Welcome to Friendica.Eskimo.Com
Home of Censorship Free Hosting
E-mail, Web Hosting, Linux Shell Accounts terminal or full remote desktops.
Sign Up For A Free Trial Here
Please tell your friends about federated social media site that speaks several fediverse protocols thus serving as a hub uniting them, hubzilla.eskimo.com, also check out friendica.eskimo.com, federated macroblogging social media site, mastodon.eskimo.com a federated microblogging site, and yacy.eskimo.com an uncensored federated search engine. All Free!
Gaomon PD1161 V2 review
My review of the Gaomon PD1161 V2. Let's go to the point: it's a bad model. I don't recommended this one. I'm not even submiting the video to Gaomon for review before posting because I know they would ask me to not post it (it happened in the past with another brand). But I think it should be also known, that's my role in reviews: cover the bad and the good.
▶️ Technical blog-post: davidrevoy.com/article1173/gao…
PROMO CODES:
Amazon US: amzn.to/4cW3YF9
Amazon FR: dub.sh/yBLkM9K
Official Store: dub.sh/N2FC0h7 (use code GM5 for 5% off)
Chapter:
0:00 intro
1:10 Unboxng
2:20 Hardware presentation
3:42 Overlay surface
4:12 Cables
4:57 Scratch test
5:37 Jitter test
6:15 Heat test
6:45 Osd menu
7:24 Colors
7:59 Clunky buttons
8:24 No stand included
8:36 Painting and Drawing
9:20 Conclusion...
License: Creative Commons Attribution 4.0 International
Video and artworks by David Revoy
www.davidrevoy.com
License: Creative Commons Attribution 4.0 International
Video and artworks by David Revoy
www.davidrevoy.com
Website:
Webcomic: peppercarrot.com/
Blog: davidrevoy.com/
Trying to control My screen time with This software
Note that i made this for myself and just my first time sharing an application i made here
Came up with this application with one aim in mind...To Control daily limit for myself as my doomscrolling had worsened quite a lot even while working. So decided to make this as an alternative to Digital wellbeing on Android.
It supports:
focus mode
per app daily limits
background daemon
so far i was able to make it work only on GNOME mutter and all x11 because that is my system...will consider updating in future if this receives positive reviews
I use fedora 44 workstation and it runs perfectly for me...and also tied it on manjaro and linux mint on my VMs with x11 , worked there too....so please check for yourselves and do tell me how it goes
NOTE: if you are a dev then please feel free to contribute
like this
YoSoySnekBoi likes this.
Is this AI generated? Do you have a link to a repository? Why would Devs contribute to some vibe coded app they didn't write?
EDIT: is it that one? Because there is another vibecoded screenguard on Github which looks different.
github.com/adityakrishnan005-a…
GitHub - adityakrishnan005-a11y/ScreenGuard: Digital Wellbeing for Linux — Screen Time Tracking, Daily App Limits & Focus Mode (GNOME Wayland & X11)
Digital Wellbeing for Linux — Screen Time Tracking, Daily App Limits & Focus Mode (GNOME Wayland & X11) - adityakrishnan005-a11y/ScreenGuardGitHub
I have worked on it personally and can assure you it's not vibe coded...just fixed certain anonymous bugs with llm when I got tired...
There has been a backlash I know but it's just what it is...thank you
Yeah please disclose that, pair programming is a fine idea with AI. I'm kind of against AI in general, but if you use it like you claim you do, sounds fine 😀
Maybe you can add an explanation on which parts are LLM assisted and which aren't, like it's done with projects in !selfhosted@lemmy.world.
