IP address, not port numbers.

Once that's in place, adding a new service is a two-step routine: one DNS rewrite in AdGuard, one proxy host in Nginx Proxy Manager. That's it.

🚧
This is my setup, built around my routers, my Zima devices, and the services I run in my homelab. Take inspiration from it and use it as a reference, but don't copy it blindly. Your IP addresses, ports, router menus and commands will almost certainly be different.

Step 1: Give the core devices fixed IPs

Everything in this setup depends on IP addresses that never change. If the DNS server's IP changes, the entire setup breaks. So the first job was setting DHCP reservations on the router.

On my TP-Link, this lives under Advanced -> Network -> DHCP Server -> Address Reservation.

It actually shows me the connected device and gives the option to reserve the IP from there itself.

reserving ip address for devices on local

That may not always be the case for all the routers. So, you can find the MAC address on Linux with:

ip link show

That will show the MAC address of the current device. You can use a networking command like arp to scan the mac address of other devices connected to your network. The best place still is the router for this activity because it sees all the connected devices to the network anyways.

💡
I also moved the start of the DHCP pool to 192.168.0.10, so no phone or laptop ever grabs an IP I've reserved.

Here's the addressing scheme I ended up with:

Device IP Notes
Router 192.168.0.1 Homelab network gateway
ZimaBoard 192.168.0.4 Runs 24x7, hosts AdGuard and Nginx Proxy Manager
ZimaCube 2 Pro 192.168.0.5 Not always on, runs heavier services
Dynamic pool 192.168.0.10 to 253 Phones, laptops, everything else

I have also assigned fixed IPs to Raspberry Pi and other SBCs in this setup. They are used for running local AI harnesses like Nanoclaw and Hermes agents. I am also setting up Frigate for the cameras. I will share my experience with those things in some later article.

Note that some devices may need to be rebooted or renew its DHCP lease to pick up the reserved IP.

📋
Since I used ZimaOS, things were more click click and install. For other setup, you will have to install and setup AdGuard DNS and Nginx Proxy Manager. Instructions can be found on their respective websites.

Step 2: Install AdGuard Home on the always-on box

AdGuard Home becomes the DNS server for the entire homelab network, so it has to be up all the time. My ZimaBoard runs 24x7 while the ZimaCube doesn't, so the choice was easy.

In the ZimaOS App Store, I installed the AdGuard Home (HOST) variant, not the regular one. Host networking lets AdGuard bind directly to port 53 and see the real IPs of clients. With Docker's default bridge network, traffic gets NATed through the container and you lose both.

The install shows a tips popup with a config script. Its wget command failed on my system with a "Can't be verbose and quiet at the same time" error, so I ran the same script with curl instead:

sudo bash -c "$(curl -fsSL https://raw.githubusercontent.com/bigbeartechworld/big-bear-scripts/master/generate-adguard-home-config/run.sh)"

Don't skip sudo here. Without it, the script fails to create directories but still prints a success message.

I accepted the default config path, restarted the app from the ZimaOS dashboard, and opened http://192.168.0.4:3000 manually. Clicking the app icon doesn't work for host-mode apps.

💡
AdGuard offers AdGuard DNS as a paid cloud service. But its open source equivalent is free to install and use on your own device. That's what I used here.

When ports are already taken

The setup wizard asks for an admin port and a DNS port, and both clashed with something. Port 80 for the web UI was taken, so I set AdGuard's admin UI to 3786 instead.

Port 53 was more surprising. Unusual, right? Turns out I had a Pi-hole container running that I had completely forgotten about. I found it with:

sudo docker ps --format "{{.Names}}: {{.Ports}}"

Pi-hole and AdGuard do the same job, so there was no point running both. I removed Pi-hole.

Step 3: Point the network at AdGuard

AdGuard was running, but no device was using it yet. On my TP Link, I went to Advanced -> Network -> Internet, expanded Advanced Settings, and switched DNS Address to "Use the Following DNS Addresses".

Primary DNS is AdGuard at 192.168.0.4, and secondary is 1.1.1.1. Here. 192.168.0.4 is the IP address of the ZimaBoard that has AdGuard running on it.

AdGuard setup as DNS in the router

Here's what this setting actually does. Devices on the network still use the router as their DNS server, and the router forwards their queries to AdGuard. That's why AdGuard's query log mostly shows the router as the client, not individual devices. For per-device stats, setting AdGuard's IP in the DHCP Server page should work, so that the router hands it to devices directly.

