<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Aquasp's blog</title><link>https://aquasp.blog/</link><description>Recent content on Aquasp's blog</description><generator>Hugo -- gohugo.io</generator><language>en-us</language><lastBuildDate>Fri, 15 May 2026 15:53:11 +0000</lastBuildDate><atom:link href="https://aquasp.blog/index.xml" rel="self" type="application/rss+xml"/><item><title>How to Setup Flutter for Development in Ubuntu 24.04</title><link>https://aquasp.blog/how-to-setup-flutter-for-development-in-ubuntu-24-04/</link><pubDate>Tue, 14 Apr 2026 01:15:39 +0000</pubDate><guid>https://aquasp.blog/how-to-setup-flutter-for-development-in-ubuntu-24-04/</guid><description>&lt;p&gt;The fastest and easiest way with the latest Flutter version.&lt;/p&gt;&#10;&lt;h2 id="step-1-install-flutter-using-snap"&gt;Step 1: Install Flutter using Snap&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo snap install flutter --classic&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-2-install-openjdk"&gt;Step 2: Install OpenJDK&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo apt install openjdk-17-jdk -y&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-3-download-android-cli-tools"&gt;Step 3: Download Android CLI Tools&#10;&lt;/h2&gt;&lt;p&gt;Go &lt;a class="link" href="https://developer.android.com/studio?ref=aquasp.blog#command-line-tools-only" target="_blank" rel="noopener"&#10; &gt;here&lt;/a&gt; and grab the latest for Linux.&lt;/p&gt;&#10;&lt;p&gt;Create folder:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;mkdir ~/Android/Sdk&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Make sure you are using this exact structure:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;~/Android/Sdk/cmdline-tools/latest/bin/ ← sdkmanager&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-4-add-to-bashrc"&gt;Step 4: Add to ~/.bashrc&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;export ANDROID_SDK_ROOT=$HOME/Android/Sdkexport ANDROID_HOME=$ANDROID_SDK_ROOTexport&#10;PATH=$PATH:$ANDROID_SDK_ROOT/cmdline-tools/latest/binexport PATH=$PATH:$ANDROID_SDK_ROOT/platform-tools # Nextexport JAVA_HOME=/usr/lib/jvm/java-17-openjdk-amd64export PATH=$PATH:$JAVA_HOME/binexport CHROME_EXECUTABLE=/usr/bin/brave-browser&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-5-install-sdkmanager"&gt;Step 5: Install sdkmanager&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;sdkmanager &amp;#34;platform-tools&amp;#34; &amp;#34;platforms;android-36&amp;#34; &amp;#34;build-tools;36.0.0&amp;#34;&#10;sdkmanager --update&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-6-flutter-setup"&gt;Step 6: Flutter Setup&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;flutter config --android-sdk ~/Android/Sdkflutter doctor --android-licenses # Accept all&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-7-check"&gt;Step 7: Check&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;flutter doctor -v&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;You now have a clean Flutter setup without Android Studio.&lt;/p&gt;&#10;&lt;p&gt;Thanks – build on! 🚀&lt;/p&gt;&#10;</description></item><item><title>Ditch the Official App: Use Your Mi Band Privately with Open-Source Alternatives</title><link>https://aquasp.blog/ditch-the-official-app-use-your-mi-band-privately-with-open-source-alternatives/</link><pubDate>Tue, 23 Dec 2025 20:23:05 +0000</pubDate><guid>https://aquasp.blog/ditch-the-official-app-use-your-mi-band-privately-with-open-source-alternatives/</guid><description>&lt;p&gt;If you love wearing a wearable device like a Mi Band but want to protect your privacy (like me), there&amp;rsquo;s a great way to do it!&lt;/p&gt;&#10;&lt;h2 id="check-device-compatibility-first"&gt;Check Device Compatibility First&#10;&lt;/h2&gt;&lt;p&gt;The first step is to verify if your device is supported. Xiaomi and Huawei devices generally have the best compatibility. I recommend checking two popular alternatives:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;GadgetBridge&lt;/strong&gt;: Fully open-source and highly privacy-focused. It works reliably, though the UI isn&amp;rsquo;t the most modern or beautiful.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Notify for Mi Band&lt;/strong&gt;: Offers a much nicer, more polished UI (in my opinion), but it&amp;rsquo;s not open-source and the Pro version (ad-free) costs about $3.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Privacy-wise, both options are far superior to the official Xiaomi app—no constant data sharing with servers.&lt;/p&gt;&#10;&lt;p&gt;It&amp;rsquo;s almost ironic that Chinese-brand devices end up providing better privacy options than many Western brands when paired with these alternatives. This is likely just a side effect of their popularity and competitive pricing.&lt;/p&gt;&#10;&lt;h2 id="extract-the-authentication-token"&gt;Extract the Authentication Token&#10;&lt;/h2&gt;&lt;p&gt;Unfortunately, you&amp;rsquo;ll need the official app temporarily. Download the &lt;strong&gt;Xiaomi Mi Fitness&lt;/strong&gt; app, pair your band, create a Xiaomi account, and update the firmware to the latest version*.&lt;/p&gt;&#10;&lt;p&gt;Once that&amp;rsquo;s done, you need to extract the authentication (auth) token from Xiaomi. The easiest method right now is using the &lt;strong&gt;Notify for Mi Band&lt;/strong&gt; app.&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;Download Notify for Mi Band from the Google Play Store (there are two versions, ensure that you are downloading the correct one for your device)&lt;/li&gt;&#10;&lt;li&gt;Start the setup process in the app.&lt;/li&gt;&#10;&lt;li&gt;You&amp;rsquo;ll see two options for getting the token: &lt;strong&gt;Offline&lt;/strong&gt; and &lt;strong&gt;Online&lt;/strong&gt;.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;The offline method requires exporting logs from the official Mi Fitness app and extracting the token from them. I tried this several times, but it never worked for me—I couldn&amp;rsquo;t even find the relevant logs manually.&lt;/p&gt;&#10;&lt;p&gt;So, I strongly recommend the &lt;strong&gt;online method&lt;/strong&gt;:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Log in with your Xiaomi account email and password.&lt;/li&gt;&#10;&lt;li&gt;Xiaomi will send a verification code to your email.&lt;/li&gt;&#10;&lt;li&gt;Enter the code, and the app will automatically retrieve the token for you.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="final-steps-switch-over-and-uninstall-the-official-app"&gt;Final Steps: Switch Over and Uninstall the Official App&#10;&lt;/h2&gt;&lt;p&gt;After getting the token:&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;Enter it in Notify for Mi Band (or GadgetBridge, if you&amp;rsquo;re using that).&lt;/li&gt;&#10;&lt;li&gt;Grant all necessary permissions.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Uninstall the official Mi Fitness app immediately&lt;/strong&gt;.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;The band can only connect and sync with one app at a time. Keeping the official app installed will cause connection issues or prevent proper syncing with your chosen alternative.&lt;/p&gt;&#10;&lt;p&gt;Now you&amp;rsquo;re all set! Customize notifications, enable/disable features as you like, find your phone or band, install free watchfaces, and track steps, calories, and heart rate—all in a clean, beautiful UI with no privacy compromises.&lt;/p&gt;&#10;&lt;p&gt;One minor issue I&amp;rsquo;ve noticed: sleep tracking is not syncing properly. I&amp;rsquo;m not sure if this is specific to the Mi Band 10, a firmware quirk, or a setting I changed. The data still shows correctly on the band itself, so it&amp;rsquo;s just a sync problem. Personally, I don&amp;rsquo;t mind—I mainly use my Mi Band for a convenient clock, flashlight,quick heart rate checks during workouts and changing music on a bluetooth speaker.&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;At least for the Mi Band 10, the latest firmware (as of Dec 2025) hasn&amp;rsquo;t broken compatibility with Notify for Mi Band.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;</description></item><item><title>Fixing Blank/Grey Screen on Album Pages in Finamp (Jellyfin Music Player)</title><link>https://aquasp.blog/fixing-blank-grey-screen-on-album-pages-in-finamp-jellyfin-music-player/</link><pubDate>Mon, 15 Dec 2025 15:02:30 +0000</pubDate><guid>https://aquasp.blog/fixing-blank-grey-screen-on-album-pages-in-finamp-jellyfin-music-player/</guid><description>&lt;p&gt;If you&amp;rsquo;re using &lt;strong&gt;Finamp&lt;/strong&gt; to stream or download music from your &lt;strong&gt;Jellyfin&lt;/strong&gt; server and encountering a blank (or grey) screen when opening an album page—where no tracks load and you may need to force-close the app—this is a common issue, especially after upgrading Jellyfin to version 10.11.x.&lt;/p&gt;&#10;&lt;p&gt;This problem typically occurs due to changes in how Jellyfin handles music metadata in newer versions, causing Finamp to fail loading album tracks properly.&lt;/p&gt;&#10;&lt;h2 id="the-fix-refresh-metadata-in-jellyfin-search-for-missing-metadata"&gt;The Fix: Refresh Metadata in Jellyfin (Search for Missing Metadata)&#10;&lt;/h2&gt;&lt;p&gt;The most reliable workaround is to force Jellyfin to refresh your music library metadata:&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;Log in to your Jellyfin web dashboard (admin account recommended).&lt;/li&gt;&#10;&lt;li&gt;Go to &lt;strong&gt;Dashboard&lt;/strong&gt; &amp;gt; &lt;strong&gt;Libraries&lt;/strong&gt;.&lt;/li&gt;&#10;&lt;li&gt;Select your &lt;strong&gt;Music&lt;/strong&gt; library.&lt;/li&gt;&#10;&lt;li&gt;Click the three dots (&amp;hellip;) menu next to the library name.&lt;/li&gt;&#10;&lt;li&gt;Choose &lt;strong&gt;Refresh Metadata&lt;/strong&gt;.&lt;/li&gt;&#10;&lt;li&gt;In the refresh options:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Check &lt;strong&gt;Search for missing metadata&lt;/strong&gt;.&lt;/li&gt;&#10;&lt;li&gt;Optionally enable other options like &amp;ldquo;Replace existing images&amp;rdquo; or &amp;ldquo;Replace all metadata&amp;rdquo; if needed.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;ol start="7"&gt;&#10;&lt;li&gt;Click &lt;strong&gt;Refresh&lt;/strong&gt; (or OK) to start the scan.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This process can take several minutes depending on your library size. Once done, restart Finamp and try opening albums again—they should now load tracks normally.&lt;/p&gt;&#10;&lt;h2 id="additional-notes-on-jellyfin-1011x"&gt;Additional Notes on Jellyfin 10.11.x&#10;&lt;/h2&gt;&lt;ul&gt;&#10;&lt;li&gt;The Finamp team and users have reported &lt;strong&gt;performance regressions&lt;/strong&gt; in Jellyfin 10.11.x, particularly with music libraries (slower loading, higher resource usage).&lt;/li&gt;&#10;&lt;li&gt;If possible, consider staying on or downgrading to Jellyfin 10.10.x for better performance until fixes are fully rolled out in later 10.11 patches.&lt;/li&gt;&#10;&lt;li&gt;For me. I can confirm that even on the latest 10.11.x, the metadata refresh resolves the blank album issue, and overall functionality works well afterward.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="credits"&gt;Credits&#10;&lt;/h2&gt;&lt;ul&gt;&#10;&lt;li&gt;GitHub Issue: &lt;a class="link" href="https://github.com/jmshrv/finamp/issues/1412?referrer=grok.com&amp;amp;ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://github.com/jmshrv/finamp/issues/1412&lt;/a&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;If the issue persists after the scan, check for Finamp updates or report it on the Finamp GitHub repository. Happy listening! :)&lt;/p&gt;&#10;</description></item><item><title>How to enable hardware-Accelerated Video Decoding in Brave on Linux: Smoother Playback and Better Battery</title><link>https://aquasp.blog/how-to-enable-hardware-accelerated-video-decoding-in-brave-on-linux-smoother-playback-and-better-battery/</link><pubDate>Sun, 14 Dec 2025 01:35:15 +0000</pubDate><guid>https://aquasp.blog/how-to-enable-hardware-accelerated-video-decoding-in-brave-on-linux-smoother-playback-and-better-battery/</guid><description>&lt;p&gt;Hardware-accelerated video decoding offloads playback from CPU to GPU, improving performance, reducing heat, and extending battery life—especially for high-resolution videos. On Linux, this works in Chromium-based browsers like Brave, but often requires flags. &lt;strong&gt;No more relying on h264ify extensions or downloading videos for MPV!&lt;/strong&gt;&lt;/p&gt;&#10;&lt;h2 id="benefits"&gt;Benefits&#10;&lt;/h2&gt;&lt;ul&gt;&#10;&lt;li&gt;Smoother high-res (1080p+) playback&lt;/li&gt;&#10;&lt;li&gt;Lower CPU usage&lt;/li&gt;&#10;&lt;li&gt;Better battery life on laptops&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="prerequisites-ubuntu-based-distros-eg-mint"&gt;Prerequisites (Ubuntu-Based Distros, e.g., Mint)&#10;&lt;/h2&gt;&lt;p&gt;For Intel GPUs (common on laptops):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo apt update&#10;sudo apt install intel-media-va-driver-non-free vainfo&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Verify with vainfo (should list supported profiles like VP9/H.264).&lt;/p&gt;&#10;&lt;p&gt;AMD/NVIDIA: Ensure Mesa/proprietary drivers are installed.&lt;/p&gt;&#10;&lt;h2 id="enabling-flags-support-on-ubuntu-based-distros"&gt;Enabling Flags Support on Ubuntu-Based Distros&#10;&lt;/h2&gt;&lt;p&gt;Brave&amp;rsquo;s Debian package doesn&amp;rsquo;t read brave-flags.conf by default (unlike Arch&amp;rsquo;s AUR package). Create a wrapper:&lt;/p&gt;&#10;&lt;p&gt;Fix permissions:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo chown --reference=/usr/bin/brave-browser-stable.original /usr/bin/brave-browser-stable&#10;sudo chmod --reference=/usr/bin/brave-browser-stable.original /usr/bin/brave-browser-stable&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Create new launcher:Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo nano /usr/bin/brave-browser-stable&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Paste:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;#!/bin/sh&#10;: $$ {XDG_CONFIG_HOME=&amp;#34; $${HOME}/.config&amp;#34;}&#10;unset -v flags_conf&#10;flags_conf=&amp;#34;${XDG_CONFIG_HOME}/brave-flags.conf&amp;#34;&#10;if [ -f &amp;#34;${flags_conf}&amp;#34; ]&#10;then&#10; unset -v flags&#10; flags=&amp;#34;$$ (sed &amp;#39;s/#.*//&amp;#39; &amp;lt; &amp;#34; $${flags_conf}&amp;#34; | tr &amp;#39;\n&amp;#39; &amp;#39; &amp;#39;)&amp;#34;&#10; set -- $$ {flags} &amp;#34; $$@&amp;#34;&#10;fi&#10;exec /usr/bin/brave-browser-stable.original &amp;#34;$@&amp;#34;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Divert the original launcher:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo dpkg-divert --add --rename --divert /usr/bin/brave-browser-stable.original /usr/bin/brave-browser-stable&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Now create/edit ~/.config/brave-flags.conf for flags.&lt;/p&gt;&#10;&lt;h2 id="recommended-flags"&gt;Recommended Flags&#10;&lt;/h2&gt;&lt;p&gt;Add to ~/.config/brave-flags.conf (one line, restart Brave):&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Wayland (often default/best):&lt;/strong&gt;&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;--enable-features=AcceleratedVideoDecodeLinuxGL,AcceleratedVideoDecodeLinuxZeroCopyGL,AcceleratedVideoEncoder&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;strong&gt;Xorg/X11 (or fallback):&lt;/strong&gt;&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;--enable-features=VaapiVideoDecoder,VaapiIgnoreDriverChecks,Vulkan,DefaultANGLEVulkan,VulkanFromANGLE&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="verification"&gt;Verification&#10;&lt;/h2&gt;&lt;ol&gt;&#10;&lt;li&gt;Play a video (e.g., YouTube 1080p+).&lt;/li&gt;&#10;&lt;li&gt;Ctrl + Shift + I → Three dots → More tools → Media.&lt;/li&gt;&#10;&lt;li&gt;Check Decoder name: VaapiVideoDecoder = GPU accelerated (avoid FFmpegVideoDecoder).&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;h3 id="credits"&gt;Credits&#10;&lt;/h3&gt;&lt;p&gt;This amazing commentary on github: &lt;a class="link" href="https://github.com/brave/brave-browser/issues/2300?ref=aquasp.blog#issuecomment-2718755680" target="_blank" rel="noopener"&#10; &gt;https://github.com/brave/brave-browser/issues/2300#issuecomment-2718755680&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;As always, the Arch Wiki is an invaluable resource for all things Linux. If hardware video acceleration still doesn&amp;rsquo;t work, check the wiki directly for the latest flags and troubleshooting tips. &lt;a class="link" href="https://wiki.archlinux.org/title/Chromium?ref=aquasp.blog#Hardware_video_acceleration" target="_blank" rel="noopener"&#10; &gt;https://wiki.archlinux.org/title/Chromium#Hardware_video_acceleration&lt;/a&gt;&lt;/p&gt;&#10;</description></item><item><title>Quick Fix: Stop Ubuntu 24.04 from Automatically Suspending/Sleeping</title><link>https://aquasp.blog/quick-fix-stop-ubuntu-24-04-from-automatically-suspending-sleeping/</link><pubDate>Fri, 12 Dec 2025 19:58:45 +0000</pubDate><guid>https://aquasp.blog/quick-fix-stop-ubuntu-24-04-from-automatically-suspending-sleeping/</guid><description>&lt;p&gt;If your Ubuntu 24.04 system (especially one that started as a server install) randomly suspends or goes to sleep even though it&amp;rsquo;s supposed to be a headless server, you&amp;rsquo;re not alone.&lt;/p&gt;&#10;&lt;p&gt;This seems to happen when a server installation gets partially or fully converted to a &amp;ldquo;desktop&amp;rdquo; environment at some point — even if you never intentionally installed a desktop. In my case, I installed Ubuntu Server 24.04 directly with balenaEtcher onto NVMe/SSD and I got this weird behavior (my N100 server was suspending after 15 minutes).&lt;/p&gt;&#10;&lt;h2 id="the-simple-one-liner-fix"&gt;The Simple One-Liner Fix&#10;&lt;/h2&gt;&lt;p&gt;Run this single command and the random suspensions stop immediately (and persist across reboots):&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo systemctl mask sleep.target suspend.target hibernate.target hybrid-sleep.target&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;That is it!&lt;/p&gt;&#10;</description></item><item><title>Fastest Monero Wallet on Android in 2025? I Timed All Three With My Own Node</title><link>https://aquasp.blog/fastest-monero-wallet-on-android-in-2025-i-timed-all-three-with-my-own-node/</link><pubDate>Wed, 10 Dec 2025 22:46:43 +0000</pubDate><guid>https://aquasp.blog/fastest-monero-wallet-on-android-in-2025-i-timed-all-three-with-my-own-node/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;One of the major pain points of Monero is restoring an old wallet. Today, I will compare the speed of three popular Monero wallets to check which one is the fastest at restoring.&lt;/p&gt;&#10;&lt;h2 id="test-data"&gt;Test data&#10;&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Date of test:&lt;/strong&gt; 2025-12-10&#10;&lt;strong&gt;Device:&lt;/strong&gt; Samsung Galaxy A56 (Exynos 1580, 8 GB RAM, mid-range 2025 phone)&#10;&lt;strong&gt;Connection:&lt;/strong&gt; Local Monero full node over Wi-Fi (same LAN, Using Deco S7)&#10;&lt;strong&gt;Wallet:&lt;/strong&gt; Legacy 25-word seed created in December 2024 (~1 year old, moderate transaction history)&#10;&lt;strong&gt;Goal:&lt;/strong&gt; Full restore + sync from my restore height with each wallet to see real-world performance on a typical self-hosted setup in 2025.&lt;/p&gt;&#10;&lt;h3 id="the-contenders"&gt;The contenders&#10;&lt;/h3&gt;&lt;table&gt;&#10;&lt;thead&gt;&#10;&lt;tr&gt;&#10;&lt;th&gt;Wallet&lt;/th&gt;&#10;&lt;th&gt;Version&lt;/th&gt;&#10;&lt;th&gt;Restore height method&lt;/th&gt;&#10;&lt;th&gt;Notes&lt;/th&gt;&#10;&lt;/tr&gt;&#10;&lt;/thead&gt;&#10;&lt;tbody&gt;&#10;&lt;tr&gt;&#10;&lt;td&gt;Cake Wallet&lt;/td&gt;&#10;&lt;td&gt;5.6.2&lt;/td&gt;&#10;&lt;td&gt;Legacy 25-word&lt;/td&gt;&#10;&lt;td&gt;Official multi-coin wallet&lt;/td&gt;&#10;&lt;/tr&gt;&#10;&lt;tr&gt;&#10;&lt;td&gt;Stack Wallet&lt;/td&gt;&#10;&lt;td&gt;2.4.2&lt;/td&gt;&#10;&lt;td&gt;Legacy 25-word&lt;/td&gt;&#10;&lt;td&gt;Privacy-focused, Bitcoin-first but good XMR support&lt;/td&gt;&#10;&lt;/tr&gt;&#10;&lt;tr&gt;&#10;&lt;td&gt;Monerujo&lt;/td&gt;&#10;&lt;td&gt;4.1.7 (Exolix build)&lt;/td&gt;&#10;&lt;td&gt;Legacy 25-word&lt;/td&gt;&#10;&lt;td&gt;Long-time Android-only Monero favorite&lt;/td&gt;&#10;&lt;/tr&gt;&#10;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h3 id="results"&gt;Results&#10;&lt;/h3&gt;&lt;table&gt;&#10;&lt;thead&gt;&#10;&lt;tr&gt;&#10;&lt;th&gt;Wallet&lt;/th&gt;&#10;&lt;th&gt;Total time to full sync&lt;/th&gt;&#10;&lt;th&gt;Behavior at 90–100%&lt;/th&gt;&#10;&lt;th&gt;Screen stay-on?&lt;/th&gt;&#10;&lt;th&gt;Finished?&lt;/th&gt;&#10;&lt;th&gt;Notes&lt;/th&gt;&#10;&lt;/tr&gt;&#10;&lt;/thead&gt;&#10;&lt;tbody&gt;&#10;&lt;tr&gt;&#10;&lt;td&gt;&lt;strong&gt;Monerujo&lt;/strong&gt;&lt;/td&gt;&#10;&lt;td&gt;&lt;strong&gt;21 minutes 45 seconds&lt;/strong&gt;&lt;/td&gt;&#10;&lt;td&gt;Steady speed, no slowdown&lt;/td&gt;&#10;&lt;td&gt;No&lt;/td&gt;&#10;&lt;td&gt;Yes&lt;/td&gt;&#10;&lt;td&gt;Absolutely crushed it&lt;/td&gt;&#10;&lt;/tr&gt;&#10;&lt;tr&gt;&#10;&lt;td&gt;Cake Wallet&lt;/td&gt;&#10;&lt;td&gt;40 minutes and 13 seconds&lt;/td&gt;&#10;&lt;td&gt;Very slow after ~90%, ETA broken&lt;/td&gt;&#10;&lt;td&gt;Yes (huge W)&lt;/td&gt;&#10;&lt;td&gt;Yes&lt;/td&gt;&#10;&lt;td&gt;Got there, but it was a bit slow&lt;/td&gt;&#10;&lt;/tr&gt;&#10;&lt;tr&gt;&#10;&lt;td&gt;Stack Wallet&lt;/td&gt;&#10;&lt;td&gt;Gave up after ~1 hour 16 minutes&lt;/td&gt;&#10;&lt;td&gt;Crawled after 98%, resync didn’t help&lt;/td&gt;&#10;&lt;td&gt;No&lt;/td&gt;&#10;&lt;td&gt;No&lt;/td&gt;&#10;&lt;td&gt;Stuck forever around 98–99%&lt;/td&gt;&#10;&lt;/tr&gt;&#10;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;h3 id="detailed-observations"&gt;Detailed observations&#10;&lt;/h3&gt;&lt;h4 id="monerujo-417--the-clear-winner"&gt;Monerujo 4.1.7 – The clear winner&#10;&lt;/h4&gt;&lt;ul&gt;&#10;&lt;li&gt;Started scanning instantly&lt;/li&gt;&#10;&lt;li&gt;Progress was smooth and predictable the entire time&lt;/li&gt;&#10;&lt;li&gt;Never slowed down, even in the final 10%&lt;/li&gt;&#10;&lt;li&gt;Just worked. 