GitHub - adityakrishnan005-a11y/ScreenGuard: Digital Wellbeing for Linux — Screen Time Tracking, Daily App Limits & Focus Mode (GNOME Wayland & X11)
Digital Wellbeing for Linux — Screen Time Tracking, Daily App Limits & Focus Mode (GNOME Wayland & X11) - adityakrishnan005-a11y/ScreenGuardGitHub
TLDR: Working on it pal....will try to add atleast kde and cinnamon support by end of this yeah...and sway , hyprland etc too but will take till next year I guess.....let's see
The longer the em dash the more likely...
ah well, enjoy it for yourself.
youtube app for plasma bigscreen/tv?
GitHub - shy1132/VacuumTube: YouTube Leanback on the desktop, with enhancements
YouTube Leanback on the desktop, with enhancements - shy1132/VacuumTubeGitHub
Switzerland ditches Windows, Omarchy now raised $18.5M - Linux & Open Source News Weekly
Check out Internxt and get 85% off your lifetime plans or the fist month of your annual plan: campaign: internxt.com/thelinuxexp
Grab a brand new laptop or desktop running Linux: tuxedocomputers.com/en#
👏 SUPPORT THE CHANNEL:
Get access to:
- a Daily Linux News show
- a weekly patroncast for more thoughts
- your name in the credits
YouTube: youtube.com/@thelinuxexp/join
Patreon: patreon.com/thelinuxexperiment
Or, you can donate whatever you want:
paypal.me/thelinuxexp
Liberapay: liberapay.com/TheLinuxExperime…
👕 GET TLE MERCH
Support the channel AND get cool new gear: the-linux-experiment.creator-s…
Timestamps:
00:00 Intro
00:43 Sponsor: Internxt
02:26 Switzerland migrates away from Microsoft solutions
04:31 Omarchy now reaches $18.5M in funding
07:02 GNOME prepares more formal process for project wide changes
08:51 GNOME looking to do a fundraising campaign
10:18 Proposed app to replace Gwenview on KDE
12:19 KDE frameworks updated
13:42 More Wayland protocols on KDE
14:59 KDE 1 revival project looks cool
16:31 Patches to start making the Macbook Neo work with Linux
17:33 New CAD software for Linux
19:15 Windows adds features we've had for decades
21:09 PS5 Linux project now works better
23:01 You can play with DLSS5 on Linux too
25:04 Sponsor: Tuxedo Computers
Links:
Switzerland migrates away from Microsoft solutions
itsfoss.com/news/switzerland-r…
Omarchy now reaches $18.5M in funding
linuxiac.com/omarchy-funding-s…
GNOME prepares more formal process for project wide changes
gitlab.gnome.org/sophie-h/rfcs…
GNOME looking to do a fundraising campaign
gitlab.gnome.org/Teams/Board/-…
gitlab.gnome.org/Teams/Website…
Proposed app to replace Gwenview on KDE
pointieststick.com/2026/09/06/…
KDE frameworks updated
9to5linux.com/kde-frameworks-6…
More Wayland protocols on KDE
phoronix.com/news/KDE-KWin-Way…
KDE 1 revival project looks cool
linuxiac.com/midesktop-1-2-bet…
Patches to start making the Macbook Neo work with Linux
phoronix.com/news/Apple-A18-Pr…
New CAD software for Linux
linuxiac.com/open-cad-studio-i…
Windows adds features we've had for decades
techradar.com/computing/window…
PS5 Linux project now works better
github.com/ps5-linux/ps5-linux…
You can play with DLSS5 on Linux too
phoronix.com/news/DLSS5VKLayer
STOP OMARCHY: Boycott Tech's Far-Right Backers
like this
warm likes this.
I'm making my own distro rn, announced it a week ago here and will likely release today or tomorrow! pu-239.org/ lemmy.ml/post/52307735
I'm in the process of making a distro that combines the way SteamOS makes Arch Linux stable and user-friendly WITH the performance optimizations of CachyOS
As the title and the website say, I'm currently making a distro with the goal that you don't have to compromise between ease of use + safety and bleeding-edge + performance optimizations.As I will likely be able to publish the 0.0.1 source code to the GitHub link and the ISO to the website sometime next week, I would like people to be aware of my project so I can have some feedback for further improvements when I release the first version. I have not posted this anywhere else yet, as I value the opinion of this community more than Reddit or whatever.
