<?xml version="1.0" encoding="utf-8" standalone="yes"?><?xml-stylesheet type="text/xsl" href="/pretty-feed-v3.xsl"?>
<rss
  version="2.0"
  xmlns:atom="http://www.w3.org/2005/Atom"
  xmlns:content="http://purl.org/rss/1.0/modules/content/"
  xmlns:source="https://source.scripting.com/"
>
  <channel>
    <title>Paul Tibbetts</title>
    <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/</link>
    <description>Posts by Paul Tibbetts published in 2025</description>
    <generator>Hugo</generator>
    <language>en-gb</language>
    <atom:link href="https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/feed.xml" rel="self" type="application/rss+xml" /><item>
      <title>Favourite Games of 2025</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/31/favourite-games-of-2025/</link>
      <pubDate>Wed, 31 Dec 2025 16:00:00 +0000</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/31/favourite-games-of-2025/</guid>
      <category>gaming</category>
      <description>Last year I wrote my own take on the Steam Awards , and in 2025 I played less games, so instead of pretending otherwise, this is a list of my favourites from this year.</description>
      <content:encoded><![CDATA[<p>Last year I wrote <a href="https://micro.paultibbetts.uk/2025/01/03/pc-games-i-liked-in.html">my own take on the Steam Awards</a>
, and in 2025 I played less games, so instead of pretending otherwise, this is a list of my favourites from this year.</p>
<h2 id="dispatch">Dispatch</h2>
<blockquote>
<p>Single-player story-driven narrative.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/2592160/Dispatch/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/2592160/header.jpg" alt="Dispatch hero image" title="Dispatch hero image">
</a>
</p>
<p>Dispatch might be <em>the</em> funniest game I&rsquo;ve ever played. It&rsquo;s extremely well written, absurdly well voice acted and expertly made by the team that used to be Telltale Games.</p>
<p>It gives a real glimpse into the life of a superhero dispatcher and kept me entertained the whole way through.</p>
<p>I&rsquo;ll be playing whatever <a href="https://www.adhocla.com/">Adhoc Studios</a>
 makes next. I hope it&rsquo;s Wolf Among Us 2 or another season of Dispatch. Either way, I&rsquo;m in.</p>
<p>It&rsquo;s rated <a href="https://www.protondb.com/app/2592160">Platinum</a>
 on ProtonDB, so it plays great on Linux.</p>
<p><a href="https://store.steampowered.com/app/2592160/Dispatch/">Steam</a>
</p>
<h2 id="arc-raiders">Arc Raiders</h2>
<blockquote>
<p>Third-person PvPvE extraction-shooter.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/1808500/ARC_Raiders/"><img src="https://steamcdn-a.akamaihd.net/steam/apps/1808500/header.jpg" alt="Arc Raiders hero image" title="Arc Raiders hero image">
</a>
</p>
<p>I wasn&rsquo;t expecting to like Arc Raiders as much as I did. It makes the sweaty extraction-shooter genre more accessible, even if it is still pretty sweaty.</p>
<p>Escape from Tarkov was a bit too much for me; Arc Raiders has a much better balance. It&rsquo;s not for everyone, but it&rsquo;s that well done you might enjoy it even if you don&rsquo;t like similar games.</p>
<p>Whilst you can get shot by other players, it&rsquo;s the Arc that are the real threat, and this mix of danger, plus the proximity voice chat, make it unlike any other game out right now.</p>
<p>It won The Game Awards&rsquo; <a href="https://nitter.net/ARCRaidersGame/status/1999420050785042508?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1999420050785042508%7Ctwgr%5E%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.gamersheroes.com%2Fgaming-news%2Farc-raiders-best-multiplayer-game-of-2025-at-the-game-awards%2F">Multiplayer Game of the Year</a>
, so don&rsquo;t just take my word for it.</p>
<p><a href="https://www.embark-studios.com/">Embark</a>
&rsquo;s previous game, <a href="https://www.reachthefinals.com/">The Finals</a>
, made it onto last year&rsquo;s list. Maybe we&rsquo;ll see a third game on next year&rsquo;s list?</p>
<p>It&rsquo;s also rated <a href="https://www.protondb.com/app/1808500">Platinum</a>
 on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/1808500/ARC_Raiders/">Steam</a>
</p>
<h2 id="battlefield-6">Battlefield 6</h2>
<blockquote>
<p>PvP FPS explosion-simulator.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/2807960/Battlefield_6/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/2807960/c12d12ce3c7d217398d3fcad77427bfc9d57c570/header.jpg" alt="Battlefield 6 hero image" title="Battlefield 6 hero image">
</a>
</p>
<p>Battlefield is back!</p>
<p>I&rsquo;ve played BF games ever since the first one, set all the way back in World War 2. I didn&rsquo;t buy BF5, and wasn&rsquo;t that impressed by 2042, so I was happy to see Battlefield make a comeback with 6.</p>
<p>And it was quite the comeback. Two of my friends bought new computers just to play it, and its launch weekend was the most active my little Discord server&rsquo;s ever been.</p>
<p>It&rsquo;s moved away from the slower, more tactical feel of its earlier entries though. If that older style is what you&rsquo;re after, games like <a href="https://www.joinsquad.com/">Squad</a>
 and <a href="https://www.hellletloose.com/">Hell Let Loose</a>
 now occupy that space.</p>
<p>With 6, Battlefield has settled into being a faster, more accessible squad-based shooter - and judged on those terms it&rsquo;s an excellent game. No wonder it was <a href="https://bsky.app/profile/matpiscatella.bsky.social/post/3ma6t4pndwc2w">the best selling FPS of the year</a>
.</p>
<p>Its only letdown is that it needs <a href="https://www.ea.com/games/battlefield/battlefield-6/news/secure-boot-information">Secure boot</a>
 to run the anti-cheat, which means you can&rsquo;t play it on Linux, so it gets a <a href="https://www.protondb.com/app/2807960">borked</a>
 rating on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/2807960/Battlefield_6/">Steam</a>
</p>
<h2 id="dying-light-the-beast">Dying Light: The Beast</h2>
<blockquote>
<p>First-person single-player/co-op story-driven parkour-action-zombie-killing.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/3008130/Dying_Light_The_Beast/"><img src="https://steamcdn-a.akamaihd.net/steam/apps/3008130/header.jpg" alt="Dying Light: The Beast hero image" title="Dying Light: The Beast hero image">
</a>
</p>
<p>The Beast is the best of the Dying Light series. Techland have improved on every part of the experience. And best of all, since I bought the deluxe edition of the second game, I got it for free!</p>
<p>It looks awesome, it runs well, and it&rsquo;s loads of fun. I&rsquo;m still playing through it in co-op, which lets up to 4 people be Kyle Crane, the protagonist from the first game.</p>
<p>Another <a href="https://www.protondb.com/app/3008130">Platinum</a>
 rating on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/3008130/Dying_Light_The_Beast/">Steam</a>
</p>
<h2 id="jump-space">Jump Space</h2>
<blockquote>
<p>Mission-based co-op PvE for up to 4 players.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/1757300/Jump_Space/"><img src="https://images.igdb.com/igdb/image/upload/t_1080p/ar3ysa.webp" alt="Jump Ship hero image" title="Jump Ship hero image">
</a>
</p>
<p>(Previously known as Jump Ship)</p>
<p>It&rsquo;s still in early access but Jump Space is more than playable right now. It&rsquo;s the chosen game for game night for us where once a week we crew a spaceship, fight some robots and <em>one of us</em> expertly puts out fires the others don&rsquo;t even notice because they&rsquo;re busy shooting space lasers.</p>
<p>Yet another <a href="https://www.protondb.com/app/1757300">Platinum</a>
 rating on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/1757300/Jump_Space/">Steam</a>
</p>
<h2 id="anno-117-pax-romana">Anno 117: Pax Romana</h2>
<blockquote>
<p>Single-player city-builder.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/3274580/Anno_117_Pax_Romana/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/3274580/88dbcce1c7630e2d4334fa25e835968e57e0ebfe/header.jpg?t=1764100083" alt="Anno 117: Pax Romana hero image" title="Anno 117: Pax Romana hero image">
</a>
</p>
<p>Anno 117 is apparently very similar to Anno 1800 but in a different setting with different people, which is exactly what I wanted.</p>
<p>You build up an island, or a few of them, from humble beginnings all the way up to a mighty city, managing buildings, production, and trade.</p>
<p>It&rsquo;s a more relaxing game than the other ones on this list. There is a bit of combat, but its main appeal to me is the city building and the setting.</p>
<p>It gets only a <a href="https://www.protondb.com/app/3274580">Gold</a>
 rating on ProtonDB, which I can&rsquo;t confirm, I haven&rsquo;t yet tried it on Linux.</p>
<p><a href="https://store.steampowered.com/app/3274580/Anno_117_Pax_Romana/">Steam</a>
</p>
<h2 id="rv-there-yet">RV There Yet?</h2>
<blockquote>
<p>Co-op friendslop.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/3949040/RV_There_Yet/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/3949040/cae24b4ed7f4531be51f0d63f785b7d253f92dc3/header.jpg?t=1766020280" alt="RV There Yet? hero image" title="RV There Yet? hero image">
</a>
</p>
<p>Friendslop is a new word for me. It&rsquo;s meant to define the low-stakes co-op games that are sold at low prices so that everyone in the group can afford to play them.</p>
<p>I don&rsquo;t know how true that definition is, I&rsquo;ve only ever played it with one person, who I can safely say is not qualified to drive an RV, whilst drinking a beer, smoking a cigarette, cooking burgers, being chased by a bear.</p>
<p>I almost put <a href="https://peak-game.com/">Peak</a>
 here, but so far I&rsquo;ve had more fun in RV There Yet?.</p>
<p>This game gets the last <a href="https://www.protondb.com/app/3949040">Platinum</a>
 rating on ProtonDB for games released in 2025, because this is the last of that list.</p>
<p><a href="https://store.steampowered.com/app/3949040/RV_There_Yet/">Steam</a>
</p>
<h2 id="not-released-in-2025">Not released in 2025</h2>
<p>These weren&rsquo;t released this year; they made the list anyway.</p>
<h3 id="the-beginners-guide">The Beginner&rsquo;s Guide</h3>
<blockquote>
<p>Single-player narrative-exploration-art.</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/303210/The_Beginners_Guide/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/303210/header.jpg?t=1765833998" alt="The Beginner&rsquo;s Guide hero image" title="The Beginner&#39;s Guide hero image">
</a>
</p>
<p>The Beginner&rsquo;s Guide took me a decade to play, and I&rsquo;m glad I finally did. It came out in 2015 and I got it this year as a Christmas present (thank you!). I played and finished it that same day.</p>
<p>It&rsquo;s made by the same developer as <a href="https://www.stanleyparable.com/">The Stanley Parable</a>
, which I really enjoyed, and it was a very different experience for this one. Whereas TSP was an interesting game, I&rsquo;d describe TBG as art. It doesn&rsquo;t involve much gameplay, and instead uses the medium of video games to do interactive storytelling.</p>
<p>Despite the rest of my list, I think you might need to view video games as an art-form, not just zombie-killing-space-laser-shooting-explosion-simulators, to really appreciate this one.</p>
<p>It gets a <a href="https://www.protondb.com/app/303210">Platinum</a>
 rating on ProtonDB and was natively released on Linux. I had to <a href="https://micro.paultibbetts.uk/2025/12/31/how-to-play-the-beginners.html">change a setting</a>
 to make it playable.</p>
<p><a href="https://store.steampowered.com/app/303210/The_Beginners_Guide/">Steam</a>
</p>
<h3 id="ministry-of-broadcast">Ministry of Broadcast</h3>
<blockquote>
<p>Single-player platformer</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/874040/Ministry_of_Broadcast/"><img src="https://images.igdb.com/igdb/image/upload/t_1080p/ardda.webp" alt="Ministry of Broadcast hero image" title="Ministry of Broadcast hero image">
</a>
</p>
<p>Another Christmas present I&rsquo;m really enjoying. It&rsquo;s perfectly suited for the Steam Deck, so it also works well with a controller, and is the only game on this list where I get to lean back in my chair instead of forward.</p>
<p>It&rsquo;s inspired by George Orwell&rsquo;s 1984, which might be why I&rsquo;m liking it so much. Though I don&rsquo;t remember Winston falling off as many buildings as I have.</p>
<p><a href="https://www.protondb.com/app/874040">Platinum</a>
 rated on ProtonDB.</p>
<p><a href="https://store.steampowered.com/app/874040/Ministry_of_Broadcast/">Steam</a>
</p>
<h3 id="baldurs-gate-3">Baldur&rsquo;s Gate 3</h3>
<blockquote>
<p>Single-player / online co-op party-based RPG</p>
</blockquote>
<p><a href="https://store.steampowered.com/app/1086940/Baldurs_Gate_3/"><img src="https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/1086940/48a2fcbda8565bb45025e98fd8ebde8a7203f6a0/header.jpg?t=1765505948" alt="Baldur&rsquo;s Gate 3 hero image" title="Baldur&#39;s Gate 3 hero image">
</a>
</p>
<p>I am still playing Baldur&rsquo;s Gate 3. I am still in Act 1. I know.</p>
<p>This is such a good game that I can&rsquo;t just turn it on mindlessly for 20 minutes. I need to settle in for an afternoon and play for a few hours at a time - to get into the right mind-frame and settle into being a powerful sorcerer.</p>
<p>Or whatever I am, I don&rsquo;t know, I&rsquo;ve never played D&amp;D before. My character keeps wanting to kill things, and I am happy to oblige.</p>
<p>I am sorry bard, I don&rsquo;t know what came over me.</p>
<p><a href="https://www.protondb.com/app/1086940">Gold</a>
 rated on ProtonDB, which is weird because it has a <a href="https://larian.com/support/faqs/steam-deck-native-version_121">native Linux build</a>
.</p>
<p><a href="https://store.steampowered.com/app/1086940/Baldurs_Gate_3/">Steam</a>
</p>]]></content:encoded><source:markdown>
Last year I wrote [my own take on the Steam Awards](https://micro.paultibbetts.uk/2025/01/03/pc-games-i-liked-in.html), and in 2025 I played less games, so instead of pretending otherwise, this is a list of my favourites from this year.

&lt;!--more--&gt;

## Dispatch

&gt; Single-player story-driven narrative.

[![Dispatch hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/2592160/header.jpg &#34;Dispatch hero image&#34;)](https://store.steampowered.com/app/2592160/Dispatch/)

Dispatch might be _the_ funniest game I&#39;ve ever played. It&#39;s extremely well written, absurdly well voice acted and expertly made by the team that used to be Telltale Games.

It gives a real glimpse into the life of a superhero dispatcher and kept me entertained the whole way through.

I&#39;ll be playing whatever [Adhoc Studios](https://www.adhocla.com/) makes next. I hope it&#39;s Wolf Among Us 2 or another season of Dispatch. Either way, I&#39;m in.

It&#39;s rated [Platinum](https://www.protondb.com/app/2592160) on ProtonDB, so it plays great on Linux.

[Steam](https://store.steampowered.com/app/2592160/Dispatch/)

## Arc Raiders

&gt; Third-person PvPvE extraction-shooter.

[![Arc Raiders hero image](https://steamcdn-a.akamaihd.net/steam/apps/1808500/header.jpg &#34;Arc Raiders hero image&#34;)](https://store.steampowered.com/app/1808500/ARC_Raiders/)

I wasn&#39;t expecting to like Arc Raiders as much as I did. It makes the sweaty extraction-shooter genre more accessible, even if it is still pretty sweaty.

Escape from Tarkov was a bit too much for me; Arc Raiders has a much better balance. It&#39;s not for everyone, but it&#39;s that well done you might enjoy it even if you don&#39;t like similar games.

Whilst you can get shot by other players, it&#39;s the Arc that are the real threat, and this mix of danger, plus the proximity voice chat, make it unlike any other game out right now.

It won The Game Awards&#39; [Multiplayer Game of the Year](https://nitter.net/ARCRaidersGame/status/1999420050785042508?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1999420050785042508%7Ctwgr%5E%7Ctwcon%5Es1_&amp;ref_url=https%3A%2F%2Fwww.gamersheroes.com%2Fgaming-news%2Farc-raiders-best-multiplayer-game-of-2025-at-the-game-awards%2F), so don&#39;t just take my word for it.

[Embark](https://www.embark-studios.com/)&#39;s previous game, [The Finals](https://www.reachthefinals.com/), made it onto last year&#39;s list. Maybe we&#39;ll see a third game on next year&#39;s list?

It&#39;s also rated [Platinum](https://www.protondb.com/app/1808500) on ProtonDB.