21m45s from entering the 25th word to “synchronized”.&lt;/li&gt;&#10;&lt;li&gt;Does NOT prevent screen timeout → Android kept suspending the process&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h4 id="cake-wallet-562--it-gets-there-eventually"&gt;Cake Wallet 5.6.2 – It gets there… eventually&#10;&lt;/h4&gt;&lt;ul&gt;&#10;&lt;li&gt;Restore started fine&lt;/li&gt;&#10;&lt;li&gt;ETA counter was not precise (showed 2 minutes for 30 minutes)&lt;/li&gt;&#10;&lt;li&gt;Massive slowdown after ~90%&lt;/li&gt;&#10;&lt;li&gt;Kept screen on the entire time ← this alone probably saved the sync from dying&lt;/li&gt;&#10;&lt;li&gt;Eventually finished&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h4 id="stack-wallet-242--disappointing"&gt;Stack Wallet 2.4.2 – Disappointing&#10;&lt;/h4&gt;&lt;ul&gt;&#10;&lt;li&gt;Actually started the fastest of all three&lt;/li&gt;&#10;&lt;li&gt;Flew to 98% in ~25 minutes… then died&lt;/li&gt;&#10;&lt;li&gt;Speed dropped&lt;/li&gt;&#10;&lt;li&gt;Restarting the app resumed at 98.49% but didn’t fix the crawl&lt;/li&gt;&#10;&lt;li&gt;Tried using the &amp;ldquo;Resync&amp;rdquo; button – no improvement&lt;/li&gt;&#10;&lt;li&gt;Does NOT prevent screen timeout → Android kept suspending the process&lt;/li&gt;&#10;&lt;li&gt;Abandoned after 1+ hours of no meaningful progress&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h3 id="conclusion-monerujo-is-the-fastest-in--2025"&gt;Conclusion: Monerujo is the fastest in 2025&#10;&lt;/h3&gt;&lt;p&gt;If you want to restore an old Monero wallet on a phone using your own node in 2025, the answer is crystal clear:&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Monerujo is in a completely different league.&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;Cake Wallet is still very usable and has an amazin UI/polish, but the sync performance lag is real. Stack Wallet unfortunately seems broken/super slow for large restores right now&lt;/p&gt;&#10;&lt;p&gt;Shoutout to the Monerujo dev(s) — whatever witchcraft you did with the scanning engine, thank you. Privacy on mobile just became faster.&lt;/p&gt;&#10;&lt;p&gt;Tested on 2025-12-10 with a local node. Your mileage may vary with transaction count, but the relative ordering should hold.&lt;/p&gt;&#10;</description></item><item><title>7 things that you should do after installing WordPress</title><link>https://aquasp.blog/7-things-that-you-should-do-after-installing-wordpress/</link><pubDate>Tue, 09 Dec 2025 01:45:24 +0000</pubDate><guid>https://aquasp.blog/7-things-that-you-should-do-after-installing-wordpress/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Starting a fresh WordPress site in 2026? Whether it&amp;rsquo;s a blog, eCommerce store, or portfolio, these tweaks will supercharge speed, lock down security, and ensure buttery-smooth performance from day one.&lt;/p&gt;&#10;&lt;p&gt;No paid tools required — just free plugins and quick configs. Let&amp;rsquo;s dive in!&lt;/p&gt;&#10;&lt;h2 id="1-auto-resize--compress-images-on-upload"&gt;1. Auto-Resize &amp;amp; Compress Images on Upload&#10;&lt;/h2&gt;&lt;p&gt;Images are the #1 bandwidth killer. Don&amp;rsquo;t upload a 10MB photo and hope for the best — automate compression to keep your site lean.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Recommended Plugin:&lt;/strong&gt; &lt;a class="link" href="https://wordpress.org/plugins/resize-image-after-upload/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Resize Image After Upload&lt;/a&gt; (Free, 90K+ active installs, 4.8/5 rating)&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Install &amp;amp; activate it first thing.&lt;/li&gt;&#10;&lt;li&gt;Set max width/height (e.g., 1920px wide) and compression level (default 82% JPEG quality is solid).&lt;/li&gt;&#10;&lt;li&gt;It auto-resizes JPEG/PNG/GIF on upload, slashes file sizes by 50–80%, and boosts SEO with faster load times.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Pro tip: For bulk-optimizing existing images, pair it with Smush (free tier handles 50 images/month).&lt;/p&gt;&#10;&lt;p&gt;Result: Pages load 2–3x faster, less server strain, happier Google rankings.&lt;/p&gt;&#10;&lt;h2 id="2-strip-out-unnecessary-bloat"&gt;2. Strip Out Unnecessary Bloat&#10;&lt;/h2&gt;&lt;p&gt;WordPress ships with &amp;ldquo;extras&amp;rdquo; you might not need — like Gutenberg blocks, XML-RPC, or emoji scripts. Trim the fat for a lighter core.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Recommended Plugin:&lt;/strong&gt; &lt;a class="link" href="https://wordpress.org/plugins/unbloater/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Unbloater&lt;/a&gt; (Free, 10K+ active installs, 5/5 rating)&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;Simple dashboard under &lt;strong&gt;Settings &amp;gt; Unbloater&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;Recommended toggles:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Backend:&lt;/strong&gt; Disable auto-updates (if you handle them manually), limit post revisions to 3, hide update nags for non-admins, disable XML-RPC.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Frontend:&lt;/strong&gt; Remove RSD/WLW manifests, shortlinks, feed links, jQuery Migrate, emoji scripts.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Block Editor:&lt;/strong&gt; Fully disable Gutenberg (if using Classic Editor) or remove unused blocks.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Extras:&lt;/strong&gt; Block DNS prefetch to WordPress.org, remove generator meta tag.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Everything is reversible — toggle off if issues arise. This cuts database queries and JS/CSS bloat by 20–30%.&lt;/p&gt;&#10;&lt;h2 id="3-tame-the-heartbeat-api"&gt;3. Tame the Heartbeat API&#10;&lt;/h2&gt;&lt;p&gt;WordPress&amp;rsquo; Heartbeat API pings your server every 15–60 seconds for autosave, user presence, etc. Great for collaboration, but it spikes CPU on shared hosting.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Recommended Plugin:&lt;/strong&gt; &lt;a class="link" href="https://wordpress.org/plugins/heartbeat-control/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Heartbeat Control&lt;/a&gt; (Free, 90K+ active installs, 4.1/5 rating)&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Go to &lt;strong&gt;Settings &amp;gt; Heartbeat Control&lt;/strong&gt;.&lt;/li&gt;&#10;&lt;li&gt;Set intervals: 60 seconds (frontend), 120 seconds (dashboard/editor).&lt;/li&gt;&#10;&lt;li&gt;Or disable entirely on frontend if you don&amp;rsquo;t need live previews.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Unbloater can handle this too. Expect 10–20% CPU savings on idle sessions.&lt;/p&gt;&#10;&lt;h2 id="4-limit-post-revisions"&gt;4. Limit Post Revisions&#10;&lt;/h2&gt;&lt;p&gt;By default, WordPress saves 25 revisions per post — bloating your database over time (e.g., a 1,000-post site = 25K+ entries).&lt;/p&gt;&#10;&lt;p&gt;Add to &lt;code&gt;wp-config.php&lt;/code&gt; (before &amp;ldquo;That&amp;rsquo;s all, stop editing!&amp;rdquo;):&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-php" data-lang="php"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;// Limit to 3 revisions (or false to disable)&#10;&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#a6e22e"&gt;define&lt;/span&gt;(&lt;span style="color:#e6db74"&gt;&amp;#39;WP_POST_REVISIONS&amp;#39;&lt;/span&gt;, &lt;span style="color:#ae81ff"&gt;3&lt;/span&gt;);&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Unbloater has a toggle for this. Clean up old ones with WP-Optimize (free).&lt;/p&gt;&#10;&lt;p&gt;Result: Smaller DB = faster queries and backups.&lt;/p&gt;&#10;&lt;h2 id="5-disable-xml-rpc-unless-needed"&gt;5. Disable XML-RPC (Unless Needed)&#10;&lt;/h2&gt;&lt;p&gt;XML-RPC enables remote posting/apps but is a brute-force magnet (most bots target it).&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;If using Jetpack/mobile apps: Keep it, but whitelist your IP.&lt;/li&gt;&#10;&lt;li&gt;Otherwise: Block via .htaccess (Apache/LiteSpeed):&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;&amp;lt;Files xmlrpc.php&amp;gt;&#10;Order Deny,Allow&#10;Deny from all&#10;# Allow from YOUR.IP.ADDRESS (uncomment if needed)&#10;&amp;lt;/Files&amp;gt;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Unbloater or &lt;a class="link" href="https://wordpress.org/plugins/loginizer/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Loginizer&lt;/a&gt; (free, 1M+ installs) can disable it too.&lt;/p&gt;&#10;&lt;h2 id="6-lock-down-logins-with-rate-limiting"&gt;6. Lock Down Logins with Rate Limiting&#10;&lt;/h2&gt;&lt;p&gt;Bots hammer /wp-login.php 24/7. Limit attempts to stop brute-force attacks cold.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Top Pick:&lt;/strong&gt; &lt;a class="link" href="https://wordpress.org/plugins/limit-login-attempts-reloaded/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Limit Login Attempts Reloaded&lt;/a&gt; (Free, 2M+ installs, 4.9/5 rating)&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Defaults: 3 failed attempts → 15-min lockout (escalates to 24h).&lt;/li&gt;&#10;&lt;li&gt;Covers wp-admin, XML-RPC, WooCommerce, custom logins.&lt;/li&gt;&#10;&lt;li&gt;Logs + notifications included.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;&lt;strong&gt;Alternative:&lt;/strong&gt; &lt;a class="link" href="https://wordpress.org/plugins/bruteguard/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;BruteGuard&lt;/a&gt; (Free, cloud-based botnet blocking via shared network).&lt;/p&gt;&#10;&lt;p&gt;&lt;a class="link" href="https://wordpress.org/plugins/loginizer/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Loginizer&lt;/a&gt; (1M+ installs) adds 2FA + reCAPTCHA for extra layers.&lt;/p&gt;&#10;&lt;p&gt;Test: Try wrong logins — you&amp;rsquo;ll see instant blocks.&lt;/p&gt;&#10;&lt;h2 id="7-vet-plugins-before-installing"&gt;7. Vet Plugins Before Installing&#10;&lt;/h2&gt;&lt;p&gt;Not all plugins are equal — some bloat your site with 1MB+ RAM usage or JS errors. Always check:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a class="link" href="https://wphive.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;&lt;strong&gt;WP Hive&lt;/strong&gt;&lt;/a&gt;: Chrome extension + site for automated tests (memory, page speed impact, PHP/WordPress compatibility, DB footprint). E.g., Yoast SEO 20.1: +0.1s load time, 1MB RAM (heavier than average).&lt;/li&gt;&#10;&lt;li&gt;&lt;a class="link" href="https://plugintests.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;&lt;strong&gt;PluginTests.com&lt;/strong&gt;&lt;/a&gt;: Basic compatibility/smoke tests for 98% of WP.org plugins (activation errors, obvious breaks).&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;&lt;strong&gt;Quick Example (2025 Benchmarks):&lt;/strong&gt;&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Yoast SEO: Solid but resource-heavy (+0.1s load, 1MB RAM). Great for readability.&lt;/li&gt;&#10;&lt;li&gt;Rank Math SEO: Lighter (no load impact, &amp;lt;250KB RAM), more free features. Often 4x faster in tests.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Aim for lightweight picks — only add &amp;ldquo;heavy&amp;rdquo; ones if essential.&lt;/p&gt;&#10;&lt;h2 id="wrap-up"&gt;Wrap-Up&#10;&lt;/h2&gt;&lt;p&gt;Implement these today, and your site will launch 2–3x faster, more secure, and future-proof. Total time: ~30 minutes. No excuses!&lt;/p&gt;&#10;&lt;p&gt;Thanks for reading! 🚀&lt;/p&gt;&#10;</description></item><item><title>How to avoid timeouts while you are logged on SSH</title><link>https://aquasp.blog/how-to-avoid-timeouts-while-you-are-logged-on-ssh/</link><pubDate>Tue, 09 Dec 2025 01:41:02 +0000</pubDate><guid>https://aquasp.blog/how-to-avoid-timeouts-while-you-are-logged-on-ssh/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;One of the most frustrating things when working on a server?&lt;/p&gt;&#10;&lt;p&gt;Your SSH session dies because of a brief Wi-Fi hiccup, idle timeout, or flaky connection.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Fix it forever in 30 seconds.&lt;/strong&gt;&lt;/p&gt;&#10;&lt;h2 id="the-universal-fix-edit-your-ssh-config"&gt;The Universal Fix: Edit Your SSH Config&#10;&lt;/h2&gt;&lt;p&gt;This works on &lt;strong&gt;Linux, macOS, and Windows&lt;/strong&gt; — and survives network glitches up to ~4–5 minutes.&lt;/p&gt;&#10;&lt;h3 id="step-1-create-or-edit-the-ssh-config-file"&gt;Step 1: Create or Edit the SSH Config File&#10;&lt;/h3&gt;&lt;p&gt;&lt;strong&gt;On Linux / macOS:&lt;/strong&gt;&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;mkdir -p ~/.ssh&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;nano ~/.ssh/config&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;&lt;strong&gt;On Windows (PowerShell):&lt;/strong&gt;&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;# Replace YourUsername with your actual Windows username&#10;mkdir &amp;#34;$HOME\.ssh&amp;#34; -Force&#10;notepad &amp;#34;$HOME\.ssh\config&amp;#34;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h3 id="step-2-add-these-lines"&gt;Step 2: Add These Lines&#10;&lt;/h3&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;sshHost *&#10; ServerAliveInterval 120&#10; ServerAliveCountMax 3&#10; TCPKeepAlive yes&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Save and exit.&lt;/p&gt;&#10;&lt;p&gt;Done. That’s it.&lt;/p&gt;&#10;&lt;h2 id="what-this-actually-does"&gt;What This Actually Does&#10;&lt;/h2&gt;&lt;table&gt;&#10;&#9;&lt;thead&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;Setting&lt;/th&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;th&gt;Meaning&lt;/th&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/thead&gt;&#10;&#9;&lt;tbody&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;Host *&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Apply these rules to &lt;strong&gt;every&lt;/strong&gt; SSH connection&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;ServerAliveInterval 120&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Every 2 minutes, your computer sends a tiny “I’m still here” packet&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;ServerAliveCountMax 3&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;If 3 packets in a row fail → only then close the connection (~6 min)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&#9;&#9;&lt;tr&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;&lt;code&gt;TCPKeepAlive yes&lt;/code&gt;&lt;/td&gt;&#10;&#9;&#9;&#9;&#9;&#9;&lt;td&gt;Extra OS-level keepalive (helps with some routers/firewalls)&lt;/td&gt;&#10;&#9;&#9;&#9;&lt;/tr&gt;&#10;&#9;&lt;/tbody&gt;&#10;&lt;/table&gt;&#10;&lt;p&gt;Result: Your SSH session now survives:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Wi-Fi switching&lt;/li&gt;&#10;&lt;li&gt;Laptop sleep/wake&lt;/li&gt;&#10;&lt;li&gt;Brief internet drops&lt;/li&gt;&#10;&lt;li&gt;VPN reconnects&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;…without freezing or dying.&lt;/p&gt;&#10;&lt;h2 id="youre-now-unbreakable"&gt;You&amp;rsquo;re Now Unbreakable&#10;&lt;/h2&gt;&lt;p&gt;From now on, when your internet blinks, your SSH session just… waits patiently.&lt;/p&gt;&#10;&lt;p&gt;No more “Connection reset by peer”&#10;No more lost tmux sessions&#10;No more rage&lt;/p&gt;&#10;&lt;p&gt;You’ve officially leveled up.&lt;/p&gt;&#10;&lt;p&gt;Thank you for reading — stay connected!&lt;/p&gt;&#10;</description></item><item><title>How to check disk usage per file or directory on linux</title><link>https://aquasp.blog/how-to-check-disk-usage-per-file-or-directory-on-linux/</link><pubDate>Tue, 09 Dec 2025 01:34:27 +0000</pubDate><guid>https://aquasp.blog/how-to-check-disk-usage-per-file-or-directory-on-linux/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Whether you&amp;rsquo;re debugging a full VPS, cleaning up a home server, or just curious — here are the &lt;strong&gt;fastest and most useful&lt;/strong&gt; commands to understand what&amp;rsquo;s eating your disk space.&lt;/p&gt;&#10;&lt;h2 id="1-find-the-biggest-files--folders-in-the-current-directory"&gt;1. Find the Biggest Files &amp;amp; Folders in the Current Directory&#10;&lt;/h2&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;du -shc * | sort -rh | head -15&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;ul&gt;&#10;&lt;li&gt;du -shc * → shows size of everything in the current folder (human-readable, with total)&lt;/li&gt;&#10;&lt;li&gt;sort -rh → sorts from biggest to smallest&lt;/li&gt;&#10;&lt;li&gt;head -15 → shows only the top 15 culprits (change number as needed)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Perfect for quickly spotting that one huge log file or backup folder.&lt;/p&gt;&#10;&lt;p&gt;Pro tip: Run it in /var, /home, or / to hunt down space hogs.&lt;/p&gt;&#10;&lt;h2 id="2-check-overall-disk-usage-all-partitions"&gt;2. Check Overall Disk Usage (All Partitions)&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;df -h&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Shows:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Total/used/available space&lt;/li&gt;&#10;&lt;li&gt;Percentage used&lt;/li&gt;&#10;&lt;li&gt;Mount point&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Look for the line with / (root) or your main drive.&#10;Example: 64G used / 226G total → 28% full&lt;/p&gt;&#10;&lt;p&gt;Add &amp;ndash;exclude-type=tmpfs to hide temporary filesystems:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;df -h --exclude-type=tmpfs --exclude-type=devtmpfs&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="3-check-inode-usage-when-disk-full-but-df-shows-space-left"&gt;3. Check Inode Usage (When &amp;ldquo;Disk Full&amp;rdquo; But df Shows Space Left)&#10;&lt;/h2&gt;&lt;p&gt;Sometimes your disk is full of &lt;strong&gt;millions of tiny files&lt;/strong&gt; (logs, cache, sessions, etc.). Each file uses one inode.&lt;/p&gt;&#10;&lt;p&gt;Check inodes per folder in current directory:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;du --inodes --max-depth=1 . | sort -nr&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Or system-wide:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;df -i&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;If &amp;ldquo;IUsed&amp;rdquo; is near 100%, you’re out of inodes — time to clean up small files!&lt;/p&gt;&#10;&lt;h2 id="bonus-one-liners"&gt;Bonus One-Liners&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;# Top 10 biggest directories in /home&#10;du -h /home | sort -rh | head -10&#10;&#10;# Find files bigger than 1GB&#10;find / -type f -size +1G 2&amp;gt;/dev/null&#10;&#10;# Show only real disks (clean output)&#10;df -h -x squashfs -x tmpfs -x devtmpfs&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;That’s it!&lt;/p&gt;&#10;&lt;p&gt;You now have the ultimate toolkit to &lt;strong&gt;never be surprised&lt;/strong&gt; by a full disk again.&lt;/p&gt;&#10;&lt;p&gt;Thank you for reading!&lt;/p&gt;&#10;</description></item><item><title>How to easily export and import docker volumes</title><link>https://aquasp.blog/how-to-easily-export-and-import-docker-volumes/</link><pubDate>Tue, 09 Dec 2025 01:22:26 +0000</pubDate><guid>https://aquasp.blog/how-to-easily-export-and-import-docker-volumes/</guid><description>&lt;p&gt;If you’re like me, you prefer to run &lt;strong&gt;everything&lt;/strong&gt; in Docker containers. They’re fast, isolated, and perfect for running multiple apps on one VPS.&lt;/p&gt;&#10;&lt;p&gt;But what happens when you want to:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Move a container to a new server?&lt;/li&gt;&#10;&lt;li&gt;Backup a database volume (NextCloud, PhotoPrism, Vaultwarden, etc.)?&lt;/li&gt;&#10;&lt;li&gt;Restore data after a crash?&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Docker doesn’t include a built-in “export volume” button — but there’s a &lt;strong&gt;super simple and reliable trick&lt;/strong&gt; using a temporary Ubuntu container.&lt;/p&gt;&#10;&lt;p&gt;Let’s go!&lt;/p&gt;&#10;&lt;h2 id="step-1-list-your-volumes"&gt;Step 1: List Your Volumes&#10;&lt;/h2&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;docker volume ls&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Example output:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;DRIVER VOLUME NAME&#10;local nextcloud_data&#10;local photoprism_storage&#10;local vaultwarden_data&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Pick the one you want to export (e.g., nextcloud_data).&lt;/p&gt;&#10;&lt;h2 id="step-2-export-a-volume--backuptargz"&gt;Step 2: Export a Volume → backup.tar.gz&#10;&lt;/h2&gt;&lt;p&gt;Run this &lt;strong&gt;one-line command&lt;/strong&gt; (replace nextcloud_data with your volume name):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;docker run --rm -v nextcloud_data:/data -v &amp;#34;$(pwd)&amp;#34;:/backup ubuntu \&#10; tar -czf /backup/nextcloud-data-backup.tar.gz -C /data ./&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;What this does:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Mounts your volume to /data inside a temporary container&lt;/li&gt;&#10;&lt;li&gt;Mounts your current folder to /backup&lt;/li&gt;&#10;&lt;li&gt;Creates a compressed archive of the entire volume&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;After it finishes, you’ll have a file like:&#10;nextcloud-data-backup.tar.gz ← ready to download or move!