📋
The 1.1.1.1 secondary is a safety net, so the internet doesn't go dark when the ZimaBoard is down. It comes with a trade-off, though. DNS clients don't always wait for the primary to fail before trying the secondary. When a query goes to Cloudflare instead, the ad slips through and .internal names don't resolve, since Cloudflare has no idea they exist. If you notice a hostname failing occasionally, this is the likely culprit.

When a device ignores the new DNS

While testing, I manually set 192.168.0.4 as DNS on a Linux laptop through GNOME's network settings. dig @192.168.0.4 google.com worked, but browser traffic never showed up in AdGuard's log. Running resolvectl status revealed the system was still using the router, as GNOME hadn't applied the change to the live connection.

Reconnecting to Wi-Fi fixed it. The more dependable way is doing it through nmcli:

nmcli connection modify "<connection-name>" ipv4.dns "192.168.0.4"
nmcli connection modify "<connection-name>" ipv4.ignore-auto-dns yes
nmcli connection down "<connection-name>" && nmcli connection up "<connection-name>"

Step 4: Create the .internal names with DNS rewrites

This is where the hostnames come to life. In AdGuard, go to Filters -> DNS rewrites -> Add DNS rewrite, enter a domain like jellyfin.internal, and point it to an IP address.

AdGuard DNS rewrites

Here's the thing. ZimaBoard runs multiple services. DNS rewrite only accepts IP address, not port numbers. If I have to add jellyfin.internal and homeassistant.internal in the DNS, both will be pointed to the same 192.168.0.4 IP address. And they won't be resolved.

I mean, I could do zimaboard.internal:8097 and that would land me on Jellyfin but what's the point? A proper jellyfin.internal is what I would want. We need the port numbers.

AdGuard DNS rewrites

This is why we need a proxy manager to properly map the domain names with both IP addresses and the port numbers. But a proxy manager cannot act as DNS and hence we need both AdGuard DNS in combination with a tool like Ngnix Proxy Manager.

📋
Why .internal? A good option was .local but it is reserved for mDNS (Bonjour, Avahi), so many devices resolve it outside your DNS server, which could lead to inconsistent results. .lan and .home aren't reserved and could become real domains someday, just like .dev did when Google bought it. .home.arpa is official but clunky to type. In 2024, ICANN permanently reserved .internal for private networks. It's short, readable, and will never clash with a real website. And it fits the entire homelab narrative.

Step 5: Use the port numbers with Nginx Proxy Manager

DNS only translates a name into an IP. It knows nothing about ports. To make http://jellyfin.internal work without :8097, something has to listen on port 80, check which hostname was requested, and forward it to the right port. That's a reverse proxy.

I'd have preferred Caddy, as that's what I use on some of my servers. But Caddy wasn't available as a one-click app in ZimaOS and I want to keep everything in Zima ecosystem. So I opted for Nginx Proxy Manager (NPM) as it does the same job with a web interface instead of a config file. Like AdGuard, it went on the always-on ZimaBoard.

Port 80 issue, again

NPM needs ports 80, 443 and 81 (its own admin UI). Port 80 was taken again, this time by zimaos-gateway, the process serving the ZimaOS dashboard for ZimaBoard. I confirmed it with:

sudo ss -tulpn | grep :80

The tempting fix is giving NPM a different port, but that defeats the whole purpose. You'd be back to typing port numbers.

Instead, I moved the ZimaOS dashboard to port 8888 from its Settings page. That was easy and that's why I like ZimaOS. It makes managing homelab a lot easier.

Anyways, the NPM install dialog still complained about port 80 for a while, and a full ZimaBoard reboot cleared that stale check.

Adding proxy hosts

Once installed, NPM's admin UI is at http://192.168.0.4:81. Log in with the default admin@example.com and changeme, and it asks you to set new credentials right away.

To add a service, go to Hosts -> Proxy Hosts -> Add Proxy Host and fill in the details.

Nginx Proxy Manager Settings
  1. Domain Names: the hostname, like jellyfin.internal
  2. Scheme: http
  3. Forward Hostname / IP: the IP of the device running the service
  4. Forward Port: the service's actual port, like 8097
  5. Websockets Support: on (Jellyfin and Home Assistant need it for live updates, and it doesn't hurt the rest so I always enable it)
📋
I left the SSL tab alone, since this traffic never leaves my home network.