[Steam](https://store.steampowered.com/app/1808500/ARC_Raiders/)

## Battlefield 6

&gt; PvP FPS explosion-simulator.

[![Battlefield 6 hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/2807960/c12d12ce3c7d217398d3fcad77427bfc9d57c570/header.jpg &#34;Battlefield 6 hero image&#34;)](https://store.steampowered.com/app/2807960/Battlefield_6/)

Battlefield is back!

I&#39;ve played BF games ever since the first one, set all the way back in World War 2. I didn&#39;t buy BF5, and wasn&#39;t that impressed by 2042, so I was happy to see Battlefield make a comeback with 6.

And it was quite the comeback. Two of my friends bought new computers just to play it, and its launch weekend was the most active my little Discord server&#39;s ever been.

It&#39;s moved away from the slower, more tactical feel of its earlier entries though. If that older style is what you&#39;re after, games like [Squad](https://www.joinsquad.com/) and [Hell Let Loose](https://www.hellletloose.com/) now occupy that space.

With 6, Battlefield has settled into being a faster, more accessible squad-based shooter - and judged on those terms it&#39;s an excellent game. No wonder it was [the best selling FPS of the year](https://bsky.app/profile/matpiscatella.bsky.social/post/3ma6t4pndwc2w).

Its only letdown is that it needs [Secure boot](https://www.ea.com/games/battlefield/battlefield-6/news/secure-boot-information) to run the anti-cheat, which means you can&#39;t play it on Linux, so it gets a [borked](https://www.protondb.com/app/2807960) rating on ProtonDB.

[Steam](https://store.steampowered.com/app/2807960/Battlefield_6/)

## Dying Light: The Beast

&gt; First-person single-player/co-op story-driven parkour-action-zombie-killing.

[![Dying Light: The Beast hero image](https://steamcdn-a.akamaihd.net/steam/apps/3008130/header.jpg &#34;Dying Light: The Beast hero image&#34;)](https://store.steampowered.com/app/3008130/Dying_Light_The_Beast/)

The Beast is the best of the Dying Light series. Techland have improved on every part of the experience. And best of all, since I bought the deluxe edition of the second game, I got it for free!

It looks awesome, it runs well, and it&#39;s loads of fun. I&#39;m still playing through it in co-op, which lets up to 4 people be Kyle Crane, the protagonist from the first game.

Another [Platinum](https://www.protondb.com/app/3008130) rating on ProtonDB.

[Steam](https://store.steampowered.com/app/3008130/Dying_Light_The_Beast/)

## Jump Space

&gt; Mission-based co-op PvE for up to 4 players.

[![Jump Ship hero image](https://images.igdb.com/igdb/image/upload/t_1080p/ar3ysa.webp &#34;Jump Ship hero image&#34;)](https://store.steampowered.com/app/1757300/Jump_Space/)

(Previously known as Jump Ship)

It&#39;s still in early access but Jump Space is more than playable right now. It&#39;s the chosen game for game night for us where once a week we crew a spaceship, fight some robots and _one of us_ expertly puts out fires the others don&#39;t even notice because they&#39;re busy shooting space lasers.

Yet another [Platinum](https://www.protondb.com/app/1757300) rating on ProtonDB.

[Steam](https://store.steampowered.com/app/1757300/Jump_Space/)

## Anno 117: Pax Romana

&gt; Single-player city-builder.

[![Anno 117: Pax Romana hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/3274580/88dbcce1c7630e2d4334fa25e835968e57e0ebfe/header.jpg?t=1764100083 &#34;Anno 117: Pax Romana hero image&#34;)](https://store.steampowered.com/app/3274580/Anno_117_Pax_Romana/)

Anno 117 is apparently very similar to Anno 1800 but in a different setting with different people, which is exactly what I wanted.

You build up an island, or a few of them, from humble beginnings all the way up to a mighty city, managing buildings, production, and trade.

It&#39;s a more relaxing game than the other ones on this list. There is a bit of combat, but its main appeal to me is the city building and the setting.

It gets only a [Gold](https://www.protondb.com/app/3274580) rating on ProtonDB, which I can&#39;t confirm, I haven&#39;t yet tried it on Linux.

[Steam](https://store.steampowered.com/app/3274580/Anno_117_Pax_Romana/)

## RV There Yet?

&gt; Co-op friendslop.

[![RV There Yet? hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/3949040/cae24b4ed7f4531be51f0d63f785b7d253f92dc3/header.jpg?t=1766020280 &#34;RV There Yet? hero image&#34;)](https://store.steampowered.com/app/3949040/RV_There_Yet/)

Friendslop is a new word for me. It&#39;s meant to define the low-stakes co-op games that are sold at low prices so that everyone in the group can afford to play them.

I don&#39;t know how true that definition is, I&#39;ve only ever played it with one person, who I can safely say is not qualified to drive an RV, whilst drinking a beer, smoking a cigarette, cooking burgers, being chased by a bear.

I almost put [Peak](https://peak-game.com/) here, but so far I&#39;ve had more fun in RV There Yet?.

This game gets the last [Platinum](https://www.protondb.com/app/3949040) rating on ProtonDB for games released in 2025, because this is the last of that list.

[Steam](https://store.steampowered.com/app/3949040/RV_There_Yet/)

## Not released in 2025

These weren&#39;t released this year; they made the list anyway.

### The Beginner&#39;s Guide

&gt; Single-player narrative-exploration-art.

[![The Beginner&#39;s Guide hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/303210/header.jpg?t=1765833998 &#34;The Beginner&#39;s Guide hero image&#34;)](https://store.steampowered.com/app/303210/The_Beginners_Guide/)

The Beginner&#39;s Guide took me a decade to play, and I&#39;m glad I finally did. It came out in 2015 and I got it this year as a Christmas present (thank you!). I played and finished it that same day.

It&#39;s made by the same developer as [The Stanley Parable](https://www.stanleyparable.com/), which I really enjoyed, and it was a very different experience for this one. Whereas TSP was an interesting game, I&#39;d describe TBG as art. It doesn&#39;t involve much gameplay, and instead uses the medium of video games to do interactive storytelling.

Despite the rest of my list, I think you might need to view video games as an art-form, not just zombie-killing-space-laser-shooting-explosion-simulators, to really appreciate this one.

It gets a [Platinum](https://www.protondb.com/app/303210) rating on ProtonDB and was natively released on Linux. I had to [change a setting](https://micro.paultibbetts.uk/2025/12/31/how-to-play-the-beginners.html) to make it playable.

[Steam](https://store.steampowered.com/app/303210/The_Beginners_Guide/)

### Ministry of Broadcast

&gt; Single-player platformer

[![Ministry of Broadcast hero image](https://images.igdb.com/igdb/image/upload/t_1080p/ardda.webp &#34;Ministry of Broadcast hero image&#34;)](https://store.steampowered.com/app/874040/Ministry_of_Broadcast/)

Another Christmas present I&#39;m really enjoying. It&#39;s perfectly suited for the Steam Deck, so it also works well with a controller, and is the only game on this list where I get to lean back in my chair instead of forward.

It&#39;s inspired by George Orwell&#39;s 1984, which might be why I&#39;m liking it so much. Though I don&#39;t remember Winston falling off as many buildings as I have.

[Platinum](https://www.protondb.com/app/874040) rated on ProtonDB.

[Steam](https://store.steampowered.com/app/874040/Ministry_of_Broadcast/)

### Baldur&#39;s Gate 3

&gt; Single-player / online co-op party-based RPG

[![Baldur&#39;s Gate 3 hero image](https://shared.fastly.steamstatic.com/store_item_assets/steam/apps/1086940/48a2fcbda8565bb45025e98fd8ebde8a7203f6a0/header.jpg?t=1765505948 &#34;Baldur&#39;s Gate 3 hero image&#34;)](https://store.steampowered.com/app/1086940/Baldurs_Gate_3/)

I am still playing Baldur&#39;s Gate 3. I am still in Act 1. I know.

This is such a good game that I can&#39;t just turn it on mindlessly for 20 minutes. I need to settle in for an afternoon and play for a few hours at a time - to get into the right mind-frame and settle into being a powerful sorcerer.

Or whatever I am, I don&#39;t know, I&#39;ve never played D&amp;D before. My character keeps wanting to kill things, and I am happy to oblige.

I am sorry bard, I don&#39;t know what came over me.

[Gold](https://www.protondb.com/app/1086940) rated on ProtonDB, which is weird because it has a [native Linux build](https://larian.com/support/faqs/steam-deck-native-version_121).