&lt;/p&gt;&#10;&lt;p&gt;Pro tip: Add the date for clarity&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;docker run --rm -v nextcloud_data:/data -v &amp;#34;$(pwd)&amp;#34;:/backup ubuntu \&#10; tar -czf &amp;#34;/backup/nextcloud-data-$(date +%Y-%m-%d).tar.gz&amp;#34; -C /data ./&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-3-import-on-the-new-server"&gt;Step 3: Import on the New Server&#10;&lt;/h2&gt;&lt;ol&gt;&#10;&lt;li&gt;Copy your backup.tar.gz file to the new server (via scp, rsync, etc.)&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;Then, &lt;strong&gt;create the empty volume&lt;/strong&gt; (important!):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;docker volume create nextcloud_data&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Run the import command (from the folder containing the backup file):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;docker run --rm -v nextcloud_data:/data -v &amp;#34;$(pwd)&amp;#34;:/backup ubuntu \&#10; tar -xzf /backup/nextcloud-data-2025-04-05.tar.gz -C /data&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Done! Your volume is now fully restored.&lt;/p&gt;&#10;&lt;p&gt;Never let Docker auto-create the volume during import — it can cause permission issues or merge problems.&lt;/p&gt;&#10;&lt;h2 id="bonus-using-external-volumes-with-docker-compose"&gt;Bonus: Using External Volumes with Docker Compose&#10;&lt;/h2&gt;&lt;p&gt;If you&amp;rsquo;re using docker-compose.yml, tell Docker that the volume is &lt;strong&gt;external&lt;/strong&gt; (already exists):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;services:&#10; nextcloud:&#10; image: nextcloud:latest&#10; volumes:&#10; - nextcloud_data:/var/www/html&#10;&#10;volumes:&#10; nextcloud_data:&#10; external: true&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Indentation matters — use &lt;strong&gt;exactly two spaces&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;h2 id="real-world-use-cases"&gt;Real-World Use Cases&#10;&lt;/h2&gt;&lt;ul&gt;&#10;&lt;li&gt;Migrating NextCloud to a new VPS&lt;/li&gt;&#10;&lt;li&gt;Backing up Vaultwarden before upgrading&lt;/li&gt;&#10;&lt;li&gt;Moving PhotoPrism library to a bigger server&lt;/li&gt;&#10;&lt;li&gt;Disaster recovery&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;This method is &lt;strong&gt;100% reliable&lt;/strong&gt;, works with any volume, and requires zero extra tools.&lt;/p&gt;&#10;&lt;p&gt;You now have a bulletproof Docker volume backup strategy.&lt;/p&gt;&#10;&lt;p&gt;Happy containerizing! 🐳&lt;/p&gt;&#10;&lt;p&gt;Thank you for reading!&lt;/p&gt;&#10;</description></item><item><title>How to easily self-host at home and put your projects online under CGNAT</title><link>https://aquasp.blog/how-to-easily-self-host-at-home-and-put-your-projects-online-under-cgnat/</link><pubDate>Tue, 09 Dec 2025 01:13:41 +0000</pubDate><guid>https://aquasp.blog/how-to-easily-self-host-at-home-and-put-your-projects-online-under-cgnat/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Want to run heavy services on a powerful server at home, even though your ISP puts you behind CGNAT? This guide shows you exactly how to put them online — the &lt;strong&gt;old-school, bulletproof way&lt;/strong&gt; using SSH reverse tunnels.&lt;/p&gt;&#10;&lt;p&gt;No Cloudflare Tunnel. No Ngrok. Just SSH + systemd.&lt;/p&gt;&#10;&lt;h2 id="the-downsides-and-why-theyre-manageable"&gt;The Downsides (and Why They’re Manageable)&#10;&lt;/h2&gt;&lt;ul&gt;&#10;&lt;li&gt;Home internet isn’t datacenter-grade (outages happen)&lt;/li&gt;&#10;&lt;li&gt;Most ISPs use CGNAT → you can’t open ports normally&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;&lt;strong&gt;Solution:&lt;/strong&gt; Use a cheap VPS as a public “jump box”. Your heavy server stays home. The VPS only forwards ports.&lt;/p&gt;&#10;&lt;h2 id="how-it-works--the-magic-of-reverse-ssh-tunnels--r"&gt;How It Works – The Magic of Reverse SSH Tunnels (-R)&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;Internet → Cheap VPS (public IP) → SSH reverse tunnel → Your home server (behind CGNAT)&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Your home server initiates an outbound SSH connection to the VPS and says:&#10;“Anything that hits port 8096 on you → send it to my local Jellyfin on 8096”&lt;/p&gt;&#10;&lt;p&gt;Zero ports opened on your home router. Zero exposure.&lt;/p&gt;&#10;&lt;h2 id="step-by-step-setup"&gt;Step-by-Step Setup&#10;&lt;/h2&gt;&lt;h3 id="1-on-your-home-server-the-powerful-one"&gt;1. On Your Home Server (the powerful one)&#10;&lt;/h3&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Create folder for tunnel configs&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo mkdir -p /etc/sshtunnels&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Example: expose Jellyfin (port 8096)&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo nano /etc/sshtunnels/jellyfin.conf&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Content of the file:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;8096:8096 # remote_port:local_port&#10;443:8443 # optional: HTTPS reverse proxy on VPS → your local 8443&#10;80:8080&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;One line per service. First number = port on the &lt;strong&gt;VPS&lt;/strong&gt;, second = port on &lt;strong&gt;your home server&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;h3 id="2-generate-an-ssh-key-if-you-dont-have-one"&gt;2. Generate an SSH Key (if you don’t have one)&#10;&lt;/h3&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;ssh-keygen -t ed25519 -C &amp;#34;home-server-tunnel&amp;#34;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Copy the public key to your VPS:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;ssh-copy-id user@your-vps-ip&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h3 id="3-create-the-tunnel-manager-script"&gt;3. Create the Tunnel Manager Script&#10;&lt;/h3&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo nano /usr/local/bin/sshtunnel.sh&#10;&lt;/code&gt;&lt;/pre&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;#!/bin/bash&#10;&#10;# === EDIT THESE ===&#10;REMOTE_USER=&amp;#34;root&amp;#34; # or your VPS user&#10;REMOTE_HOST=&amp;#34;123.45.67.89&amp;#34; # your VPS public IP&#10;SSH_KEY=&amp;#34;/home/youruser/.ssh/id_ed25519&amp;#34;&#10;SSH_PORT=&amp;#34;22&amp;#34; # change if you use a non-standard port&#10;# ==================&#10;&#10;INSTANCE=&amp;#34;$1&amp;#34;&#10;CONFIG_FILE=&amp;#34;/etc/sshtunnels/${INSTANCE}.conf&amp;#34;&#10;&#10;if [[ ! -f &amp;#34;$CONFIG_FILE&amp;#34; ]]; then&#10; echo &amp;#34;Error: Config file $CONFIG_FILE not found!&amp;#34;&#10; exit 1&#10;fi&#10;&#10;# Build -R arguments&#10;FORWARD_OPTS=&amp;#34;&amp;#34;&#10;while IFS=: read -r remote_port local_port; do&#10; [[ -z &amp;#34;$remote_port&amp;#34; || &amp;#34;$remote_port&amp;#34; =~ ^# ]] &amp;amp;&amp;amp; continue&#10; # Clean any old process using the remote port&#10; ssh -p &amp;#34;$SSH_PORT&amp;#34; &amp;#34;$REMOTE_USER@$REMOTE_HOST&amp;#34; \&#10; &amp;#34;lsof -i :$remote_port -t | xargs -r kill -9&amp;#34; 2&amp;gt;/dev/null&#10; FORWARD_OPTS=&amp;#34;$FORWARD_OPTS -R $remote_port:localhost:$local_port&amp;#34;&#10;done &amp;lt; &amp;#34;$CONFIG_FILE&amp;#34;&#10;&#10;echo &amp;#34;Starting tunnel $INSTANCE → $REMOTE_HOST ($FORWARD_OPTS)&amp;#34;&#10;&#10;exec ssh -o StrictHostKeyChecking=no \&#10; -o ServerAliveInterval=30 \&#10; -o ServerAliveCountThreshold=3 \&#10; -o ExitOnForwardFailure=yes \&#10; -o GatewayPorts=yes \&#10; -N -T \&#10; -i &amp;#34;$SSH_KEY&amp;#34; \&#10; -p &amp;#34;$SSH_PORT&amp;#34; \&#10; $FORWARD_OPTS \&#10; &amp;#34;$REMOTE_USER@$REMOTE_HOST&amp;#34;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Make it executable:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo chmod +x /usr/local/bin/sshtunnel.sh&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h3 id="4-create-a-systemd-service-auto-start--auto-reconnect"&gt;4. Create a Systemd Service (Auto-Start &amp;amp; Auto-Reconnect)&#10;&lt;/h3&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo nano /etc/systemd/system/sshtunnel@.service&#10;&lt;/code&gt;&lt;/pre&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;[Unit]&#10;Description=SSH Reverse Tunnel for %i&#10;After=network-online.target&#10;Wants=network-online.target&#10;&#10;[Service]&#10;User=youruser # ← change to your home user (not root!)&#10;Group=youruser&#10;ExecStart=/usr/local/bin/sshtunnel.sh %i&#10;Restart=always&#10;RestartSec=10&#10;&#10;[Install]&#10;WantedBy=multi-user.target&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reload and enable:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo systemctl daemon-reload&#10;&#10;# Start a tunnel (example: jellyfin)&#10;sudo systemctl enable --now sshtunnel@jellyfin.service&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Check status:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo systemctl status sshtunnel@jellyfin.service&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h3 id="5-on-the-vps-side-optional-but-recommended"&gt;5. On the VPS Side (Optional but Recommended)&#10;&lt;/h3&gt;&lt;p&gt;Install a tiny web server or Caddy/nginx to terminate TLS and proxy to the forwarded ports.&lt;/p&gt;&#10;&lt;p&gt;Example with Caddy (automatic HTTPS):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;# On the VPS&#10;apt install caddy&#10;&#10;# /etc/caddy/Caddyfile&#10;jellyfin.yourdomain.com {&#10; reverse_proxy localhost:8096&#10;}&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Now jellyfin.yourdomain.com → your home Jellyfin, fully encrypted.&lt;/p&gt;&#10;&lt;p&gt;All running on my beast home server behind CGNAT.&lt;/p&gt;&#10;&lt;h2 id="pros-of-this-setup"&gt;Pros of This Setup&#10;&lt;/h2&gt;&lt;ul&gt;&#10;&lt;li&gt;Works behind any CGNAT / ISP block&lt;/li&gt;&#10;&lt;li&gt;No third-party dependency (no Cloudflare, no Ngrok)&lt;/li&gt;&#10;&lt;li&gt;Full encryption possible&lt;/li&gt;&#10;&lt;li&gt;Survives reboots (systemd + Restart=always)&lt;/li&gt;&#10;&lt;li&gt;Costs almost nothing&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="final-words"&gt;Final Words&#10;&lt;/h2&gt;&lt;p&gt;This is the one really cool way I’ve found to self-host heavy services at home in 2025.&lt;/p&gt;&#10;&lt;p&gt;Your powerful hardware stays home. Your $1/month VPS is just a traffic cop.&lt;/p&gt;&#10;&lt;p&gt;Thank you for reading — now go build your unstoppable home lab!&lt;/p&gt;&#10;</description></item><item><title>How to Automatically Backup Your Self-Hosted Ghost Blog</title><link>https://aquasp.blog/how-to-automatically-backup-your-self-hosted-ghost-blog/</link><pubDate>Tue, 09 Dec 2025 01:05:55 +0000</pubDate><guid>https://aquasp.blog/how-to-automatically-backup-your-self-hosted-ghost-blog/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Ghost is an &lt;strong&gt;incredibly fast and elegant&lt;/strong&gt; blogging platform. But unlike WordPress, it doesn’t have built-in one-click backup plugins.&lt;/p&gt;&#10;&lt;p&gt;That changes today.&lt;/p&gt;&#10;&lt;p&gt;In this guide, you’ll set up a &lt;strong&gt;fully automated daily backup system&lt;/strong&gt; that:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Dumps your MySQL database&lt;/li&gt;&#10;&lt;li&gt;Backs up all themes, images, and content&lt;/li&gt;&#10;&lt;li&gt;Compresses everything into a single &lt;code&gt;.zip&lt;/code&gt;&lt;/li&gt;&#10;&lt;li&gt;Uploads it securely to your cloud storage (pCloud, NextCloud, Google Drive, Dropbox, etc.)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;All using &lt;strong&gt;free tools&lt;/strong&gt;: &lt;code&gt;rclone&lt;/code&gt; + a simple bash script + cron.&lt;/p&gt;&#10;&lt;p&gt;Let’s get started.&lt;/p&gt;&#10;&lt;h2 id="step-1-install-rclone"&gt;Step 1: Install Rclone&#10;&lt;/h2&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo apt update &lt;span style="color:#f92672"&gt;&amp;amp;&amp;amp;&lt;/span&gt; sudo apt install -y rclone&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Rclone is the Swiss Army knife of cloud storage — it supports &lt;strong&gt;over 70 providers&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;p&gt;Full list: &lt;a class="link" href="https://rclone.org/overview/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://rclone.org/overview/&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="step-2-configure-rclone-connect-your-cloud-storage"&gt;Step 2: Configure Rclone (Connect Your Cloud Storage)&#10;&lt;/h2&gt;&lt;p&gt;Run:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;rclone config&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Follow the prompts:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;n → new remote&lt;/li&gt;&#10;&lt;li&gt;Name it something like ghost-backup or pcloud&lt;/li&gt;&#10;&lt;li&gt;Choose your provider (e.g., webdav for NextCloud, pcloud, google drive, etc.)&lt;/li&gt;&#10;&lt;li&gt;Enter your credentials/URL when asked&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Test it works:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;rclone ls ghost-backup:&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;You should see your remote files (or an empty folder if new).&lt;/p&gt;&#10;&lt;p&gt;Type q to quit.&lt;/p&gt;&#10;&lt;h2 id="step-3-get-your-ghost-database-credentials"&gt;Step 3: Get Your Ghost Database Credentials&#10;&lt;/h2&gt;&lt;p&gt;Log in as your Ghost user (not root):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;su - yourghostuser&#10;cd /var/www/ghost # or wherever you installed Ghost&#10;cat config.production.json&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Look for the database section. You’ll see something like:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;&amp;#34;database&amp;#34;: {&#10; &amp;#34;client&amp;#34;: &amp;#34;mysql&amp;#34;,&#10; &amp;#34;connection&amp;#34;: {&#10; &amp;#34;host&amp;#34;: &amp;#34;localhost&amp;#34;,&#10; &amp;#34;user&amp;#34;: &amp;#34;ghost_db_user&amp;#34;,&#10; &amp;#34;password&amp;#34;: &amp;#34;yoursecretpassword&amp;#34;,&#10; &amp;#34;database&amp;#34;: &amp;#34;ghost_prod&amp;#34;&#10; }&#10;}&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;strong&gt;Write down&lt;/strong&gt;:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Database name (ghost_prod)&lt;/li&gt;&#10;&lt;li&gt;Username (ghost_db_user)&lt;/li&gt;&#10;&lt;li&gt;Password&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="step-4-create-the-backup-script"&gt;Step 4: Create the Backup Script&#10;&lt;/h2&gt;&lt;p&gt;Create the script as root:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;nano /root/backup-ghost.sh&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Paste this (then edit the variables below):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;#!/bin/bash&#10;&#10;# === EDIT THESE VALUES ===&#10;GHOST_USER=&amp;#34;yourghostuser&amp;#34; # e.g. ghost&#10;GHOST_PATH=&amp;#34;/var/www/ghost&amp;#34; # path to your Ghost install&#10;DB_NAME=&amp;#34;ghost_prod&amp;#34; # from config.production.json&#10;DB_USER=&amp;#34;ghost_db_user&amp;#34; # from config.production.json&#10;DB_PASS=&amp;#34;yoursecretpassword&amp;#34; # from config.production.json&#10;BACKUP_NAME=&amp;#34;theselfhostingart-blog&amp;#34; # name for your backup zip&#10;RCLONE_REMOTE=&amp;#34;ghost-backup&amp;#34; # name you gave in rclone config&#10;RCLONE_PATH=&amp;#34;/&amp;#34; # folder in your cloud (use / for root)&#10;# =========================&#10;&#10;DATE=$(date +&amp;#39;%Y-%m-%d_%H-%M&amp;#39;)&#10;BACKUP_DIR=&amp;#34;/home/$GHOST_USER/backups/$DATE&amp;#34;&#10;ZIP_FILE=&amp;#34;$BACKUP_DIR/$BACKUP_NAME-$DATE.zip&amp;#34;&#10;&#10;echo &amp;#34;Starting Ghost backup: $DATE&amp;#34;&#10;&#10;# Create backup directory&#10;mkdir -p &amp;#34;$BACKUP_DIR&amp;#34;&#10;&#10;# Backup database&#10;echo &amp;#34;Backing up database...&amp;#34;&#10;mysqldump -u &amp;#34;$DB_USER&amp;#34; -p&amp;#34;$DB_PASS&amp;#34; --add-drop-table &amp;#34;$DB_NAME&amp;#34; | gzip &amp;gt; &amp;#34;$BACKUP_DIR/db.sql.gz&amp;#34;&#10;&#10;# Backup content folder (themes, images, etc.)&#10;echo &amp;#34;Backing up content folder...&amp;#34;&#10;rsync -av --exclude=&amp;#39;logs&amp;#39; --exclude=&amp;#39;cache&amp;#39; &amp;#34;$GHOST_PATH/content/&amp;#34; &amp;#34;$BACKUP_DIR/content/&amp;#34;&#10;&#10;# Compress everything&#10;echo &amp;#34;Compressing backup...&amp;#34;&#10;zip -r &amp;#34;$ZIP_FILE&amp;#34; &amp;#34;$BACKUP_DIR/content&amp;#34; &amp;#34;$BACKUP_DIR/db.sql.gz&amp;#34; &amp;gt; /dev/null&#10;&#10;# Upload to cloud&#10;echo &amp;#34;Uploading to cloud storage...&amp;#34;&#10;rclone copy &amp;#34;$ZIP_FILE&amp;#34; &amp;#34;$RCLONE_REMOTE:$RCLONE_PATH&amp;#34;&#10;&#10;# Cleanup: remove local backups older than 1 day (optional but recommended)&#10;echo &amp;#34;Cleaning up old local backups...&amp;#34;&#10;find /home/$GHOST_USER/backups -type d -mtime +1 -exec rm -rf {} +&#10;&#10;echo &amp;#34;Backup complete: $ZIP_FILE → $RCLONE_REMOTE:$RCLONE_PATH&amp;#34;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Make it executable:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;chmod +x /root/backup-ghost.sh&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;strong&gt;Test it manually first&lt;/strong&gt;:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;/root/backup-ghost.sh&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Check your cloud storage — you should see a file like:&#10;theselfhostingart-blog-2025-04-05_03-22.zip&lt;/p&gt;&#10;&lt;h2 id="step-5-automate-with-cron-daily-backups"&gt;Step 5: Automate with Cron (Daily Backups)&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;crontab -e&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Add this line for &lt;strong&gt;daily backup at 2:00 AM&lt;/strong&gt;:&lt;/p&gt;&#10;&lt;p&gt;cron&lt;code&gt;0 2 * * * /usr/bin/bash /root/backup-ghost.sh &amp;gt;&amp;gt; /var/log/ghost-backup.log 2&amp;gt;&amp;amp;1&lt;/code&gt;&lt;/p&gt;&#10;&lt;p&gt;Save and exit.&lt;/p&gt;&#10;&lt;p&gt;Your Ghost blog is now &lt;strong&gt;automatically backed up every day&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;h2 id="whats-included-in-the-backup"&gt;What’s Included in the Backup?&#10;&lt;/h2&gt;&lt;ul&gt;&#10;&lt;li&gt;Full database (posts, users, settings)&lt;/li&gt;&#10;&lt;li&gt;All uploaded images&lt;/li&gt;&#10;&lt;li&gt;Custom themes&lt;/li&gt;&#10;&lt;li&gt;Everything needed to restore or migrate&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;You can even send this .zip to Ghost(Pro) support — they can import it directly.&lt;/p&gt;&#10;&lt;h2 id="bonus-restore-in-case-of-disaster"&gt;Bonus: Restore in Case of Disaster&#10;&lt;/h2&gt;&lt;p&gt;To restore:&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;Install fresh Ghost&lt;/li&gt;&#10;&lt;li&gt;Unzip backup&lt;/li&gt;&#10;&lt;li&gt;Import DB: gunzip &amp;lt; db.sql.gz | mysql -u user -p dbname&lt;/li&gt;&#10;&lt;li&gt;Replace content/ folder&lt;/li&gt;&#10;&lt;li&gt;Run ghost restart&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;h2 id="credits--thanks"&gt;Credits &amp;amp; Thanks&#10;&lt;/h2&gt;&lt;p&gt;This method is inspired and improved from this excellent post:&#10;&lt;a class="link" href="https://dev.to/kvizdos/how-to-automatically-backup-ghost-blogs-4he1?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;How to Automatically Backup Ghost Blogs – Kenton Vizdos&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;Thank you, Kenton!&lt;/p&gt;&#10;&lt;hr&gt;&#10;&lt;p&gt;Your self-hosted blog now sleeps better at night. 😴💾&lt;/p&gt;&#10;&lt;p&gt;Thank you for reading!&lt;/p&gt;&#10;</description></item><item><title>How to install NextCloud with OpenLiteSpeed (LOMP stack)</title><link>https://aquasp.blog/how-to-install-nextcloud-with-openlitespeed-lomp-stack/</link><pubDate>Tue, 09 Dec 2025 00:59:45 +0000</pubDate><guid>https://aquasp.blog/how-to-install-nextcloud-with-openlitespeed-lomp-stack/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Today I’ll show you how to build what I genuinely believe is the &lt;strong&gt;fastest NextCloud stack&lt;/strong&gt; available in 2025:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;OpenLiteSpeed&lt;/strong&gt; – the fastest web server with built-in cache&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;LSPHP 8.1/8.2&lt;/strong&gt; – LiteSpeed’s ultra-fast PHP implementation&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Redis + APCu&lt;/strong&gt; – for blazing-fast caching and locking&lt;/li&gt;&#10;&lt;li&gt;Runs completely &lt;strong&gt;non-root&lt;/strong&gt;, under its own user&lt;/li&gt;&#10;&lt;li&gt;Hardened with proper security headers, HSTS, and isolated data folder&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Even if NextCloud gets compromised, the attacker still can’t touch the rest of your server.&lt;/p&gt;&#10;&lt;p&gt;Let’s go!&lt;/p&gt;&#10;&lt;h2 id="step-1-secure-your-vps-first"&gt;Step 1: Secure Your VPS First&#10;&lt;/h2&gt;&lt;p&gt;Before anything, harden your server. Follow my full guide here:&#10;&lt;a class="link" href="https://aquasp.blog/how-to-make-your-vps-secure/" &gt;How to Make Your VPS Secure&lt;/a&gt;&lt;/p&gt;&#10;&lt;h2 id="step-2-install-openlitespeed-lsphp-redis--tools"&gt;Step 2: Install OpenLiteSpeed, LSPHP, Redis &amp;amp; Tools&#10;&lt;/h2&gt;&lt;p&gt;Run as root:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Update system&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt update &lt;span style="color:#f92672"&gt;&amp;amp;&amp;amp;&lt;/span&gt; apt upgrade -y&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Add OpenLiteSpeed repository&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;wget -O - https://repo.litespeed.sh | bash&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Install essentials&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt install -y curl gnupg2 imagemagick ffmpeg redis openlitespeed lsphp81* lsphp82* zip unzip mariadb-server mariadb-client&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&#10; &lt;blockquote&gt;&#10; &lt;p&gt;Note: On Ubuntu 22.04+, the ImageMagick package might be libmagickwand-dev + imagemagick. The above works on most recent Debian/Ubuntu.