Save it, open http://jellyfin.internal in a new tab, and there it is. No port number.

Here's how my proxy hosts look right now:

Nginx Proxy Manager
💡
The "Public" access label might look scary, but it only means NPM doesn't add its own login prompt. These names resolve only through my AdGuard, so nobody outside my network can reach them. To access it from outside, a service like Tailscale should be used.

Troubleshooting afterwards

Network setup never goes 100% trouble free. I did a face a couple of issues. Here are at least two that I recall (and have recorded):

Home Assistant threw a 400 error

Everything worked except Home Assistant, which returned 400: Bad Request through homeassistant.internal. Direct access on port 8123 was fine. Home Assistant rejects proxied requests unless it explicitly trusts the proxy, as protection against spoofed headers.

The fix goes in Home Assistant's configuration.yaml:

http:
  use_x_forwarded_for: true
  trusted_proxies:
    - 172.17.0.3   # NPM container's IP on the Docker bridge network

I found the NPM container's IP with sudo docker inspect nginxproxymanager | grep IPAddress, then restarted Home Assistant with sudo docker restart homeassistant.

One catch: this IP can change if the NPM container gets recreated. Trusting the whole bridge subnet (172.17.0.0/16) instead of a single IP is more durable.

Netflix stopped working on the TV

Shortly after switching DNS, Netflix on my smart TV refused to connect. AdGuard's query log showed two blocked domains in red: logs.netflix.com and nrdp26.logs.netflix.com. They're telemetry endpoints, but the Netflix app treats them as part of its connectivity check.

You can unblock an entry from the query log's menu in AdGuard, or add allowlist rules under Filters -> Custom filtering rules:

@@||logs.netflix.com^
@@||nrdp26.logs.netflix.com^

Restart the app on the TV and it should work again.

💡
If something else breaks after you enable AdGuard, the query log is the first place to look.

Port conflicts

Port conflicts came up three times during this project, so this little drill is worth keeping handy. To see which process is using a port:

sudo ss -tulpn | grep :<port>

The process name in the output tells you who the culprit is. If it says docker-proxy, check which container it belongs to:

sudo docker ps --format "{{.Names}}: {{.Ports}}"

Then decide whether to remove the conflicting container or move the other service to a different port. Just don't remap the port of the thing you're trying to make port-free, like NPM.

One more thing to keep in mind: all of this works only inside your home network. The .internal names exist only in your AdGuard, so they won't resolve when you're outside, unless you bring a VPN into the picture.

Adding a new service later

This is where all the effort I put in this setup pays off. When I deployed Karakeep a few days later, giving it a proper name took just two steps:

  1. In AdGuard, add a DNS rewrite: karakeep.internal pointing to the ZimaBoard (192.168.0.4).
  2. In Nginx Proxy Manager, add a proxy host: karakeep.internal forwarding to the service's IP and port (14592 in my case).

If the service does its own host validation, like Home Assistant, it may also need to trust the proxy.

Wrapping up

I did all this a few months ago and it has been running smoothly so far. HTTPS for the .internal names would be nice to have. Perhaps I will think about implementing it some weekend.

I am sure there are other, perhaps better (?) ways of doing this. For now, this setup works for me, and I no longer have to remember a single IP address or port number in my homelab. I hope it gives you a few ideas for taming your own.

I welcome your questions and suggestions. What else could I do here? What would you like to do about a similar setup?



from It's FOSS https://ift.tt/E5bmxQJ
via IFTTT

Rabu, 30 September 2026

Local AI Weekly #4: The Fine Print of Running AI Locally

local ai weekly

Welcome to Local AI Weekly #4.

"Local AI" keeps meaning different things these days. Sometimes the model runs on your computer. Sometimes only the app does, while the model and your chat still run elsewhere.

There are lots of such "local AI" tools that are not really local. Before you pick a local AI tool, ask three things: where does inference happen, what account or network service is still required, and what does the license let you do? The best local AI tool is the one that doesn't need any of that.

🧪 On my bench

Team It's FOSS has moved from Discord to Buzz for internal chat. Buzz, from Jack Dorsey of Twitter fame, is a decentralized communication tool for humans and agents. Agents can run on remote servers or a local harness over ACP.