If you have any questions or any criticism, please voice it, I would love to hear it, good or bad, in the end I want to make a proper OS. (I'll go to bed now so expect replies to take a few hours from posting.)
Pu-239
Pu-239 is an atomic Arch Linux distribution: sealed read-only root, ostree A/B deployments with automatic rollback, and the 1000 Hz linux-cachyos kernel.pu-239.org
Linux reshared this.
‘Oh come on!’ was my initial reaction, but I’ve read your website, and thought: ‘hey, that sounds nice!’
I’m not going to migrate all my Arch boxes (basically all my x86/64 boxes), but I may use it somewhere else, just to test the idea.
I loved the idea of Atomic Fedora, but it did not work seamlessly, and to my experience, it did the opposite: worse than a regular Fedora. I needed to babysit it, and also it didn’t auto switch the previous working system for me. Perhaps it’s me who missed something. As an idea, though, I think that’s what should click to a normie: you tell them to install this distro, get your handful of apps as Flatpaks and forget about the system, as it manages itself.
To keep this topic alive, let me ask you a question: how would you know what’s a working state, so you need to return to the previous one? Does it mean it didn’t boot, or anything else? Just yesterday, I had faced a weird issue: my old trusty MacBook Pro serving as a server now, had no WiFi (it has Ethernet port, but temporarily I cannot use it, so it’s wireless). The broadcom-wl driver switched to linux-headers, which I didn’t have installed. I don’t remember me changing anything, and fortunately that was an easy fix (with an external USB WiFi card): just install Linux headers, and it would rebuild itself. So I’m just curious whether it’s even possible to find out a stupid issue a normie user may face.
On the other hand, perhaps the distros like this are meant to be installed by someone skilled to then be used mostly unattended by a regular user.
‘Oh come on!’ was my initial reaction, but I’ve read your website, and thought: ‘hey, that sounds nice!’
Haha, I know I know, yet another Arch-based distro in this economy, but I really feel like this does fill a gap, thank you for your interest!
On the other hand, perhaps the distros like this are meant to be installed by someone skilled to then be used mostly unattended by a regular user.
My aim is to make this both appealing for the normie who just wants to use it like "SteamOS but with CachyOS speed" and run Flatpaks on it AND for the more experienced user who wants all the benefits of Arch but with a little more peace of mind.
how would you know what’s a working state, so you need to return to the previous one?
As the website explains, it automatically falls back to the last working state if it doesn't boot, but obviously it can't detect if something is messed up but still booting like in your example. In that case you just reboot and manually select the last working state (wip but kinda working already) just like a BTRFS snapshot, BUT it only rolls back the system itself, NOT your files. A BTRFS snapshot will also roll back your documents or whatever so my system, when it's stable and tested, will be superior in every way to BTRFS snapshots.
A BTRFS snapshot will also roll back your documents or whatever
Not necessarily. You can have your documents on one subvolume and the root system on another. I version and snapshot my root disk and home disk separately.
They passed a bunch on to Hyprland. Fuck all these transphobes and other bigoted right-wing assholes.
Actually, no. Fuck someone nice. Or don't; I'm not your mother.
Jk, I do think hyprland is a nice WM. But man... The drama around it.
"Judge"? My brother free/libre software, they're the ones who want me to not exist. I do not wish an ill fate upon them; however, I cannot tolerate intolerance.
Also, if they were vocally hateful against any other marginalised community, it would be totally unacceptable to the vast majority of Linux users.
There will be a day when I finally learn to code properly and fork the fuck out of X. I'll name it antifaX .
Or not, because it sounds... what's the opposite of sex positive? 🥵
Fork it if it's so good.
What are they getting for their money?
It's a marketing campaign to devalue Linux in the public eye.