&lt;/p&gt;&#10;&#10; &lt;/blockquote&gt;&#10;&lt;p&gt;Enable and restart Redis:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;systemctl enable --now redis-server&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-3-create-a-dedicated-system-user-for-nextcloud"&gt;Step 3: Create a Dedicated System User for NextCloud&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;adduser --shell /bin/bash files&#10;usermod -aG redis files # Allow access to Redis socket&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-4-download--extract-nextcloud-as-the-files-user"&gt;Step 4: Download &amp;amp; Extract NextCloud as the &amp;ldquo;files&amp;rdquo; User&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;su - files&#10;mkdir -p ~/public_html&#10;cd ~/public_html&#10;&#10;wget https://download.nextcloud.com/server/releases/latest.zip&#10;unzip latest.zip&#10;rsync -av nextcloud/ ./&#10;rm -rf nextcloud latest.zip .htaccess .user.ini&#10;exit&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-5-configure-openlitespeed-web-admin-port-7080"&gt;Step 5: Configure OpenLiteSpeed Web Admin (Port 7080)&#10;&lt;/h2&gt;&lt;p&gt;Set an admin password:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;/usr/local/lsws/admin/misc/admpass.sh&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Now visit: https://your-vps-ip:7080 and log in.&lt;/p&gt;&#10;&lt;h3 id="virtual-host-setup"&gt;Virtual Host Setup&#10;&lt;/h3&gt;&lt;ol&gt;&#10;&lt;li&gt;Delete the default &amp;ldquo;Example&amp;rdquo; virtual host&lt;/li&gt;&#10;&lt;li&gt;Add new Virtual Host:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Virtual Host Name: yourdomain.com&lt;/li&gt;&#10;&lt;li&gt;Virtual Host Root: /home/files/&lt;/li&gt;&#10;&lt;li&gt;Config File: $SERVER_ROOT/conf/vhosts/$VH_NAME/vhconf.conf&lt;/li&gt;&#10;&lt;li&gt;Document Root: $VH_ROOT/public_html&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;ol start="3"&gt;&#10;&lt;li&gt;Script Handler → Add:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Suffix: php&lt;/li&gt;&#10;&lt;li&gt;Handler Type: LiteSpeed LVE&lt;/li&gt;&#10;&lt;li&gt;Handler: lsphp81 (or lsphp82 if you prefer PHP 8.2)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;ol start="4"&gt;&#10;&lt;li&gt;Rewrite Rules (force HTTPS):&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;RewriteEngine On&#10;RewriteCond %{HTTPS} !=on&#10;RewriteRule ^(.*)$ https://%{HTTP_HOST}$1 [R=301,L]&#10;&lt;/code&gt;&lt;/pre&gt;&lt;ol&gt;&#10;&lt;li&gt;Security Headers (Context → Static → Add new context /):&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;Strict-Transport-Security &amp;#34;max-age=63072000; includeSubDomains; preload&amp;#34;&#10;Content-Security-Policy &amp;#34;upgrade-insecure-requests&amp;#34;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;ol&gt;&#10;&lt;li&gt;External App → LSPHP → Edit:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Run as User/Group: files&lt;/li&gt;&#10;&lt;li&gt;PHP_LSAPI_CHILDREN = 100&lt;/li&gt;&#10;&lt;li&gt;LSAPI_AVOID_FORK = 0&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;ol start="2"&gt;&#10;&lt;li&gt;Listeners:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Delete default listeners&lt;/li&gt;&#10;&lt;li&gt;Add HTTP → port 80&lt;/li&gt;&#10;&lt;li&gt;Add HTTPS → port 443 (Secure = Yes)&lt;/li&gt;&#10;&lt;li&gt;Map your domain to both listeners&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Graceful restart → OpenLiteSpeed → Graceful Restart&lt;/p&gt;&#10;&lt;h2 id="step-6-issue-lets-encrypt-ssl"&gt;Step 6: Issue Let’s Encrypt SSL&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;apt install -y certbot&#10;certbot certonly --webroot -w /home/files/public_html -d yourdomain.com&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Note the paths (you’ll need them):&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Fullchain: /etc/letsencrypt/live/yourdomain.com/fullchain.pem&lt;/li&gt;&#10;&lt;li&gt;Privkey: /etc/letsencrypt/live/yourdomain.com/privkey.pem&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Add them in:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Virtual Host → SSL tab&lt;/li&gt;&#10;&lt;li&gt;Listener HTTPS → SSL tab&lt;/li&gt;&#10;&lt;li&gt;Chained Certificate = Yes&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Graceful restart again.&lt;/p&gt;&#10;&lt;h2 id="step-7-auto-renew-ssl"&gt;Step 7: Auto-Renew SSL&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;crontab -e&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Add:&lt;/p&gt;&#10;&lt;p&gt;cron&lt;code&gt;0 3 * * * /usr/bin/certbot renew --quiet&lt;/code&gt;&lt;/p&gt;&#10;&lt;h2 id="step-8-install--secure-mariadbmysql"&gt;Step 8: Install &amp;amp; Secure MariaDB/MySQL&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;mysql_secure_installation&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Then create database &amp;amp; user:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;mysql -u root -p&#10;CREATE DATABASE nextcloud CHARACTER SET utf8mb4 COLLATE utf8mb4_general_ci;&#10;CREATE USER &amp;#39;ncuser&amp;#39;@&amp;#39;localhost&amp;#39; IDENTIFIED BY &amp;#39;strong-password-here&amp;#39;;&#10;GRANT ALL PRIVILEGES ON nextcloud.* TO &amp;#39;ncuser&amp;#39;@&amp;#39;localhost&amp;#39;;&#10;FLUSH PRIVILEGES;&#10;EXIT;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-9-optimize-php--enable-opcache--apcu"&gt;Step 9: Optimize PHP &amp;amp; Enable OPCache + APCu&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;# Edit the correct php.ini (adjust path if using lsphp82)&#10;sed -i &amp;#39;/usr/local/lsws/lsphp81/etc/php/8.1/litespeed/php.ini&amp;#39; \&#10; -e &amp;#39;s/memory_limit = .*/memory_limit = 1024M/&amp;#39; \&#10; -e &amp;#39;s/upload_max_filesize = .*/upload_max_filesize = 10G/&amp;#39; \&#10; -e &amp;#39;s/post_max_size = .*/post_max_size = 10G/&amp;#39; \&#10; -e &amp;#39;s/max_execution_time = .*/max_execution_time = 3600/&amp;#39; \&#10; -e &amp;#39;s/opcache.enable=.*/opcache.enable=1/&amp;#39; \&#10; -e &amp;#39;s/;opcache.memory_consumption=.*/opcache.memory_consumption=512/&amp;#39; \&#10; -e &amp;#39;s/;opcache.interned_strings_buffer=.*/opcache.interned_strings_buffer=64/&amp;#39; \&#10; -e &amp;#39;s/;opcache.max_accelerated_files=.*/opcache.max_accelerated_files=20000/&amp;#39;&#10;&#10;# Enable APCu CLI&#10;echo &amp;#34;apc.enable_cli = 1&amp;#34; &amp;gt;&amp;gt; /usr/local/lsws/lsphp81/etc/php/8.1/litespeed/php.ini&#10;&#10;pkill -f lsphp&#10;systemctl restart lsws&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-10-configure-redis-as-unix-socket"&gt;Step 10: Configure Redis as Unix Socket&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;sed -i &amp;#39;s/port 6379/port 0/&amp;#39; /etc/redis/redis.conf&#10;sed -i &amp;#39;s|# unixsocket /var/run/redis/redis-server.sock|unixsocket /var/run/redis/redis-server.sock|&amp;#39; /etc/redis/redis.conf&#10;sed -i &amp;#39;s/# unixsocketperm 700/unixsocketperm 770/&amp;#39; /etc/redis/redis.conf&#10;sed -i &amp;#39;s/# maxmemory .*/maxmemory 1gb/&amp;#39; /etc/redis/redis.conf&#10;&#10;systemctl restart redis-server&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-11-final-nextcloud-configuration"&gt;Step 11: Final NextCloud Configuration&#10;&lt;/h2&gt;&lt;h3 id="move-data-folder-outside-web-root-critical"&gt;Move Data Folder Outside Web Root (Critical!)&#10;&lt;/h3&gt;&lt;p&gt;During setup, set data directory to: /home/files/data&lt;/p&gt;&#10;&lt;h3 id="edit-configphp-after-first-login"&gt;Edit config.php (after first login)&#10;&lt;/h3&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;su - files&#10;nano /home/files/public_html/config/config.php&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Add &lt;strong&gt;right after&lt;/strong&gt; &amp;lsquo;installed&amp;rsquo; =&amp;gt; true,:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;&amp;#39;memcache.local&amp;#39; =&amp;gt; &amp;#39;\\OC\\Memcache\\APCu&amp;#39;,&#10; &amp;#39;memcache.distributed&amp;#39; =&amp;gt; &amp;#39;\\OC\\Memcache\\Redis&amp;#39;,&#10; &amp;#39;memcache.locking&amp;#39; =&amp;gt; &amp;#39;\\OC\\Memcache\\Redis&amp;#39;,&#10; &amp;#39;redis&amp;#39; =&amp;gt; [&#10; &amp;#39;host&amp;#39; =&amp;gt; &amp;#39;/var/run/redis/redis-server.sock&amp;#39;,&#10; &amp;#39;port&amp;#39; =&amp;gt; 0,&#10; ],&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h3 id="set-up-background-jobs-cron"&gt;Set Up Background Jobs (Cron)&#10;&lt;/h3&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;su - files&#10;crontab -e&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Add:&lt;/p&gt;&#10;&lt;p&gt;cron&lt;code&gt;*/5 * * * * /usr/local/lsws/lsphp81/bin/php -f /home/files/public_html/cron.php&lt;/code&gt;&lt;/p&gt;&#10;&lt;p&gt;Then in NextCloud Admin → Basic Settings → Background jobs → Select &lt;strong&gt;Cron&lt;/strong&gt; (recommended).&lt;/p&gt;&#10;&lt;h2 id="bonus-make-occ-easy-to-use-forever"&gt;Bonus: Make occ Easy to Use Forever&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;su - files&#10;echo &amp;#34;alias occ=&amp;#39;/usr/local/lsws/lsphp81/bin/php /home/files/public_html/occ&amp;#39;&amp;#34; &amp;gt;&amp;gt; ~/.bashrc&#10;source ~/.bashrc&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Now from anywhere in ~/public_html:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;cd ~/public_html&#10;occ status&#10;occ maintenance:repair&#10;occ db:add-missing-indices&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="youre-done"&gt;You&amp;rsquo;re Done!&#10;&lt;/h2&gt;&lt;p&gt;You now have:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;The &lt;strong&gt;fastest&lt;/strong&gt; NextCloud stack (OpenLiteSpeed + Redis + APCu)&lt;/li&gt;&#10;&lt;li&gt;Fully &lt;strong&gt;non-root&lt;/strong&gt; and isolated&lt;/li&gt;&#10;&lt;li&gt;Automatic SSL renewal&lt;/li&gt;&#10;&lt;li&gt;Hardened security headers&lt;/li&gt;&#10;&lt;li&gt;Proper data folder protection&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Enjoy your blazing-fast, private cloud!&lt;/p&gt;&#10;&lt;p&gt;Thank you for reading! 🚀&lt;/p&gt;&#10;</description></item><item><title>How to Make Your VPS Safer Against Accidental Deletions</title><link>https://aquasp.blog/how-to-make-your-vps-safer-against-accidental-deletions/</link><pubDate>Tue, 09 Dec 2025 00:31:57 +0000</pubDate><guid>https://aquasp.blog/how-to-make-your-vps-safer-against-accidental-deletions/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Have you ever deleted a file or a folder by mistake in a VPS? That feeling sucks. Sometimes you are working fast and you delete a really important file/folder. This happened to me previously. Today I want to share an amazing tool with you guys: &lt;code&gt;trash-cli&lt;/code&gt; . It adds a trash in the CLI to prevent these human mistakes.&lt;/p&gt;&#10;&lt;h2 id="installing-trash-cli"&gt;Installing trash-cli&#10;&lt;/h2&gt;&lt;p&gt;&lt;code&gt;trash-cli&lt;/code&gt; is a lightweight, command-line tool available in Debian repositories, making it ideal for VPS environments with limited resources.&lt;/p&gt;&#10;&lt;h3 id="installation-steps"&gt;Installation Steps&#10;&lt;/h3&gt;&lt;ol&gt;&#10;&lt;li&gt;Update your package list:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo apt update&#10;&lt;/code&gt;&lt;/pre&gt;&lt;ol start="2"&gt;&#10;&lt;li&gt;Install &lt;code&gt;trash-cli&lt;/code&gt;:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo apt install trash-cli&#10;&lt;/code&gt;&lt;/pre&gt;&lt;ol start="3"&gt;&#10;&lt;li&gt;Verify the installation:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;trash --version&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;You should see version information if installed correctly.&lt;/p&gt;&#10;&lt;p&gt;This process is quick and adds minimal overhead to your VPS.&lt;/p&gt;&#10;&lt;h2 id="using-trash-cli-for-safer-deletions"&gt;Using trash-cli for Safer Deletions&#10;&lt;/h2&gt;&lt;p&gt;Once installed, &lt;code&gt;trash-cli&lt;/code&gt; provides commands to manage files safely. It moves items to &lt;code&gt;~/.local/share/Trash/&lt;/code&gt; instead of deleting them.&lt;/p&gt;&#10;&lt;h3 id="basic-commands"&gt;Basic Commands&#10;&lt;/h3&gt;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Trash a file or directory&lt;/strong&gt;: &lt;code&gt;trash file.txt&lt;/code&gt; or &lt;code&gt;trash directory&lt;/code&gt;.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;List trashed items&lt;/strong&gt;: &lt;code&gt;trash-list&lt;/code&gt; (shows files with deletion dates).&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Restore items&lt;/strong&gt;: &lt;code&gt;trash-restore&lt;/code&gt; (interactive menu to select and recover files).&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Empty the trash&lt;/strong&gt;: &lt;code&gt;trash-empty&lt;/code&gt; (permanently deletes all trashed items).&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Empty old items&lt;/strong&gt;: &lt;code&gt;trash-empty 30&lt;/code&gt; (deletes items older than 30 days).&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Example workflow:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;trash important_file.txt # Move to trash&#10;trash-list # Check what&amp;#39;s there&#10;trash-restore # Recover if needed&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;This replaces risky &lt;code&gt;rm&lt;/code&gt; usage in daily operations.&lt;/p&gt;&#10;&lt;h2 id="aliasing-rm-to-use-trash-cli"&gt;Aliasing rm to Use trash-cli&#10;&lt;/h2&gt;&lt;p&gt;To make &lt;code&gt;rm&lt;/code&gt; safer by default, alias it to &lt;code&gt;trash&lt;/code&gt; in your shell configuration. This ensures most deletions go to the trash bin.&lt;/p&gt;&#10;&lt;h3 id="setting-up-the-alias"&gt;Setting Up the Alias&#10;&lt;/h3&gt;&lt;ol&gt;&#10;&lt;li&gt;Edit your &lt;code&gt;~/.bashrc&lt;/code&gt; file:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;nano ~/.bashrc&#10;&lt;/code&gt;&lt;/pre&gt;&lt;ol start="2"&gt;&#10;&lt;li&gt;Add this line at the end:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;alias rm=&amp;#39;trash&amp;#39;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;ol start="3"&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;Save and exit (Ctrl+X, Y, Enter).&lt;/p&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;Reload the configuration:&lt;/p&gt;&#10;&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;source ~/.bashrc&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Now, &lt;code&gt;rm file.txt&lt;/code&gt; will use &lt;code&gt;trash&lt;/code&gt; instead of permanent deletion.&lt;/p&gt;&#10;&lt;h2 id="automating-trash-emptying-with-cron"&gt;Automating Trash Emptying with Cron&#10;&lt;/h2&gt;&lt;p&gt;To prevent the trash from accumulating indefinitely, automate emptying with a cron job.&lt;/p&gt;&#10;&lt;h3 id="setting-up-weekly-emptying"&gt;Setting Up Weekly Emptying&#10;&lt;/h3&gt;&lt;ol&gt;&#10;&lt;li&gt;Edit your crontab:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;crontab -e&#10;&lt;/code&gt;&lt;/pre&gt;&lt;ol start="2"&gt;&#10;&lt;li&gt;Add this line for weekly deletion (e.g., every Sunday at 2 AM):&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;0 2 * * 0 /usr/bin/trash-empty&#10;&lt;/code&gt;&lt;/pre&gt;&lt;ul&gt;&#10;&lt;li&gt;&lt;code&gt;0 2 * * 0&lt;/code&gt;: Sunday at 2:00 AM.&lt;/li&gt;&#10;&lt;li&gt;&lt;code&gt;/usr/bin/trash-empty&lt;/code&gt;: Clears all trash.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;ol start="3"&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;Save and exit.&lt;/p&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;Verify:&lt;/p&gt;&#10;&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;crontab -l&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Adjust the schedule as needed (e.g., change &lt;code&gt;0&lt;/code&gt; to &lt;code&gt;1-6&lt;/code&gt; for weekdays). For partial emptying, use &lt;code&gt;trash-empty 30&lt;/code&gt; to delete items older than 30 days.&lt;/p&gt;&#10;&lt;h2 id="conclusion"&gt;Conclusion&#10;&lt;/h2&gt;&lt;p&gt;By installing &lt;code&gt;trash-cli&lt;/code&gt;, aliasing &lt;code&gt;rm&lt;/code&gt; to &lt;code&gt;trash&lt;/code&gt;, and setting up automated emptying, you can make your VPS much safer against accidental deletions. This approach adds a recoverable layer without sacrificing performance. Remember to combine it with regular backups and cautious command usage. If you&amp;rsquo;re new to VPS management, start small and test thoroughly. For more advanced setups, explore integrating with monitoring tools. Stay safe out there!&lt;/p&gt;&#10;</description></item><item><title>How to make your VPS secure</title><link>https://aquasp.blog/how-to-make-your-vps-secure/</link><pubDate>Tue, 09 Dec 2025 00:30:29 +0000</pubDate><guid>https://aquasp.blog/how-to-make-your-vps-secure/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;If you just bought a VPS and are starting to self-host, this is one of the &lt;strong&gt;most important security improvements&lt;/strong&gt; you can make.&lt;/p&gt;&#10;&lt;p&gt;By switching to SSH key authentication and disabling password login, your server becomes nearly immune to brute-force attacks — even if someone discovers your password or you&amp;rsquo;re still using the default port 22.&lt;/p&gt;&#10;&lt;h2 id="step-1-generate-an-ssh-key-pair-on-your-local-machine"&gt;Step 1: Generate an SSH Key Pair on Your Local Machine&#10;&lt;/h2&gt;&lt;h3 id="linux--macos"&gt;Linux &amp;amp; macOS&#10;&lt;/h3&gt;&lt;p&gt;Open a terminal and run:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ssh-keygen -t rsa -b &lt;span style="color:#ae81ff"&gt;4096&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;or (newer recommended format):&lt;/p&gt;&#10;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;ssh-keygen -t ed25519&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Press Enter to accept the default file location and &lt;strong&gt;leave the passphrase empty&lt;/strong&gt; (just hit Enter twice).&lt;/p&gt;&#10;&lt;p&gt;Your keys will be saved as:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Private key: ~/.ssh/id_rsa or ~/.ssh/id_ed25519&lt;/li&gt;&#10;&lt;li&gt;Public key: ~/.ssh/id_rsa.pub or ~/.ssh/id_ed25519.pub&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;&lt;strong&gt;Never share the private key!&lt;/strong&gt;&lt;/p&gt;&#10;&lt;h3 id="windows-powershell"&gt;Windows (PowerShell)&#10;&lt;/h3&gt;&lt;p&gt;Open PowerShell and run:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;ssh-keygen.exe -t ed25519&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;(or -t rsa -b 4096 if ed25519 is not supported)&lt;/p&gt;&#10;&lt;p&gt;Press Enter through the prompts (no passphrase). Keys will be created in C:\Users\YourUser.ssh\&lt;/p&gt;&#10;&lt;h2 id="step-2-copy-your-public-key-to-the-vps"&gt;Step 2: Copy Your Public Key to the VPS&#10;&lt;/h2&gt;&lt;h3 id="linux--macos-easiest-method"&gt;Linux &amp;amp; macOS (Easiest Method)&#10;&lt;/h3&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;ssh-copy-id user@your-vps-ip&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Replace user and your-vps-ip with your actual username and server IP.&lt;/p&gt;&#10;&lt;h3 id="windows"&gt;Windows&#10;&lt;/h3&gt;&lt;ol&gt;&#10;&lt;li&gt;Paste your public key (it’s one long line starting with ssh-ed25519 or ssh-rsa) → Save with &lt;strong&gt;Ctrl+O → Enter → Ctrl+X&lt;/strong&gt;&lt;/li&gt;&#10;&lt;li&gt;Test it: Open a &lt;strong&gt;new&lt;/strong&gt; terminal/PowerShell and try logging in. It should work &lt;strong&gt;without asking for a password&lt;/strong&gt;.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;Edit the file:Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;nano ~/.ssh/authorized_keys&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Create the .ssh folder and authorized_keys file (if they don&amp;rsquo;t exist):Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;mkdir -p ~/.ssh&#10;chmod 700 ~/.ssh&#10;touch ~/.ssh/authorized_keys&#10;chmod 600 ~/.ssh/authorized_keys&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Log into your VPS normally (with password):PowerShell&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;ssh user@your-vps-ip&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Copy your public key to clipboard:PowerShell&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;Get-Content $HOME\.ssh\id_ed25519.pub | Set-Clipboard&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;(or id_rsa.pub if you used RSA)&lt;/p&gt;&#10;&lt;h2 id="step-3-disable-password-authentication"&gt;Step 3: Disable Password Authentication&#10;&lt;/h2&gt;&lt;p&gt;Now that key login works, disable password login entirely.&lt;/p&gt;&#10;&lt;p&gt;Log into your VPS (using your key) and edit the SSH config:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo nano /etc/ssh/sshd_config&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Find and change (or add) these lines:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;PasswordAuthentication no&#10;ChallengeResponseAuthentication no&#10;UsePAM no&#10;PubkeyAuthentication yes&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Save and exit.