[Steam](https://store.steampowered.com/app/1086940/Baldurs_Gate_3/)
</source:markdown></item><item>
      <title>Pangolin on a Pi</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/30/pangolin-on-a-pi/</link>
      <pubDate>Tue, 30 Dec 2025 15:10:00 +0000</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/12/30/pangolin-on-a-pi/</guid>
      <category>homelab</category>
      <category>IPv6</category>
      <category>Pangolin</category>
      <category>Raspberry Pi</category>
      <description>This post is not a step-by-step guide. It’s a record of what I tried and what I learned getting Pangolin to run on a Raspberry Pi with NFS storage in an IPv6-only environment.
TLDR: if you want to run Pangolin hassle-free, use a VPS with local SSD storage on an IPv4 network.</description>
      <content:encoded><![CDATA[<p>This post is not a step-by-step guide. It&rsquo;s a record of what I tried and what I learned getting Pangolin to run on a Raspberry Pi with NFS storage in an IPv6-only environment.</p>
<p><strong>TLDR</strong>: if you want to run Pangolin hassle-free, use a VPS with local SSD storage on an IPv4 network.</p>
<h2 id="pangolin">Pangolin</h2>
<p><a href="https://digpangolin.com/">Pangolin</a>
 is a &ldquo;secure access platform&rdquo; for safely exposing internal services. I&rsquo;m using it to let friends and family reach a few apps in my homelab without giving them the keys to everything.</p>
<p>It&rsquo;s a free, open-source alternative to <a href="https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/">Cloudflare Tunnel</a>
 for those who like independence from Cloudflare, want to self-host the stack themselves, or prefer not to rely on a third-party network for media streaming, which is not its intended use-case.</p>
<p>If none of those things bother you then you&rsquo;ll be fine using Cloudflare Tunnel or one of the alternatives. Read the terms and conditions first, media streaming is a bit of a grey area, I am not a lawyer and that wasn&rsquo;t legal advice.</p>
<h2 id="alternatives">Alternatives</h2>
<p>I already use <a href="https://www.wireguard.com/">Wireguard</a>
 as a VPN, and I still use it myself to get into my home network. VPNs work, but they&rsquo;re not fun to manage for friends and family and I wanted the ability to lock them down to certain apps.</p>
<p>There&rsquo;s also <a href="https://tailscale.com/">Tailscale</a>
, <a href="https://netbird.io/">Netbird</a>
, and <a href="https://www.zerotier.com/">ZeroTier</a>
, which use Wireguard to make a mesh network, but that&rsquo;s more of the same VPN solution. I&rsquo;d need to set up profiles and install clients on devices, and I wanted something easier. Tailscale now has its own <a href="https://tailscale.com/kb/1223/funnel">Funnel</a>
 project, but by the time I&rsquo;d seen it I was already setting up Pangolin.</p>
<p>The last alternative to mention is that you can achieve a similar result by renting a server, adding it to your VPN, and setting up a reverse proxy on it. But then you&rsquo;d need something else to make it secure, and you end up back at Pangolin.</p>
<h2 id="hosting">Hosting</h2>
<p>Pangolin needs to be hosted outside your network, so I needed to rent a server. It doesn&rsquo;t need to be a big one, Pangolin can work with 1 vCPU and 1GB of RAM, but ideally it would be close to your internal network and the users that want to get into it.</p>
<p>I live in the UK, so my options were UK, Ireland or Europe. UK-based hosting turned out to be expensive, with Krystal charging <a href="https://krystal.io/cloud-vps">£12 per month</a>
, whereas Hetzner, based in Germany, offers the same specs for <a href="https://www.hetzner.com/cloud">£3.97</a>
.</p>
<p>I should have gone with Hetzner. The extra latency would likely have been ~20ms and for Pangolin&rsquo;s use case - web apps and media streaming - that wouldn&rsquo;t have been noticeable.</p>
<p>But at the time I wanted my server to be based in the UK, so I carried on looking, until I found <a href="https://www.mythic-beasts.com/">Mythic Beasts</a>
. Not only had they recently <a href="https://www.mythic-beasts.com/blog/2025/02/25/supporting-the-open-rights-group/">donated to the Open Rights Group</a>
, an organisation I also support, but they have a cluster of Raspberry Pis you can use.</p>
<p>My search was over. I wanted Pangolin on a Pi. I did some initial testing, and the early signs were good, so I signed up for a year.</p>
<h2 id="raspberry-pi">Raspberry Pi</h2>
<p>The Mythic Beasts Pis come with two obstacles to running Pangolin. The first is that they are IPv6 only, and the second is the storage they use. One of these involves a little workaround and the other makes it a bad choice for hosting Pangolin.</p>
<h3 id="nfs-storage">NFS Storage</h3>
<p>Pangolin is actually more of a stack, with Pangolin as the control plane, Traefik doing reverse proxying, Gerbil running the tunnel and a thing called Badger to do the middleware that checks for authentication. The easiest way to run it all is with Docker Compose, and this is the first hurdle to running Pangolin on a Mythic Beasts Pi.</p>
<p>The Pis only have network storage available, and Docker doesn&rsquo;t like that because NFS doesn&rsquo;t provide the kind of guarantees Docker wants from a filesystem. Docker <em>can</em> work with NFS, but only using the <code>vfs</code> storage driver. Unlike the default <code>overlay2</code> driver, which uses a layered filesystem, <code>vfs</code> doesn&rsquo;t share layers, so every image consumes more space than it should.</p>
<p>So not only does NFS end up being slow, copying over lots of small files, it means the Docker images can&rsquo;t do any of the space saving that would normally happen. I have 50GB of storage and it&rsquo;s at 70% usage, even though the final images only take up 2GB, all because of the way <code>vfs</code> does its layering.</p>
<p>Did I mention that it&rsquo;s slow? Starting up the containers takes about 15 minutes. Turning them off isn&rsquo;t fast either. And upgrades? You won&rsquo;t have room for the new images, so you&rsquo;ll have to turn everything off to remove the old ones before you can start downloading the new ones. This means upgrades can take about an hour, with Pangolin down the entire time.</p>
<h3 id="ipv6">IPv6</h3>
<p>The internet&rsquo;s ran out of IPv4 addresses, by the way, so the Pis are IPv6 only. This means you have to do a bit of extra work to make Pangolin available for everyone.</p>
<p>IPv6 is the future but support for it is still mixed, so Mythic Beasts have an IPv4 to IPv6 proxy to allow users stuck on IPv4-only networks to get to your server. To use it you configure the proxy to forward requests to your domain on to the IPv6 address of the Pi.</p>
<p>The other end of the tunnel, the one in your home network, is managed by a service called Newt. It needs to speak to Gerbil on the Pi, and I was not successful getting it to run with the default <code>pangolin.example.com</code> address I was using.</p>
<p>Newt is configured by pointing it at Pangolin, which advertises the Gerbil endpoint it should connect to. Maybe it was Pangolin, or the proxy, or even something else; I could not get it to work. To make some progress I changed the <code>base_endpoint</code> in <code>config/config.yml</code>. First I tried the IPv6 address of the Pi, but that still didn&rsquo;t work, so I created an AAAA record for Gerbil and pointed it at the Pi. This would do the same thing as the CNAME I&rsquo;d used for Pangolin, except that went through the proxy and maybe that was messing things up. This time, it worked.</p>
<p>Mythic Beasts <a href="https://www.mythic-beasts.com/support/topics/proxy">state their proxy</a>
:</p>
<blockquote>
<p>will relay traffic for common services, such as HTTP and HTTPS</p>
</blockquote>
<p>and I have a suspicion that Wireguard doesn&rsquo;t count as a &ldquo;common service&rdquo;.</p>
<h2 id="home-network">Home network</h2>
<p>The final hurdle to getting this setup to work was my own network. Since the proxy doesn&rsquo;t seem to forward Wireguard traffic, and I have to connect directly to the Pi with IPv6, my network needs to let me do that.</p>
<p>This means I need at least IPv6 egress. That doesn&rsquo;t mean full IPv6 support everywhere, just enough to have a usable outbound path. I tried a bunch of different things to get it to work, and some of my changes actually made things worse, so what follows is what worked for me, in case your setup is similar, most likely it isn&rsquo;t.</p>
<h3 id="isp-router">ISP router</h3>
<p>I&rsquo;m still using the router my ISP gave me, which has very basic IPv6 support. I&rsquo;m with Vodafone and it&rsquo;s the standard &ldquo;WiFi hub&rdquo; they gave out several years ago.</p>
<p>The right combination of buttons to press is under <code>Settings -&gt; Local Network</code> and you want:</p>
<p><code>IPv6</code> <strong>Enabled</strong></p>
<p><code>IPv6 ULA</code> <strong>Disabled</strong></p>
<p>The <code>IPv6</code> toggle enables Router Advertisements (RA) from the router and this gives hosts a global IPv6 address, and also tells them what the default route for IPv6 traffic is, which is through this router.</p>
<p>The <code>IPv6 ULA</code> toggle disables Unique Local Addresses, which is a private IPv6 space used for hosts to speak to each other over IPv6, and is not necessary for Newt to reach Gerbil, so it can be disabled.</p>
<h3 id="mesh-router">Mesh router</h3>
<p>I&rsquo;ve also got a pair of mesh devices I use as a wireless bridge between floors, since I&rsquo;m not able to run an ethernet cable.</p>
<p>They&rsquo;re definitely in bridge mode. However, in the admin panel under <code>Settings -&gt; Network -&gt; Advanced</code>, IPv6 was set to &ldquo;Auto Configuration&rdquo;, meaning they were also doing SLAAC and DHCPv6. This added to the confusion, not just for myself but for my devices, so I changed that to &ldquo;Local Connectivity Only&rdquo; to simplify things.</p>
<h3 id="dhcp">DHCP</h3>
<p>My ISP router sucks, it even crashed when I double checked the settings I mentioned above, so I&rsquo;ve moved DHCP off of it and instead do that with Pi-hole. It&rsquo;s way more stable and lets me view the admin panel without crashing.</p>
<p>An extra benefit of this is that when Pi-hole tells a device what its address is it will also tell them to use it as the DNS server, which makes it an automatic setup. The device now gets ad-blocking and can see the custom DNS records I&rsquo;ve set in Pi-hole without me doing anything.</p>
<h3 id="rdnss">RDNSS</h3>
<p>Except now that my ISP router is doing IPv6, it&rsquo;s also doing <abbr title="Recursive DNS Server">RDNSS</abbr>, which is DNS for IPv6, and I can&rsquo;t turn it off. This means it does the same thing that Pi-hole is doing but for IPv6 instead of 4. Since IPv6 is the future, every device on the network now prefers going to the router for DNS, instead of Pi-hole, so they lose the ad-blocking and custom DNS records I&rsquo;ve set.</p>
<p>If I had a better router that let me turn on IPv6 and either disable RDNSS, or advertise Pi-hole as the IPv6 DNS server, then this wouldn&rsquo;t be a problem. With my ISP router not letting me do that I could manually set every device to use Pi-hole for DNS, which is fine, unless you want to do it on Android.</p>
<h3 id="android">Android</h3>
<p>Most of the mobile devices in this house run iOS, which lets you manually set the DNS server, and allows you to enter an IPv4 address, which is fine for Pi-hole.</p>
<p>Android does it differently. It lets you set an IPv4 address, but if it sees RDNSS then it ignores your manual setting and uses that instead, which for me is the ISP router. So no ad-blocking or custom DNS records for Android devices.</p>
<p>This means if you&rsquo;re in the kitchen and want to check Mealie to see the recipe for tonight&rsquo;s meal you have to go out over the internet to come back and reach the server in the other room.</p>
<p>I don&rsquo;t personally use Android, but as the architect of the setup it still feels bad.</p>
<h3 id="router-dns">Router DNS</h3>
<p>There is a fix, although it&rsquo;s not ideal, and that&rsquo;s to set my router&rsquo;s DNS to use Pi-hole. I had initially forgotten about doing this, because I thought it was already setup, but it turns out I&rsquo;d turned it off for good reason.</p>
<p>Whilst it works, and the Android devices can now see apps in my homelab, all the traffic goes to Pi-hole through the router, so you can&rsquo;t distinguish where it came from. I don&rsquo;t really need this, but I remember now why I preferred Pi-hole handing out its own address as the DNS server.</p>
<h2 id="what-i-could-do-to-improve-it">What I could do to improve it</h2>
<p>This project has made me question, well a lot of things. The ability to update my RSS feeds without toggling my VPN on and off is kinda nice, and I can share limited access to my homelab with my friends and family, so for now it can stay.</p>
<p>Here&rsquo;s what would make it better:</p>
<h3 id="use-a-vps-with-ssd-storage-on-an-ipv4-network">Use a VPS with SSD storage on an IPv4 network</h3>
<p>This is the most obvious improvement to the setup.</p>
<p>The NFS storage on the Pi makes it a bad choice to run Docker Compose setups like the Pangolin stack. It works, but startup and even shutdown take too long and so upgrades have far more downtime than they should. NFS is fine for storage for the containers, but it&rsquo;s not suitable for running the containers themselves.</p>
<p>The IPv4 to IPv6 proxy that I&rsquo;m using doesn&rsquo;t forward Wireguard traffic, so I&rsquo;ve had to set up IPv6 in my network, which has caused some manual work I wasn&rsquo;t expecting.</p>
<p>To be clear, the Pi itself is not to blame for any of this, it&rsquo;s more than capable of handling the Pangolin stack. It&rsquo;s the fact it only has NFS storage that lets it down. The proxy not forwarding Wireguard can be worked around, and both are completely understandable tradeoffs that Mythic Beasts have made to make Raspberry PI hosting available in the first place.</p>
<p>The improvement would be to use a VPS, or even another Pi if I could find one, that uses fast local storage and is on an IPv4 network, or has a proxy available that also forwards Wireguard traffic.</p>
<p>If I hadn&rsquo;t already committed to a 12 month contract for the Pi I would have already done this. If I can find an alternative use for it maybe I&rsquo;ll move before the contract runs out.</p>
<p>Until then, I&rsquo;m not doing this.</p>
<h3 id="host-pangolin-without-docker">Host Pangolin without Docker</h3>
<p>This is entirely possible, but goes against the point of using Pangolin. I wanted an easy to use system, and as soon as I start deploying each part of it myself and connecting all the parts together it&rsquo;s no longer simple or easy to use.</p>
<p>The same goes for installing Wireguard manually on the Pi and reverse proxying through it into my homelab. I&rsquo;ve already got a Wireguard server up and running, so that&rsquo;s half the job already done, but then I&rsquo;d need to setup something to secure access into that tunnel, and that&rsquo;s what Pangolin&rsquo;s for.</p>
<h3 id="bluegreen-deployments">Blue/Green deployments</h3>
<p>NFS means the Pi takes a while to run upgrades, so there&rsquo;s about an hour of downtime.</p>
<p>I could get around this by spinning up a second Pi, installing the upgraded software, somehow sync the configs, and then switch the DNS to point to the upgraded Pi.</p>
<p>This wouldn&rsquo;t solve any of the problems except the downtime, and it would cost me more money to do so. I&rsquo;m not doing that. My friends and family will have to put up with the downtime.</p>
<p>They could chip in to cover the costs, but that turns the whole thing into a business arrangement and I don&rsquo;t want to go down that road.</p>
<h3 id="get-a-better-router">Get a better router</h3>
<p>This is more of a homelab quality-of-life improvement than a Pangolin-specific fix.</p>
<p>Getting rid of the ISP router and replacing it with something better would mean I can stop using Pi-hole for DHCP and only use it for its original intended purpose, DNS.</p>
<p>It only needs the ability to change the RDNSS setting to advertise Pi-hole as the DNS server to be better than my ISP router. Forwarding DNS through the router works, but advertising Pi-hole directly would preserve the per-device visibility in Pi-hole that I originally had for all devices.</p>
<p>This may need to happen anyway, but I wasn&rsquo;t looking to do this right now, so for now it isn&rsquo;t a priority. When I do upgrade, OpenWRT, OPNsense and pfSense would all allow me to use Pi-hole for RDNSS.</p>
<h3 id="host-my-own-ipv4-to-ipv6-proxy">Host my own IPv4 to IPv6 proxy</h3>
<p>I could technically go back to IPv4 only in my network if the proxy I use to connect to the Pi also forwarded Wireguard connections. Since the current one doesn&rsquo;t, the only options are to setup IPv6 in my home network or host my own proxy that can.</p>
<p>I picked the Pi because it was the cheapest UK-based hosting I could find, and this doubles the cost, so it isn&rsquo;t really an option.</p>
<p>Also I don&rsquo;t want to host a tunnel for my tunnel. That&rsquo;s too many tunnels.</p>
<h2 id="would-i-do-this-again">Would I do this again?</h2>
<p>Absolutely not.</p>
<h3 id="am-i-glad-i-tried-it">Am I glad I tried it?</h3>
<p>Yes. That&rsquo;s the point of a homelab.</p>]]></content:encoded><source:markdown>
This post is not a step-by-step guide. It&#39;s a record of what I tried and what I learned getting Pangolin to run on a Raspberry Pi with NFS storage in an IPv6-only environment.

**TLDR**: if you want to run Pangolin hassle-free, use a VPS with local SSD storage on an IPv4 network.

&lt;!--more--&gt;

## Pangolin

[Pangolin](https://digpangolin.com/) is a &#34;secure access platform&#34; for safely exposing internal services. I&#39;m using it to let friends and family reach a few apps in my homelab without giving them the keys to everything.

It&#39;s a free, open-source alternative to [Cloudflare Tunnel](https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/) for those who like independence from Cloudflare, want to self-host the stack themselves, or prefer not to rely on a third-party network for media streaming, which is not its intended use-case.

If none of those things bother you then you&#39;ll be fine using Cloudflare Tunnel or one of the alternatives. Read the terms and conditions first, media streaming is a bit of a grey area, I am not a lawyer and that wasn&#39;t legal advice.

## Alternatives

I already use [Wireguard](https://www.wireguard.com/) as a VPN, and I still use it myself to get into my home network. VPNs work, but they&#39;re not fun to manage for friends and family and I wanted the ability to lock them down to certain apps.

There&#39;s also [Tailscale](https://tailscale.com/), [Netbird](https://netbird.io/), and [ZeroTier](https://www.zerotier.com/), which use Wireguard to make a mesh network, but that&#39;s more of the same VPN solution. I&#39;d need to set up profiles and install clients on devices, and I wanted something easier. Tailscale now has its own [Funnel](https://tailscale.com/kb/1223/funnel) project, but by the time I&#39;d seen it I was already setting up Pangolin.

The last alternative to mention is that you can achieve a similar result by renting a server, adding it to your VPN, and setting up a reverse proxy on it. But then you&#39;d need something else to make it secure, and you end up back at Pangolin.

## Hosting

Pangolin needs to be hosted outside your network, so I needed to rent a server. It doesn&#39;t need to be a big one, Pangolin can work with 1 vCPU and 1GB of RAM, but ideally it would be close to your internal network and the users that want to get into it.

I live in the UK, so my options were UK, Ireland or Europe. UK-based hosting turned out to be expensive, with Krystal charging [£12 per month](https://krystal.io/cloud-vps), whereas Hetzner, based in Germany, offers the same specs for [£3.97](https://www.hetzner.com/cloud).

I should have gone with Hetzner. The extra latency would likely have been ~20ms and for Pangolin&#39;s use case - web apps and media streaming - that wouldn&#39;t have been noticeable.

But at the time I wanted my server to be based in the UK, so I carried on looking, until I found [Mythic Beasts](https://www.mythic-beasts.com/). Not only had they recently [donated to the Open Rights Group](https://www.mythic-beasts.com/blog/2025/02/25/supporting-the-open-rights-group/), an organisation I also support, but they have a cluster of Raspberry Pis you can use.

My search was over. I wanted Pangolin on a Pi. I did some initial testing, and the early signs were good, so I signed up for a year.

## Raspberry Pi

The Mythic Beasts Pis come with two obstacles to running Pangolin. The first is that they are IPv6 only, and the second is the storage they use. One of these involves a little workaround and the other makes it a bad choice for hosting Pangolin.

### NFS Storage

Pangolin is actually more of a stack, with Pangolin as the control plane, Traefik doing reverse proxying, Gerbil running the tunnel and a thing called Badger to do the middleware that checks for authentication. The easiest way to run it all is with Docker Compose, and this is the first hurdle to running Pangolin on a Mythic Beasts Pi.

The Pis only have network storage available, and Docker doesn&#39;t like that because NFS doesn&#39;t provide the kind of guarantees Docker wants from a filesystem. Docker _can_ work with NFS, but only using the `vfs` storage driver. Unlike the default `overlay2` driver, which uses a layered filesystem, `vfs` doesn&#39;t share layers, so every image consumes more space than it should.

So not only does NFS end up being slow, copying over lots of small files, it means the Docker images can&#39;t do any of the space saving that would normally happen. I have 50GB of storage and it&#39;s at 70% usage, even though the final images only take up 2GB, all because of the way `vfs` does its layering.

Did I mention that it&#39;s slow? Starting up the containers takes about 15 minutes. Turning them off isn&#39;t fast either. And upgrades? You won&#39;t have room for the new images, so you&#39;ll have to turn everything off to remove the old ones before you can start downloading the new ones. This means upgrades can take about an hour, with Pangolin down the entire time.

### IPv6

The internet&#39;s ran out of IPv4 addresses, by the way, so the Pis are IPv6 only. This means you have to do a bit of extra work to make Pangolin available for everyone.

IPv6 is the future but support for it is still mixed, so Mythic Beasts have an IPv4 to IPv6 proxy to allow users stuck on IPv4-only networks to get to your server. To use it you configure the proxy to forward requests to your domain on to the IPv6 address of the Pi.

The other end of the tunnel, the one in your home network, is managed by a service called Newt. It needs to speak to Gerbil on the Pi, and I was not successful getting it to run with the default `pangolin.example.com` address I was using.

Newt is configured by pointing it at Pangolin, which advertises the Gerbil endpoint it should connect to. Maybe it was Pangolin, or the proxy, or even something else; I could not get it to work. To make some progress I changed the `base_endpoint` in `config/config.yml`. First I tried the IPv6 address of the Pi, but that still didn&#39;t work, so I created an AAAA record for Gerbil and pointed it at the Pi. This would do the same thing as the CNAME I&#39;d used for Pangolin, except that went through the proxy and maybe that was messing things up. This time, it worked.

Mythic Beasts [state their proxy](https://www.mythic-beasts.com/support/topics/proxy):

&gt; will relay traffic for common services, such as HTTP and HTTPS

and I have a suspicion that Wireguard doesn&#39;t count as a &#34;common service&#34;.

## Home network

The final hurdle to getting this setup to work was my own network. Since the proxy doesn&#39;t seem to forward Wireguard traffic, and I have to connect directly to the Pi with IPv6, my network needs to let me do that.

This means I need at least IPv6 egress. That doesn&#39;t mean full IPv6 support everywhere, just enough to have a usable outbound path. I tried a bunch of different things to get it to work, and some of my changes actually made things worse, so what follows is what worked for me, in case your setup is similar, most likely it isn&#39;t.

### ISP router

I&#39;m still using the router my ISP gave me, which has very basic IPv6 support. I&#39;m with Vodafone and it&#39;s the standard &#34;WiFi hub&#34; they gave out several years ago.

The right combination of buttons to press is under `Settings -&gt; Local Network` and you want:

`IPv6` **Enabled**

`IPv6 ULA` **Disabled**

The `IPv6` toggle enables Router Advertisements (RA) from the router and this gives hosts a global IPv6 address, and also tells them what the default route for IPv6 traffic is, which is through this router.

The `IPv6 ULA` toggle disables Unique Local Addresses, which is a private IPv6 space used for hosts to speak to each other over IPv6, and is not necessary for Newt to reach Gerbil, so it can be disabled.

### Mesh router

I&#39;ve also got a pair of mesh devices I use as a wireless bridge between floors, since I&#39;m not able to run an ethernet cable.

They&#39;re definitely in bridge mode. However, in the admin panel under `Settings -&gt; Network -&gt; Advanced`, IPv6 was set to &#34;Auto Configuration&#34;, meaning they were also doing SLAAC and DHCPv6. This added to the confusion, not just for myself but for my devices, so I changed that to &#34;Local Connectivity Only&#34; to simplify things.

### DHCP

My ISP router sucks, it even crashed when I double checked the settings I mentioned above, so I&#39;ve moved DHCP off of it and instead do that with Pi-hole. It&#39;s way more stable and lets me view the admin panel without crashing.

An extra benefit of this is that when Pi-hole tells a device what its address is it will also tell them to use it as the DNS server, which makes it an automatic setup. The device now gets ad-blocking and can see the custom DNS records I&#39;ve set in Pi-hole without me doing anything.

