Wednesday, 7 October 2026

Omarchy - the new darling of the Linux world

 Omarchy is the buzzword at the moment, with it turning up on Network Chuck's YouTube channel. I came across it via DHH's blog post here: https://world.hey.com/dhh/omarchy-is-out-4666dd31 and thought it was pretty neat. I'm usually a Linux Mint kind of dude, but I'm open to change and trying new things so I briefly looked at it back in '25 to see what was happening there. The colours and the set up were very different from the darker greys and greens of Mint, but I stuck at it for a bit, trying to get used to the different way of managing things. It didn't stick and I reinstalled Linux Mint and went on with my life.

Recently I watched the Network Chuck videos on Omarchy and decided to give it a try again. You can watch them here: https://www.youtube.com/watch?v=9SDkU5VDQEQ I have an X1 Carbon - 6th Gen with an 8th Gen i5, 8GB of RAM and a nice quick SSD. It's got the nice, higher resolution screen, good battery and the keyboard you know I love.

Omarchy took 2 minutes to install completely on the X1. Ready to go. It tried (in vain) to configure my fingerprint reader - which Linux still hates, had WiFi, Bluetooth and everything else ready to go on boot and is snappy. Once I started to figure out the SUPER KEY + to get to menus, maximise windows, close stuff and so on, I found myself starting to enjoy Omarchy. There's tonnes of great configuration options easily accessible including plugins which are used to deliver all kinds of useful tools. For example, the plugin that controls multiple monitors was installed quickly and gave me easy access to manage monitors, arrangement of them and also the resolution. Handy when I had to deliver a presentation the day after installing it on a TV. Everything just worked and this is a bar that I hold dear to my heart. 

Printers worked perfectly and Omarchy found both of mine on the network without delay, printing in colour and double sided without any issue. The themes are comprehensively built and look lovely - the base, out of the box ones are great. Changing between the themes is easy too, and I really like that you can do SUPER + space and get to a menu without taking my hands off the keyboard. 

Omarchy is built on Arch Linux, which has a reputation of being a bit of a challenge to manage - it really needs a Linux nerd driving it to make it sing and dance. What Omarchy does really well is to take that complexity - which really covers a very capable system indeed - and turns it into an easy to use and powerful system. Updates are straightforward and the system manages it beautifully. I just updated it and it asked me to reboot. On a "No", it restarted the plugins and waits patiently for the reboot. Easy! Installing Brave was simple too - SUPER + Space -> Install -> Package -> Brave and boom, it's done. Brave works as advertised and as usual so happy days. Damn this is great! I'm getting impressive battery life from this distro too.

To help put things in perspective, this computer could run Windows 11, but not well. That pig of an OS uses up resources like RAM is free, and is a bloated bastard to run. Omarchy (and Mint) make this old laptop crack along and its still a great machine that has plenty of years left in it. Omarchy has breathed new life into this great little machine. It's an easy install and I can recommend you having a crack at it. Pick an old machine - hell, go to eBay and get a nice little X1 like this (I'm writing this blog post on this machine) and have a crack at Omarchy (or Mint, or any Linux install) and see how you go. It's a great bit of fun, and you never know - you might convert to a wide new world of Linux!

Thursday, 27 August 2026

AppleTV and Jellyfin

 I like the AppleTV - what a great little bit of kit. The sad thing is, the application that connects to my Jellyfin server has been very hit and miss. I've tried a few different things and it has not been a great outcome at times. 

Swiftfin was OK but had issues with some file types and then stopped working entirely. I'm not sure what happened with it, so I got frustrated and ditched it.

JellyTV was initially promising and the carousel look was pretty neat, but the connection to my server was consistently crap and fell over a lot. It would stop playing videos, lag, and have all kinds of problems. No network issues or anything like that so again, I got frustrated and got rid of it.

Infuse looked amazing, but as soon as I tried to play anything it wanted to upgrade to Pro and that was that. Off with it. Open Source for the win!

Ah look! A new version of Swiftfin has arrived. I installed it - it looks different, and the functionality has improved. OK that's exciting - initial testing is going very well.

At the back end of all of this I added an Nvidia graphics adaptor to my server to try and improve Jellyfin's capabilities and it has certainly helped, especially with the higher end formats of videos (8K for example). I thought this would help the AppleTV deliver vision to my eye balls better, but it did not. It appears the app you use is a big chunk of the problem and so getting the right one is key. My continued testing has shown Swiftfin to work pretty well. It's supposed to be a native app so my expectations are it will work fairly well. 

I have read that the Jellyfin leads have finished up or walked off? I'm not sure, but I want to thank everyone who has worked on the project - it's pretty amazing and works really well. You all have done a great job and end users like me are very grateful. 