&lt;/p&gt;&#10;&lt;p&gt;Restart the SSH service:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo systemctl restart sshd&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;(or sudo service ssh restart on older systems)&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Final test&lt;/strong&gt;: Try logging in from a new terminal. It should only work with your private key — password attempts will be rejected instantly.&lt;/p&gt;&#10;&lt;h2 id="done"&gt;Done!&#10;&lt;/h2&gt;&lt;p&gt;Your VPS is now protected against:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Brute-force attacks&lt;/li&gt;&#10;&lt;li&gt;Credential stuffing&lt;/li&gt;&#10;&lt;li&gt;Weak or leaked passwords&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Even if an attacker knows your username and password, they &lt;strong&gt;cannot log in&lt;/strong&gt; without your private key file.&lt;/p&gt;&#10;&lt;p&gt;Pro tip: Back up your private key securely and consider adding a passphrase later using ssh-keygen -p.&lt;/p&gt;&#10;&lt;p&gt;Thank you for reading! 😊&lt;/p&gt;&#10;</description></item><item><title>How to remove upload limits on All In One WP Migration</title><link>https://aquasp.blog/how-to-remove-upload-limits-on-all-in-one-wp-migration/</link><pubDate>Tue, 09 Dec 2025 00:25:04 +0000</pubDate><guid>https://aquasp.blog/how-to-remove-upload-limits-on-all-in-one-wp-migration/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Unfortunately, many hosting providers impose very low upload limits (sometimes as little as 2–50 MB), and the official Unlimited Extension costs $69.&lt;/p&gt;&#10;&lt;p&gt;If you’re in that situation and need a free way to upload huge backups (10 GB, 40 GB, or more), this simple trick will help.&lt;/p&gt;&#10;&lt;h2 id="the-solution-use-big-file-uploads-plugin"&gt;The Solution: Use &amp;ldquo;Big File Uploads&amp;rdquo; Plugin&#10;&lt;/h2&gt;&lt;p&gt;The free version of All-in-One WP Migration doesn’t artificially limit uploads — it simply respects whatever limit your hosting or server enforces. The paid Unlimited Extension works by splitting the &lt;code&gt;.wpress&lt;/code&gt; file into smaller chunks during upload.&lt;/p&gt;&#10;&lt;p&gt;Good news: there’s a completely free plugin that does the exact same chunking trick!&lt;/p&gt;&#10;&lt;h3 id="step-by-step-guide"&gt;Step-by-Step Guide&#10;&lt;/h3&gt;&lt;ol&gt;&#10;&lt;li&gt;Install and activate the plugin called &lt;strong&gt;Big File Uploads&lt;/strong&gt;&#10;→ Direct link: &lt;a class="link" href="https://wordpress.org/plugins/tuxedo-big-file-uploads/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://wordpress.org/plugins/tuxedo-big-file-uploads/&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;After activation, go to:&#10;&lt;strong&gt;Settings → Big File Uploads&lt;/strong&gt;&#10;(or find it under the Plugins page → “Settings” link under the plugin name)&lt;/li&gt;&#10;&lt;li&gt;You’ll see the current maximum upload size (it will match your host’s default limit at first).&lt;/li&gt;&#10;&lt;li&gt;Change it to whatever you want:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;1 GB = 1024 MB&lt;/li&gt;&#10;&lt;li&gt;10 GB = 10240 MB&lt;/li&gt;&#10;&lt;li&gt;40 GB = 40960 MB&#10;(Just type the number in megabytes — no need to add “MB” or “GB”)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;ol start="5"&gt;&#10;&lt;li&gt;Click &lt;strong&gt;Save Changes&lt;/strong&gt;&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;That’s it! The new limit takes effect immediately.&lt;/p&gt;&#10;&lt;p&gt;Now when you go back to &lt;strong&gt;All-in-One WP Migration → Import&lt;/strong&gt;, the max file size will reflect your new value (even 40 GB or higher works perfectly).&lt;/p&gt;&#10;&lt;h2 id="conclusion"&gt;Conclusion&#10;&lt;/h2&gt;&lt;p&gt;This is &lt;strong&gt;not&lt;/strong&gt; meant as an attack on ServMask — they’ve built an amazing plugin and absolutely deserve support. If you can afford it, please buy the official Unlimited Extension.&lt;/p&gt;&#10;&lt;p&gt;But if budget is tight and you just need to migrate or restore a huge site once or twice, the &lt;strong&gt;Big File Uploads&lt;/strong&gt; plugin is a 100% free and reliable alternative that works perfectly with the free version of All-in-One WP Migration.&lt;/p&gt;&#10;&lt;p&gt;Thank you for reading! 🙂&lt;/p&gt;&#10;</description></item><item><title>How to run your own monero node</title><link>https://aquasp.blog/how-to-run-your-own-monero-node/</link><pubDate>Tue, 09 Dec 2025 00:07:50 +0000</pubDate><guid>https://aquasp.blog/how-to-run-your-own-monero-node/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Monero is one of the most important cryptocurrencies in my opinion. It does not have the same market share as Bitcoin, but it is quite unique in one aspect: &lt;strong&gt;privacy&lt;/strong&gt;. Monero is just like cash — no one needs to know how much Monero was sent or who sent it. It&amp;rsquo;s the opposite of Bitcoin in this regard. In fact, Bitcoin is &lt;strong&gt;worse than fiat money&lt;/strong&gt; when it comes to privacy.&lt;/p&gt;&#10;&lt;p&gt;You can read more details here:&#10;&lt;a class="link" href="https://lukesmith.xyz/articles/monero-maximalism-or-how-bitcoin-is-a-coin/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://lukesmith.xyz/articles/monero-maximalism-or-how-bitcoin-is-a-coin/&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;Obs:&lt;/strong&gt; I&amp;rsquo;m &lt;strong&gt;NOT&lt;/strong&gt; recommending anyone invest in Monero. Monero is supposed to be a currency, but since crypto is still extremely volatile, many people treat it as an investment. Do your own research — I&amp;rsquo;m not responsible for any investments you make.&lt;/p&gt;&#10;&lt;h2 id="1-choose-a-vps-or-set-it-up-at-home"&gt;1. Choose a VPS or set it up at home&#10;&lt;/h2&gt;&lt;p&gt;First things first, you will need a server. You can use your own home PC if you prefer, or a VPS. A VPS is easier because it stays online 24/7 and you can always open the required ports.&lt;/p&gt;&#10;&lt;p&gt;At home, many ISPs block incoming ports, so your node wouldn’t be public (it would still help the network, but you couldn’t easily connect to it from outside without something like ngrok).&lt;/p&gt;&#10;&lt;p&gt;I personally recommend &lt;strong&gt;Contabo&lt;/strong&gt; for running a Monero node because they offer excellent prices on storage VPS plans.&#10;Check their pricing here: &lt;a class="link" href="https://contabo.com/en/storage-vps/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Contabo Storage VPS&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;The &lt;strong&gt;Storage VPS S&lt;/strong&gt; is more than enough. The Monero blockchain currently uses about 175 GB, less than 2 GB of RAM, and barely any CPU once fully synced (~3 % usage).&lt;/p&gt;&#10;&lt;h2 id="2-securing-the-vps"&gt;2. Securing the VPS&#10;&lt;/h2&gt;&lt;p&gt;First of all, &lt;strong&gt;disable password login&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;p&gt;Then install and configure UFW (if it’s not already set up):&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo apt install ufw&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo ufw default deny incoming&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo ufw default allow outgoing&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo ufw allow ssh&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo ufw allow &lt;span style="color:#ae81ff"&gt;18080&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo ufw allow &lt;span style="color:#ae81ff"&gt;18089&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo ufw enable&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="3-creating-a-dedicated-user"&gt;3. Creating a dedicated user&#10;&lt;/h2&gt;&lt;p&gt;For security reasons, never run Monero as root. Create a normal user instead:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;adduser monerouser&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Set a password and press Enter through the rest of the prompts.&lt;/p&gt;&#10;&lt;h2 id="4-changing-settings-and-syncing-the-node"&gt;4. Changing settings and syncing the node&#10;&lt;/h2&gt;&lt;p&gt;Switch to the new user:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;su monerouser&#10;cd ~&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Download the official Monero CLI binaries (Linux 64-bit):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;wget -c https://downloads.getmonero.org/cli/monero-linux-x64-v0.18.3.4.tar.bz2&#10;mkdir monero&#10;tar -xjvf monero-linux-x64-v0.18.3.4.tar.bz2 -C monero --strip-components=1&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;(Replace the version in the URL/filename with the latest one from &lt;a class="link" href="https://getmonero.org/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://getmonero.org&lt;/a&gt; if needed.)&lt;/p&gt;&#10;&lt;p&gt;Enter the folder and start monerod once just to create the config files (stop it after a few seconds with Ctrl+C):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;cd monero&#10;./monerod&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Now edit the configuration file:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;nano ~/.bitmonero/bitmonero.conf&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Paste the following recommended settings:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;# P2P full node&#10;public-node=true # Advertises the RPC-restricted port over p2p&#10;&#10;# RPC settings&#10;rpc-restricted-bind-ip=0.0.0.0&#10;rpc-restricted-bind-port=18089&#10;&#10;# Node settings&#10;enforce-dns-checkpointing=true&#10;db-sync-mode=safe # Slow but reliable db writes&#10;enable-dns-blocklist=true # Block known-malicious nodes&#10;no-igd=true # Disable UPnP&#10;no-zmq=true&#10;&#10;# Bandwidth settings (much faster sync + better contribution)&#10;out-peers=32&#10;in-peers=32&#10;limit-rate-up=1048576 # 1 GB/s upload&#10;limit-rate-down=1048576 # 1 GB/s download&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Save with &lt;strong&gt;Ctrl+O → Enter → Ctrl+X&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;p&gt;Start the node in detached mode:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;./monerod --detach&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;You&amp;rsquo;re done! Now just wait for it to fully sync.&lt;/p&gt;&#10;&lt;p&gt;Check sync status anytime with:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;./monerod status&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;The initial sync usually takes a few hours depending on your connection and VPS speed.&lt;/p&gt;&#10;&lt;p&gt;Once it&amp;rsquo;s fully synced, you can connect any Monero wallet (Cake Wallet, Monero GUI, Feather, etc.) to your own node using your VPS IP and port &lt;strong&gt;18089&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;h2 id="conclusion--credits"&gt;Conclusion &amp;amp; Credits&#10;&lt;/h2&gt;&lt;p&gt;That&amp;rsquo;s it! Running your own full node is strongly encouraged by the Monero community. It makes the network more decentralized and gives you maximum privacy.&lt;/p&gt;&#10;&lt;p&gt;This guide wouldn’t have been possible without these excellent resources:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;a class="link" href="https://www.getmonero.org/resources/user-guides/vps_run_node.html?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://www.getmonero.org/resources/user-guides/vps_run_node.html&lt;/a&gt;&lt;/li&gt;&#10;&lt;li&gt;&lt;a class="link" href="https://www.coincashew.com/coins/overview-xmr/guide-or-how-to-run-a-full-node?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://www.coincashew.com/coins/overview-xmr/guide-or-how-to-run-a-full-node&lt;/a&gt;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Thank you for reading! 🙂&lt;/p&gt;&#10;</description></item><item><title>How to Self Host your own Piped Instance</title><link>https://aquasp.blog/how-to-self-host-your-own-piped-instance/</link><pubDate>Mon, 08 Dec 2025 23:58:10 +0000</pubDate><guid>https://aquasp.blog/how-to-self-host-your-own-piped-instance/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Piped is a privacy-first, open-source alternative YouTube front-end. No Google tracking, no ads (even on videos that normally have unskippable ones), and it works perfectly with SponsorBlock and dearrow.&lt;/p&gt;&#10;&lt;p&gt;Self-hosting your own instance is incredibly easy with Docker and takes less than 20 minutes.&lt;/p&gt;&#10;&lt;h2 id="requirements"&gt;Requirements&#10;&lt;/h2&gt;&lt;ul&gt;&#10;&lt;li&gt;A domain (or subdomain)&lt;/li&gt;&#10;&lt;li&gt;A cheap KVM VPS with Docker support (avoid OpenVZ — old kernel)&lt;/li&gt;&#10;&lt;li&gt;~$3–6/month is more than enough (1 CPU, 1–2 GB RAM)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Great cheap providers in 2025:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;RackNerd&lt;/li&gt;&#10;&lt;li&gt;Hostinger (my affiliate if you want to support &lt;a class="link" href="https://hostinger.com.br/?REFERRALCODE=waterdownfall&amp;amp;ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://hostinger.com.br?REFERRALCODE=waterdownfall&lt;/a&gt;)&lt;/li&gt;&#10;&lt;li&gt;Cloudcone, Hetzner Cloud, BuyVM, etc.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="step-1-secure--prepare-your-vps"&gt;Step 1: Secure &amp;amp; Prepare Your VPS&#10;&lt;/h2&gt;&lt;p&gt;(SSH keys only, firewall, etc. — do this first!)&lt;/p&gt;&#10;&lt;p&gt;Then install Docker (Ubuntu/Debian example):&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt update &lt;span style="color:#f92672"&gt;&amp;amp;&amp;amp;&lt;/span&gt; apt upgrade -y&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt install -y ca-certificates curl gnupg lsb-release&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&lt;span style="color:#75715e"&gt;# Add Docker repo&lt;/span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo mkdir -p /etc/apt/keyrings&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;curl -fsSL https://download.docker.com/linux/ubuntu/gpg | gpg --dearmor -o /etc/apt/keyrings/docker.gpg&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;echo &lt;span style="color:#e6db74"&gt;&amp;#34;deb [arch=&lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;dpkg --print-architecture&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;&lt;span style="color:#e6db74"&gt; signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/ubuntu &lt;/span&gt;&lt;span style="color:#66d9ef"&gt;$(&lt;/span&gt;lsb_release -cs&lt;span style="color:#66d9ef"&gt;)&lt;/span&gt;&lt;span style="color:#e6db74"&gt; stable&amp;#34;&lt;/span&gt; &amp;gt; /etc/apt/sources.list.d/docker.list&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt update&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="step-2-deploy-piped-with-the-official-docker-setup"&gt;Step 2: Deploy Piped with the Official Docker Setup&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;cd /opt&#10;git clone https://github.com/TeamPiped/Piped-Docker&#10;cd Piped-Docker&#10;./configure-instance.sh&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;During the script:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;Choose &lt;strong&gt;Caddy&lt;/strong&gt; as reverse proxy (easiest + automatic SSL)&lt;/p&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;Enter your domain and subdomains:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Frontend → piped.yourdomain.com&lt;/li&gt;&#10;&lt;li&gt;Backend API → pipedapi.yourdomain.com&lt;/li&gt;&#10;&lt;li&gt;Proxy → pipedproxy.yourdomain.com&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="step-3-point-dns-to-your-vps"&gt;Step 3: Point DNS to Your VPS&#10;&lt;/h2&gt;&lt;p&gt;Create three A records at your DNS provider:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;piped.yourdomain.com → VPS_IP&#10;pipedapi.yourdomain.com → VPS_IP&#10;pipedproxy.yourdomain.com → VPS_IP&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-4-launch-everything"&gt;Step 4: Launch Everything&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;docker compose up -d&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;That’s it!&#10;After DNS propagates (usually &amp;lt; 10 minutes), your private YouTube will be live at:&lt;/p&gt;&#10;&lt;p&gt;&lt;a class="link" href="https://piped.yourdomain.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://piped.yourdomain.com&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;Caddy automatically handles free Let’s Encrypt SSL — no manual certbot needed.&lt;/p&gt;&#10;&lt;h2 id="step-5-optional-check-logs"&gt;Step 5: (Optional) Check Logs&#10;&lt;/h2&gt;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;# See what Caddy is doing&#10;docker logs -f caddy&#10;&#10;# Or any other container&#10;docker logs -f piped-frontend&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="bonus-tips"&gt;Bonus Tips&#10;&lt;/h2&gt;&lt;ul&gt;&#10;&lt;li&gt;Want to make it public? Just share the URL — anyone can use your instance.&lt;/li&gt;&#10;&lt;li&gt;Want it private? Block it with Cloudflare firewall rules or basic auth in Caddy.&lt;/li&gt;&#10;&lt;li&gt;Pair it with the &lt;strong&gt;LibreTube&lt;/strong&gt; (Android) app for the full de-Googled experience.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;You now have your own ad-free, tracking-free, SponsorBlock-enabled YouTube — fully under your control.&lt;/p&gt;&#10;&lt;p&gt;Thanks for reading!&lt;/p&gt;&#10;</description></item><item><title>How to setup grub for Dual Boot on Ubuntu 23.10 (fix)</title><link>https://aquasp.blog/how-to-setup-grub-for-dual-boot-on-ubuntu-23-10-fix/</link><pubDate>Mon, 08 Dec 2025 23:53:06 +0000</pubDate><guid>https://aquasp.blog/how-to-setup-grub-for-dual-boot-on-ubuntu-23-10-fix/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;GRUB Menu Not Showing → Windows Not Appearing on Boot&lt;/p&gt;&#10;&lt;p&gt;Just installed Xubuntu (or Ubuntu) 23.10 alongside Windows and now it boots straight into Linux without showing the GRUB menu?&#10;Don’t worry — this is the new default behavior. Starting with recent Ubuntu versions, &lt;code&gt;GRUB_TIMEOUT_STYLE&lt;/code&gt; is set to hidden and the timeout is 0 seconds, so the menu is completely skipped unless you hold Shift during boot.&lt;/p&gt;&#10;&lt;p&gt;Here’s the permanent two-line fix.&lt;/p&gt;&#10;&lt;h2 id="the-fix-takes-30-seconds"&gt;The Fix (Takes 30 Seconds)&#10;&lt;/h2&gt;&lt;p&gt;Open a terminal and edit the GRUB config:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;sudo nano /etc/default/grub&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Make sure these lines are present and exactly like this (add them if missing):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;GRUB_TIMEOUT_STYLE=menu&#10;GRUB_TIMEOUT=10&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Optional but recommended — make the menu look nicer and be 100% reliable:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;GRUB_TERMINAL=console&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Full example of the relevant section:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;# Show the GRUB menu every time&#10;GRUB_TIMEOUT_STYLE=menu&#10;GRUB_TIMEOUT=10 # seconds to wait before auto-booting the default entry&#10;GRUB_TERMINAL=console&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Save (Ctrl+O → Enter → Ctrl+X) and update GRUB:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo update-grub&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reboot and you’ll now see the full GRUB menu with both Ubuntu/Xubuntu and Windows listed.&#10;You can change the 10 to any number you like (or even -1 to wait indefinitely until you pick an entry).&lt;/p&gt;&#10;&lt;h2 id="why-this-happens"&gt;Why This Happens&#10;&lt;/h2&gt;&lt;p&gt;Canonical decided to hide the menu by default for a “cleaner” boot experience on single-OS machines.&#10;For dual-boot users it’s just annoying — this fix restores the classic behavior permanently.&lt;/p&gt;&#10;&lt;p&gt;That’s it — enjoy easy access to both operating systems again!&lt;/p&gt;&#10;&lt;p&gt;(Original solution via AskUbuntu community)&lt;/p&gt;&#10;&lt;p&gt;Thanks for reading!&lt;/p&gt;&#10;</description></item><item><title>How to setup WordPress on LEMP with Redis and WP CLI on Debian 11</title><link>https://aquasp.blog/how-to-setup-wordpress-on-lemp-with-redis-and-wp-cli-on-debian-11/</link><pubDate>Mon, 08 Dec 2025 23:47:36 +0000</pubDate><guid>https://aquasp.blog/how-to-setup-wordpress-on-lemp-with-redis-and-wp-cli-on-debian-11/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;This is the fastest, most secure, and most resource-efficient way to self-host WordPress in 2025.&#10;We’ll use a proper LEMP stack (Linux + Nginx + MySQL/MariaDB + PHP-FPM) with per-site PHP isolation, Redis object caching, automatic SSL, and WP-CLI — everything tuned for speed and security.&lt;/p&gt;&#10;&lt;p&gt;Let’s go.&lt;/p&gt;&#10;&lt;h2 id="step-0-secure--update-your-vps"&gt;Step 0: Secure &amp;amp; Update Your VPS&#10;&lt;/h2&gt;&lt;p&gt;(If you haven’t already, follow a VPS hardening guide first — SSH keys only, firewall, fail2ban, etc.)