### RDNSS

Except now that my ISP router is doing IPv6, it&#39;s also doing &lt;abbr title=&#34;Recursive DNS Server&#34;&gt;RDNSS&lt;/abbr&gt;, which is DNS for IPv6, and I can&#39;t turn it off. This means it does the same thing that Pi-hole is doing but for IPv6 instead of 4. Since IPv6 is the future, every device on the network now prefers going to the router for DNS, instead of Pi-hole, so they lose the ad-blocking and custom DNS records I&#39;ve set.

If I had a better router that let me turn on IPv6 and either disable RDNSS, or advertise Pi-hole as the IPv6 DNS server, then this wouldn&#39;t be a problem. With my ISP router not letting me do that I could manually set every device to use Pi-hole for DNS, which is fine, unless you want to do it on Android.

### Android

Most of the mobile devices in this house run iOS, which lets you manually set the DNS server, and allows you to enter an IPv4 address, which is fine for Pi-hole.

Android does it differently. It lets you set an IPv4 address, but if it sees RDNSS then it ignores your manual setting and uses that instead, which for me is the ISP router. So no ad-blocking or custom DNS records for Android devices.

This means if you&#39;re in the kitchen and want to check Mealie to see the recipe for tonight&#39;s meal you have to go out over the internet to come back and reach the server in the other room.

I don&#39;t personally use Android, but as the architect of the setup it still feels bad.

### Router DNS

There is a fix, although it&#39;s not ideal, and that&#39;s to set my router&#39;s DNS to use Pi-hole. I had initially forgotten about doing this, because I thought it was already setup, but it turns out I&#39;d turned it off for good reason.

Whilst it works, and the Android devices can now see apps in my homelab, all the traffic goes to Pi-hole through the router, so you can&#39;t distinguish where it came from. I don&#39;t really need this, but I remember now why I preferred Pi-hole handing out its own address as the DNS server.

## What I could do to improve it

This project has made me question, well a lot of things. The ability to update my RSS feeds without toggling my VPN on and off is kinda nice, and I can share limited access to my homelab with my friends and family, so for now it can stay.

Here&#39;s what would make it better:

### Use a VPS with SSD storage on an IPv4 network

This is the most obvious improvement to the setup.

The NFS storage on the Pi makes it a bad choice to run Docker Compose setups like the Pangolin stack. It works, but startup and even shutdown take too long and so upgrades have far more downtime than they should. NFS is fine for storage for the containers, but it&#39;s not suitable for running the containers themselves.

The IPv4 to IPv6 proxy that I&#39;m using doesn&#39;t forward Wireguard traffic, so I&#39;ve had to set up IPv6 in my network, which has caused some manual work I wasn&#39;t expecting.

To be clear, the Pi itself is not to blame for any of this, it&#39;s more than capable of handling the Pangolin stack. It&#39;s the fact it only has NFS storage that lets it down. The proxy not forwarding Wireguard can be worked around, and both are completely understandable tradeoffs that Mythic Beasts have made to make Raspberry PI hosting available in the first place.

The improvement would be to use a VPS, or even another Pi if I could find one, that uses fast local storage and is on an IPv4 network, or has a proxy available that also forwards Wireguard traffic.

If I hadn&#39;t already committed to a 12 month contract for the Pi I would have already done this. If I can find an alternative use for it maybe I&#39;ll move before the contract runs out.

Until then, I&#39;m not doing this.

### Host Pangolin without Docker

This is entirely possible, but goes against the point of using Pangolin. I wanted an easy to use system, and as soon as I start deploying each part of it myself and connecting all the parts together it&#39;s no longer simple or easy to use.

The same goes for installing Wireguard manually on the Pi and reverse proxying through it into my homelab. I&#39;ve already got a Wireguard server up and running, so that&#39;s half the job already done, but then I&#39;d need to setup something to secure access into that tunnel, and that&#39;s what Pangolin&#39;s for.

### Blue/Green deployments

NFS means the Pi takes a while to run upgrades, so there&#39;s about an hour of downtime.

I could get around this by spinning up a second Pi, installing the upgraded software, somehow sync the configs, and then switch the DNS to point to the upgraded Pi.

This wouldn&#39;t solve any of the problems except the downtime, and it would cost me more money to do so. I&#39;m not doing that. My friends and family will have to put up with the downtime.

They could chip in to cover the costs, but that turns the whole thing into a business arrangement and I don&#39;t want to go down that road.

### Get a better router

This is more of a homelab quality-of-life improvement than a Pangolin-specific fix.

Getting rid of the ISP router and replacing it with something better would mean I can stop using Pi-hole for DHCP and only use it for its original intended purpose, DNS.

It only needs the ability to change the RDNSS setting to advertise Pi-hole as the DNS server to be better than my ISP router. Forwarding DNS through the router works, but advertising Pi-hole directly would preserve the per-device visibility in Pi-hole that I originally had for all devices.

This may need to happen anyway, but I wasn&#39;t looking to do this right now, so for now it isn&#39;t a priority. When I do upgrade, OpenWRT, OPNsense and pfSense would all allow me to use Pi-hole for RDNSS.

### Host my own IPv4 to IPv6 proxy

I could technically go back to IPv4 only in my network if the proxy I use to connect to the Pi also forwarded Wireguard connections. Since the current one doesn&#39;t, the only options are to setup IPv6 in my home network or host my own proxy that can.

I picked the Pi because it was the cheapest UK-based hosting I could find, and this doubles the cost, so it isn&#39;t really an option.

Also I don&#39;t want to host a tunnel for my tunnel. That&#39;s too many tunnels.

## Would I do this again?

Absolutely not.

### Am I glad I tried it?

Yes. That&#39;s the point of a homelab.
</source:markdown></item><item>
      <title>The Self-Inflicted Pain Ruining My Homelab</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/10/the-self-inflicted-pain-ruining-my-homelab/</link>
      <pubDate>Wed, 10 Sep 2025 15:30:00 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/10/the-self-inflicted-pain-ruining-my-homelab/</guid>
      <category>homelab</category>
      <category>networking</category>
      <category>DHCP</category>
      <category>Pi-hole</category>
      <description>The worst pains in tech are self-inflicted. Then it’s bad Wi-Fi.
I’ve just fixed a very niche problem that was both.</description>
      <content:encoded><![CDATA[<p>The worst pains in tech are self-inflicted. Then it&rsquo;s bad Wi-Fi.</p>
<p>I&rsquo;ve just fixed a very niche problem that was both.</p>
<h2 id="home-network">Home Network</h2>
<p>My home network&rsquo;s a bit unusual. The internet comes in downstairs, like the internet usually does, and I need it upstairs where my computers are. I&rsquo;m renting, and the property owner doesn&rsquo;t want wires going up and into walls, so I have to do it wirelessly.</p>
<p>WiFi is fine for most of my devices but a few of them are servers that don&rsquo;t have adapters. They want to be plugged in, so I share the internet between floors with a pair of <a href="https://www.dlink.com/en/products/m15-3-pack-ax1500-mesh-system">mesh routers</a>
 and plug in the servers to the upstairs mesh device.</p>
<p>It all works great and I can recommend the mesh routers, although they&rsquo;re a bit old and have probably been superseded by now.</p>
<h2 id="homelab">Homelab</h2>
<p>The problems started along with my homelab.</p>
<p>I was creating lots of virtual machines on one of the servers that weren&rsquo;t being recognised by the router, so they wouldn&rsquo;t join the network and had no internet access.</p>
<p>I couldn&rsquo;t get onto the admin panel of the router because it&rsquo;s the free one you get from the ISP and it wasn&rsquo;t powerful enough to keep up.</p>
<p>I was getting annoyed.</p>
<h3 id="dhcp">DHCP</h3>
<p>Then I found that Pi-hole, something I was already using for ad-blocking and DNS, could also <a href="https://discourse.pi-hole.net/t/how-do-i-use-pi-holes-built-in-dhcp-server-and-why-would-i-want-to/3026">act as a DHCP server</a>
. This would undoubtedly be better than doing it on the free ISP router that couldn&rsquo;t keep up, so I disabled it on the router and enabled it in Pi-hole.</p>
<p>The way DHCP works is that something on your network needs to answer requests from clients telling them what their address is. Usually this is the router, but it doesn&rsquo;t need to be.</p>
<p>So I set my instance of Pi-hole to handle DHCP.</p>
<p>And it all worked great.</p>
<p>Kind of.</p>
<h3 id="dhcp-over-mesh-wifi">DHCP over mesh WiFi?</h3>
<p>The first clue that things weren&rsquo;t quite right came when my devices wouldn&rsquo;t reconnect to WiFi. The next was when my PC wouldn&rsquo;t get a connection at all, until after I restarted the mesh router.</p>
<p>It took a while for me to connect the dots, but something about the mesh routers was making things weird.</p>
<p>If it didn&rsquo;t work then that was fine, I would move on. But it worked some of the time?</p>
<h3 id="have-you-tried-not-doing-that">Have you tried not doing that?</h3>
<p>I spent a lot of time this week trying to diagnose the issue.</p>
<p>I even started preparing to replace the router.</p>
<p>I needn&rsquo;t have bothered.</p>
<p>Moving the server with Pi-hole on it downstairs, where it doesn&rsquo;t need to use the mesh routers, has fixed the issue.</p>
<p>Pi-hole now responds to DHCP requests and all my devices can connect to the network.</p>
<h2 id="summary">Summary</h2>
<p>So if you ever have DHCP issues because your instance of Pi-hole is behind a mesh router, try not doing that and see if it fixes things.</p>]]></content:encoded><source:markdown>
The worst pains in tech are self-inflicted. Then it&#39;s bad Wi-Fi.

I&#39;ve just fixed a very niche problem that was both.

&lt;!--more--&gt;

## Home Network

My home network&#39;s a bit unusual. The internet comes in downstairs, like the internet usually does, and I need it upstairs where my computers are. I&#39;m renting, and the property owner doesn&#39;t want wires going up and into walls, so I have to do it wirelessly.

WiFi is fine for most of my devices but a few of them are servers that don&#39;t have adapters. They want to be plugged in, so I share the internet between floors with a pair of [mesh routers](https://www.dlink.com/en/products/m15-3-pack-ax1500-mesh-system) and plug in the servers to the upstairs mesh device.

It all works great and I can recommend the mesh routers, although they&#39;re a bit old and have probably been superseded by now.

## Homelab

The problems started along with my homelab.

I was creating lots of virtual machines on one of the servers that weren&#39;t being recognised by the router, so they wouldn&#39;t join the network and had no internet access.

I couldn&#39;t get onto the admin panel of the router because it&#39;s the free one you get from the ISP and it wasn&#39;t powerful enough to keep up.

I was getting annoyed.

### DHCP

Then I found that Pi-hole, something I was already using for ad-blocking and DNS, could also [act as a DHCP server](https://discourse.pi-hole.net/t/how-do-i-use-pi-holes-built-in-dhcp-server-and-why-would-i-want-to/3026). This would undoubtedly be better than doing it on the free ISP router that couldn&#39;t keep up, so I disabled it on the router and enabled it in Pi-hole.

The way DHCP works is that something on your network needs to answer requests from clients telling them what their address is. Usually this is the router, but it doesn&#39;t need to be.

So I set my instance of Pi-hole to handle DHCP.

And it all worked great.

Kind of.

### DHCP over mesh WiFi?

The first clue that things weren&#39;t quite right came when my devices wouldn&#39;t reconnect to WiFi. The next was when my PC wouldn&#39;t get a connection at all, until after I restarted the mesh router.

It took a while for me to connect the dots, but something about the mesh routers was making things weird.

If it didn&#39;t work then that was fine, I would move on. But it worked some of the time?

### Have you tried not doing that?

I spent a lot of time this week trying to diagnose the issue.

I even started preparing to replace the router.

I needn&#39;t have bothered.

Moving the server with Pi-hole on it downstairs, where it doesn&#39;t need to use the mesh routers, has fixed the issue.

Pi-hole now responds to DHCP requests and all my devices can connect to the network.

## Summary

So if you ever have DHCP issues because your instance of Pi-hole is behind a mesh router, try not doing that and see if it fixes things.
</source:markdown></item><item>
      <title>Into the Fediverse 🖖</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/10/into-the-fediverse/</link>
      <pubDate>Wed, 10 Sep 2025 12:00:00 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/10/into-the-fediverse/</guid>
      <category>IndieWeb</category>
      <category>Fediverse</category>
      <category>Bluesky</category>
      <category>Mastodon</category>
      <category>Micro.blog</category>
      <description>We live in strange times, with strange social networks doing strange things.
So why, on the same day I said I was team IndieWeb, did I enter the Fediverse?</description>
      <content:encoded><![CDATA[<p>We live in strange times, with strange social networks doing strange things.</p>
<p>So why, on the same day I said I was team IndieWeb, did I enter the Fediverse?</p>
<h2 id="indieweb">IndieWeb</h2>
<p>I&rsquo;ve been following the <a href="https://indieweb.org/">IndieWeb</a>
 for a decade now and have recently started blogging again, slowly adding IndieWeb features to my site.</p>
<p>Right now it&rsquo;s readable and followable, a bare minimum website experience, but with a little <a href="https://indieweb.org/webmention">webmention</a>
 magic it can grow into something more social. That&rsquo;s the plan anyway.</p>
<p>I&rsquo;d be able to write and respond to others on the IndieWeb that also do webmentions.</p>
<p>But not everyone wants to make their own website, or buy into a platform with strange features they don&rsquo;t understand , so there&rsquo;s a limit to how social it can really end up being.</p>
<h2 id="mastodon">Mastodon</h2>
<p>Enter Mastodon, which erupted in popularity when Musk started to ruin Twitter. It&rsquo;s a decentralised social network that works a bit like Twitter did but without as many nazis.</p>
<p>Mastodon is powered by <a href="https://activitypub.rocks/">ActivityPub</a>
, which means it&rsquo;s part of the Fediverse - a whole network of apps that can all talk to each other.</p>
<p>My website isn&rsquo;t connected yet because I haven&rsquo;t added support for it. I do already have ActivityPub on my Micro.blog account, although it&rsquo;s a little complicated.</p>
<h2 id="microblog">Micro.blog</h2>
<p><a href="https://micro.blog">Micro.blog</a>
 is a microblogging platform with both IndieWeb and Fediverse functionality. I use it at <a href="https://micro.paultibbetts.uk">micro.paultibbetts.uk</a>
 to post shorter content and links to my stuff around the web.</p>
<p>It speaks ActivityPub, so technically you can interact with me at <code>@paultibbetts@micro.blog</code>.</p>
<p>It also has an RSS importer, which I use to posts links from my main site to the Micro.blog timeline, so other users can follow my blog using Micro.blog.</p>
<p>What it does not do, unfortunately, is post those links to ActivityPub.</p>
<p>So I&rsquo;m going to use Micro.blog to cross-post to my own Mastodon account.</p>
<h2 id="bluesky">Bluesky</h2>
<p>So if I&rsquo;m going to check out the Fediverse, and other non-IndieWeb social networks, why not check out Bluesky?</p>
<p>Bluesky is taking a different approach to Mastodon and the rest of the Fediverse.</p>
<p>It does not use ActivityPub, it uses the <a href="https://docs.bsky.app/docs/advanced-guides/atproto">AT Protocol</a>
, something else I don&rsquo;t yet understand or want to add to my own site. So again I&rsquo;m using Micro.blog to cross-post for me.</p>
<h2 id="posse">POSSE</h2>
<p>It&rsquo;s all in an effort to <strong>P</strong>ost to my <strong>O</strong>wn <strong>S</strong>ite and <strong>S</strong>yndicate <strong>E</strong>lsewhere.</p>
<p>I&rsquo;m taking <a href="https://indieweb.org/POSSE">the IndieWeb approach</a>
 and putting my content in one place and then posting links to it in as many places and on as many platforms as I can.</p>
<p>There are more advanced approaches than this, ones where I can pull back comments to my own site, but I&rsquo;m not there just yet.</p>
<p>For now I&rsquo;m building an online presence and testing out the future of social networking.</p>
<h2 id="follow-me">Follow me</h2>
<p>Which changes how you can follow me, again.</p>
<p>You can follow my blog with <a href="https://paultibbetts.uk/feed.xml">RSS</a>
.</p>
<p>You can follow my microblog with <a href="https://micro.paultibbetts.uk/feed.xml">RSS</a>
.</p>
<p>You can follow both using <a href="https://micro.blog/paultibbetts">Micro.blog</a>
, <a href="https://indieweb.social/@paultibbetts">Mastodon</a>
 and <a href="https://bsky.app/profile/paultibbetts.uk">Bluesky</a>
.</p>]]></content:encoded><source:markdown>
We live in strange times, with strange social networks doing strange things.