It has quirks. Clipboard screenshots won't paste into chat, and desktop notifications only fire for direct messages. Manageable for now.

🔍 Discover AI tools

Kubutu developer Rick Timmis is working on Klara, a local desktop AI assistant for KDE Plasma. The idea is to let you control the desktop via voice input. It is a work in progress for now.

OpenMuse is an MIT-licensed personal-agent app with a browser worker, durable tasks, and an optional Docker-based Linux computer. You can host it yourself, but setup still needs a CopilotKit Intelligence key, and open-ended tasks default to cloud providers. You can point it at an OpenAI-compatible endpoint, but there's no documented native Ollama path. Self-hosted software, not an assured offline agent.

🎫 Get MCP Certified

The Linux Foundation now offers AI certifications. The Model Context Protocol Associate one could interest you if you're building MCP integrations, or want an AI credential on your resume. I plan to take it just for the sake of learning new skills.

📡 Open Model News

OpenDecider is a more modest use for local models: answer bounded questions, like which queue a ticket should go to, instead of writing long replies. Its nano model is about 400M parameters; the 4B small model is a Qwen-based adapter. The author says both were distilled from larger teachers, and reports 2.0 GiB for nano and 8.9 GiB for small in the tested setups.

Basically, you don't always need a giant model to route routine requests. A small student model can be the triage step ahead of a slower agent.

👀 Big Tech Watch

NVIDIA's September PAIR announcement also promises easier local-model setup in Hermes and OpenClaw. The one-click Hermes path launched on Windows, with Linux "coming soon." Don't confuse that future path with the Linux PAIR beta available now.

NVIDIA also quotes up to 1.9x throughput from llama.cpp optimizations on an RTX 5090. That's a vendor number on specific hardware, not a speedup I'd expect on yours.

🗂 AI Jargon: Distillation

Imagine you have a giant, super-smart teacher who knows everything about the world. This teacher has a massive brain, but its so big that it can only stay inside a giant school building.

AI distillation is like that big teacher sharing all their secrets with a little kid (the student).

Instead of making the kid read millions of textbooks, the big teacher says: "Don't worry, just watch how I solve these puzzles, and listen to how I think."

The little kid watches closely and learns the teacher's smart shortcuts. Soon, the kid becomes almost as smart as the teacher, but with a much smaller brain!

You can learn more about distillation here. And you will see that teacher-student is kind of official term in this context.

😂 Meme

When the open-weights drop looks a little too familiar...

AI meme

⚡ Quick Tip: Back up your Hermes agent before you need to rebuild the harness

Last issue: ollama ps, to see if your model was really on the GPU. This week, make sure you could rebuild the setup around it too.

If you run Hermes, run hermes backup. It writes a ZIP of your Hermes home, config and state included, restored later with hermes import path/to/backup.zip. hermes backup --keep N caps retained backups, and a script-only cron job runs it on schedule without starting an agent.

Then move one encrypted copy off the machine. That archive can hold credentials, sessions, memory, and config, so don't drop the raw ZIP in Git, even a private repo. It won't be wise.

If you have not subscribed to Local AI Weekly yet, you can subscribe from this page.

Subscribe to Local AI Weekly

See you next week.



from It's FOSS https://ift.tt/2zLDaTK
via IFTTT

Microsoft Has Made WSL Containers Available to Everyone

wsl containers banner shown with a laptop and two miniature containers

Announced via a two-part series of blogs, Microsoft has moved WSL containers (WSLC) out of public preview and into general availability. Let's take a look at what it offers.

The new release comes with wslc.exe, a dedicated command-line tool for Linux container workflows on Windows. It ships with a built-in alias, container.exe, for those who prefer that syntax.

A Windows API also ships alongside it, giving native Windows applications a way to spin up and manage containers directly from code, as well as some new commands that include wslc events for tracking container activity, and --mount and --stop-timeout flags on create and run operations.

Networking is handled through a new model called Consommé, where container traffic leaves the virtual machine as Ethernet frames and is picked up by a Windows process running under the calling user's account. That process handles DNS, routing, and port mapping, letting traffic pass through VPNs and firewalls like any other Windows process.

For organizations, Microsoft Intune has gained two new settings specific to WSL containers. The first lets administrators enable or disable access to the WSLC feature entirely across managed devices. The second is a container registry allow list, which restricts image pulls to a defined set of approved sources.