&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt update &lt;span style="color:#f92672"&gt;&amp;amp;&amp;amp;&lt;/span&gt; apt upgrade -y&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt autoremove --purge&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;reboot&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="step-1-install-the-core-stack"&gt;Step 1: Install the Core Stack&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;# Nginx&#10;apt install nginx -y&#10;systemctl enable nginx&#10;&#10;# MariaDB (better than MySQL on Debian)&#10;apt install mariadb-server -y&#10;systemctl enable mariadb&#10;&#10;# PHP 8.3 + all needed extensions (using ondrej/sury repo)&#10;apt install ca-certificates apt-transport-https lsb-release -y&#10;wget -qO- https://packages.sury.org/php/apt.gpg | gpg --dearmor &amp;gt; /usr/share/keyrings/sury-php.gpg&#10;echo &amp;#34;deb [signed-by=/usr/share/keyrings/sury-php.gpg] https://packages.sury.org/php/ $(lsb_release -sc) main&amp;#34; &amp;gt; /etc/apt/sources.list.d/sury-php.list&#10;apt update&#10;apt install php8.3-fpm php8.3-mysql php8.3-curl php8.3-gd php8.3-mbstring php8.3-xml php8.3-zip php8.3-intl php8.3-imagick php8.3-redis -y&#10;systemctl enable php8.3-fpm&#10;&#10;# Redis&#10;curl -fsSL https://packages.redis.io/gpg | gpg --dearmor -o /usr/share/keyrings/redis-archive-keyring.gpg&#10;echo &amp;#34;deb [signed-by=/usr/share/keyrings/redis-archive-keyring.gpg] https://packages.redis.io/deb $(lsb_release -cs) main&amp;#34; &amp;gt; /etc/apt/sources.list.d/redis.list&#10;apt update &amp;amp;&amp;amp; apt install redis-server -y&#10;systemctl enable redis-server&#10;&#10;# Certbot + WP-CLI&#10;apt install python3-certbot-nginx -y&#10;curl -O https://raw.githubusercontent.com/wp-cli/builds/gh-pages/phar/wp-cli.phar&#10;chmod +x wp-cli.phar &amp;amp;&amp;amp; mv wp-cli.phar /usr/local/bin/wp&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-2-secure-mariadb--create-database"&gt;Step 2: Secure MariaDB &amp;amp; Create Database&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;mysql_secure_installation&#10;&lt;/code&gt;&lt;/pre&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;mysql -u root -p&#10;CREATE DATABASE wp_yoursite;&#10;CREATE USER &amp;#39;wp_yoursite&amp;#39;@&amp;#39;localhost&amp;#39; IDENTIFIED BY &amp;#39;strongpassword&amp;#39;;&#10;GRANT ALL ON wp_yoursite.* TO &amp;#39;wp_yoursite&amp;#39;@&amp;#39;localhost&amp;#39;;&#10;FLUSH PRIVILEGES;&#10;EXIT;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-3-isolate-php-fpm-per-site-security--stability"&gt;Step 3: Isolate PHP-FPM Per Site (Security + Stability)&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;cd /etc/php/8.3/fpm/pool.d/&#10;cp www.conf yoursite.conf&#10;nano yoursite.conf&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Replace:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;[www] → [yoursite]&lt;/li&gt;&#10;&lt;li&gt;user = www-data → user = yoursiteuser (we’ll create this user soon)&lt;/li&gt;&#10;&lt;li&gt;group = www-data → group = yoursiteuser&lt;/li&gt;&#10;&lt;li&gt;listen = /run/php/php8.3-fpm.sock → listen = /run/php/php8.3-fpm-yoursite.sock&lt;/li&gt;&#10;&lt;li&gt;Change process manager from dynamic → ondemand (saves RAM)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;systemctl restart php8.3-fpm&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;(It will fail until the user exists — that’s fine.)&lt;/p&gt;&#10;&lt;h2 id="step-4-optimize-php--enable-opcache"&gt;Step 4: Optimize PHP &amp;amp; Enable OPcache&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;sed -i &amp;#34;s/memory_limit = .*/memory_limit = 1024M/&amp;#34; /etc/php/8.3/fpm/php.ini&#10;sed -i &amp;#34;s/upload_max_filesize = .*/upload_max_filesize = 10240M/&amp;#34; /etc/php/8.3/fpm/php.ini&#10;sed -i &amp;#34;s/post_max_size = .*/post_max_size = 10240M/&amp;#34; /etc/php/8.3/fpm/php.ini&#10;sed -i &amp;#34;s/max_execution_time = .*/max_execution_time = 600/&amp;#34; /etc/php/8.3/fpm/php.ini&#10;sed -i &amp;#34;s/;opcache.enable=1/opcache.enable=1/&amp;#34; /etc/php/8.3/fpm/php.ini&#10;sed -i &amp;#34;s/;opcache.memory_consumption=.*/opcache.memory_consumption=512/&amp;#34; /etc/php/8.3/fpm/php.ini&#10;sed -i &amp;#34;s/;opcache.max_accelerated_files=.*/opcache.max_accelerated_files=20000/&amp;#34; /etc/php/8.3/fpm/php.ini&#10;sed -i &amp;#34;s/;cgi.fix_pathinfo=1/cgi.fix_pathinfo=0/&amp;#34; /etc/php/8.3/fpm/php.ini&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-5-create-system-user--site-directory"&gt;Step 5: Create System User &amp;amp; Site Directory&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;adduser yoursiteuser --shell /bin/bash&#10;su yoursiteuser&#10;mkdir ~/public_html &amp;amp;&amp;amp; cd ~/public_html&#10;echo &amp;#34;cd ~/public_html&amp;#34; &amp;gt;&amp;gt; ~/.bashrc&#10;exit&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-6-nginx-config-fast--secure"&gt;Step 6: Nginx Config (Fast &amp;amp; Secure)&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;nano /etc/nginx/sites-available/yoursite.conf&#10;&lt;/code&gt;&lt;/pre&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;upstream php-yoursite {&#10; server unix:/run/php/php8.3-fpm-yoursite.sock;&#10;}&#10;&#10;server {&#10; listen 80;&#10; listen [::]:80;&#10; server_name yourdomain.com www.yourdomain.com;&#10; root /home/yoursiteuser/public_html;&#10; index index.php index.html;&#10;&#10; client_max_body_size 10G;&#10;&#10; location / {&#10; try_files $uri $uri/ /index.php?$args;&#10; }&#10;&#10; location ~ \.php$ {&#10; include fastcgi_params;&#10; fastcgi_pass php-yoursite;&#10; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;&#10; }&#10;&#10; location ~* \.(js|css|png|jpg|jpeg|gif|ico|svg|woff2?|ttf|eot)$ {&#10; expires max;&#10; log_not_found off;&#10; }&#10;}&#10;&lt;/code&gt;&lt;/pre&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;ln -s /etc/nginx/sites-available/yoursite.conf /etc/nginx/sites-enabled/&#10;nginx -t &amp;amp;&amp;amp; systemctl reload nginx&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-7-install-wordpress-via-wp-cli-as-the-site-user"&gt;Step 7: Install WordPress via WP-CLI (as the site user)&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;su yoursiteuser&#10;cd ~/public_html&#10;&#10;wp core download&#10;wp config create --dbname=wp_yoursite --dbuser=wp_yoursite --dbpass=&amp;#39;strongpassword&amp;#39; --locale=en_US&#10;wp core install --url=https://yourdomain.com --title=&amp;#34;Your Site&amp;#34; --admin_user=admin --admin_password=&amp;#39;strongpass&amp;#39; --admin_email=you@domain.com&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-8-ssl-with-lets-encrypt-auto-renew"&gt;Step 8: SSL with Let’s Encrypt (Auto-renew)&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;certbot --nginx -d yourdomain.com -d www.yourdomain.com&#10;# Choose redirect to HTTPS when asked&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Add auto-renew cron:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;crontab -e&#10;# Add:&#10;0 0 * * 0 certbot renew --quiet&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-9-enable-redis-object-cache"&gt;Step 9: Enable Redis Object Cache&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;# As root&#10;usermod -aG redis yoursiteuser&#10;chmod 770 /var/run/redis/redis-server.sock&#10;&#10;# Optimize Redis config&#10;sed -i &amp;#39;s/port 6379/port 0/&amp;#39; /etc/redis/redis.conf&#10;sed -i &amp;#39;s|# unixsocket /run/redis/redis-server.sock|unixsocket /var/run/redis/redis-server.sock|&amp;#39; /etc/redis/redis.conf&#10;sed -i &amp;#39;s/# unixsocketperm 700/unixsocketperm 770/&amp;#39; /etc/redis/redis.conf&#10;sed -i &amp;#39;s/# maxmemory .*/maxmemory 1024mb/&amp;#39; /etc/redis/redis.conf&#10;systemctl restart redis-server&#10;&lt;/code&gt;&lt;/pre&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;# As yoursiteuser&#10;cd ~/public_html&#10;wp plugin install redis-cache --activate&#10;wp config set WP_REDIS_SCHEME unix&#10;wp config set WP_REDIS_PATH &amp;#39;/var/run/redis/redis-server.sock&amp;#39;&#10;wp redis enable&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="done"&gt;Done!&#10;&lt;/h2&gt;&lt;p&gt;You now have:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Fully isolated PHP-FPM pool (1 user = 1 site = no cross-site damage)&lt;/li&gt;&#10;&lt;li&gt;Redis object caching over Unix socket&lt;/li&gt;&#10;&lt;li&gt;OPcache + huge upload limits&lt;/li&gt;&#10;&lt;li&gt;Automatic SSL renewal&lt;/li&gt;&#10;&lt;li&gt;Fastest possible Nginx routing&lt;/li&gt;&#10;&lt;li&gt;WP-CLI ready&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Your wp-admin will feel instant, and the site will handle traffic like a champ — even on a $5/month VPS.&lt;/p&gt;&#10;&lt;p&gt;Next steps:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Install a page cache plugin (any free one is ok)&lt;/li&gt;&#10;&lt;li&gt;Set up Cloudflare (optional but recommended)&lt;/li&gt;&#10;&lt;li&gt;Regular backups&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Enjoy your blazing-fast, private WordPress setup!&lt;/p&gt;&#10;&lt;p&gt;Thanks for reading! 😊&lt;/p&gt;&#10;</description></item><item><title>How to setup your own email server</title><link>https://aquasp.blog/how-to-setup-your-own-email-server/</link><pubDate>Mon, 08 Dec 2025 23:35:02 +0000</pubDate><guid>https://aquasp.blog/how-to-setup-your-own-email-server/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Want your own ultra-private email like &lt;a class="link" href="" &gt;name@yourdomain.com&lt;/a&gt; with a beautiful webmail interface?&#10;This guide walks you through setting up a full mail server in under an hour using Luke Smith’s legendary &lt;strong&gt;EmailWiz&lt;/strong&gt; script + &lt;strong&gt;Roundcube&lt;/strong&gt; webmail — all on a $2–3/month VPS.&lt;/p&gt;&#10;&lt;p&gt;Everything is free, open-source, and 100% under your control.&lt;/p&gt;&#10;&lt;h2 id="step-0-grab-a-cheap-vps"&gt;Step 0: Grab a Cheap VPS&#10;&lt;/h2&gt;&lt;p&gt;Good providers with frequent sales:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Contabo&lt;/li&gt;&#10;&lt;li&gt;LowEndTalk “Offers” section&lt;/li&gt;&#10;&lt;li&gt;Hostinger (my affiliate if you want to support me -&amp;gt; &lt;a class="link" href="https://hostinger.com.br/?REFERRALCODE=waterdownfall&amp;amp;ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://hostinger.com.br?REFERRALCODE=waterdownfall&lt;/a&gt;)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Requirements:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Any location (USA works fine)&lt;/li&gt;&#10;&lt;li&gt;Debian 10 or 11 (we’ll use Debian 10 in this guide)&lt;/li&gt;&#10;&lt;li&gt;At least 1 GB RAM (2 GB+ recommended)&lt;/li&gt;&#10;&lt;li&gt;Set hostname during signup to your domain (e.g., sobremail.com)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Wait for deployment → grab root password from email → SSH in.&lt;/p&gt;&#10;&lt;h2 id="step-1-basic-vps-hardening"&gt;Step 1: Basic VPS Hardening&#10;&lt;/h2&gt;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ssh root@your-vps-ip&#10;&lt;/span&gt;&lt;/span&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;apt update &lt;span style="color:#f92672"&gt;&amp;amp;&amp;amp;&lt;/span&gt; apt upgrade -y&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Change root password:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;passwd&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Create and upload an SSH key (do this from your local machine):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;ssh-copy-id root@your-vps-ip&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Now disable password login:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;nano /etc/ssh/sshd_config&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Change:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;PasswordAuthentication no&#10;UsePAM no&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Then:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;systemctl restart sshd&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Only your SSH key works now — much safer.&lt;/p&gt;&#10;&lt;h2 id="step-2-install-emailwiz-the-magic-script"&gt;Step 2: Install EmailWiz (the magic script)&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;apt install curl nginx python3-certbot-nginx -y&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Point these DNS records to your VPS IP:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;yourdomain.com → VPS IP (A record)&lt;/li&gt;&#10;&lt;li&gt;mail.yourdomain.com → VPS IP (A record)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Run Luke’s script:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;curl -LO lukesmith.xyz/emailwiz.sh&#10;sh emailwiz.sh&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Follow the prompts:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Say Yes/Y to everything&lt;/li&gt;&#10;&lt;li&gt;When asked for “System mail name” → enter ONLY yourdomain.com (NOT mail.yourdomain.com!)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Wait ~5–10 minutes. When it finishes, it gives you three DNS records to add:&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;DKIM TXT record (mail._domainkey.yourdomain.com)&lt;/li&gt;&#10;&lt;li&gt;DMARC TXT record (_dmarc.yourdomain.com)&lt;/li&gt;&#10;&lt;li&gt;SPF TXT record (root domain)&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;Add them at your DNS provider (Cloudflare, Namecheap, etc.).&lt;/p&gt;&#10;&lt;h2 id="step-3-set-up-reverse-dns-critical-for-deliverability"&gt;Step 3: Set Up Reverse DNS (Critical for Deliverability!)&#10;&lt;/h2&gt;&lt;p&gt;In Cloudcone panel → Networking → rDNS → set to yourdomain.com&#10;&lt;strong&gt;Do NOT enable IPv6&lt;/strong&gt; (Cloudcone doesn’t support IPv6 rDNS yet — it will hurt deliverability).&lt;/p&gt;&#10;&lt;h2 id="step-4-create-your-first-mailbox"&gt;Step 4: Create Your First Mailbox&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;useradd -G mail -m yourusername&#10;passwd yourusername&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Your email is now: &lt;a class="link" href="mailto:yourusername@yourdomain.com" &gt;yourusername@yourdomain.com&lt;/a&gt;&lt;/p&gt;&#10;&lt;p&gt;Test in Thunderbird/IMAP client:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;IMAP: mail.yourdomain.com (port 993, SSL/TLS)&lt;/li&gt;&#10;&lt;li&gt;SMTP: mail.yourdomain.com (port 465, SSL/TLS)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="step-5-install-roundcube-webmail"&gt;Step 5: Install Roundcube Webmail&#10;&lt;/h2&gt;&lt;p&gt;Add backports + PHP 8.x repo:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;apt install -y lsb-release ca-certificates apt-transport-https software-properties-common gnupg2&#10;echo &amp;#34;deb https://packages.sury.org/php/ $(lsb_release -sc) main&amp;#34; | tee /etc/apt/sources.list.d/sury-php.list&#10;wget -qO - https://packages.sury.org/php/apt.gpg | apt-key add -&#10;apt update&#10;apt install -y php8.0-fpm php8.0-common php8.0-gd php8.0-imap php8.0-mysql php8.0-curl php8.0-zip php8.0-xml php8.0-mbstring php8.0-intl mariadb-server&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Secure MySQL:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;mysql_secure_installation&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Create Roundcube database:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;mysql -u root -p&#10;CREATE DATABASE roundcube;&#10;CREATE USER &amp;#39;roundcubeuser&amp;#39;@&amp;#39;localhost&amp;#39; IDENTIFIED BY &amp;#39;strongpassword&amp;#39;;&#10;GRANT ALL ON roundcube.* TO &amp;#39;roundcubeuser&amp;#39;@&amp;#39;localhost&amp;#39;;&#10;FLUSH PRIVILEGES;&#10;EXIT;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Download &amp;amp; extract Roundcube (latest complete version):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;cd /var/www&#10;wget https://github.com/roundcube/roundcubemail/releases/download/1.6.9/roundcubemail-1.6.9-complete.tar.gz&#10;tar xvf roundcubemail-1.6.9-complete.tar.gz&#10;mv roundcubemail-1.6.9 roundcube&#10;rm roundcubemail-1.6.9-complete.tar.gz&#10;chown -R www-data:www-data /var/www/roundcube/temp /var/www/roundcube/logs&#10;mysql roundcube &amp;lt; /var/www/roundcube/SQL/mysql.initial.sql&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Nginx config for Roundcube (/etc/nginx/sites-enabled/roundcube):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;server {&#10; listen 80;&#10; listen [::]:80;&#10; server_name yourdomain.com;&#10; root /var/www/roundcube;&#10; index index.php;&#10;&#10; location / {&#10; try_files $uri $uri/ /index.php;&#10; }&#10;&#10; location ~ \.php$ {&#10; include fastcgi_params;&#10; fastcgi_pass unix:/run/php/php8.0-fpm.sock;&#10; fastcgi_param SCRIPT_FILENAME $document_root$fastcgi_script_name;&#10; }&#10;&#10; location ~* \.(jpg|jpeg|gif|png|webp|svg|woff|woff2|ttf|css|js|ico|xml)$ {&#10; expires 360d;&#10; access_log off;&#10; }&#10;}&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Test &amp;amp; reload Nginx, then get SSL:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;nginx -t &amp;amp;&amp;amp; systemctl reload nginx&#10;certbot --nginx -d yourdomain.com&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Visit &lt;a class="link" href="https://yourdomain.com/installer" target="_blank" rel="noopener"&#10; &gt;https://yourdomain.com/installer&lt;/a&gt; → follow the wizard:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Database: roundcube, user roundcubeuser, password you set&lt;/li&gt;&#10;&lt;li&gt;IMAP host: localhost&lt;/li&gt;&#10;&lt;li&gt;SMTP host: localhost&lt;/li&gt;&#10;&lt;li&gt;Default host: mail.yourdomain.com&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Enable all plugins &lt;strong&gt;except Enigma&lt;/strong&gt; (it breaks identities in older versions).&lt;/p&gt;&#10;&lt;p&gt;After finishing, delete the installer:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;rm -rf /var/www/roundcube/installer&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-6-quality-of-life-tweaks"&gt;Step 6: Quality-of-Life Tweaks&#10;&lt;/h2&gt;&lt;p&gt;Edit /var/www/roundcube/config/config.inc.php:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;// Login with just username (no need to type @domain.com)&#10;$config[&amp;#39;username_domain&amp;#39;] = &amp;#39;yourdomain.com&amp;#39;;&#10;&#10;// Stay logged in for 6 months&#10;$config[&amp;#39;session_lifetime&amp;#39;] = 259200;&#10;&#10;// Disable Enigma if you enabled it&#10;// Remove &amp;#39;enigma&amp;#39; from $config[&amp;#39;plugins&amp;#39;] array&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Increase attachment size:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;nano /etc/php/8.0/fpm/php.ini&#10;&lt;/code&gt;&lt;/pre&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;upload_max_filesize = 50M&#10;post_max_size = 50M&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Then:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;systemctl restart php8.0-fpm&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="step-7-brute-force-protection-with-fail2ban"&gt;Step 7: Brute-Force Protection with Fail2Ban&#10;&lt;/h2&gt;&lt;pre tabindex="0"&gt;&lt;code&gt;apt install fail2ban -y&#10;cd /var/www/roundcube/plugins&#10;wget https://github.com/texxasrulez/roundcube_fail2ban/archive/refs/tags/1.4.zip&#10;unzip 1.4.zip&#10;mv roundcube_fail2ban-1.4 fail2ban&#10;rm 1.4.zip&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Enable in Roundcube config (config.inc.php):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;$config[&amp;#39;plugins&amp;#39;][] = &amp;#39;fail2ban&amp;#39;;&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Add jail (/etc/fail2ban/jail.local – create if missing):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;[roundcube]&#10;enabled = true&#10;port = http,https&#10;filter = roundcube&#10;action = iptables-multiport[name=roundcube, port=&amp;#34;http,https&amp;#34;]&#10;logpath = /var/www/roundcube/logs/errors.log&#10;maxretry = 5&#10;bantime = 3600&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Create filter (/etc/fail2ban/filter.d/roundcube.conf):&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;[Definition]&#10;failregex = IMAP Error: Login failed for .* from &amp;lt;HOST&amp;gt;&#10;ignoreregex =&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Restart:&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;systemctl restart fail2ban php8.0-fpm&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Done! Your webmail is now protected.&lt;/p&gt;&#10;&lt;h2 id="final-result"&gt;Final Result&#10;&lt;/h2&gt;&lt;p&gt;You now have:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Full email server with DKIM, SPF, DMARC&lt;/li&gt;&#10;&lt;li&gt;Beautiful, fast Roundcube webmail&lt;/li&gt;&#10;&lt;li&gt;Zero Google/Microsoft involvement&lt;/li&gt;&#10;&lt;li&gt;Login once every 6 months&lt;/li&gt;&#10;&lt;li&gt;Brute-force protection&lt;/li&gt;&#10;&lt;li&gt;All for ~$50/year&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Welcome to real email freedom.&lt;/p&gt;&#10;&lt;p&gt;Thanks for reading! 😊&lt;/p&gt;&#10;</description></item><item><title>How to use AI privately at Brave browser (2 methods)</title><link>https://aquasp.blog/how-to-use-ai-privately-at-brave-browser-2-methods/</link><pubDate>Mon, 08 Dec 2025 23:15:59 +0000</pubDate><guid>https://aquasp.blog/how-to-use-ai-privately-at-brave-browser-2-methods/</guid><description>&lt;hr&gt;&#10;&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;Brave Browser 1.69 introduced a game-changing feature: you can now connect &lt;strong&gt;Leo&lt;/strong&gt; (Brave’s built-in AI assistant) to &lt;strong&gt;any&lt;/strong&gt; model you want — including fully local models or third-party APIs.&#10;This means you get an always-available AI sidebar with zero subscription and total control over privacy and cost.&lt;/p&gt;&#10;&lt;p&gt;Here are the two best methods I’ve tested (one ultra-private, one smarter but cloud-based).&lt;/p&gt;&#10;&lt;h2 id="method-1--maximum-privacy-run-a-local-model-with-ollama-no-gpu-needed"&gt;Method 1 – Maximum Privacy: Run a Local Model with Ollama (No GPU Needed)&#10;&lt;/h2&gt;&lt;p&gt;You can run a surprisingly capable model completely offline, even on very modest hardware.&#10;The current sweet spot is &lt;strong&gt;Google’s Gemma 2 2B&lt;/strong&gt; — it’s tiny (~1.4 GB), runs great on CPU, and works perfectly even with just 4–6 GB of RAM free.