So why, on the same day I said I was team IndieWeb, did I enter the Fediverse?

&lt;!--more--&gt;

## IndieWeb

I&#39;ve been following the [IndieWeb](https://indieweb.org/) for a decade now and have recently started blogging again, slowly adding IndieWeb features to my site.

Right now it&#39;s readable and followable, a bare minimum website experience, but with a little [webmention](https://indieweb.org/webmention) magic it can grow into something more social. That&#39;s the plan anyway.

I&#39;d be able to write and respond to others on the IndieWeb that also do webmentions.

But not everyone wants to make their own website, or buy into a platform with strange features they don&#39;t understand , so there&#39;s a limit to how social it can really end up being.

## Mastodon

Enter Mastodon, which erupted in popularity when Musk started to ruin Twitter. It&#39;s a decentralised social network that works a bit like Twitter did but without as many nazis.

Mastodon is powered by [ActivityPub](https://activitypub.rocks/), which means it&#39;s part of the Fediverse - a whole network of apps that can all talk to each other.

My website isn&#39;t connected yet because I haven&#39;t added support for it. I do already have ActivityPub on my Micro.blog account, although it&#39;s a little complicated.

## Micro.blog

[Micro.blog](https://micro.blog) is a microblogging platform with both IndieWeb and Fediverse functionality. I use it at [micro.paultibbetts.uk](https://micro.paultibbetts.uk) to post shorter content and links to my stuff around the web.

It speaks ActivityPub, so technically you can interact with me at `@paultibbetts@micro.blog`.

It also has an RSS importer, which I use to posts links from my main site to the Micro.blog timeline, so other users can follow my blog using Micro.blog.

What it does not do, unfortunately, is post those links to ActivityPub.

So I&#39;m going to use Micro.blog to cross-post to my own Mastodon account.

## Bluesky

So if I&#39;m going to check out the Fediverse, and other non-IndieWeb social networks, why not check out Bluesky?

Bluesky is taking a different approach to Mastodon and the rest of the Fediverse.

It does not use ActivityPub, it uses the [AT Protocol](https://docs.bsky.app/docs/advanced-guides/atproto), something else I don&#39;t yet understand or want to add to my own site. So again I&#39;m using Micro.blog to cross-post for me.

## POSSE

It&#39;s all in an effort to **P**ost to my **O**wn **S**ite and **S**yndicate **E**lsewhere.

I&#39;m taking [the IndieWeb approach](https://indieweb.org/POSSE) and putting my content in one place and then posting links to it in as many places and on as many platforms as I can.

There are more advanced approaches than this, ones where I can pull back comments to my own site, but I&#39;m not there just yet.

For now I&#39;m building an online presence and testing out the future of social networking.

## Follow me

Which changes how you can follow me, again.

You can follow my blog with [RSS](https://paultibbetts.uk/feed.xml).

You can follow my microblog with [RSS](https://micro.paultibbetts.uk/feed.xml).

You can follow both using [Micro.blog](https://micro.blog/paultibbetts), [Mastodon](https://indieweb.social/@paultibbetts) and [Bluesky](https://bsky.app/profile/paultibbetts.uk).
</source:markdown></item><item>
      <title>Getting My Own Site</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/09/getting-my-own-site/</link>
      <pubDate>Tue, 09 Sep 2025 20:00:00 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/09/getting-my-own-site/</guid>
      <category>IndieWeb</category>
      <category>meta</category>
      <description>The second step to getting on the IndieWeb is to have your own site.
This is easier said than done, and there are lots of different ways of doing it.
This is what I did.</description>
      <content:encoded><![CDATA[<p>The second step to <a href="https://indieweb.org/Getting_Started">getting on the IndieWeb</a>
 is to have your own site.</p>
<p>This is easier said than done, and there are lots of different ways of doing it.</p>
<p>This is what I did.</p>
<h2 id="as-a-web-developer">As a web developer</h2>
<p>There are three paths to getting your own site.</p>
<h3 id="service">Service</h3>
<p>You could use an existing service like <a href="https://micro.blog/">Micro.blog</a>
 to host your site.</p>
<p>I already do this for my <a href="https://micro.paultibbetts.uk/">microblog</a>
 because it comes with a bunch of features out of the box and gets me onto the IndieWeb, even while I don&rsquo;t yet support all the IndieWeb features on my main site.</p>
<h3 id="cms">CMS</h3>
<p>An alternative path is to use an existing content management system and add on IndieWeb features with plugins.</p>
<p>I&rsquo;ve done this in the past with <a href="https://wordpress.org/">WordPress</a>
 but I moved on from the WordPress world a while ago.</p>
<h3 id="self-starter">Self-starter</h3>
<p>I decided I was more comfortable writing and doing it myself.</p>
<h2 id="what-it-needs-to-do">What it needs to do</h2>
<p>Before I wrote any code I made sure to cover the basics.</p>
<h3 id="information-about-me">Information about me</h3>
<p>The homepage of my site needs to include a <a href="https://indieweb.org/h-card">h-card</a>
 with my name, an icon, and <a href="https://indieweb.org/rel-me">rel-me</a>
 links to my social network profiles.</p>
<p>This is not only useful for humans but I can also use it to sign in to other sites using <a href="https://indieweb.org/IndieAuth">IndieAuth</a>
.</p>
<p>I used <a href="https://indiewebify.me/">IndieWebify.me</a>
 to check I&rsquo;d done it correctly.</p>
<h3 id="publish-content">Publish content</h3>
<p>My posts should be marked up using <a href="https://indieweb.org/h-entry">h-entry</a>
 so that others can understand my content.</p>
<p>The original site design had words with titles, which makes them technically &ldquo;articles&rdquo;, although that could change in the fture.</p>
<h2 id="how-the-site-works">How the site works</h2>
<p>There are lots of different ways to do this.</p>
<p>In fact there are too many, so I kept it as simple as I could.</p>
<h3 id="static-site-generator">Static site generator</h3>
<p>I want to write my content in <a href="https://www.markdownguide.org/">Markdown</a>
, I would prefer doing that on my laptop instead of my phone, and I&rsquo;m ok running commands to publish things.</p>
<p>Which means I can use a <a href="https://en.wikipedia.org/wiki/Static_site_generator">static site generator</a>
 like <a href="https://gohugo.io">Hugo</a>
 to turn my markdown files into HTML.</p>
<h2 id="hosting">Hosting</h2>
<p>One of the best parts about using a static site generator is that it makes hosting simpler.</p>
<p>Once you have generated a static site you can upload the files to a web host and you&rsquo;re done.</p>
<p>And you can automate it, so all you do is update it and it gets deployed automatically.</p>
<h3 id="github-pages">GitHub pages</h3>
<p>I host copies of my code on GitHub so that others can view the source and I was planning on doing the same with my site.</p>
<p>This meant I could use one of GitHub&rsquo;s other features, which is <a href="https://pages.github.com/">free hosting for static content</a>
.</p>
<p>All I would need to do is add a <a href="https://github.com/paultibbetts/paultibbetts.uk/blob/a24aa42e17d0b8f059d9f12118fd69147b3fa12b/.github/workflows/hugo.yaml">workflow</a>
 for GitHub Actions to perform each time the code gets updated and the site gets deployed automatically.</p>
<h2 id="indiemark">IndieMark</h2>
<p>There&rsquo;s no official measure of a site&rsquo;s &ldquo;IndieWebness&rdquo; but the closest right now is the still-in-development <a href="https://indieweb.org/IndieMark">IndieMark</a>
 which would score me a level 1.</p>
<p>Level 0 involves owning your own domain, something I have <a href="https://paultibbetts.uk/2025/09/09/getting-my-own-domain/">written about before</a>
, and having a personal site at that domain.</p>
<p>Level 1 involves:</p>
<ul>
<li><strong>identity</strong>, I&rsquo;ll be using this at my primary domain</li>
<li><strong>authentication</strong> using <a href="https://indieweb.org/rel-me">rel-me</a>
 links to my external social network profiles</li>
<li><strong>posts</strong> with <strong>permalinks</strong>, <strong>h-entry</strong> markup and other <strong>microformats</strong></li>
<li><strong>searchable</strong> by <strong>allowing robots to index my site</strong>, my <strong>content is written in HTML</strong> and <strong>no JavaScript is required to read it</strong></li>
</ul>
<h2 id="view-source">View source</h2>
<p>You can <a href="https://github.com/paultibbetts/paultibbetts.uk">view the source code</a>
 to see how I&rsquo;ve abused Hugo and <a href="https://tailwindcss.com/">TailwindCSS</a>
 into creating my own site, hosted on GitHub Pages.</p>]]></content:encoded><source:markdown>
The second step to [getting on the IndieWeb](https://indieweb.org/Getting_Started) is to have your own site.

This is easier said than done, and there are lots of different ways of doing it.

This is what I did.

&lt;!--more--&gt;

## As a web developer

There are three paths to getting your own site.

### Service

You could use an existing service like [Micro.blog](https://micro.blog/) to host your site.

I already do this for my [microblog](https://micro.paultibbetts.uk/) because it comes with a bunch of features out of the box and gets me onto the IndieWeb, even while I don&#39;t yet support all the IndieWeb features on my main site.

### CMS

An alternative path is to use an existing content management system and add on IndieWeb features with plugins.

I&#39;ve done this in the past with [WordPress](https://wordpress.org/) but I moved on from the WordPress world a while ago.

### Self-starter

I decided I was more comfortable writing and doing it myself.

## What it needs to do

Before I wrote any code I made sure to cover the basics.

### Information about me

The homepage of my site needs to include a [h-card](https://indieweb.org/h-card) with my name, an icon, and [rel-me](https://indieweb.org/rel-me) links to my social network profiles.

This is not only useful for humans but I can also use it to sign in to other sites using [IndieAuth](https://indieweb.org/IndieAuth).

I used [IndieWebify.me](https://indiewebify.me/) to check I&#39;d done it correctly.

### Publish content

My posts should be marked up using [h-entry](https://indieweb.org/h-entry) so that others can understand my content.

The original site design had words with titles, which makes them technically &#34;articles&#34;, although that could change in the fture.

## How the site works

There are lots of different ways to do this.

In fact there are too many, so I kept it as simple as I could.

### Static site generator

I want to write my content in [Markdown](https://www.markdownguide.org/), I would prefer doing that on my laptop instead of my phone, and I&#39;m ok running commands to publish things.

Which means I can use a [static site generator](https://en.wikipedia.org/wiki/Static_site_generator) like [Hugo](https://gohugo.io) to turn my markdown files into HTML.

## Hosting

One of the best parts about using a static site generator is that it makes hosting simpler.

Once you have generated a static site you can upload the files to a web host and you&#39;re done.

And you can automate it, so all you do is update it and it gets deployed automatically.

### GitHub pages

I host copies of my code on GitHub so that others can view the source and I was planning on doing the same with my site.

This meant I could use one of GitHub&#39;s other features, which is [free hosting for static content](https://pages.github.com/).

All I would need to do is add a [workflow](https://github.com/paultibbetts/paultibbetts.uk/blob/a24aa42e17d0b8f059d9f12118fd69147b3fa12b/.github/workflows/hugo.yaml) for GitHub Actions to perform each time the code gets updated and the site gets deployed automatically.

## IndieMark

There&#39;s no official measure of a site&#39;s &#34;IndieWebness&#34; but the closest right now is the still-in-development [IndieMark](https://indieweb.org/IndieMark) which would score me a level 1.

Level 0 involves owning your own domain, something I have [written about before](https://paultibbetts.uk/2025/09/09/getting-my-own-domain/), and having a personal site at that domain.

Level 1 involves:

- **identity**, I&#39;ll be using this at my primary domain
- **authentication** using [rel-me](https://indieweb.org/rel-me) links to my external social network profiles
- **posts** with **permalinks**, **h-entry** markup and other **microformats**
- **searchable** by **allowing robots to index my site**, my **content is written in HTML** and **no JavaScript is required to read it**

## View source

You can [view the source code](https://github.com/paultibbetts/paultibbetts.uk) to see how I&#39;ve abused Hugo and [TailwindCSS](https://tailwindcss.com/) into creating my own site, hosted on GitHub Pages.
</source:markdown></item><item>
      <title>Getting My Own Domain</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/09/getting-my-own-domain/</link>
      <pubDate>Tue, 09 Sep 2025 15:53:46 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/09/getting-my-own-domain/</guid>
      <category>IndieWeb</category>
      <category>meta</category>
      <description>The first step to getting on the IndieWeb is to have your own domain.
I’ve already got one, so I thought I’d explain how I got it.</description>
      <content:encoded><![CDATA[<p>The first step to <a href="https://indieweb.org/Getting_Started">getting on the IndieWeb</a>
 is to have your own domain.</p>
<p>I&rsquo;ve already got one, so I thought I&rsquo;d explain how I got it.</p>
<h2 id="ruler">Ruler</h2>
<p>Years ago I registered my name as my domain.</p>
<p>I&rsquo;m not a company, so I didn&rsquo;t want <code>.com</code>, but there weren&rsquo;t many options, and so to make me &ldquo;Paul Tibbetts from the UK&rdquo; I went with <code>.co.uk</code>.</p>
<p>Some time later <code>.uk</code> was made available and to make it fair to the <code>.co.uk</code> owners who wanted to drop the <code>.co</code> you had to also own the <code>.co.uk</code> version to register it, so for a while I owned both.</p>
<p>This was all before the newer extensions like <code>.blog</code> and <code>.dev</code> came out. When they did I considered changing but decided against it.</p>
<h2 id="registrar">Registrar</h2>
<p>I registered my domain with <a href="https://www.heartinternet.uk/">Heart Internet</a>
 because that&rsquo;s who we used at work and I didn&rsquo;t have any kind of preference.</p>
<p>They don&rsquo;t expose my personal data when you run a <a href="https://www.whois.com/whois/paultibbetts.uk">whois query on the domain</a>
 so I haven&rsquo;t found a reason to move away from them.</p>
<p>Renewals are £9.99 per year.</p>
<h2 id="management">Management</h2>
<p>For a while I managed the domain using the interface on Heart Internet but since then I&rsquo;ve moved it to <a href="https://www.cloudflare.com/">Cloudflare</a>
.</p>
<p>To do this I changed the nameservers that the domain uses from Heart Internet&rsquo;s to Cloudflare&rsquo;s.</p>
<h2 id="records">Records</h2>
<p>There aren&rsquo;t that many records right now.</p>
<h3 id="heading">@</h3>
<p>The apex domain, as in the bare one without any subdomains (<code>https://paultibbetts.uk</code>), points to a really small landing page I made for myself.</p>
<p>I&rsquo;ll be redoing this soon so I won&rsquo;t talk about it yet.</p>
<h3 id="www">www</h3>
<p>I <strong>don&rsquo;t</strong> use the <code>www</code> subdomain.</p>
<p>I know there are people who think this is wrong but growing up sharing links with others the moment I discovered you could get rid of it I did and haven&rsquo;t looked back.</p>
<p>Maybe one day I will revisit this.</p>
<h3 id="micro">micro</h3>
<p><code>micro.paultibbetts.uk</code> is powered by <a href="https://micro.blog">Micro.blog</a>
.</p>
<p>I <em>could</em> run my main domain with Micro.blog but I want to have a go at doing that myself.</p>
<p>I followed <a href="https://help.micro.blog/t/custom-domain-names/53">the Micro.blog guide to set up a custom domain</a>
 and used a <code>CNAME</code> on my domain to point <code>micro</code> to <code>https://paultibbetts.micro.blog</code>.</p>
<h2 id="emails">Emails</h2>
<p>Once upon a time I hosted my own email server.</p>
<p>The company I worked at, Sixth Story, had an email address <code>iwanttowork @ sixthstory</code> that I thought was clever, so I wanted <code>hire @ paultibbetts</code> for myself. Applying for jobs as a web developer I thought it would help me stand out.</p>
<p>Even after all the work though I still found myself using my regular Apple email address because I knew it was more stable, and less likely to get marked as spam, so when Apple announced <a href="https://support.apple.com/en-us/102540">you can use custom domains with iCloud mail</a>
 I got rid of my email server and used Apple&rsquo;s instead.</p>
<p>This means I have some <code>MX</code> and <code>TXT</code> records to allow that to work.</p>
<h2 id="in-review">In review</h2>
<p>I have always been jealous of others with better domains than me.</p>
<h3 id="difficult-to-spell">Difficult to spell</h3>
<p>I have trouble getting people to spell my surname correctly.</p>
<p>I don&rsquo;t blame them, there&rsquo;s lots of Bs and Ts, and saying &ldquo;technically there&rsquo;s 3 Ts&rdquo; isn&rsquo;t helpful when they&rsquo;re typing the double T towards the end.</p>
<h4 id="potential-fix">Potential fix</h4>
<p>Aral&rsquo;s <code>ar.al</code> domain is much better than mine. It&rsquo;s short and easy to spell.</p>
<p>Maybe I could find a short domain and set it up to redirect?</p>
<p>Time for another disappointing trip to <a href="https://iwantmyname.com/">IWantMyName</a>
 to see all the good domains have been taken.</p>
<h3 id="did-you-mean-the-other-one">Did you mean the other one?</h3>
<p>I share a name with someone way more famous than me.</p>
<p>It&rsquo;s spelt a little different but search engines will assume you meant the other Paul.</p>
<h4 id="potential-fix-1">Potential fix</h4>
<p>There are a few ways I can improve my search engine rankings.</p>
<p>I&rsquo;m going to try writing lots of content to go on my domain, hoping that does it.</p>
<p>I will <strong>not</strong> do what the other guy did.</p>
<h3 id="dot-uk">dot UK</h3>
<p>My <code>.uk</code> address works whilst I live here but it wouldn&rsquo;t if I moved.</p>
<h4 id="potential-fix-2">Potential fix</h4>
<p>I don&rsquo;t have any immediate plans to move abroad so I&rsquo;m not too concerned with this.</p>
<p>If I ever did I can setup redirects.</p>
<h3 id="not-a-cool-internet-name">Not a cool internet name</h3>
<p>Jeremy Keith&rsquo;s <code>adactio.com</code> domain regularly reminds me I&rsquo;m not creative enough to come up with a cool internet name.</p>
<h4 id="potential-fix-3">Potential fix</h4>
<p>Maybe another decade of thinking about it will help.</p>
<h2 id="reposted">Reposted</h2>
<p>This was originally posted on my <a class="u-repost-of" href="https://micro.paultibbetts.uk/2025/01/02/getting-my-own-domain.html">microblog</a> before this site existed and I wanted a copy of it here.</p>]]></content:encoded><source:markdown>
The first step to [getting on the IndieWeb](https://indieweb.org/Getting_Started) is to have your own domain.