Microsoft Defender for Endpoint's WSL plugin has also been extended to cover container activity. It can retrieve process, file, and network events from inside WSLC, connecting them back to the Windows host.

What is WSLC?

wslc --version and wslc --help command outputs

First you have to know about WSL, which stands for Windows Subsystem for Linux, that lets developers run Linux environments directly on Windows without needing to partition their drive or setting up a separate Linux machine.

Since WSL 2, it has shipped with a real Linux kernel inside a managed virtual machine, giving users access to Linux tools, distributions, and command-line workflows from within Windows.

WSLC extends this further by adding a dedicated layer for creating and managing Linux containers within that same WSL environment, making containerized workflows a native part of the setup.

It also separates container operations from the main WSL service by routing them through a dedicated child process, wslcsession.exe, which runs under the current user's account. This keeps each session isolated and container operations in a less privileged state than the WSL service itself.

For developers already working inside WSL, this means containerized applications can run in the same environment without reaching for a separate tool. The Windows API exposure also means native Windows applications can interact with containers programmatically.

Microsoft's WSLC architecture deep dive is a must-read if you want to know more.

Get it now

wsl 3.0.1 release

Running wsl --update in your terminal pulls in the latest WSL release, which includes WSL containers. Once updated, wslc is ready to use.

You can use these new commands to manage your containers. 👇

Command What it does
wslc container restart Restart a container.
wslc container cp Transfer files to and from a container as a tar archive.
wslc system info Check the state of your WSLC environment.
wslc network connect / wslc network disconnect Join or remove a container from a network.
wslc network create Create a network, with support for custom driver options.

For the full changelog and access to the source, head to WSL 3.0.1's release page on GitHub.



from It's FOSS https://ift.tt/1njvFUR
via IFTTT

Selasa, 29 September 2026

The Netherlands Picked NixOS. France Was Already Using It

france securix nixos banner

When we heard about the Netherlands' DAWO initiative, a formal mandate to replace outside software across Dutch public institutions with a NixOS-powered platform, we asked ourselves: How could France miss out on this?

Turns out, they didn't. DINUM, the country's Interministerial Directorate for Digital Affairs, has been running its own NixOS-based workstation setup on internal machines for months now.

Sécurix and its NixOS Bet

github repo for the securix project from dinum

DINUM has developed Sécurix, a security-hardened NixOS setup aimed at system administrators. It builds on top of NixOS without forking it, applying the security guidelines published by ANSSI, France's national cybersecurity authority.

The project is MIT licensed, lives under the cloud-gouv GitHub organization, and is currently in alpha, with v0.20.1 being its newest release having been introduced just a few hours ago.

According to Emilien Ercolani of The Stack, who attended a DINUM briefing in April, they are targeting implementation across ~250 of their staff's workstations. This comes after a successful pilot run across 70 machines.

In its current avatar, Sécurix uses FIDO2 hardware security keys as the main login method, supports TPM2 and YubiKey, and leans on NixOS's reproducible build model.

Keep in mind that this is not meant to be a Linux distro but rather a foundation from which workstations can be operated and managed centrally.

Alongside it, DINUM has published Bureautix, a companion reference template for regular office workstations. It ships with KDE Plasma, LibreOffice, ONLYOFFICE, and WPS Office.

The docs describe it as a "dummy example" that organizations are meant to fork and adapt privately, not a separately running system.

Why is NixOS the go-to?

The project itself has a European origin. Eelco Dolstra created it at Utrecht University in the Netherlands, and the NixOS Foundation is a Dutch nonprofit. For European governments, the appeal is obvious.

Mainstream Linux distro offerings like Fedora trace back to Red Hat, which is owned by the US-based IBM; openSUSE is tied to the Luxembourg-based SUSE; and Ubuntu is from England's Canonical.

The underlying approach here seems to be avoiding projects that are based in foreign countries that could be forced to comply with the whims of their leaders.

From what I can see, France, the Netherlands, and Denmark are each taking a different path to the same place. In the end, if one wants control over their infrastructure, vendor-neutral and reproducible is the way to go.


Suggested Read 📖: postmarketOS is no more; not in that sense! It has undergone a rebrand.



from It's FOSS https://ift.tt/amo9sAW
via IFTTT