&lt;/p&gt;&#10;&lt;h3 id="step-1-install-ollama"&gt;Step 1: Install Ollama&#10;&lt;/h3&gt;&lt;p&gt;Download and install Ollama from the official site: &lt;a class="link" href="https://ollama.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://ollama.com&lt;/a&gt;&#10;(It has native packages for Windows, macOS, and Linux.)&lt;/p&gt;&#10;&lt;h3 id="step-2-download-gemma-2-2b"&gt;Step 2: Download Gemma 2 2B&#10;&lt;/h3&gt;&lt;p&gt;Open a terminal and run:&lt;/p&gt;&#10;&lt;div class="highlight"&gt;&lt;pre tabindex="0" style="color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span style="display:flex;"&gt;&lt;span&gt;ollama pull gemma2:2b&#10;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;(If you use Docker: docker exec -it ollama ollama pull gemma2:2b)&lt;/p&gt;&#10;&lt;h3 id="step-3-verify-its-running"&gt;Step 3: Verify it’s running&#10;&lt;/h3&gt;&lt;p&gt;Open &lt;a class="link" href="http://localhost:11434/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;http://localhost:11434&lt;/a&gt; in your browser.&#10;You should see “Ollama is running” — that’s all you need.&lt;/p&gt;&#10;&lt;h3 id="step-4-add-the-model-to-brave-leo"&gt;Step 4: Add the model to Brave Leo&#10;&lt;/h3&gt;&lt;ol&gt;&#10;&lt;li&gt;Open Brave → Settings → Leo&lt;/li&gt;&#10;&lt;li&gt;Click &lt;strong&gt;Add new model&lt;/strong&gt;&lt;/li&gt;&#10;&lt;li&gt;Fill in the details exactly like this:&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Label&lt;/strong&gt; → anything you want (e.g., “Gemma 2 2B Local”)&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Model Request Name&lt;/strong&gt; → gemma2:2b&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Server Endpoint&lt;/strong&gt; → http://localhost:11434/v1/chat/completions&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;API Key&lt;/strong&gt; → leave empty&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;(Optional but recommended) Set this model as your &lt;strong&gt;default&lt;/strong&gt; for new chats.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;Done! You now have a fully private, offline AI inside Brave that uses almost no resources.&lt;/p&gt;&#10;&lt;h2 id="method-2--smarter-answers-cloud-use-cryptotalksai-pay-as-you-go-no-subscription"&gt;Method 2 – Smarter Answers (Cloud): Use CryptoTalks.ai (Pay-as-you-go, No Subscription)&#10;&lt;/h2&gt;&lt;p&gt;If you want access to the absolute best models (GPT-4o, Claude 3.5 Sonnet, Gemini 1.5 Flash, Llama 3.1 405B, etc.) without creating accounts at OpenAI/Anthropic/Google, CryptoTalks.ai is currently the best option.&#10;You pay only for what you use and can fund the account with Bitcoin or Lightning.&lt;/p&gt;&#10;&lt;h3 id="step-1-create-an-account--get-your-token"&gt;Step 1: Create an account &amp;amp; get your token&#10;&lt;/h3&gt;&lt;p&gt;Go to &lt;a class="link" href="https://cryptotalks.ai/signup?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://cryptotalks.ai/signup&lt;/a&gt; → sign up → copy your API token (keep it safe!).&lt;/p&gt;&#10;&lt;h3 id="step-2-add-a-tiny-amount-of-credit"&gt;Step 2: Add a tiny amount of credit&#10;&lt;/h3&gt;&lt;p&gt;Deposit any amount via Bitcoin or Lightning. Even $1–2 lasts a very long time for personal use.&lt;/p&gt;&#10;&lt;h3 id="step-3-add-the-models-to-brave-leo"&gt;Step 3: Add the model(s) to Brave Leo&#10;&lt;/h3&gt;&lt;p&gt;Same process as before, just different values:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;&lt;strong&gt;Label&lt;/strong&gt; → e.g., “Claude 3.5 Sonnet”, “GPT-4o”, etc.&lt;/p&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;&lt;strong&gt;Model Request Name&lt;/strong&gt; → exact model ID from their docs, examples:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;openai/chatgpt-4o-latest&lt;/li&gt;&#10;&lt;li&gt;anthropic/claude-3.5-sonnet&lt;/li&gt;&#10;&lt;li&gt;google/gemini-flash-1.5&lt;/li&gt;&#10;&lt;li&gt;meta-llama/llama-3.1-405b-instruct&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;&lt;strong&gt;Server Endpoint&lt;/strong&gt; → &lt;a class="link" href="https://cryptotalks.ai/v1/chat/completions/" target="_blank" rel="noopener"&#10; &gt;https://cryptotalks.ai/v1/chat/completions/&lt;/a&gt;&lt;/p&gt;&#10;&lt;/li&gt;&#10;&lt;li&gt;&#10;&lt;p&gt;&lt;strong&gt;API Key&lt;/strong&gt; → paste your token&lt;/p&gt;&#10;&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;You can add as many models as you want and switch between them instantly in the Leo sidebar.&lt;/p&gt;&#10;&lt;p&gt;Pro tip: Check current model rankings at &lt;a class="link" href="https://artificialanalysis.ai/models?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://artificialanalysis.ai/models&lt;/a&gt; to pick the best one for your needs.&lt;/p&gt;&#10;&lt;h2 id="real-world-use"&gt;Real-World Use&#10;&lt;/h2&gt;&lt;p&gt;With Leo + your own model you can:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Summarize long articles or YouTube videos in one click&lt;/li&gt;&#10;&lt;li&gt;Explain complex code snippets&lt;/li&gt;&#10;&lt;li&gt;Draft emails or messages&lt;/li&gt;&#10;&lt;li&gt;Translate on the fly&lt;/li&gt;&#10;&lt;li&gt;All without ever leaving the browser and without sending data to big tech&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;When I’m on battery and want zero extra power draw → I switch to the local Gemma 2 2B.&#10;When I need maximum intelligence → I switch to Claude 3.5 Sonnet or GPT-4o via CryptoTalks.&lt;/p&gt;&#10;&lt;h2 id="conclusion"&gt;Conclusion&#10;&lt;/h2&gt;&lt;p&gt;Brave just turned every browser into a private, customizable AI workstation.&#10;Pick Method 1 for 100% privacy and zero cost, or Method 2 when you want the absolute best answers available today.&lt;/p&gt;&#10;&lt;p&gt;Either way — welcome to the future of browsing.&lt;/p&gt;&#10;&lt;p&gt;Thanks for reading! 😊&lt;/p&gt;&#10;</description></item><item><title>Page Cache, Object Cache and CDN cache - Understanding all types of caching</title><link>https://aquasp.blog/page-cache-object-cache-and-cdn-cache-understanding-all-types-of-caching/</link><pubDate>Mon, 08 Dec 2025 23:13:04 +0000</pubDate><guid>https://aquasp.blog/page-cache-object-cache-and-cdn-cache-understanding-all-types-of-caching/</guid><description>&lt;hr&gt;&#10;&lt;h2 id="understanding-the-different-types-of-caching-especially-for-scaling-cms-sites"&gt;Understanding the Different Types of Caching (Especially for Scaling CMS Sites)&#10;&lt;/h2&gt;&lt;p&gt;If you’ve ever wondered what people mean when they talk about “page cache,” “object cache,” or “CDN cache,” this post is for you. These are the three main caching layers that make a massive difference when scaling WordPress, WooCommerce, or any other CMS.&lt;/p&gt;&#10;&lt;h2 id="what-is-page-caching"&gt;What is Page Caching?&#10;&lt;/h2&gt;&lt;p&gt;Page caching (also called &lt;strong&gt;full-page caching&lt;/strong&gt; or &lt;strong&gt;HTML caching&lt;/strong&gt;) is exactly what it sounds like: the entire rendered HTML page is saved as a static file.&lt;/p&gt;&#10;&lt;p&gt;With a truly static site (plain HTML + CSS + JS), there’s no need for page caching because every file is already static.&#10;But with a CMS like WordPress, every request normally triggers PHP → theme → plugins → database queries → HTML output. That process eats CPU and takes time.&lt;/p&gt;&#10;&lt;p&gt;Full-page caching shortcuts all of that. The first visitor triggers the full PHP+MySQL process, the resulting HTML is saved, and every visitor after that gets served the pre-generated static HTML instantly — no PHP, no database queries, almost zero CPU.&lt;/p&gt;&#10;&lt;p&gt;Result: 10–100× lower server load and dramatically faster page loads.&lt;/p&gt;&#10;&lt;h2 id="what-is-object-caching"&gt;What is Object Caching?&#10;&lt;/h2&gt;&lt;p&gt;Object caching stores the results of expensive database queries (or any slow computation) in fast memory (usually Redis or Memcached).&lt;/p&gt;&#10;&lt;p&gt;Think of it as a super-fast middleman between your PHP code and the database.&lt;/p&gt;&#10;&lt;p&gt;Example with WordPress:&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;WordPress needs the list of published posts → it asks MySQL.&lt;/li&gt;&#10;&lt;li&gt;First request: MySQL does the work, returns the data, object cache saves it in RAM.&lt;/li&gt;&#10;&lt;li&gt;Next 10 000 requests: object cache instantly returns the same data from memory → MySQL sleeps peacefully.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;Object cache is smart — it automatically invalidates itself when data changes (e.g., you publish a new post).&lt;/p&gt;&#10;&lt;p&gt;Why you still need it even with full-page caching:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Logged-in users (including the WordPress dashboard, WooCommerce account pages, etc.) can’t be fully cached for everyone.&lt;/li&gt;&#10;&lt;li&gt;Those pages still hit PHP and MySQL → object cache makes them tolerable instead of painfully slow.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Object cache + full-page cache together is the classic high-traffic combo.&lt;/p&gt;&#10;&lt;h2 id="what-is-cdn-caching"&gt;What is CDN Caching?&#10;&lt;/h2&gt;&lt;p&gt;A CDN (Content Delivery Network) copies your static assets (CSS, JS, images, fonts) — and optionally your full HTML pages — to “PoP” servers all over the world.&lt;/p&gt;&#10;&lt;p&gt;Without a CDN: a visitor in Japan downloads everything from your origin server in, say, Brazil → high latency.&lt;/p&gt;&#10;&lt;p&gt;With a CDN:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Static files are served from the closest PoP (often &amp;lt; 30 ms away).&lt;/li&gt;&#10;&lt;li&gt;If you also enable full-page caching on the CDN, the entire HTML page is served from that nearby PoP too → the origin server is never touched for cached pages.&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;This is why some sites load instantly from anywhere on the planet.&lt;/p&gt;&#10;&lt;h2 id="real-world-example-wordpress-traffic-flow"&gt;Real-World Example: WordPress Traffic Flow&#10;&lt;/h2&gt;&lt;h3 id="no-caching-at-all"&gt;No caching at all&#10;&lt;/h3&gt;&lt;p&gt;Visitor → Web server → PHP → dozens of plugin files → MySQL queries → HTML → visitor&#10;→ High CPU, slow TTFB, easily hits resource limits.&lt;/p&gt;&#10;&lt;h3 id="with-full-page-caching-only"&gt;With full-page caching only&#10;&lt;/h3&gt;&lt;p&gt;First visitor: same slow path as above (but the HTML is saved).&#10;Next 10 000 visitors: Web server instantly serves the pre-built HTML → almost zero CPU.&lt;/p&gt;&#10;&lt;h3 id="with-object-caching-only"&gt;With object caching only&#10;&lt;/h3&gt;&lt;p&gt;Every request still runs PHP + plugins, but database queries are answered from RAM instead of disk → faster than no cache, but still heavy.&lt;/p&gt;&#10;&lt;h3 id="with-full-page-cache--object-cache"&gt;With full-page cache + object cache&#10;&lt;/h3&gt;&lt;ul&gt;&#10;&lt;li&gt;Anonymous visitors → static HTML (super fast, almost no load)&lt;/li&gt;&#10;&lt;li&gt;Logged-in users → PHP runs, but object cache makes DB queries instant → manageable load&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h3 id="add-cdn-with-full-page-caching-on-top"&gt;Add CDN with full-page caching on top&#10;&lt;/h3&gt;&lt;p&gt;Even the static HTML is now served from edge locations worldwide. Your origin server can basically take a nap until something actually needs PHP (e.g., form submissions, cache invalidation).&lt;/p&gt;&#10;&lt;h2 id="conclusion"&gt;Conclusion&#10;&lt;/h2&gt;&lt;p&gt;Here’s the hierarchy from most impactful to least (for most CMS sites):&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;&lt;strong&gt;Full-page caching on the CDN&lt;/strong&gt; → fastest for visitors, scales to millions of hits with almost zero origin load.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Full-page caching on the origin&lt;/strong&gt; → still massive win if you can’t cache on the CDN.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Object caching (Redis/Memcached)&lt;/strong&gt; → mandatory for logged-in users, WooCommerce, dashboards, etc.&lt;/li&gt;&#10;&lt;li&gt;Everything else (OPcache, browser cache, etc.) → nice to have, usually enabled by default.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;p&gt;If you only do one thing: enable proper full-page caching (and push it to your CDN if possible).&#10;If you have logged-in traffic or a shop: add Redis/Memcached object caching.&lt;/p&gt;&#10;&lt;p&gt;That’s it — the three caching layers that power basically every high-traffic WordPress site on the planet.&lt;/p&gt;&#10;&lt;p&gt;Hope this cleared things up!&lt;/p&gt;&#10;&lt;p&gt;Thanks for reading! 😊&lt;/p&gt;&#10;</description></item><item><title>Pop!_OS 22.04 review after 6 months of use</title><link>https://aquasp.blog/pop-os-22-04-review-after-6-months-of-use/</link><pubDate>Mon, 08 Dec 2025 22:28:25 +0000</pubDate><guid>https://aquasp.blog/pop-os-22-04-review-after-6-months-of-use/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;Pop!_OS&lt;/strong&gt; is one of the most used Linux Distros. It&amp;rsquo;s also a recommendation for beginners, gamers and even experienced users.&lt;/p&gt;&#10;&lt;p&gt;But is it worthy it? In today&amp;rsquo;s post I will write about my experience using it, from the installation to the day-to-day usage.&lt;/p&gt;&#10;&lt;h2 id="installation"&gt;Installation&#10;&lt;/h2&gt;&lt;p&gt;Pop have one of the best installers there, I must admit. It&amp;rsquo;s simple, beautiful and feels modern. The installation is pretty simple, you can just click in a few buttons to setup language and a few other options. It&amp;rsquo;s also possible to encrypt the disk during the installation, which helps if you travel a lot and contain confidential information inside your laptop (like personal passwords, documents, photos, etc).&lt;/p&gt;&#10;&lt;p&gt;For the installation process, I will rate Pop 9/10. Why not 10? Well, it doesn&amp;rsquo;t contain a option to dual boot automatically. You need to do it manually if you are using Windows for example. Other than that, it works really well and does a great job to provide you a nice experience.&lt;/p&gt;&#10;&lt;h2 id="first-boot"&gt;First boot&#10;&lt;/h2&gt;&lt;p&gt;Pop first boot is also a great experience. You will be able to create your user and password and login normally at your new Gnome environment. Pop helps you to customize a few options (dark mode, docker location and online accounts). Those are all great options for beginners.&lt;/p&gt;&#10;&lt;p&gt;The default apps are also well integrated with the system and everything feels just in place.&lt;/p&gt;&#10;&lt;p&gt;Overall, I hate the post installation as 10/10, I don&amp;rsquo;t see anything to improve here, they just did great.&lt;/p&gt;&#10;&lt;h2 id="details-that-makes-pop_"&gt;&lt;strong&gt;Details that makes Pop!_OS special&lt;/strong&gt;&#10;&lt;/h2&gt;&lt;p&gt;Probably this is the best part of Pop, that makes it a really really solid choice. These are some characteristics that are &lt;strong&gt;rare&lt;/strong&gt; to find in other Distros:&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;&lt;a class="link" href="https://github.com/pop-os/system76-scheduler?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;System76 Scheduler&lt;/a&gt; - Did you konow that Pop contains CPU optimizations by default? Yep, that is right. By defualt, Pop will reduce the latency and improve performance on apps, specially when the laptop is charging. This is also great for gaming, since you don&amp;rsquo;t need &lt;a class="link" href="https://github.com/FeralInteractive/gamemode?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;gamemode&lt;/a&gt; anymore.&lt;/li&gt;&#10;&lt;li&gt;&lt;a class="link" href="https://github.com/pop-os/system76-power?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;System76-Power&lt;/a&gt; - By default, Pop provides three options for your Battery: Economy, Balanced and high performance. That is amazing because under pop, battery optmimizations are already applied by default. You don&amp;rsquo;t need TLP and you have a easy GUI to control the battery mode. That is just awesome.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Swappiness is set to 10&lt;/strong&gt;. On most linux distros that I&amp;rsquo;ve ever used, swappiness is set to 60. This means that your Distro will start to use swap when ram usage reaches 40%. On Pop, swap will only be used when you use abour 90% of your ram. That feels amazing and much smoother since swap is really slow, even on a NVME ssd.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Kernel isn&amp;rsquo;t the same of Ubuntu 22.04&lt;/strong&gt;. Pop does a great job on keeping the kernel updated. This is great specially if you are using a newer desktop/laptop. As far as I know, Ubuntu 22.04 is serving Kernel 5.15.x. Pop os already on 6.1.x&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Custom shortcuts.&lt;/strong&gt; At first, I hated it, but after trying the &amp;ldquo;pop way&amp;rdquo;, I loved it and I actually change other distros to their defaults on shortcuts! For example, instead of alt + f4 (which usually requires 2 hands), Pop uses &amp;ldquo;windows + q&amp;rdquo; which is more accessible and easier to use. Instead of ctrl + alt + t for the terminal, you can use &amp;ldquo;windows + t&amp;rdquo; on Pop. This is really great and helps when you are working with a lot of multitasking (pretty much anyone who works with CS will love it).&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Easy Firmware updates.&lt;/strong&gt; Pop comes with a option inside gnome settings to make hardware updates. That is really great because it gives you more controls and details on these upgrades.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Recovery as a option.&lt;/strong&gt; On pop, you can have a &amp;ldquo;copy of the ISO&amp;rdquo; in the settings and &amp;ldquo;refresh the OS&amp;rdquo; if you ever need it. It may be useful if you broke something and want to restore the system without using a USB stick.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;SystemD boost instead of Grub.&lt;/strong&gt; This doesn&amp;rsquo;t makes difference for me, but a lot of people seems to praise systemdboot. I think it provides a faster boot time and it&amp;rsquo;s &amp;ldquo;simpler to setup&amp;rdquo; (I&amp;rsquo;m used to grub, so grub is easier for me, but I barely customize anything on the boot)&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Pipewire instead of Pulseaudio.&lt;/strong&gt; For years one of the softwares that people used to complain a lot about was Pulseaudio. It used to lag, crash, do not recognize devices, etc. Pipewire is the new guy that is leaner and has a lower latency. A lot of people praise it too. For much, I prefer Pipewire too as it just feels simpler and better to use than Pulseaudio.&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Flatpak theming right and not Snap&lt;/strong&gt;. Snaps are being &amp;ldquo;forced&amp;rdquo; by Ubuntu distros, but a lot of people dislike them. Some dislike about the server not being open source, some complain about the bugs, space used some complain about auto updates (which can&amp;rsquo;t be turned off). For me, I also prefer Flatpaks, and it&amp;rsquo;s great to see that on Pop Flatpaks looks like native applications and flathub is Added by default. It&amp;rsquo;s also nice to see that Pop_Shop integrates well with Flatpaks.&lt;/li&gt;&#10;&lt;li&gt;&lt;a class="link" href="https://github.com/pop-os/popsicle?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;&lt;strong&gt;Pop created popsicle&lt;/strong&gt;&lt;/a&gt;&lt;strong&gt;.&lt;/strong&gt; This probably doesn&amp;rsquo;t get enough attention, but man! It&amp;rsquo;s WONDERFUL to have a iso flasher by default. And this one is so beautiful and integrates well with Pop. I like it more than Balena Etcher and other common software used on linux to create bootable sticks.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;h2 id="pop-downsides"&gt;Pop downsides&#10;&lt;/h2&gt;&lt;p&gt;Although Pop is amazing, I see a few downsides on it as well. Most of them are personal, so you may not actually see them as downsides.&lt;/p&gt;&#10;&lt;ol&gt;&#10;&lt;li&gt;Gnome. I just don&amp;rsquo;t like gnome at all. Feels heavy and changes all the time with major updates, breaking plugins and the user experience. The good part is that Pop is developing their own rust DE, which will be &lt;strong&gt;HOT&lt;/strong&gt; when it releases.&lt;/li&gt;&#10;&lt;li&gt;Pop_Shop uses 0.5GB of ram when idle. That may not be a issue for computers with more ram, but when you have less, that is kinda bad. If you have 4GB of ram for example (that is still common on third world countries) you will feel the difference. You can disable pop shop, but honestly the usage in idle should be lower.&lt;/li&gt;&#10;&lt;li&gt;tracker-miner-fs can suck your CPU if you download folders that contains a lot of subdfolders. Once I downloaded a WordPress site backup and extracted it. It had a lot of subfolders. I did notice my laptop slower, but I didn&amp;rsquo;t know what was happening. When I checked the task manage, tracker miner was acting and sucking all the CPU trying to index that subfolder. I tried to reset tracker miner, clean, see the status but it wasn&amp;rsquo;t replying. In the end, I disabled it as a &lt;a class="link" href="https://www.reddit.com/r/pop_os/comments/10q046k/trackerminerfs3_is_killing_my_performance/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;pop developer said it was 100% safe&lt;/a&gt;.