I&#39;ve already got one, so I thought I&#39;d explain how I got it.

&lt;!--more--&gt;

## Ruler

Years ago I registered my name as my domain.

I&#39;m not a company, so I didn&#39;t want `.com`, but there weren&#39;t many options, and so to make me &#34;Paul Tibbetts from the UK&#34; I went with `.co.uk`.

Some time later `.uk` was made available and to make it fair to the `.co.uk` owners who wanted to drop the `.co` you had to also own the `.co.uk` version to register it, so for a while I owned both.

This was all before the newer extensions like `.blog` and `.dev` came out. When they did I considered changing but decided against it.

## Registrar

I registered my domain with [Heart Internet](https://www.heartinternet.uk/) because that&#39;s who we used at work and I didn&#39;t have any kind of preference.

They don&#39;t expose my personal data when you run a [whois query on the domain](https://www.whois.com/whois/paultibbetts.uk) so I haven&#39;t found a reason to move away from them.

Renewals are £9.99 per year.

## Management

For a while I managed the domain using the interface on Heart Internet but since then I&#39;ve moved it to [Cloudflare](https://www.cloudflare.com/).

To do this I changed the nameservers that the domain uses from Heart Internet&#39;s to Cloudflare&#39;s.

## Records

There aren&#39;t that many records right now.

### @

The apex domain, as in the bare one without any subdomains (`https://paultibbetts.uk`), points to a really small landing page I made for myself.

I&#39;ll be redoing this soon so I won&#39;t talk about it yet.

### www

I **don&#39;t** use the `www` subdomain.

I know there are people who think this is wrong but growing up sharing links with others the moment I discovered you could get rid of it I did and haven&#39;t looked back.

Maybe one day I will revisit this.

### micro

`micro.paultibbetts.uk` is powered by [Micro.blog](https://micro.blog).

I _could_ run my main domain with Micro.blog but I want to have a go at doing that myself.

I followed [the Micro.blog guide to set up a custom domain](https://help.micro.blog/t/custom-domain-names/53) and used a `CNAME` on my domain to point `micro` to `https://paultibbetts.micro.blog`.

## Emails

Once upon a time I hosted my own email server.

The company I worked at, Sixth Story, had an email address `iwanttowork @ sixthstory` that I thought was clever, so I wanted `hire @ paultibbetts` for myself. Applying for jobs as a web developer I thought it would help me stand out.

Even after all the work though I still found myself using my regular Apple email address because I knew it was more stable, and less likely to get marked as spam, so when Apple announced [you can use custom domains with iCloud mail](https://support.apple.com/en-us/102540) I got rid of my email server and used Apple&#39;s instead.

This means I have some `MX` and `TXT` records to allow that to work.

## In review

I have always been jealous of others with better domains than me.

### Difficult to spell

I have trouble getting people to spell my surname correctly.

I don&#39;t blame them, there&#39;s lots of Bs and Ts, and saying &#34;technically there&#39;s 3 Ts&#34; isn&#39;t helpful when they&#39;re typing the double T towards the end.

#### Potential fix

Aral&#39;s `ar.al` domain is much better than mine. It&#39;s short and easy to spell.

Maybe I could find a short domain and set it up to redirect?

Time for another disappointing trip to [IWantMyName](https://iwantmyname.com/) to see all the good domains have been taken.

### Did you mean the other one?

I share a name with someone way more famous than me.

It&#39;s spelt a little different but search engines will assume you meant the other Paul.

#### Potential fix

There are a few ways I can improve my search engine rankings.

I&#39;m going to try writing lots of content to go on my domain, hoping that does it.

I will **not** do what the other guy did.

### dot UK

My `.uk` address works whilst I live here but it wouldn&#39;t if I moved.

#### Potential fix

I don&#39;t have any immediate plans to move abroad so I&#39;m not too concerned with this.

If I ever did I can setup redirects.

### Not a cool internet name

Jeremy Keith&#39;s `adactio.com` domain regularly reminds me I&#39;m not creative enough to come up with a cool internet name.

#### Potential fix

Maybe another decade of thinking about it will help.

## Reposted

This was originally posted on my &lt;a class=&#34;u-repost-of&#34; href=&#34;https://micro.paultibbetts.uk/2025/01/02/getting-my-own-domain.html&#34;&gt;microblog&lt;/a&gt; before this site existed and I wanted a copy of it here.
</source:markdown></item><item>
      <title>IndieWeb: Why</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/09/indieweb-why/</link>
      <pubDate>Tue, 09 Sep 2025 15:50:00 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/09/09/indieweb-why/</guid>
      <category>IndieWeb</category>
      <description>The IndieWeb is a people-focused alternative to the “corporate web”.
I’ve been a believer for over a decade.
Here’s why.</description>
      <content:encoded><![CDATA[<p>The <a href="https://indieweb.org/">IndieWeb</a>
 is a people-focused alternative to the &ldquo;corporate web&rdquo;.</p>
<p>I&rsquo;ve been a believer for over a decade.</p>
<p>Here&rsquo;s why.</p>
<h2 id="i-own-my-data">I own my data</h2>
<p>I used to use the social networks. They&rsquo;d make money from me being there, and that was my price of admission. Everybody did it. It was normal.</p>
<p>Except it isn&rsquo;t normal, and it shouldn&rsquo;t be thought of as normal.</p>
<p>We gave up our ownership for ease of use, and I think that&rsquo;s wrong.</p>
<p>The IndieWeb puts content ownership first.</p>
<h2 id="i-am-better-connected">I am better connected</h2>
<p>Since Musk bought Twitter I haven&rsquo;t been able to view any tweets on my phone. It complains about me using an adblocker and refuses to load the page, even though I&rsquo;m not using one.</p>
<p>I left Instagram before they stopped letting you include links in your posts.</p>
<p>And I&rsquo;ve ran out of free Medium articles to read this month, so I can&rsquo;t read your latest post on that platform.</p>
<p>But I&rsquo;ve never had a problem using other people&rsquo;s personal sites.</p>
<p>Everyone else being on the IndieWeb helps me, so I do the same for them.</p>
<h2 id="i-am-in-control">I am in control</h2>
<p>On the IndieWeb it&rsquo;s up to me to choose how I&rsquo;m represented online and what gets made available.</p>
<p>Which is how the web should be.</p>
<h2 id="i-want-the-web-to-be-more-open">I want the web to be more open</h2>
<p>The web was built on openness. Anyone could publish a page and send it to others.</p>
<p>Since then it&rsquo;s consolidated into a handful of platforms that dictate how things happen and how posts get seen, if they get seen at all.</p>
<p>Which means the IndieWeb is more than having your own site, it&rsquo;s a movement, to restore the web&rsquo;s original promise: to be a network that connects people.</p>
<h2 id="if-you-agree">If you agree</h2>
<p><a href="https://indieweb.org/Getting_Started">Here&rsquo;s how you can join in</a>
.</p>]]></content:encoded><source:markdown>
The [IndieWeb](https://indieweb.org/) is a people-focused alternative to the &#34;corporate web&#34;.

I&#39;ve been a believer for over a decade.

Here&#39;s why.

&lt;!--more--&gt;

## I own my data

I used to use the social networks. They&#39;d make money from me being there, and that was my price of admission. Everybody did it. It was normal.

Except it isn&#39;t normal, and it shouldn&#39;t be thought of as normal.

We gave up our ownership for ease of use, and I think that&#39;s wrong.

The IndieWeb puts content ownership first.

## I am better connected

Since Musk bought Twitter I haven&#39;t been able to view any tweets on my phone. It complains about me using an adblocker and refuses to load the page, even though I&#39;m not using one.

I left Instagram before they stopped letting you include links in your posts.

And I&#39;ve ran out of free Medium articles to read this month, so I can&#39;t read your latest post on that platform.

But I&#39;ve never had a problem using other people&#39;s personal sites.

Everyone else being on the IndieWeb helps me, so I do the same for them.

## I am in control

On the IndieWeb it&#39;s up to me to choose how I&#39;m represented online and what gets made available.

Which is how the web should be.

## I want the web to be more open

The web was built on openness. Anyone could publish a page and send it to others.

Since then it&#39;s consolidated into a handful of platforms that dictate how things happen and how posts get seen, if they get seen at all.

Which means the IndieWeb is more than having your own site, it&#39;s a movement, to restore the web&#39;s original promise: to be a network that connects people.

## If you agree

[Here&#39;s how you can join in](https://indieweb.org/Getting_Started).
</source:markdown></item><item>
      <title>Developer Environment Setup</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/07/07/developer-environment-setup/</link>
      <pubDate>Mon, 07 Jul 2025 16:36:59 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/07/07/developer-environment-setup/</guid>
      <category>dev-env</category>
      <category>digital garden</category>
      <description>I’ve pushed my developer environment setup scripts up to GitHub, and now they have their own little website to go with them.</description>
      <content:encoded><![CDATA[<p>I&rsquo;ve pushed my developer environment setup scripts up to GitHub, and now they have their own little website to go with them.</p>
<h2 id="dotfiles">Dotfiles</h2>
<p>Dotfiles are the files on your system that are hidden by default, which is done by adding a <code>.</code> in front of the name, hence &ldquo;dotfiles&rdquo;.</p>
<p>They&rsquo;re used for settings and preferences and between them they configure your system just the way you like it. They are arguably the most important part of a developer setup.</p>
<p>Lots of developers will store their dotfiles on GitHub, and <a href="https://dotfiles.github.io/bootstrap/">GitHub has a little site</a>
 telling you why and how to do so.</p>
<p>But they aren&rsquo;t enough to setup the whole system. What use is a dotfile that tells Git I want to use a certain tool for looking at diffs if that tool isn&rsquo;t even installed?</p>
<p>So together with my dotfiles are my setup scripts. They install the tools that the dotfiles reference and then they install the dotfiles. Between them my developer environment is prepared and ready to use.</p>
<h2 id="sharing-on-github">Sharing on GitHub</h2>
<p>I&rsquo;ve pushed my setup scripts up to GitHub. This is both a backup, in case I lose my local copy, and also part of the installation process.</p>
<p>If I had to setup a new machine from scratch I can download the install script from GitHub and use it to install the rest of the scripts. The script itself pulls other files down from GitHub, so it needs to be publicly available for me to do that.</p>
<p>But I also did it because I learnt so much about setting up my developer environment from other people sharing their setups and I wanted to do the same.</p>
<p>Usually it&rsquo;s just the code itself that&rsquo;s shared, since most devs will skip the readme and go straight to the code, but I added a little website as an experiment.</p>
<h2 id="digital-garden">Digital Garden</h2>
<p>The main reason I created a website for my scripts was to test out <a href="https://astro.build/">Astro</a>
 and <a href="https://starlight.astro.build/">Starlight</a>
 for creating documentation sites. It was pretty easy, and I liked the result, so I will most likely use them for something like this again in the future.</p>
<p>The other reason was to plant a seed in my digital garden.</p>
<p>Digital gardens are a bit like blogs, except they aren&rsquo;t usually sorted by date. They&rsquo;re more like notebooks that you share publicly. You might even go back to your notes and refine them over time, growing them from seedlings to full blown&hellip; idea bushes? I don&rsquo;t know what to call them. Some people call them trees, which can grow fruit. That sounds good. Let&rsquo;s go with that.</p>
<p>So the site is a seedbed in my digital garden. It&rsquo;s a place for me to share my notes on developer environment setups and dotfiles and stuff. It&rsquo;s not a project I want other people to use, in fact I&rsquo;ll probably write up what the alternatives are and which one you should pick instead of mine.</p>
<h2 id="seedling-">Seedling <span aria-hidden="true">🌱</span></h2>
<p>If you&rsquo;re curious you can <a href="https://dev.paultibbetts.uk/">check it out</a>
.</p>
<p>It&rsquo;s just a seedling right now, but who knows, maybe I can grow it into something fruitful.</p>]]></content:encoded><source:markdown>
I&#39;ve pushed my developer environment setup scripts up to GitHub, and now they have their own little website to go with them.

&lt;!--more--&gt;

## Dotfiles

Dotfiles are the files on your system that are hidden by default, which is done by adding a `.` in front of the name, hence &#34;dotfiles&#34;.

They&#39;re used for settings and preferences and between them they configure your system just the way you like it. They are arguably the most important part of a developer setup.

Lots of developers will store their dotfiles on GitHub, and [GitHub has a little site](https://dotfiles.github.io/bootstrap/) telling you why and how to do so.

But they aren&#39;t enough to setup the whole system. What use is a dotfile that tells Git I want to use a certain tool for looking at diffs if that tool isn&#39;t even installed?

So together with my dotfiles are my setup scripts. They install the tools that the dotfiles reference and then they install the dotfiles. Between them my developer environment is prepared and ready to use.

## Sharing on GitHub

I&#39;ve pushed my setup scripts up to GitHub. This is both a backup, in case I lose my local copy, and also part of the installation process.

If I had to setup a new machine from scratch I can download the install script from GitHub and use it to install the rest of the scripts. The script itself pulls other files down from GitHub, so it needs to be publicly available for me to do that.

But I also did it because I learnt so much about setting up my developer environment from other people sharing their setups and I wanted to do the same.

Usually it&#39;s just the code itself that&#39;s shared, since most devs will skip the readme and go straight to the code, but I added a little website as an experiment.

## Digital Garden

The main reason I created a website for my scripts was to test out [Astro](https://astro.build/) and [Starlight](https://starlight.astro.build/) for creating documentation sites. It was pretty easy, and I liked the result, so I will most likely use them for something like this again in the future.

The other reason was to plant a seed in my digital garden.

Digital gardens are a bit like blogs, except they aren&#39;t usually sorted by date. They&#39;re more like notebooks that you share publicly. You might even go back to your notes and refine them over time, growing them from seedlings to full blown... idea bushes? I don&#39;t know what to call them. Some people call them trees, which can grow fruit. That sounds good. Let&#39;s go with that.

So the site is a seedbed in my digital garden. It&#39;s a place for me to share my notes on developer environment setups and dotfiles and stuff. It&#39;s not a project I want other people to use, in fact I&#39;ll probably write up what the alternatives are and which one you should pick instead of mine.

## Seedling &lt;span aria-hidden=&#34;true&#34;&gt;🌱&lt;/span&gt;

If you&#39;re curious you can [check it out](https://dev.paultibbetts.uk/).