If they can state that AI came up with a "good enough" distro you know what non-savvy people will think about it: that making a distro is "easy", and "anybody can do it", and that anybody involved with making distros "manually" is redundant and giving themselves airs etc.
It has already happened to many other fields.
Yes baby ! What a great page. Thank you, to this Brennan dude(tte) for creating it, and quick apolls to others for me primitively raging against every sign of this nazi/fascist club/product, and the whole nazi/fascist enshittification/normalization of 'open source'.
One nasty surprise in secondary list: 'suckless' - oh well, can't win them all 🙁
Let's post this great page as a standard reply to all posts/mentions of omacom/omarchy going forward, so all those not knowing, can be warned about what it really is !
[ait] (warning - AI topic tag)
Dear anti-ai, if you can muster it, then please lower defences slightly for just a sec:
It's really time and energy consuming to follow and document this yucky movement as they are now heavily funded and work/move constantly 24/7. Brennan is a super cool Human, but can't work on this always, all the time. We might need an active agentic system that also work constantly 24/7 to track the whole fascist/nazi network, all its players, update the lists and make it easier for ordinary good peeps to reject and boycott it all. Supervised by a human oc.
We might need an active agentic system that also work constantly 24/7 to track the whole fascist/nazi network, all its players, update the lists
Why?
I mean, I'm not anti-AI completely, but building denylists with AI seems to be a bad idea. Is it really that time consuming that we couldn't just do a git repo and allow merge requests for people to collaborate?
Yeah, suckless was a bummer for sure. 🙁 Although, with their elitist attitude, I'm not surprised. There's supposed to be a fork of their window manager at least, written by a really young person. Can't quite recall its name now...
I wonder if your idea is doable without using LLMs though! 😀
Antix, pretty cool Debian-based distro made by (at least nominally self proclaimed) antifascists. I guess we could also count some socialist-backed distros like Nova linux.
Beyond distros though, I'd say there are plenty of left leaning people working on various projects, such as Gnome.
I mean, Redstar... I think that'd technically that'd be socialist, though.
More seriously, I think most of the non-fork distros don't tolerate that crap. Think Arch, Debian, Void, etc.
Something I'm keeping an eye on is this project. No clue what, if anything, will come of it.
Personally, I use Artix, and I'm considering NetBSD. I'm also consodering making my own Unix-like distro, possibly using the NetBSD kernel.
Not really, just use something normal that's there to provide software. Fedora (but remember to install video codecs), Arch (but use the AUR with caution), Debian (if you're okay with using neolithic-age software), SUSE (European Fedora with AppArmor instead of SELinux), Void (but software availability can suffer).
The BSDs seem cool but it really depends on your hardware if you can run them. NixOS is awesome technology but has problematic business relations1 so you might want to take a look at GNU Guix.
- I'm not totally sure what's going on there. There was something about a community split between Nix (the package manager) and NixOS (the distro) but I don't remember which side is which. Using NixOS with Lix instead of Nix might be what you want. ↩︎
AntiX (based on Debian) is the only distro I know of that is developed by vocally anticapitalist leftist devs, even putting "proudly Anti-fascist" on their main page.
They also are one of the few distros to take an anti-LLM stance (though with Debian itself being pro-AI now, it remains to be seen how far they will go to avoid new LLM contributions made to the Debian base).
communist
basically whatever the FSF/GNU makes. check out Guix if you can put up with learning a little Lisp.
I am all on board with letting people know when open source is a bit too aligned with major companies or is somehow compromised.
I have no intent or need to use Omarchy.
This sites list of YouTubers to shun however is a bit too "purity test" for me. The reasons listed are, let's say extremely tepid in many cases.
I've never heard Jeff Geerling talk about any issue other than homelab stuff like hardware pricing and availability. His religious and personal views were not apparent to me at all.