Sunday, 23 August 2026

Humbled playing Elden Ring

 I've been a computer gamer for a long time - and I mean like, a really long time. Think Double Dragon on an old Amstrad around the late 1980's old.

To wind down and relax I've picked up a few different games, and being older and behind the time I'll often grab a game that's a couple of years old, cheap on the Microsoft Store or Steam and then launch into it. My little fella encouraged me to try Subnautica - saying it looked pretty cool. 

And it is! I dived into the game (see what I did there? :-) ) and got into it, dying very frequently and enjoying some of the jump scares as the aquatic life decided I was a tasty morsel and good for a bite. Lots of fun indeed. I finished it, ran through it again with a lot more panache and far fewer deaths and got into the second iteration - Subnautica Sub Zero which adds some entertaining cold environment and ice related elements to it. While not as long as the first one, it was very enjoyable and the new equipment and habitats fun to mess around with.

Subnautica 2 has come out in a pre-release version and I've gotten as far as I can in that too. My advice is simple when playing these games - pay attention and search everything! Also, watch out for the big fish!

I quite like the Dungeons & Dragons style of games and have spent many, many hours in Skyrim, Oblivion and Baldurs Gate (1, 2 and 3), so I decided to try out another in development game Enshrouded. Quite fun indeed and nearing the 1.0 release so it's quite polished. I've risen in levels and found that the inevitable grind has impacted my enjoyment somewhat. My nephew suggested Elden Ring, citing it was the best game he's played, he's finished it and it is a challenge.

A challenge you say! Well let's get to it.

Yes it indeed is a challenge and I had my butt whipped on a very constant basis. One cannot simply swing a sword with abandon in Elden Ring - you get killed, and you get killed frequently. The very first major dude kicks your arse and that's when I thought it might be worth checking out a bit of Youtube or other media to learn about this game before I rage quit forever. It turns out that the designers really don't want you to just bash your way through, and you need to take your time. I have not yet passed through much of the game - I am still learning all the ways that this game subtly differs from the aforementioned fun I've had in the more survival, base building type games. Elden Ring is not that kind of game. 

It's refreshing to come up against a game I can't just blast through, but equally frustrating because a lot of the tried and true techniques I've used in the past are not applicable. I'm also battling with the keyboard and mouse - my normal modus operandi, as I'm playing on my Legion gaming laptop. Sadly, I think this might be easier with a game pad of some type. As I've bought it through Steam, I'm not that keen to re-buy it on PS5 which is a bummer. 

So far, it's been very swearingly frustrating, yet equally entertaining. Stay tuned as I attempt to get myself through a play session without dying (it hasn't happened yet). 

Tuesday, 9 June 2026

Webtop - an impressive remote access tool

 I've been looking for a while for something that allows me to remotely access my home systems. I can't use a VPN, or RDS to connect back to my systems, so it had to be something useful via a web interface. Finding an option that allows for a Remote Desktop in a web interface isn't easy. I tried a few different options and had very little success, which was annoying and required quite some time to get things to work. Until I stumbled on webtop! You can find it here: https://docs.linuxserver.io/images/docker-webtop/ and it's worth having a look at.

I'm running it in docker, and I used this https://github.com/linuxserver/docker-webtop to set it up. The process is relatively straightforward and I'm running it in a Linux container. I've found with my server that 4vCPUs, 6GB of RAM and a 30GB disk have proven adequate for my daily computing needs via the webtop system.

It's an immutable file system, so any changes you make will be rolled back on restarting it. Instead, to add more software, you must use the Proot method - this makes the software stick. My needs are relatively simple, so I've installed Obsidian and a different browser. It wall works very acceptably, is fairly quick and usable. I also use the built in Office system LibreOffice for spreadsheets and files. The Documents/Downloads etc folders are not immutable and these retain your changes which is handy. I've had it manage some very sizeable spreadsheet files and it was fine to use. 

One of the great things about using Webtop is having a foothold outside of the office, so if I'm doing pen testing, or vulnerability scanning I can do it from outside the production network and see what I can find. It also allows me to access different websites than what I can see in the office. For example, if we have a class of websites blocked, like AI ones, but I'd like to read about Claude Mythos I can't at work, no matter how important it is for actual work. So I can use webtop to do that research without waiting until I get home. 

It's handy also, because you can drag stuff to the webtop page and upload it into your desktop or file system. As an exfiltration system it could be very good, so I made sure our DLP was up to the challenge - and it proved an interesting test system to verify that the DLP rules were working and firing when they were supposed to. 

