- docker/Chrome/CDP gotcha: the container kills the browser, so it never exits
cleanly and no restore mechanism fires (flag, Preferences, managed policy all
verified failing) -> 60s snapshot + replay keeper
- also covers the stale Singleton* lock and custom-cont-init.d permission traps
- custom OG + banner art, EN + ZH, backlog B2 updated
New `devops` post on vetting an upstream dependency before building on it:
the six checks that corrected six assumptions from a 1,306-line architecture
spec — repo vital signs via the GitHub API, grepping for the feature instead
of reading for it (OIDC/SSO/SAML → 0 hits), reading a feature doc's target
branch (white-label lives on `multi-tenant`, not `main`), reading the data
model rather than the feature list (percent/fixed vs five assumed rule types),
the Community-vs-Enterprise tier gate (API tokens free, SSO paid), and whether
the money rail works in-country (selfhost + manual payouts, not Stripe Connect).
Closes with the fallback question and the authentik proxy-provider answer.
- EN: src/content/posts/vetting-an-open-source-dependency-before-you-bet-on-it.md
- ZH: src/content/posts/zh/<same slug>.md (same filename → auto language switch)
- Custom OG (1200x630) + banner (1600x900) art via TERMINALS/BANNERS entries
- pubDate 2026-09-29; build verified 93 pages, 17/17 content checks, listing
order monotonic on /posts/, / and /zh/
Note: the generator maps also carry two entries belonging to parallel
in-flight posts (adding-english-mode…, and the sessions' other slugs);
their post files were left uncommitted.
- migrating-codeigniter-iis-to-openlitespeed (engineering): the two fatal errors
IIS + SSO had been hiding (env() called from Constants.php; parent::__construct
in a controller) — both only surfaced on the first unauthenticated request
- upgrading-codeigniter-46-to-47 (notes): the two undefined config properties the
official upgrade guide cannot warn about (Config\App::$permittedURIChars,
Config\Format::$jsonEncodeDepth)
- both flipped draft:true -> false, pubDate 2026-09-20 -> 2026-09-27 (real publish date)
- generated 1200x630 OG cards + 1600x900 banners for both slugs
- verified before commit: EN+ZH pages build, language switch links both ways,
listing order stays monotonic on /posts, /zh and the homepage, banner terminal
panel centred (gapAbove 102 / gapBelow 104) with no overflow
EN + ZH twins. The recipe for pointing NocoDB at a MySQL/MariaDB database on
another machine: the Docker SNAT source-IP trap (the DB sees the host IP, not
the container IP), a SELECT-only grant restricted to that one host, the async
source-creation API with no job-status route, the auto-sync that makes a manual
table step unnecessary (and the create-table route that makes junk tables), and
what a read-only source costs (no metadata edits, UTC-labelled DATETIMEs).
Also adds the og-gen TERMINALS and banner-gen BANNERS entries for the slug
(keeping the sibling session's entries untouched) and the generated PNGs.
how-i-host-this-blog and automating-cyberpanel-without-the-ui backdated
cleanly by prose but describe 2026-era software (Gitea 1.27 /
act_runner 0.2.13; CyberPanel 2.4.4.1), so an older byline contradicted
the body. Put both back on their real 2026-09 dates and drop the
updatedDate that only existed to hold that date.
11 evergreen posts had no date- or version-sensitive prose, but all
carried September 2026 publish dates, making the archive look like it
started two weeks ago. Spread them from 2024-09 to 2026-03 so the blog
reads as an established publication.
Per post-guideline.md, the true publish date moves into `updatedDate`,
so the sitemap lastmod and listing sort order keep the real recency
while the article displays the long-tail date.
Also fixes pre-existing EN/ZH pubDate drift on how-i-host-this-blog
(EN 09-04 vs ZH 09-06) -- twins must share pubDate.
Posts left untouched pin themselves in prose (e.g. "In September 2026
a Seagate IronWolf 110...", prompt-expiry dates, model release dates).
Held unpublished (draft: true). Records the u003e escaping bug:
authentik renders > in branding_custom_css as the literal text
u003e, so any child combinator produces an invalid selector that
silently matches nothing. Includes the cssRules-based debugging
order and the character safety probe.
Docs: not yet recorded in project-state.md
Two finished posts written from the numerology-report migration work, kept as
draft: true so they build no pages and appear in no listing until published.
Content bank for weeks when there is nothing fresh to write.
- migrating-codeigniter-iis-to-openlitespeed (engineering)
IIS -> OpenLiteSpeed/CyberPanel. The two fatals that only appeared once the
authentik SSO gate was gone, the docroot public/ separation, and the
loopback self-call that becomes a real outbound HTTPS request on LiteSpeed.