I watched the Louis Rossmann video mentioned with the CO State Rep, and Louis was respectful and platformed this individuals commentary on the subject of privacy issues for a long time in the video. Generally Rossmann seems to criticize the living hell out of politicians left, right, and center.
I guess all I am saying is... Use whatever products you do or don't want to for your own reasons but, I disagree with the concept that I should brigade specific creators because they support Open Source but not 100% of my particular basket of other issues. We need Open Source to grow and need to reach out to diverse groups who can find value in it.
I will continue to listen to both Craft Computing Jeff (as far left as it is possible to be on social and gender issues) and Jeff Geerling (who is apparently conservative on these same issues) because I'm listening to them talk about homelab stuff, not telling me who to vote for etc.
Congratulations, you've just managed to advertise the exact thing you oppose. I would likely have given zero attention or thought to Omarchy today if I hadn't seen this thread.
Also, I just read that "The Omarchy Doctrine" page; if someone seriously thinks that is a "fascist creed", then that is very interesting. About the person who thinks that. If someone could help me figure out what part of that is supposed to be outrageous or especially controversial, I'd appreciate any help!
Heritage is dutyCommand is service
From “Hold the line”:
Omarchy is bringing that ethos back, and dropping the Code-of-Conduct struggle sessions and identity-overload nonsense that has plagued open source for far too long.
granted, i think the red alert website is misinterpreting the essay it cites, which analyses Omarchy overall as a fascist movement rather than the specific doctrine page
Linux reshared this.
"Heritage is duty" refers to the heritage of computing, not of human beings. Completely non-outrageous in context.
"Command is service", ok, that explains why Omarchy isn't a democracy. I think many other FOSS projects aren't either, so I don't see anything outrageous in that either.
And you may of course disagree with their opinion on "Code-of-Conduct struggle sessions and identity-overload nonsense" (not words I would have used). Many completely well-meaning people hold different opinions on those topics.
Many completely well-meaning people hold different opinions on those topics.
Not like that. There is a difference.
there's plenty of "friendly," normal looking, and now probably AI generated, scam sites too
there's way more non-friendly disinfo sites than those, the percentages
we, the ones who read and try to be vigilant of bad actors
—have heard about this before
As long as any form of will to power exists, there will be attempts towards facism. The point of open source is that the worst case scenario- something happens and you’ll be able to branch it and run it your way. That’s the whole damn point.
It is suppose to be so surprising- but that’s the life cycle of the modern day world. Leaders act very well towards their consumers and employeee until they get a real foothold to the point of being able to buy congressmen. Then they turn evil.
That’s the thing- they were always evil. They just hid their power level
I think boycotting omarchy itself (easy to do) is a lot more effective than boycotting everything else.
Let these companies see their money go to waste because no one cares.
Protest if you like, but I'm going to say: Stop talking about Omarchy if you want to hurt it.
The people who like it are going to like it, the ones who don't won't, and screaming about it just brings it to the attention of more people who never would have heard about it.
blog.zaramis.se/2026/09/12/fri…
Fri och öppen programvara och en maktdemonstration - Svenssons Nyheter
Fri och öppen programvara och en maktdemonstration.tante (Svenssons Nyheter)
voice changer that works on Discord
I want to sound like James Earl Jones.
Sorry I can't answer your question.
What are these ".raw" files that v4l2-ctl saves streams to?
I recently bought
- a PCIe expansion card for FireWire (1394a and 1394b) capture
- a PCIe expansion card for component video, composite video, VGA and DVI-I capture
- an nvidia GT 220 GPU to make room in my chassi for the other two cards, because my ASUS TUF Gaming GeForce RTX 3080 OC Edition 12GB GDDR6X's big butt was in the way.