I haven't go screenshots for you to see - instead go and check out the developer's site and spin it up in a docker container. It won't take long and the outcome is a great tool for work and play. 

Sunday, 31 May 2026

TheHive - an excellent case management tool for Digital Forensics!

 In my work in cybersecurity, I've been quietly using TheHive made by Strange Bee https://strangebee.com/thehive/ for the last few years. Initially I was searching for something to analyse forensic data and stumbled on this project. It's got both an Open Source and a paid version, and I've had great value from the community version. Paired with Cortex, TheHive is a powerful tool for the cybersecurity professional. Cortex is the system that does the analysis of your artefacts and then reports back into TheHive. This isn't the only integration that TheHive supports. You can push new cases into it from both MISP and from Wazuh, and then run triage and analysis from within TheHive. It will push details back into MISP so when you review an alert or report, then you can classify it in TheHive once, and it will update it back into MISP which is pretty neat.

Here is what a couple of entries on the Dashboard looks like:


The dialogue box to create a case is below 



And this is what the case page looks like:


Typically, I'll do the following:

  • Create a case, choosing the appropriate level of severity
  • Add at least one task to the case - usually "Review Observables" which is TheHive talk for artefacts associated with the case - and these can be all different types
  • Add the observables - of which there can be many types as seen in this screenshot: 

    and with the "Type" sorted out:

    Here is where TheHive and Cortex shine together. The observable type is linked to analytics that Cortex runs for you - you'll have to set it up, but the good news is, it's quite straightforward and can all run on a single server. Cortex will run the analysis of your observable and then report back. For example, you might configure Cortex to query Google DNS for bad websites, VirusTotal for known bad artefacts, AbuseFinder is handy, and so is Urlscan.io. Here is an example of what a couple of bad IP addresses look like after Cortex has analysed them:
    Red is bad, Orange is suspected bad and green is... well Cortex either isn't sure or the results are inconclusive. 
Cortex requires some grunt to run, so when you read that TheHive + Cortex needs 16GB of RAM and at least 8 CPUs you can understand why - with many concurrent analytics being performed against the observables, and doing it in a timely manner. I run it on my Proxmox server and it gets along quite adequately. 

When you're working through the case, I use the Tasks to capture what I'm seeing, and use the "Comments" to report on my findings. These can be timestamped (which you should always do) and if you happen across an observable or a similarity to another case, TheHive will automatically link it through. Then you can begin the next phase of action, whatever that may be, and track the case to its finale. In the example above, we saw significant attacks on our Web Application Firewall and blocked the addresses, fixing the problem from a known bad (at the time) IP address. It may have been fixed since, and that's why it is important to re-analyse observables. Hijacked sites/IPs or similar can be recovered and I always want to give my fellow cyber security and IT pros the chance to fix their systems without needlessly blocking anyone. 

TheHive has nice reporting (I don't have an example that doesn't have sensitive data in it), and I've found as a system for managing what I am seeing and being asked to respond to, it has been excellent. I use the Community edition - I don't get a lot of cases through work, but I do get a few when I'm helping out people outside of the office and TheHive is great for supporting that community work. I've had several interactions with their team and they've been generally very good, so thank you StrangeBee members!

I've meant to write about TheHive for a while - it's a great tool, and I think that if you've got a forensic element to your work it can really add value to that work. 

Wednesday, 26 November 2025

Taking notes with Bookstack

 I've been looking to use a different note taking tool than Confluence - only because I want to have my stuff self-hosted, so I've been poking around at a few different options. I've played with rwMarkable, Trillium, Notion and others. Suffice to say, I've been down a rabbit hole on this... and I've ended up on Bookstack.

You can find the website here: https://www.bookstackapp.com/  Self-hosted is very attractive to me at the moment. I really don't have a lot of love for having my data out there with anyone else - especially US based companies. There's a bit of uncertainty out there with the behaviour of the US government, so I'd prefer to repatriate my data where possible.

So I needed somewhere I could punch a heap of written data, with some features, a nice editor and not too hard to manage. Happily, I discovered Bookstack.

Under Proxmox, I set up an LXC (Linux Container) and then using a script from https://community-scripts.github.io/ProxmoxVE/scripts?id=bookstack I installed my instance fairly simply! It's running with 1 vCPU, 1GB of RAM and 4GB of disk space - it's hardly the biggest VM I'm running (ah the beauty of the LXC in all it's glory!). Even with these modest specifications, I've found it to run very efficiently, easily uploading images and managing some quite sizeable documents.