It&#39;s just a seedling right now, but who knows, maybe I can grow it into something fruitful.
</source:markdown></item><item>
      <title>Take Two</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/30/take-two/</link>
      <pubDate>Mon, 30 Jun 2025 21:31:09 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/30/take-two/</guid>
      <category>IndieWeb Carnival</category>
      <description>June’s IndieWeb Carnival prompt is “Take Two” and there’s a hundred different ways I could join in on this.
So here’s my first post joining in with an IndieWeb Carnival; Take Two.</description>
      <content:encoded><![CDATA[<p>June&rsquo;s <a href="https://indieweb.org/indieweb-carnival">IndieWeb Carnival</a>
 prompt is <a href="https://www.nicksimson.com/posts/2025-indieweb-carnival-take-two.html">&ldquo;Take Two&rdquo;</a>
 and there&rsquo;s a hundred different ways I could join in on this.</p>
<p>So here&rsquo;s my first post joining in with an IndieWeb Carnival; Take Two.</p>
<h2 id="regrets">Regrets?</h2>
<p>Right off the bat I&rsquo;ll say yes, there are plenty of things I&rsquo;d have liked a second take at.</p>
<p>I don&rsquo;t see this as bad, to me this is growth. Looking back on something and seeing how you could have done it better shows wisdom and maturity.</p>
<p>It&rsquo;d be easy to get stuck here though, wallowing in sadness and longing for what you could have had, so you have to accept it as take one and move on, which is the theme I&rsquo;ll be sticking with for this post.</p>
<h2 id="take-two-with-tech">Take Two with Tech</h2>
<p>I have a friend who wants to get into tech. They&rsquo;ve tried before, and it didn&rsquo;t stick, so this is their take two, and I want to let them know I&rsquo;m proud of them for coming back.</p>
<p>It isn&rsquo;t easy changing careers, or even considering it, when you have bills to pay and a lifestyle to maintain, but with tech it&rsquo;s possible.</p>
<p>I&rsquo;d even say a second take in tech is encouraged. Let&rsquo;s look at Apple for a second. They didn&rsquo;t invent the MP3 player, but they had a very popular second take on it.</p>
<p>First impressions matter and all that, but I think what counts in tech is the second take, and then the third, and all the improvements that reveal themselves with each iteration. My dad would probably include a reference here to WD-40 and the 39 complete and utter failures that came before it.</p>
<h2 id="personal-takes">Personal Takes</h2>
<p>You&rsquo;re reading this on take <del>seven</del> two of my blog, something that could have been running for 10 years if I had stuck at it when I started it.</p>
<p>I&rsquo;m no better with <a href="https://micro.paultibbetts.uk">microblogging</a>
, which constantly feels like take two for me. My &ldquo;how I got my website online&rdquo; series stalled after the first post and needs redoing.</p>
<p>This week I am finishing off some work I started last week. It was only meant to take a few days, but I didn&rsquo;t know what I was doing, so I had to make something just to find out what it was I was meant to be making in the first place.</p>
<p>All this whilst taking a second break from work. I tried it last year, went back to my job and then proceeded to burn myself out all over again.</p>
<p>So here I am, a year later, Taking a Break From Work and Switching Things Up: Take Two.</p>
<h2 id="kaizen-改善">Kaizen (改善)</h2>
<p>So it&rsquo;s on to the next iteration.</p>
<p>And then the next.</p>
<p>As long as I&rsquo;m continuously learning, always aiming to do better, that&rsquo;s ok with me.</p>]]></content:encoded><source:markdown>
June&#39;s [IndieWeb Carnival](https://indieweb.org/indieweb-carnival) prompt is [&#34;Take Two&#34;](https://www.nicksimson.com/posts/2025-indieweb-carnival-take-two.html) and there&#39;s a hundred different ways I could join in on this.

So here&#39;s my first post joining in with an IndieWeb Carnival; Take Two.

&lt;!--more--&gt;

## Regrets?

Right off the bat I&#39;ll say yes, there are plenty of things I&#39;d have liked a second take at.

I don&#39;t see this as bad, to me this is growth. Looking back on something and seeing how you could have done it better shows wisdom and maturity.

It&#39;d be easy to get stuck here though, wallowing in sadness and longing for what you could have had, so you have to accept it as take one and move on, which is the theme I&#39;ll be sticking with for this post.

## Take Two with Tech

I have a friend who wants to get into tech. They&#39;ve tried before, and it didn&#39;t stick, so this is their take two, and I want to let them know I&#39;m proud of them for coming back.

It isn&#39;t easy changing careers, or even considering it, when you have bills to pay and a lifestyle to maintain, but with tech it&#39;s possible.

I&#39;d even say a second take in tech is encouraged. Let&#39;s look at Apple for a second. They didn&#39;t invent the MP3 player, but they had a very popular second take on it.

First impressions matter and all that, but I think what counts in tech is the second take, and then the third, and all the improvements that reveal themselves with each iteration. My dad would probably include a reference here to WD-40 and the 39 complete and utter failures that came before it.

## Personal Takes

You&#39;re reading this on take ~~seven~~ two of my blog, something that could have been running for 10 years if I had stuck at it when I started it.

I&#39;m no better with [microblogging](https://micro.paultibbetts.uk), which constantly feels like take two for me. My &#34;how I got my website online&#34; series stalled after the first post and needs redoing.

This week I am finishing off some work I started last week. It was only meant to take a few days, but I didn&#39;t know what I was doing, so I had to make something just to find out what it was I was meant to be making in the first place.

All this whilst taking a second break from work. I tried it last year, went back to my job and then proceeded to burn myself out all over again.

So here I am, a year later, Taking a Break From Work and Switching Things Up: Take Two.

## Kaizen (改善)

So it&#39;s on to the next iteration.

And then the next.

As long as I&#39;m continuously learning, always aiming to do better, that&#39;s ok with me.
</source:markdown></item><item>
      <title>Homelab V1</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/13/homelab-v1/</link>
      <pubDate>Fri, 13 Jun 2025 16:00:00 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/13/homelab-v1/</guid>
      <category>homelab</category>
      <description>My Homelab has hit its first milestone 🚀</description>
      <content:encoded><![CDATA[<p>My Homelab has hit its first milestone 🚀</p>
<h2 id="cloud">Cloud</h2>
<p>The biggest problem with my homelab was that I kept breaking it.</p>
<p>I couldn&rsquo;t get used to using <a href="https://mealie.io/">mealie</a>
 as a meal planner because I would go to use it and it didn&rsquo;t work. Or it did, but I couldn&rsquo;t connect to it properly. Or something else went wrong.</p>
<p>So for my first &ldquo;release&rdquo; I aimed for a &ldquo;cloud&rdquo;. Some people call it &ldquo;HomeProd&rdquo;.</p>
<p>I used things I was used to, and a few things I wasn&rsquo;t, to make a simple, stable platform on which I could host my <em>actual</em> homelab.</p>
<p>Here&rsquo;s what&rsquo;s in it:</p>
<h3 id="nas">NAS</h3>
<p>I have a machine dedicated to running <a href="https://www.truenas.com/truenas-scale/">TrueNAS Scale</a>
.</p>
<p>I bought the hype that I needed <a href="https://www.truenas.com/docs/scale/gettingstarted/scalehardwareguide/">ECC RAM</a>
 so that my data would be safe and so I also needed a server-grade processor, which meant a server-grade motherboard, and all the other bits to go with it.</p>
<p>At the time Scale had built-in Kubernetes so I used TrueCharts to set up some apps. And then they stopped working. And then there were all the updates with breaking changes. And then I got fed up.</p>
<p>This was meant to be a machine that did storage and I didn&rsquo;t want to mess with it.</p>
<p>The TrueNAS devs thought the same thing and took out Kubernetes and replaced it with Docker, so I updated to follow and now I only run two storage apps on it.</p>
<h4 id="usage">Usage</h4>
<ul>
<li><strong>file storage</strong> over <strong>NFS</strong> to Linux and Mac and <strong>SMB</strong> for Windows</li>
<li><strong>object storage</strong> via <a href="https://min.io">MinIO</a>
 installed as a Docker container</li>
<li><strong>backups</strong> for virtual machines via <a href="https://www.proxmox.com/en/products/proxmox-backup-server/overview">Proxmox Backup Server</a>
</li>
</ul>
<p>and <strong>nothing else</strong>.</p>
<p>I just want it to do network attached storage, and I don&rsquo;t want to mess with it.</p>
<h4 id="storage">Storage</h4>
<ul>
<li>2 NVME for 4TB of fast storage</li>
<li>1 SSD for 500GB internal storage</li>
<li>4 HDD RAIDZ2 for 10TB of slow storage</li>
</ul>
<h3 id="nuc">NUC</h3>
<p>After getting burned trying to do server things on my NAS I looked for a replacement and found the <a href="https://turingpi.com">Turing Pi</a>
, and then in true Kickstarter fashion it got delayed, and then delayed again.</p>
<p>I impatiently bought an Intel NUC.</p>
<p>I <em>could</em> have installed Linux on it and used it as a server but I wanted to use Terraform for Infrastructure as Code, so instead I installed <a href="https://www.proxmox.com/en/products/proxmox-virtual-environment/overview">Proxmox VE</a>
 and used Terraform to create the virtual machines and LXC containers I needed with code.</p>
<p>This meant I could get some practise in using <a href="https://docs.ansible.com/ansible/latest/index.html">Ansible</a>
 to configure things and try out <a href="https://k3s.io">K3s</a>
 to run Kubernetes.</p>
<h4 id="usage-1">Usage</h4>
<ul>
<li><strong>compute</strong> for running services and apps</li>
<li>experience using <strong>Proxmox</strong></li>
<li>practise using IaC with <strong>Terraform</strong> and <strong>Ansible</strong></li>
<li>a place to try out <strong>Kubernetes</strong> stuff</li>
<li>a better GPU than the NAS for <strong>Jellyfin</strong> to use for transcoding</li>
</ul>
<h4 id="services">Services</h4>
<ul>
<li><strong><a href="https://pi-hole.net/">Pi-hole</a>
</strong> for blocking adverts as well as DNS and DHCP for my network</li>
<li><strong><a href="https://www.pivpn.io/">Wireguard</a>
</strong> for a VPN so I can connect from out the house</li>
<li><strong>MySQL</strong> and <strong>Postgres</strong> databases for &ldquo;cloud&rdquo; things to use</li>
<li><strong><a href="https://caddyserver.com/">Caddy</a>
</strong> as a reverse proxy to provide access to my &ldquo;cloud&rdquo; apps and services</li>
<li><strong><a href="https://about.gitea.com/">Gitea</a>
</strong> for storing my git repositories</li>
<li><strong><a href="https://jellyfin.org/">Jellyfin</a>
</strong> to watch my own media content</li>
</ul>
<h4 id="apps">Apps</h4>
<ul>
<li><strong><a href="https://mealie.io/">Mealie</a>
</strong> for recipe management and meal planning</li>
<li><strong><a href="https://www.freshrss.org/">FreshRSS</a>
</strong> for my RSS clients to sync from</li>
</ul>
<h3 id="deskpi">DeskPi</h3>
<p>The last part of my &ldquo;cloud&rdquo; is the Raspberry Pi 4 I have on my desk.</p>
<p>(I named it before I heard about the company with the same name)</p>
<p>I had future plans for it, since it&rsquo;s sat on my desk, so I installed the desktop version of Ubuntu and hooked it up to my second screen.</p>
<p>Then I installed <a href="https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/13/homelab-v1/">Uptime Kuma</a>
 on it to monitor all my services and apps.</p>
<p>Apparently I cheaped out when I bought it and got the 2GB version, so it&rsquo;s really really slow and struggles with showing the dashboard.</p>
<p><img src="https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/13/homelab-v1/uptime-kuma-status-page.png" alt="screenshot of Uptime Kuma status page">
</p>
<p>I&rsquo;ve been looking for a good excuse to buy a Raspberry Pi 5 but technically this works, so for now it can stay.</p>
<h2 id="lab">Lab</h2>
<p>Now that the stable self-hosted part is out of the way I&rsquo;m going to leave it alone and use something else for the new ideas.</p>
<p>My Turing Pi 2.5 has finally arrived, along with its case, 3 x <a href="https://turingpi.com/product/turing-rk1/?attribute_ram=8&#43;GB">RK1</a>
 compute modules and 3 x 1 TB NVME drives. I&rsquo;m planning on using it as a cluster to run Kubernetes and potentially host my own website, but we&rsquo;ll see about that.</p>
<p>Right now it&rsquo;s on the bench in the lab.</p>]]></content:encoded><source:markdown>
My Homelab has hit its first milestone 🚀

&lt;!--more--&gt;

## Cloud

The biggest problem with my homelab was that I kept breaking it.

I couldn&#39;t get used to using [mealie](https://mealie.io/) as a meal planner because I would go to use it and it didn&#39;t work. Or it did, but I couldn&#39;t connect to it properly. Or something else went wrong.

So for my first &#34;release&#34; I aimed for a &#34;cloud&#34;. Some people call it &#34;HomeProd&#34;.

I used things I was used to, and a few things I wasn&#39;t, to make a simple, stable platform on which I could host my _actual_ homelab.

Here&#39;s what&#39;s in it:

### NAS

I have a machine dedicated to running [TrueNAS Scale](https://www.truenas.com/truenas-scale/).

I bought the hype that I needed [ECC RAM](https://www.truenas.com/docs/scale/gettingstarted/scalehardwareguide/) so that my data would be safe and so I also needed a server-grade processor, which meant a server-grade motherboard, and all the other bits to go with it.

At the time Scale had built-in Kubernetes so I used TrueCharts to set up some apps. And then they stopped working. And then there were all the updates with breaking changes. And then I got fed up.

This was meant to be a machine that did storage and I didn&#39;t want to mess with it.

The TrueNAS devs thought the same thing and took out Kubernetes and replaced it with Docker, so I updated to follow and now I only run two storage apps on it.

#### Usage

- **file storage** over **NFS** to Linux and Mac and **SMB** for Windows
- **object storage** via [MinIO](https://min.io) installed as a Docker container
- **backups** for virtual machines via [Proxmox Backup Server](https://www.proxmox.com/en/products/proxmox-backup-server/overview)

and **nothing else**.

I just want it to do network attached storage, and I don&#39;t want to mess with it.

#### Storage

- 2 NVME for 4TB of fast storage
- 1 SSD for 500GB internal storage
- 4 HDD RAIDZ2 for 10TB of slow storage

### NUC

After getting burned trying to do server things on my NAS I looked for a replacement and found the [Turing Pi](https://turingpi.com), and then in true Kickstarter fashion it got delayed, and then delayed again.

I impatiently bought an Intel NUC.

I _could_ have installed Linux on it and used it as a server but I wanted to use Terraform for Infrastructure as Code, so instead I installed [Proxmox VE](https://www.proxmox.com/en/products/proxmox-virtual-environment/overview) and used Terraform to create the virtual machines and LXC containers I needed with code.

This meant I could get some practise in using [Ansible](https://docs.ansible.com/ansible/latest/index.html) to configure things and try out [K3s](https://k3s.io) to run Kubernetes.

#### Usage

- **compute** for running services and apps
- experience using **Proxmox**
- practise using IaC with **Terraform** and **Ansible**
- a place to try out **Kubernetes** stuff
- a better GPU than the NAS for **Jellyfin** to use for transcoding

#### Services

- **[Pi-hole](https://pi-hole.net/)** for blocking adverts as well as DNS and DHCP for my network
- **[Wireguard](https://www.pivpn.io/)** for a VPN so I can connect from out the house
- **MySQL** and **Postgres** databases for &#34;cloud&#34; things to use
- **[Caddy](https://caddyserver.com/)** as a reverse proxy to provide access to my &#34;cloud&#34; apps and services
- **[Gitea](https://about.gitea.com/)** for storing my git repositories
- **[Jellyfin](https://jellyfin.org/)** to watch my own media content

#### Apps

- **[Mealie](https://mealie.io/)** for recipe management and meal planning
- **[FreshRSS](https://www.freshrss.org/)** for my RSS clients to sync from

### DeskPi

The last part of my &#34;cloud&#34; is the Raspberry Pi 4 I have on my desk.

(I named it before I heard about the company with the same name)

I had future plans for it, since it&#39;s sat on my desk, so I installed the desktop version of Ubuntu and hooked it up to my second screen.

Then I installed [Uptime Kuma]() on it to monitor all my services and apps.

Apparently I cheaped out when I bought it and got the 2GB version, so it&#39;s really really slow and struggles with showing the dashboard.

![screenshot of Uptime Kuma status page](uptime-kuma-status-page.png)

I&#39;ve been looking for a good excuse to buy a Raspberry Pi 5 but technically this works, so for now it can stay.

## Lab

Now that the stable self-hosted part is out of the way I&#39;m going to leave it alone and use something else for the new ideas.