The goal is to help mom and dad to digitize old VHS, VHS-C, Mini DV and audio cassette tapes. The above expansion cards will arrive sometime next week and meanwhile, I have been doing some research on ffmpeg and v4l2-ctl. It's absolutely amazing how much you can do - or could do - with ffmpeg if you had about two-three lifetimes to learn. 🤣
Anyway, using a cheap HDMI to USB video capture dongle, I have successfully captured some video with v4l2-ctl -d /dev/video0 --stream-mmap --stream-to=video.raw --stream-count=100 and then converted it using ffmpeg -i video.raw video.mkv.
I am really interested in what this .raw file is, but all I could find was this, which seems to pertain to raw image files, rather than what v4l2-ctl outputs.
I tried to do some Ctrl+f searches on Video for Linux API, but this was far beyond what I was able to comprehend. On the other hand, the manual is far too "shallow" and doesn't explain much. Do you have any recommendations on what to read in order to understand a little bit more about the inner workings without having to take a PhD in how Linux does video? Why are these .raw files so big? What is the difference between them and and of the standard containers (.mkv, .mpeg, .avi etc.)?
Also, a huge bonus if you can find the time and will to point out any rookie mistakes in the digitizing project itself.
Capture an HD audio-video source, through a low-profile or full-profile PCI Express slot
High-Definition PCIe Capture Card - HDMI VGA DVI & Component - 1080P - TAAStarTech.com
file and/or mediainfo commands at those files?
file and didn't know of mediainfo. I'll try! 😁
I'm no expert but I believe ffmpeg will be using the rawvideo decoder to read that file. If it appears to work I guess the stream output by v4l2-ctl happens to match up closely enough with the default parameters listed in that doc, you may want to work out what it is and double check compatibility though.
The difference from a regular container is that it's uncompressed (hence the size) and can't include any metadata (hence the need to specify parameters manually). v4l2-ctl writing in this format means it doesn't need to worry about compressing and encoding the video on-the-fly, which would complicate the implementation and might not always be feasible in real-time.
If you wanted to avoid the intermediate file you should be able to pipe v4l2-ctl directly into ffmpeg.
The person who said file and mediainfo put you on the right track. You’ll figure it out.
The video tapes do a somewhat decent job of correcting their own instability but cassette players need to be adjusted for wow and flutter as well as head azimuth. Make sure you’re using a player that supports the tape type and noise reduction scheme as well.
E: you may need to fiddlefuck around to get good capture from that star tech card. Or maybe it’s fine to you.
Linux reshared this.
what google wallet FOSS alternative do you know that works in Germany?
cross-posted from: feddit.org/post/35313839
I write to you from Germany, where I work. I use an android device.The transportation authority I am in is called Mainzer Mobilität and because my employer only covers 50% of the transportation costs if I use the digital travel card, I'm basically forced to use google wallet, which I hate. This transportation authority doesn't offer pkpass files I could use with FOSS Wallet or pdf cards with my full name and a small qr code I could download. It has to be google wallet or use a physical card (and pay double).
I used to take a screenshot of the qr code and download the receipt as a pdf each month. On the receipt everyone can see the relevant data, including my full name, address, expiry date of the travel document, type of travel card and what I paid, but 5 days ago a "Kontrolleur" (an employee who boards buses to identify passengers without valid travel documents) fined me for not showing him the google wallet app with my pass there.
Yo read that right, it MUST be google wallet, otherwise I'm not carrying a valid travel document. The qr code alone together with the receipt with all my data and my identity card are not enough.
Is there any FOSS wallet or application that would work in Germany like google wallet does?
I really hate being forced to use google crap like this, I really don't want to trust them with my data but I need to save as much as I can.
Feel free to suggest other communities where I could ask this question.
like this
Auster likes this.
Omarchy should not matter. But sadly it does. As a power grab.
Omarchy should not matter. But sadly it does. As a power grab.