Here's a screenshot of what my page looks like:


I have two "Shelves" and each Shelf has multiple books in it. I won't show them - there's secret stuff in there :-)

While it's hosted on my Proxmox server internally, I've used Cloudflare tunnels to provide me with a nice Zero Trust way to access my own systems from anywhere. MFA + Conditional Access all courtesy of the Cloudflare's free tier. Additionally, and I can't shout this out enough - I used Cloudflare for all my DNS which means that managing tunnels and published applications is that much easier. It's a lovely way to do things and I'm praying that we don't get a bunch of enshittification take place. For the moment, it's a wonderful way to do things.

But onto Bookstack - it's a nice WYSIWYG interface. I'm using the dark theme and it looks like this: 


Now, here's a tip - up until about 2 hours ago, it didn't quite look like this. Make sure in the .env file that you have the correct URL or things won't work properly - drafts won't save, the scroll bar won't work, and the text on the dark page will be black not white. Easily fixed by up sorting out the .env file and then running the php update command. 

Bookstack is a nice, lightweight application and works very well. Combined with the easy Proxmox backups, I have found it to be an excellent system for keeping my documentation together. Try it out!

Wednesday, 24 September 2025

Experiences with Jellyfin

 I've been running Jellyfin for a while now - I tried Plex but it didn't gel for me. Jellyfin was pretty straightforward and just seemed to work really easily. So here's their website: https://jellyfin.org/ 

There are a few different ways to run Jellyfin - install it on a system running on bare metal, or a virtual machine, or even in a container (either a Proxmox LXC or a docker container). I messed around with it a bit, and decided to take a straightforward route - install it onto a virtual Ubuntu Server running on one of my Proxmox servers. 

The set up was pretty straightforward - there's some good details here: https://jellyfin.org/downloads/server and it was easy to set up the repositories and get the thing going. The initial configuration is fairly simple, and for me it required a few components:

  • a server to run Jellyfin
  • a link of some type to where all my media (TV and Movies) live
I have a NAS with plenty of disk space so I set up an NFS link and hooked the two servers up together. This was pretty easy, and for this install, I gave Jellyfin read/write access to the different directories - so if Jellyfin was downloading images or metadata I had a chance to keep it all neat and tidy together. The security is simple, but reasonably OK - it won't keep anyone determined out, but it's not critical data.

So after the initial install and set up of Jellyfin - there are some great guides out there so it's worth finding one and getting into it - I added the TV and Movie folders to Jellyfin and kicked off the initial scan. There's a fair bit in those folders - I've spent a small fortune on DVDs and digital media over the last few years, so this took a while to complete. Then there was the work to go through and make sure that the Movies were properly identied. Gran Turino never seems to be detected properly - but it's reasonably straightforward to fix it up. The data flows between servers got fairly intense for a while but eventually settled down.

There are some tuning options in Jellyfin - go to the three lines in the top left, and then Dashboard:
Plenty of things to touch and play with in there :-) It's worth reading through some of the documentation to make sure you pick the best options. I typically will enable a few extra plugins:


These are to get the box sets of TV series right, and the images / identifiers correct for files. Choose your own adventure. 

I had been watching Jellyfin via iPad or via a web browser, and it wasn't until I was poking around a bit that I found an app for the Apple TV - Swiftfin! This was a game changer in our house - we had used a media PC for all our TV and movie watching and now we could just use the Apple TV which is great! 

With a relatively slow internet connection (25/5Mbps) I had been downloading only low res stuff - otherwise it took forever to get and wasn't great for fast movie viewing. This was fine - I was running Jellyfin on a server with Xeon 4114 Silver processors - which are great for compute and server stuff and absolutely crap for video decoding. As the Australian NBN network was upgraded and I managed to get a fiber upgrade to 100/20 speeds and then, almost unbelievably a free upgrade to 500/50 meant all of a sudden those high res, much nicer looking downloads were in my reach! So excitement!

But with great speeds (and resolutions) come great encoding and decoding requirements. Dual Xeon processors don't cut it (especially when they are server CPUs) so I have a little problem - the load on the CPUs is huge and it takes a long time to sort out the video to deliver it. To fix this, I lashed out and picked up an Nvidia Tesla P4 server GPU - and wow what an impact this has made. The load on the CPUs has dropped to a negligible level and the responsiveness of the video playback is excellent - virtually real time which is fantastic!

Settings look like this (so I have a record if Jellyfin dies):



It's really worth the $130AUD that I spent on it - gotta love second hand gear off eBay! Really worth it. 

I've had very little trouble with Jellyfin - it's been a solid bit of software to work with. If you combine with the *ARR servers, then it becomes a thing of great beauty - but more on that later!

Omarchy - the new darling of the Linux world

 Omarchy is the buzzword at the moment, with it turning up on Network Chuck's YouTube channel. I came across it via DHH's blog post ...