Step CA + ACME — Internal TLS Certificates for Your Homelab

Run your own internal Certificate Authority with step-ca in Docker, issue TLS certificates via ACME, integrate with Traefik for automatic renewal, and distribute the root CA to all your devices — no more self-signed certificate warnings.

May 22, 2026 · 9 min · 1899 words · GnTech

nginx-poolslip Zero-Day — NGINX RCE Vulnerability Guide for Homelabs

The nginx-poolslip zero-day RCE affects NGINX 1.31.0 with ASLR bypass. This guide covers version detection, risk assessment, practical mitigations for homelab setups, and a patch readiness plan.

May 22, 2026 · 7 min · 1309 words · GnTech

MikroTik Containers — Run Docker Images on RouterOS

Run Docker containers directly on MikroTik RouterOS 7 — enable container mode, configure veth bridges, pull images from Docker Hub, and deploy Pi-hole or AdGuard Home without extra hardware.

May 21, 2026 · 8 min · 1559 words · GnTech

Docker IPv6 Networking — Enable Dual-Stack in Your Homelab

Complete guide to enabling IPv6 in Docker — from daemon configuration and address pools to Compose networks, Traefik reverse proxy, and IPv6 firewall rules for your homelab.

May 21, 2026 · 10 min · 2028 words · GnTech

Nginx Docker Deployment — Reverse Proxy and Static Caching for Homelabs

Complete guide to deploying Nginx with Docker Compose as a reverse proxy and caching layer. Covers multi-service proxying, static file caching, gzip compression, SSL termination, and performance tuning for homelab environments.

May 20, 2026 · 10 min · 2121 words · GnTech

WireGuard Performance Tuning — Kernel sysctl and MTU Optimization

A practical guide to maximizing WireGuard throughput on Linux — covering kernel sysctl tuning, BBR congestion control, UDP buffer sizes, MTU/MSS clamping, NAPI polling optimization, and proper benchmarking with iperf3.

May 20, 2026 · 8 min · 1587 words · GnTech

MikroTik RouterOS 7 DNS Over HTTPS and Adlist — Block Ads Without Pi-Hole

Configure DNS over HTTPS and the built-in DNS Adlist feature on MikroTik RouterOS 7 to block ads, trackers, and malware network-wide — no Pi-hole, no extra hardware, no containers needed.

May 20, 2026 · 11 min · 2318 words · GnTech

Headscale — Self-Hosted Tailscale Mesh VPN Server with Docker Compose

Deploy Headscale with Docker Compose to run your own WireGuard mesh VPN control plane. Complete guide from setup to client registration, ACL configuration, subnet routing, and production hardening.

May 19, 2026 · 14 min · 2913 words · GnTech

Proxmox SDN — Centralized Virtual Networking for Homelab Clusters

Complete guide to Proxmox SDN — configure centralized virtual networks with VXLAN overlays, VNets, subnets, and integrated DHCP across your multi-node cluster.

May 19, 2026 · 9 min · 1906 words · GnTech

Traefik Middleware Security Hardening — Headers, Rate Limiting, and Auth

Complete guide to Traefik middleware security hardening with real-world configs — security headers, rate limiting, IP whitelisting, basic auth, redirect schemes, and chaining middlewares for an A+ security rating.

May 18, 2026 · 15 min · 3006 words · GnTech