&lt;/li&gt;&#10;&lt;/ol&gt;&#10;&lt;h2 id="performance-overall-after-6-months"&gt;Performance overall after 6 months&#10;&lt;/h2&gt;&lt;p&gt;After 6 months using Pop, I can say that I was quite satisfied with the performance. I had a issue while for a few seconds mouse was slow and audio was freezing, but that is probably due to something I did (or maybe due to my hardware not being able to handle encryption well. I&amp;rsquo;m on a 12GB ram Ryzen 5 5500U laptop with NVME ssd of 256GB).&lt;/p&gt;&#10;&lt;p&gt;Due to the issues with tracker miner and this freezing issue, I decided to leave Pop and try Linux Mint XFCE for a while (I love XFCE and Mint is stable enough, so I decided to give it a try). I will probably review it after using it for a while as well.&lt;/p&gt;&#10;&lt;p&gt;Overall, using pop was a pleasure and I could do a bunch of great work on it. I work as CS/Devops, so most of the time I was chatting with customers or using bash scripts on the server, and for that Pop worked fine. For gaming it also worked well so I&amp;rsquo;m not complaining and I definitely would recommend it for most people. Pop &lt;strong&gt;has the best defaults that I&amp;rsquo;ve ever seen&lt;/strong&gt;. It&amp;rsquo;s the distro that I tweaked less, because it comes with everything that I need and use.&lt;/p&gt;&#10;&lt;h2 id="conclusion"&gt;Conclusion&#10;&lt;/h2&gt;&lt;p&gt;Pop is awesome! If you like gnome, give it a try. It will give you a great performance and all optimizations that matters are there out of the box. Battery will be nice on laptops and drivers will probably be optimized for gaming. Vulkan is also enabled by default.&lt;/p&gt;&#10;&lt;p&gt;My dad is using Pop on his laptop (I installed it) and he loves it.&lt;/p&gt;&#10;&lt;p&gt;I will definitely try Pop again once they release their new DE. In the meanwhile, I will enjoy my XFCE experience.&lt;/p&gt;&#10;&lt;p&gt;Thank you for reading :)&lt;/p&gt;&#10;</description></item><item><title>Top 7 things you should do after installing Xubuntu 22.04</title><link>https://aquasp.blog/top-7-things-that-you-should-do-after-installing-xubuntu-22-04/</link><pubDate>Mon, 08 Dec 2025 22:24:22 +0000</pubDate><guid>https://aquasp.blog/top-7-things-that-you-should-do-after-installing-xubuntu-22-04/</guid><description>&lt;h2 id="introduction"&gt;Introduction&#10;&lt;/h2&gt;&lt;p&gt;I recently reviewed Pop!_OS 22.04 after using it for a long time. I loved it, but I wanted to try something else long-term and ended up choosing Ubuntu 22.04 — specifically the Xubuntu flavor with XFCE.&lt;/p&gt;&#10;&lt;p&gt;Whenever I install a fresh OS, there are a few things I always do to make sure the system feels snappy, performs well in games, and (on laptops) gets the best possible battery life.&lt;/p&gt;&#10;&lt;p&gt;Before starting any of the steps below, I strongly recommend &lt;strong&gt;doing a full system upgrade&lt;/strong&gt;&lt;/p&gt;&#10;&lt;h2 id="install-the-liquorix-kernel"&gt;Install the Liquorix Kernel&#10;&lt;/h2&gt;&lt;p&gt;Liquorix is an enthusiast Linux kernel optimized for desktop responsiveness, low-latency audio/video work, and reduced frame-time jitter in games.&lt;/p&gt;&#10;&lt;p&gt;The stock Ubuntu kernel is a general-purpose kernel that has to work well on both desktops and servers. Liquorix takes the same Linux kernel source and applies desktop-focused patches and build options. The result feels noticeably snappier, especially under heavy load or when alt-tabbing quickly in games.&lt;/p&gt;&#10;&lt;p&gt;Installing it on Ubuntu/Debian is one command:&lt;/p&gt;&#10;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;curl &amp;#39;https://liquorix.net/install-liquorix.sh&amp;#39; | sudo bash&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reboot afterward and you’ll be running the new kernel.&lt;/p&gt;&#10;&lt;h2 id="add-the-latest-graphics-drivers"&gt;Add the Latest Graphics Drivers&#10;&lt;/h2&gt;&lt;p&gt;&lt;strong&gt;For Nvidia users:&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo add-apt-repository ppa:graphics-drivers/ppa&#10;sudo dpkg --add-architecture i386&#10;sudo apt update&#10;sudo apt install -y nvidia-driver-560 libvulkan1 libvulkan1:i386&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;&lt;strong&gt;For AMD or Intel users (Kisak’s PPA – latest Mesa):&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo add-apt-repository ppa:kisak/kisak-mesa&#10;sudo dpkg --add-architecture i386&#10;sudo apt update &amp;amp;&amp;amp; sudo apt upgrade&#10;sudo apt install libgl1-mesa-dri:i386 mesa-vulkan-drivers mesa-vulkan-drivers:i386&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Even on an older LTS release, this gives you the newest open-source drivers and Vulkan support.&lt;/p&gt;&#10;&lt;h2 id="lower-swappiness"&gt;Lower Swappiness&#10;&lt;/h2&gt;&lt;p&gt;Pop!_OS sets vm.swappiness=10 by default (swap is only used when RAM is ~90% full). Ubuntu/Xubuntu defaults to 60, which is far too aggressive for desktop use.&lt;/p&gt;&#10;&lt;p&gt;Change it permanently:&lt;/p&gt;&#10;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo nano /etc/sysctl.conf&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Add this line at the end:&lt;/p&gt;&#10;&lt;p&gt;text&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;vm.swappiness=10&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Save and exit. The change applies immediately or on next reboot.&lt;/p&gt;&#10;&lt;h2 id="install-essential-utilities"&gt;Install Essential Utilities&#10;&lt;/h2&gt;&lt;p&gt;These are the tools I install on every fresh setup:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;&lt;strong&gt;Redshift&lt;/strong&gt; – blue-light filter&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Flameshot&lt;/strong&gt; – best screenshot tool&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;AppImageLauncher&lt;/strong&gt; – integrates AppImages into your menu&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;Gamemode&lt;/strong&gt; – massive FPS improvements in many games&lt;/li&gt;&#10;&lt;li&gt;&lt;strong&gt;TLP&lt;/strong&gt; – essential for laptops (often doubles battery life)&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;sudo apt install redshift flameshot appimagelauncher gamemode tlp tlp-rdw&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;(Enable TLP if needed: sudo tlp start)&lt;/p&gt;&#10;&lt;h2 id="install-your-favorite-everyday-apps"&gt;Install Your Favorite Everyday Apps&#10;&lt;/h2&gt;&lt;p&gt;My personal picks:&lt;/p&gt;&#10;&lt;ul&gt;&#10;&lt;li&gt;Brave Browser (privacy-focused Chromium)&lt;/li&gt;&#10;&lt;li&gt;VLC (preferably via AppImage/Flatpak/Snap to avoid heavy Qt dependencies on XFCE)&lt;/li&gt;&#10;&lt;li&gt;LibreOffice&lt;/li&gt;&#10;&lt;/ul&gt;&#10;&lt;h2 id="create-handy-aliases"&gt;Create Handy Aliases&#10;&lt;/h2&gt;&lt;p&gt;Open your .bashrc:&lt;/p&gt;&#10;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;nano ~/.bashrc&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Add some useful aliases at the bottom, for example:&lt;/p&gt;&#10;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;alias apply_filter=&amp;#39;redshift -O 1900&amp;#39;&#10;alias update=&amp;#39;sudo apt update &amp;amp;&amp;amp; sudo apt upgrade -y&amp;#39;&#10;alias please=&amp;#39;sudo $(history -p !!)&amp;#39; # rerun last command with sudo&#10;&lt;/code&gt;&lt;/pre&gt;&lt;p&gt;Reload the file:&lt;/p&gt;&#10;&lt;p&gt;Bash&lt;/p&gt;&#10;&lt;pre tabindex="0"&gt;&lt;code&gt;source ~/.bashrc&#10;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id="customize-the-look--feel-optional"&gt;Customize the Look &amp;amp; Feel (Optional)&#10;&lt;/h2&gt;&lt;p&gt;Xubuntu + XFCE is extremely customizable. I run a very minimal setup and control almost everything with keyboard shortcuts. You can configure them in &lt;strong&gt;Settings → Window Manager&lt;/strong&gt; and &lt;strong&gt;Settings → Keyboard → Application Shortcuts&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;h2 id="conclusion"&gt;Conclusion&#10;&lt;/h2&gt;&lt;p&gt;The three biggest performance wins — Liquorix kernel, latest graphics drivers, and low swappiness — make a dramatic difference. Real-world example: &lt;em&gt;Life is Strange: True Colors&lt;/em&gt; jumped from ~23 FPS with stuttering on stock settings to a smooth 40+ FPS after applying these changes.&lt;/p&gt;&#10;&lt;p&gt;If you’re getting random lags or freezes on Xubuntu/Ubuntu, try these steps first. They solve a surprising number of issues.&lt;/p&gt;&#10;&lt;p&gt;Thanks for reading!&lt;/p&gt;&#10;</description></item><item><title>Zcash is losing</title><link>https://aquasp.blog/zcash-is-losing/</link><pubDate>Mon, 08 Dec 2025 22:11:49 +0000</pubDate><guid>https://aquasp.blog/zcash-is-losing/</guid><description>&lt;hr&gt;&#10;&lt;h2 id="zcash-is-not-the-most-important-project-in-the-world-and-it-is-losing"&gt;Zcash is NOT the most important project in the world, and it is losing.&#10;&lt;/h2&gt;&lt;p&gt;Zcash was born as a project to fix Bitcoin&amp;rsquo;s major flaw: privacy. But launching a new coin isn&amp;rsquo;t easy, and it&amp;rsquo;s not just about technical aspects.&lt;/p&gt;&#10;&lt;p&gt;A serious cryptocurrency is supposed to be money, and it needs to be better than what we currently have with governments; otherwise, we should keep using the dollar. This means that while the technical aspects of any cryptocurrency are important, it should also be reliable, trustworthy, and as stable as possible. The main flaw in government money is inflation. Governments typically love to spend money and can charge a hidden tax by printing it. When money is printed, the amount of goods and services in society remains the same, but there is more money in circulation.&lt;/p&gt;&#10;&lt;p&gt;This means your money will now have reduced value. The winner in this case is the government or whoever spends the newly printed money first, because the market will adjust itself, leading to higher prices for services and goods.&lt;/p&gt;&#10;&lt;h3 id="the-issue-with-zcash"&gt;The issue with Zcash&#10;&lt;/h3&gt;&lt;p&gt;Zcash sounds good. It deploys zk-SNARKs technology to prove transactions and store them privately, meaning that when you send transactions, everything is hidden (so no one can see the sender, the amount sent, or the receiver). Sounds amazing, right? Let&amp;rsquo;s buy Zcash then!!&lt;/p&gt;&#10;&lt;p&gt;No. And why not?&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;1. Zcash was launched with a trusted setup&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;Yes, that&amp;rsquo;s right. When Zcash launched, it utilized a trusted setup to bootstrap the network. In this event, multiple participants collaboratively created cryptographic parameters without any single party having full control. This assumed that at least one participant destroyed their portion of the secret keys to guarantee privacy. &lt;strong&gt;If participants united their parameters, they could, in theory, create unlimited Zcash and trace shielded transactions&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;p&gt;Now, I have to be fair. Zcash is currently running on NU5 (Network Upgrade 5). This upgrade &lt;strong&gt;removed the trusted setup, ensuring that after May 2022, Zcash does not depend on trusting anyone else&lt;/strong&gt;.&lt;/p&gt;&#10;&lt;p&gt;But at the same time, as far as I know, &lt;strong&gt;there is no way to prove that everyone destroyed their parameters and that no Zcash was generated or traced.&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;2. Zcash is not private by default.&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;Considering the latest updates (not using &lt;strong&gt;Sprout&lt;/strong&gt; or &lt;strong&gt;Sapling&lt;/strong&gt;), users can leave Zcash in a public address (t-address) or a shielded address (&lt;strong&gt;Orchard&lt;/strong&gt;, ideally). So if some users want to use Zcash just like Bitcoin, they can.&lt;/p&gt;&#10;&lt;p&gt;Zcash aims to fix this by recommending privacy-friendly wallets. For example, Zashi wallet tries to shield your funds by default. The issue with this? Zcash is not widely used, so buying Zcash peer-to-peer or from a decentralized exchange like Bisq or Haveno Reto is very hard.&lt;/p&gt;&#10;&lt;p&gt;So you have to buy it from a non-privacy-friendly exchange like Binance or Coinbase. And of course, these exchanges do not support shielded addresses. You need to use your transparent address to receive your Zcash before shielding it.&lt;/p&gt;&#10;&lt;p&gt;Zcash somehow believes it can provide full privacy while complying with governments and anti-privacy laws. Zcash community and users are accustomed to buying their coins through non-private means. If the government decides that shielding your Zcash is illegal, you will not be able to buy and shield your coins because the government knows the t-address is related to you, and if you make a shielding transaction, you&amp;rsquo;ve just committed a crime.&lt;/p&gt;&#10;&lt;p&gt;They can even block &amp;ldquo;tainted&amp;rdquo; coins, so if a Zcash was ever shielded, it can be considered &amp;ldquo;tainted&amp;rdquo; and blocked on exchanges. During the Canada convoy protest, the government tried to seize Bitcoin, but since the wallet was non-custodial, they couldn&amp;rsquo;t. They quickly realized they could ask all exchanges to refuse those &amp;ldquo;dirty&amp;rdquo; Bitcoins.&lt;/p&gt;&#10;&lt;p&gt;Now you may be wondering how Monero is any different. Well, Monero is private by default, meaning users don&amp;rsquo;t have to worry about shielding and &amp;ldquo;unshielding&amp;rdquo; coins. And every shop that accepts Monero does so for privacy, unlike Zcash, where shoppers and exchanges can accept Zcash only on transparent addresses.&lt;/p&gt;&#10;&lt;p&gt;And yes, as you may have thought, some governments and exchanges have banned Monero, which was actually good for Monero. Why? Because it is now miles ahead of Zcash. Monero has an actual ecosystem. You can buy goods and services directly with Monero, you can buy Monero without any exchanges, and Monero knows how to survive in an environment without legal approval.&lt;/p&gt;&#10;&lt;p&gt;For example, you can buy gift cards at &lt;a class="link" href="https://www.coinsbee.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Coinsbee&lt;/a&gt; or &lt;a class="link" href="https://cakepay.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Cake Pay&lt;/a&gt; directly with Monero, sell services and products for Monero directly at &lt;a class="link" href="https://xmrbazaar.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;XMRBazaar&lt;/a&gt;, find different kinds of services accepting Monero at &lt;a class="link" href="https://monerica.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Monerica&lt;/a&gt;, use AI privately with Monero at &lt;a class="link" href="https://nano-gpt.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;Nano-GPT&lt;/a&gt;, or trade Monero privately with no KYC at &lt;a class="link" href="https://retoswap.com/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;RetoSwap&lt;/a&gt;.&lt;/p&gt;&#10;&lt;p&gt;And this is just the beginning. Monero usage has been increasing, and the goal is to be able to live entirely with Monero to achieve financial freedom.&lt;/p&gt;&#10;&lt;p&gt;So, private by default is definitely the superior choice. Cash is private by default, just like Monero.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;3. Zcash is very centralized&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;Yep, that&amp;rsquo;s right. Perhaps you aren&amp;rsquo;t aware of this, but one mining pool of Zcash, ViaBTC, has &lt;a class="link" href="https://miningpoolstats.stream/zcash?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;nearly 70%&lt;/a&gt; of the mining power.&lt;/p&gt;&#10;&lt;p&gt;This means that if ViaBTC starts to act maliciously, they could, in theory, double-spend ZEC or censor transactions.&lt;/p&gt;&#10;&lt;p&gt;Zcash has a plan to fix that, but for now, it&amp;rsquo;s a promise and not something live. They want to create a PoS layer (proof-of-stake) to ensure users have more control over transaction validation.&lt;/p&gt;&#10;&lt;p&gt;I don&amp;rsquo;t have a specific opinion about this PoS layer yet, so I will refrain from talking about it.&lt;/p&gt;&#10;&lt;p&gt;The point remains valid, though: Zcash is very centralized. And not only due to the mining pool. We can clearly see that the community on Reddit is not very active; you don&amp;rsquo;t see people promoting and running Zcash nodes as you do in the Monero community. The community groups are typically made up of Zcash-related institutions.&lt;/p&gt;&#10;&lt;p&gt;Zcash has to put effort into marketing and convincing people to use it, while Monero has natural adoption, and users spread the word for free. There are several community-based sites, podcasts, and you can actually see people using it instead of just buying it and hoping for a massive price increase.&lt;/p&gt;&#10;&lt;p&gt;There are several guides on how to use a Monero wallet, how to run a node, how to spend it, etc. With Zcash, you typically have promises that &amp;ldquo;the technology is amazing and it will have more value than Bitcoin.&amp;rdquo;&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;4. Zcash has a developer tax&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;If you were proposing a global money to be used by everyone in the world, do you think it&amp;rsquo;s fair to allocate 20% of the mined money to pay for its development?&lt;/p&gt;&#10;&lt;p&gt;I don&amp;rsquo;t think so, and most people don&amp;rsquo;t think so. Zcash did exactly that. 20% of the mined coins go directly to Zcash institutions that are supposed to develop and market Zcash.&lt;/p&gt;&#10;&lt;p&gt;With this proposal, developers and the governance of the coin do not need to gain the trust of users. They are compensated by default and will obviously sell the Zcash for fiat since that is basically their salary, and they have bills to pay.&lt;/p&gt;&#10;&lt;p&gt;With that in mind, potential investors and users will always fear a massive dump in the cryptocurrency when prices spike.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;5. Zcash UX still sucks&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;Zcash is still somewhat complex for the average user. To fix that, the recommended way to use Zcash nowadays is with Zashi, which tries to shield transactions by default.&lt;/p&gt;&#10;&lt;p&gt;Zashi has some serious issues, though. The first issue is the language. Only English is supported. I mean, is that serious? The most recommended wallet only supports English? Is Zcash only meant to be used in America/UK? It&amp;rsquo;s a shame that a project with a development tax can&amp;rsquo;t make a multi-language wallet. Cake Wallet, Stack Wallet, and Monerujo didn&amp;rsquo;t have any development tax, but they support several languages. What is your excuse, Zashi?&lt;/p&gt;&#10;&lt;p&gt;The second issue is that Zashi doesn&amp;rsquo;t seem to be stable, especially with larger amounts of Zcash. Recently, a user reported that &lt;a class="link" href="https://x.com/0xakramus/status/1977322983829242320?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;he cannot spend his Zcash&lt;/a&gt;.&#10;That happens because Zashi only allows you to spend shielded Zcash, and the wallet is unable to shield his Zcash.&lt;/p&gt;&#10;&lt;p&gt;I know this isn&amp;rsquo;t specifically a skill issue because not long ago, when I was testing Zcash, I had a similar issue. I received Zcash on Zashi but was unable to shield it. I don&amp;rsquo;t remember exactly what I did to solve the issue (I was trying Ywallet and Nighthawk), but it definitely wasn&amp;rsquo;t a good first impression of Zcash. I remember testing receiving Zcash on an older phone vs. a newer phone (both using Zashi), and my newer phone was able to receive and shield the coins easily, but the older phone struggled.&lt;/p&gt;&#10;&lt;p&gt;I&amp;rsquo;m not sure if this was a coincidence, but it seemed that Zashi is heavy on your phone. I never had this issue with Monero before.&lt;/p&gt;&#10;&lt;p&gt;Sure, syncing Monero takes a while, but it works in the background seamlessly with Monerujo by just waiting. It runs even faster if you have a local Monero node running at your home, which I suspect 99% of Zcash users don&amp;rsquo;t have.&lt;/p&gt;&#10;&lt;p&gt;Right now, Zashi also needs to be synced to be properly used, and it takes a lot of time and requires you to leave your screen turned on.&lt;/p&gt;&#10;&lt;p&gt;Both coins need to be easier to use, but Monero is still better than Zcash for UI. Users don&amp;rsquo;t need to worry about Sapling or Orchard pools or have issues &amp;ldquo;shielding&amp;rdquo; their coins.&lt;/p&gt;&#10;&lt;p&gt;&lt;strong&gt;6. Price action&lt;/strong&gt;&lt;/p&gt;&#10;&lt;p&gt;Due to the trusted setup launch and the development tax, Zcash is likely destined to be a pump coin. With no real-world adoption, its price can be manipulated to rise, but such gains are unlikely to last.&lt;/p&gt;&#10;&lt;p&gt;Cryptocurrency enthusiasts are currently focused on Zcash due to a massive price pump, but I doubt this will sustain. If you zoom out the price graph for Zcash, it still looks ridiculous. In contrast, zooming out for Monero reveals steady and slow growth over time.&lt;/p&gt;&#10;&lt;h2 id="conclusion"&gt;Conclusion&#10;&lt;/h2&gt;&lt;p&gt;Zcash sucks. After studying it better, calling it Ztrash is the right thing to do. Doing otherwise is not honest.&lt;/p&gt;&#10;&lt;h2 id="credits"&gt;Credits&#10;&lt;/h2&gt;&lt;p&gt;&lt;a class="link" href="https://lukesmith.xyz/articles/monero-and-other-privacy-coins/?ref=aquasp.blog" target="_blank" rel="noopener"&#10; &gt;https://lukesmith.xyz/articles/monero-and-other-privacy-coins/&lt;/a&gt;&lt;/p&gt;&#10;</description></item></channel></rss>