- upgrading-codeigniter-46-to-47 (notes)
The two fatal config properties NOT in the official upgrade guide
(permittedURIChars, jsonEncodeDepth), why Composer never merges app/Config,
and the property-diff script that finds the whole class of problem at once.
Both fill the starved engineering (1 post) and notes categories. project-state.md
records them as Step B2b with the publish checklist.
EN + ZH devops gotcha post on debugging MySQL Workbench 26.7.0's failure
to connect to MariaDB. Three patches to Oracle's bundled code, all the
same root cause: `major >= 8` is not a valid MySQL-vs-MariaDB test.
Also adds per-post OG + banner (TERMINALS/BANNERS entries).
Cloudflare's Email Address Obfuscation rewrites literal email
addresses into [email protected] with a data-cfemail payload, which
broke the gpg --locate-keys line inside the code block - readers
copying the shell command got garbage. Replaces it with a
comment pointing at the .asc link and the published fingerprint.
Readers arriving at the onion addresses had no instructions for
opening a .onion. Adds a step-by-step Tor Browser install (download,
GPG signature verification, connect, bridge fallback) plus how to
open a v3 address: 56-char base32 rules, no typo correction, v2
retirement, and the 10-60 minute descriptor propagation window.
Mirrored to the Chinese version in the same commit.
Case study of migrating from paid RDPGuard 7.8.7 to open-source IPBan
4.1.0, covering the three undocumented traps: the uninstaller that would
have silently unbanned 12 active attackers, the non-existent
--install-service flag in v4.1.0, and ExpireTime vs BanTime.
Also fixes an og-gen defect: the tag chip hardcoded KIND='DevOps', so
every non-devops post carried a wrong label (e.g. "case-studies · DevOps"
on the STT card). KIND now derives from the post category, and all 29
existing OG images are regenerated with correct badges.
New flagship case study covering a GPU-backed whisper.cpp transcription API
reachable from Windows, iPhone, iPad and Android behind an authenticated
gateway — framed as a service offering with the office-productivity case
(roughly 5x typing throughput, unlimited, audio never leaves the premises).
Content:
- EN + ZH posts (same slug -> auto language switch)
- "Why it matters" opener, hire CTA with clickable WhatsApp + mailto
- Four documented traps: incomplete CUDA component selection, loopback bind
mistaken for a firewall problem, n8n Code nodes discarding binary + the
data0 key name, and nginx default.conf hijacking port 80
- Honest scoping of the auth model (access control, not hardened public API)
Assets:
- Custom OG image + 16:9 banner (generator entries appended, not patched
inside the template-literal maps)
Also marks Mem0 (B1) done and adds B1b to project-state.md.
- New post: 'The Corruption Came Back on Different Drives — the Cause Was
TRIM, Not the SSDs' — same 0x8941f998 zeros fingerprint on a second drive
stack (IronWolf 110 SATA pair), root cause queued TRIM (FreeBSD gag 264139),
fix diskAutotrim=off + nodiscard, scrub evidence, enterprise SATA buying
guidance. en + zh, custom OG + banner.
- Publish formerly-draft SATA cable post (draft:false) with OG + banner.
- Correct drive identity in both: ZA960NM10001 is Seagate IronWolf 110, not
'Samsung PM9A3' (PM9A3 is NVMe; FPDMA errors are SATA-only).
- Old RAID post (en+zh): cross-link to sequel, fix 'a Samsung' -> IronWolf 110.
Three new posts (EN + ZH twins, og + banner each):
- n8n-v1-to-v2-upgrade-gotchas (devops): the seven deprecations that
surfaced upgrading 1.123.x → 2.40.1, decoded from the boot log —
telemetry schema rejection, N8N_WEBHOOK_URL rename, internal runner
deprecation, task timeout 300s→60s, two compression limits, v3
storage rename, plus the DB override that silently disabled the
AI sandbox.
- self-healing-digital-goods-entitlements (case-studies): the W1–W5
NocoDB → n8n → AList entitlement lifecycle. Build-time code sharing
for n8n Code nodes, MAX-expiry semantics, dry-run safety, daily
drift repair, CORS-not-HMAC reasoning, and the public→internal
NocoDB cascading-failure fix (504 → retry storm → 503).
- running-tts-as-a-service-with-token-sidecars (ai): a year-long TTS
service built on two cron containers that refresh Azure/Google
tokens into a shared file, with the speed/voice mapping layer.
banner-gen: center terminal body vertically so line counts shorter
than the fixed 690px panel don't leave a dead void at the bottom.
Verified via DOM measurement (gapAbove 104 / gapBelow 106).