My Turing Pi 2.5 has finally arrived, along with its case, 3 x [RK1](https://turingpi.com/product/turing-rk1/?attribute_ram=8+GB) compute modules and 3 x 1 TB NVME drives. I&#39;m planning on using it as a cluster to run Kubernetes and potentially host my own website, but we&#39;ll see about that.

Right now it&#39;s on the bench in the lab.
</source:markdown></item><item>
      <title>Using Terraform as the Inventory for Ansible</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/13/using-terraform-as-the-inventory-for-ansible/</link>
      <pubDate>Fri, 13 Jun 2025 11:30:21 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/13/using-terraform-as-the-inventory-for-ansible/</guid>
      <category>Ansible</category>
      <category>Terraform</category>
      <description>Terraform and Ansible are complementary tools with which you can do Infrastructure as Code. You would use Terraform to request machines from providers and then Ansible to configure them.
Using both of them together, with a dynamic inventory to link them, has been technically possible for years but never obvious enough for me to work out.
Until I found the Terraform provider.</description>
      <content:encoded><![CDATA[<p>Terraform and Ansible are complementary tools with which you can do Infrastructure as Code. You would use <a href="https://www.terraform.io/">Terraform</a>
 to request machines from providers and then <a href="https://docs.ansible.com/ansible/latest/index.html">Ansible</a>
 to configure them.</p>
<p>Using both of them together, with a dynamic inventory to link them, has been technically possible for years but never obvious enough for me to work out.</p>
<p>Until I found the Terraform provider.</p>
<h2 id="ansible-provider-for-terraform">Ansible provider for Terraform</h2>
<p>By using the <a href="https://registry.terraform.io/providers/ansible/ansible/latest">Ansible provider</a>
 you can teach Terraform what an Ansible inventory entry would look like next to the rest of its code.</p>
<p>You start by defining the provider:</p>
<pre><code class="language-terraform">terraform {
  required_providers {
    ansible = {
      source  = &#34;ansible/ansible&#34;
      version = &#34;1.3.0&#34;
    }
  }
}</code></pre>
<p>and then you can define the Ansible inventory entry right next to the resource:</p>
<pre><code class="language-terraform">resource &#34;proxmox_vm_qemu&#34; &#34;gitea&#34; {
  cores = 1
	...
}

resource &#34;ansible_host&#34; &#34;gitea&#34; {
  name   = proxmox_vm_qemu.gitea.ssh_host
  groups = [&#34;gitea&#34;]
  variables = {
    ansible_user = &#34;ansible&#34;
  }
}</code></pre>
<p>which means you don&rsquo;t need to hardcode IP addresses anywhere.</p>
<p>You would need to <code>terraform apply</code> this plan so that Terraform adds these resources to the state file so that Ansible can use them.</p>
<h2 id="terraform-plugin-for-ansible">Terraform plugin for Ansible</h2>
<p>On the Ansible side you use <a href="https://github.com/ansible-collections/cloud.terraform">a plugin</a>
 to tell it how to use Terraform as its inventory.</p>
<p>Add the following to your <code>requirements.yaml</code> file:</p>
<pre><code class="language-yaml">collections:
  - name: cloud.terraform
    version: 1.1.0</code></pre>
<p>and then install the collection using <code>ansible-galaxy collection install -r requirements.yaml</code>,</p>
<p>then create an <code>inventory.yaml</code> with the following content:</p>
<pre><code class="language-yaml">plugin: cloud.terraform.terraform_provider
# project_path: ../terraform # if your Terraform code is in a different directory
# state_file: mycustomstate.tfstate # if you wanted to define which state file</code></pre>
<p>and set it as the default inventory in <code>ansible.cfg</code>:</p>
<pre><code class="language-ini">[defaults]
inventory = inventory.yaml</code></pre>
<p>You can confirm the plugin works by doing:</p>
<pre><code class="language-sh">ansible-inventory --graph</code></pre>
<p>which should return something like the following:</p>
<pre><code class="language-sh">@all:
  |--@ungrouped:
  |--@gitea:
  |  |--192.168.1.211</code></pre>
<h2 id="heading">🎉</h2>
<p>What&rsquo;s good about this is now you can be hands-off with IP addresses.</p>
<p>Terraform can request a new machine, wait for it to receive an IP address and then make it available for Ansible to use, without you needing to do anything.</p>
<h3 id="remote-state">Remote state</h3>
<p>The Ansible plugin will default to using whichever backend you use for the Terraform state file, whether that&rsquo;s local or in an S3-compatible location.</p>
<p>This means Ansible is always running against the current infrastructure, which helps when colleagues and automations are updating things a <del>hundred</del> thousand times a day.</p>
<h2 id="in-conclusion">In Conclusion</h2>
<p>Using Terraform and Ansible together can cover all aspects of Infrastructure as Code.</p>
<p>The Ansible provider lets you keep all your resource code together in Terraform and then makes it available to Ansible, which uses a plugin to let it use the state file as its inventory.</p>]]></content:encoded><source:markdown>
Terraform and Ansible are complementary tools with which you can do Infrastructure as Code. You would use [Terraform](https://www.terraform.io/) to request machines from providers and then [Ansible](https://docs.ansible.com/ansible/latest/index.html) to configure them.

Using both of them together, with a dynamic inventory to link them, has been technically possible for years but never obvious enough for me to work out.

Until I found the Terraform provider.

&lt;!--more--&gt;

## Ansible provider for Terraform

By using the [Ansible provider](https://registry.terraform.io/providers/ansible/ansible/latest) you can teach Terraform what an Ansible inventory entry would look like next to the rest of its code.

You start by defining the provider:

```terraform
terraform {
  required_providers {
    ansible = {
      source  = &#34;ansible/ansible&#34;
      version = &#34;1.3.0&#34;
    }
  }
}
```

and then you can define the Ansible inventory entry right next to the resource:

```terraform
resource &#34;proxmox_vm_qemu&#34; &#34;gitea&#34; {
  cores = 1
	...
}

resource &#34;ansible_host&#34; &#34;gitea&#34; {
  name   = proxmox_vm_qemu.gitea.ssh_host
  groups = [&#34;gitea&#34;]
  variables = {
    ansible_user = &#34;ansible&#34;
  }
}
```

which means you don&#39;t need to hardcode IP addresses anywhere.

You would need to `terraform apply` this plan so that Terraform adds these resources to the state file so that Ansible can use them.

## Terraform plugin for Ansible

On the Ansible side you use [a plugin](https://github.com/ansible-collections/cloud.terraform) to tell it how to use Terraform as its inventory.

Add the following to your `requirements.yaml` file:

```yaml
collections:
  - name: cloud.terraform
    version: 1.1.0
```

and then install the collection using `ansible-galaxy collection install -r requirements.yaml`,

then create an `inventory.yaml` with the following content:

```yaml
plugin: cloud.terraform.terraform_provider
# project_path: ../terraform # if your Terraform code is in a different directory
# state_file: mycustomstate.tfstate # if you wanted to define which state file
```

and set it as the default inventory in `ansible.cfg`:

```ini
[defaults]
inventory = inventory.yaml
```

You can confirm the plugin works by doing:

```sh
ansible-inventory --graph
```

which should return something like the following:

```sh
@all:
  |--@ungrouped:
  |--@gitea:
  |  |--192.168.1.211
```

## 🎉

What&#39;s good about this is now you can be hands-off with IP addresses.

Terraform can request a new machine, wait for it to receive an IP address and then make it available for Ansible to use, without you needing to do anything.

### Remote state

The Ansible plugin will default to using whichever backend you use for the Terraform state file, whether that&#39;s local or in an S3-compatible location.

This means Ansible is always running against the current infrastructure, which helps when colleagues and automations are updating things a ~~hundred~~ thousand times a day.

## In Conclusion

Using Terraform and Ansible together can cover all aspects of Infrastructure as Code.

The Ansible provider lets you keep all your resource code together in Terraform and then makes it available to Ansible, which uses a plugin to let it use the state file as its inventory.
</source:markdown></item><item>
      <title>Homelab v0</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/04/homelab-v0/</link>
      <pubDate>Wed, 04 Jun 2025 22:30:59 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/04/homelab-v0/</guid>
      <category>homelab</category>
      <description>As my homelab is about to reach a milestone I thought I’d look back on where it started.</description>
      <content:encoded><![CDATA[<p>As my homelab is about to reach a milestone I thought I&rsquo;d look back on where it started.</p>
<h2 id="whats-a-homelab">What&rsquo;s a homelab?</h2>
<p>A homelab is a personal setup of computer stuff that some of us spend way too much time and money on.</p>
<h2 id="why-would-i-want-one">Why would I want one?</h2>
<p>Here&rsquo;s a few reasons:</p>
<h3 id="learning">Learning</h3>
<p>The biggest reason I wanted a homelab was for learning. I can get hands-on experience with tech I wouldn&rsquo;t normally use, and as a DevOps Engineer that often ends up being useful at work.</p>
<h3 id="applications">Applications</h3>
<p>There are loads of open source apps you can run for free at home.</p>
<p>You can <a href="https://pi-hole.net">block adverts</a>
, <a href="https://jellyfin.org">run your own Netflix</a>
 and <a href="https://www.awesome-homelab.com/">plenty more</a>
.</p>
<h3 id="services">Services</h3>
<p>You could backup your devices and centralise storage with a NAS, then setup a VPN and connect to it from anywhere.</p>
<h2 id="how-do-i-get-one">How do I get one?</h2>
<p>The biggest thing I want you to take away from this is that you already have one.</p>
<blockquote>
<p>the homelab was inside you all along</p>
</blockquote>
<p>Pretend for a moment you&rsquo;re a mad scientist, hacking away at some computery stuff. There are several blinking lights and a faint computery hum fills the air.</p>
<p>What kind of computery stuff did you imagine?</p>
<p>Did it involve loads of blinky lights? You might be interested in networking. I bought a <a href="https://techspecs.ui.com/unifi/switching/unifi-flex-xg?s=uk">Ubiquiti switch</a>
 and it&rsquo;s way blinkier than my old one. It&rsquo;s also 10 times faster.</p>
<p>Did you see yourself coding? Maybe you could setup your own git server, add on CI/CD and get your apps hosted on your own network. That&rsquo;s what I&rsquo;m doing.</p>
<p>Or maybe you want to try out AI on your own hardware?</p>
<p>Whatever it is, you can probably get started right now with the things that you already have. You don&rsquo;t need to go and buy anything just yet. Start acting like a mad scientist doing computery stuff and eventually you&rsquo;ll become one.</p>
<p>When I wanted to learn about Docker images I used my own laptop. Then when I was given a Raspberry Pi I tested out running Docker images on that and so my homelab doubled in size.</p>
<p>I didn&rsquo;t realise it was called a homelab at the time. I was just doing computery stuff.</p>
<h2 id="my-homelab-v0">My Homelab v0</h2>
<p><strong>Macbook Pro</strong> (2012)</p>
<p><strong>Raspberry Pi 1</strong></p>
<p><strong>Notebook</strong></p>
<p><strong>Pen</strong> for writing it all down, otherwise it&rsquo;s not science.</p>]]></content:encoded><source:markdown>
As my homelab is about to reach a milestone I thought I&#39;d look back on where it started.

&lt;!--more--&gt;

## What&#39;s a homelab?

A homelab is a personal setup of computer stuff that some of us spend way too much time and money on.

## Why would I want one?

Here&#39;s a few reasons:

### Learning

The biggest reason I wanted a homelab was for learning. I can get hands-on experience with tech I wouldn&#39;t normally use, and as a DevOps Engineer that often ends up being useful at work.

### Applications

There are loads of open source apps you can run for free at home.

You can [block adverts](https://pi-hole.net), [run your own Netflix](https://jellyfin.org) and [plenty more](https://www.awesome-homelab.com/).

### Services

You could backup your devices and centralise storage with a NAS, then setup a VPN and connect to it from anywhere.

## How do I get one?

The biggest thing I want you to take away from this is that you already have one.

&gt; the homelab was inside you all along

Pretend for a moment you&#39;re a mad scientist, hacking away at some computery stuff. There are several blinking lights and a faint computery hum fills the air.

What kind of computery stuff did you imagine?

Did it involve loads of blinky lights? You might be interested in networking. I bought a [Ubiquiti switch](https://techspecs.ui.com/unifi/switching/unifi-flex-xg?s=uk) and it&#39;s way blinkier than my old one. It&#39;s also 10 times faster.

Did you see yourself coding? Maybe you could setup your own git server, add on CI/CD and get your apps hosted on your own network. That&#39;s what I&#39;m doing.

Or maybe you want to try out AI on your own hardware?

Whatever it is, you can probably get started right now with the things that you already have. You don&#39;t need to go and buy anything just yet. Start acting like a mad scientist doing computery stuff and eventually you&#39;ll become one.

When I wanted to learn about Docker images I used my own laptop. Then when I was given a Raspberry Pi I tested out running Docker images on that and so my homelab doubled in size.

I didn&#39;t realise it was called a homelab at the time. I was just doing computery stuff.

## My Homelab v0

**Macbook Pro** (2012)

**Raspberry Pi 1**

**Notebook**

**Pen** for writing it all down, otherwise it&#39;s not science.
</source:markdown></item><item>
      <title>Technical Difficulties</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/02/technical-difficulties/</link>
      <pubDate>Mon, 02 Jun 2025 14:30:00 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/06/02/technical-difficulties/</guid>
      <category>meta</category>
      <description>I don’t like starting sentences with I.</description>
      <content:encoded><![CDATA[<p>I don&rsquo;t like starting sentences with I.</p>
<p>There were also a few real technical difficulties starting a blog, which were more frustrating because usually I was the one who had caused them, but they were fixed pretty quickly.</p>
<p>No, the biggest problem came instead from me, not getting past the awkward part and making it a regular habit.</p>
<p>I made a slight effort earlier this year publishing a <a href="https://micro.paultibbetts.uk/2025/01/02/the-plan.html">&ldquo;plan&rdquo;</a>
 on Micro.blog but apparently it wasn&rsquo;t the right time and I didn&rsquo;t follow it up.</p>
<p>I was already aware of it, and making an effort to fix it, but I was burnt out.</p>
<p>What I didn&rsquo;t write in my &ldquo;plan&rdquo; was that I would be taking some time off work for a while to recover. It&rsquo;s not like I was stuck in bed, unable to move, but I had lost interest in coding and computers, which isn&rsquo;t great when that&rsquo;s what you do for money.</p>
<p>So I handed in my notice and took a break.</p>
<hr>
<p>Two months later and I&rsquo;m definitely feeling better.</p>
<p>The fact you are reading this at all is a testament to my newly rediscovered ability to sit down at a computer and not hate it.</p>
<p>I&rsquo;ve also had the time to work on my homelab, on which I&rsquo;ve made more progress in the last two weeks than I have in the last two years.</p>
<p>So maybe now is a good time to start blogging.</p>]]></content:encoded><source:markdown>
I don&#39;t like starting sentences with I.

&lt;!--more--&gt;

There were also a few real technical difficulties starting a blog, which were more frustrating because usually I was the one who had caused them, but they were fixed pretty quickly.

No, the biggest problem came instead from me, not getting past the awkward part and making it a regular habit.

I made a slight effort earlier this year publishing a [&#34;plan&#34;](https://micro.paultibbetts.uk/2025/01/02/the-plan.html) on Micro.blog but apparently it wasn&#39;t the right time and I didn&#39;t follow it up.

I was already aware of it, and making an effort to fix it, but I was burnt out.

What I didn&#39;t write in my &#34;plan&#34; was that I would be taking some time off work for a while to recover. It&#39;s not like I was stuck in bed, unable to move, but I had lost interest in coding and computers, which isn&#39;t great when that&#39;s what you do for money.

So I handed in my notice and took a break.

---

Two months later and I&#39;m definitely feeling better.

The fact you are reading this at all is a testament to my newly rediscovered ability to sit down at a computer and not hate it.

I&#39;ve also had the time to work on my homelab, on which I&#39;ve made more progress in the last two weeks than I have in the last two years.

So maybe now is a good time to start blogging.
</source:markdown></item><item>
      <title>Hello, World!</title>
      <link>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/05/20/hello-world/</link>
      <pubDate>Tue, 20 May 2025 12:54:11 +0100</pubDate>
      <guid>https://paultibbetts-uk-feat-cooks.preview.lab.paultibbetts.uk/2025/05/20/hello-world/</guid>
      <category>meta</category>
      <description>👋</description>
      <content:encoded><![CDATA[<p>👋</p>]]></content:encoded><source:markdown>
👋
</source:markdown></item>
  </channel>
</rss>