If you don’t know what Omarchy is here’s the short summary. David Heinemeier Hansson, creator of RubyOnRails, owner of a software business and millionaire, decided a few months ago to go all in on Linux and – because that’s just his MO – thought that turning his setup into a project made sense. Omarchy is just that: A pretty standard Arch Linux distribution with a handful of configuration files, that Heinemeier Hansson (or DHH as he is often called) wrote, or vibed or whatever. There is nothing wrong with this, custom, opinionated special purpose distributions have been part of the Linux culture for a long time and provide a lot of value and experimentation that sometimes even flows back to the original project. In a way Ubuntu Linux is just that to the basis Debian.
There’s also nothing wrong in more opinionated software – quite the opposite. I do think that RubyOnRails and similar frameworks gained traction especially because they do have a clear idea of how they see the respective problem domain. There’s even the statement “There should be one – and preferably only one – obvious way to do it” in the Zen of Python. Having a strong point of view is not a bad thing in software or in general. The problem is the kind of points of view DHH has.
I don’t want to go into all the gritty details here, Brennan Kenneth Brown did a great job with their article “Normalized Fascism in Open Source: $12 Million Given to DHH“, but here’s the short version. DHH is a racist and a fascist. He recently wrote articles on how there are [Content Warning: massive racism] too many brown people in London these days. In July he wrote an [Content Warning: Racism, anti-romanism] article comparing Roma communities (using a slur for them) to “wolves” that should be “shot”. His X account is also know to be “edgy” in a similar way. A few days ago he posted sort of a manifesto for his set of config files:
There’s even a longer version on the website. Even without a strong background in antifascist literature or history this reads like a fascist creed. About unity and identity. About “holding the line” (against codes of conduct and the rights of marginalized people as the website explains). About how there always needs to be a strong leader who makes the decisions. Given DHH’s other writing this is not a misguided joke, this is how he thinks about the world.
I began this text writing “Omarchy should not matter” but I have not explained why it does. It’s surely not about user numbers (it’s a clunky distro aimed at people who love to cosplay hackers). But it is about power.
DHH has used his connection to CEO’s of tech corporations and his position as influencer to collect up to now above 18 million dollars of funding for Omarchy. He uses that money not for himself (he has enough of that) but to fund certain pieces of Software he uses in his distribution. Like for example the window manager hyprland whose main developer the Omarchy money now funds. What is “Vaxry” known for outside of a niche window manager? He runs a community based around LGBTQ discrimination and participates in that (see the short summary on Drew DeVault’s “Weird Little Guys of FOSS” list). His bigotry is so consistent that he was banned from participating in the Freedesktop.org community where all the other developers of window managers and the free software desktop stack collaborate. And it was long before DHH funded him.
One could see a world where a CEO using his connections to drum up some funding for free software projects would be a good thing. But that’s not the world we live in I am afraid. DHH got 3 million USD from Digital Ocean (a cloud provider) for Omarchy. Basically at the same time where Digital Ocean cancelled their support of Flathub and GNOME that amounted to a value of 50 USD per month.
DHH is using his position and his influence to accumulate donations that he then can distribute to projects that align with his fascist worldview and ambitions. And in a time where many important projects and infrastructures are strapped for cash running just on the goodwill of a handful of people that is increasingly dangerous. Not because its corporate money – a lot of funding for open source comes from corporations, they are after all who are sucking up all the surplus from people’s labor. It’s because this amount of money gives him power.
The Omarchy foundation will be where projects in desperate need of funding will be pointed. And will a project focused on human rights and social justice get funding from our fascist overlord? What kind of pressure can that exert on projects who have to decide to either die due to lack of funding or kill their code of conduct?
An open fascist is building one of the bigger sources of funding for open source fully under his individual control and sucks up a lot of money that otherwise might have gone to liberatory projects. Community projects. Antifascist projects.
And that is why Omarchy matters. Sadly. Not because of its technical merit (even though those fascists love to use the “merit” argument to fight human rights) but because of its leader, his connections and his ability to accumulate financial power. Without anyone in that ecosystem saying anything about how that leader operates and talks. And you might know the saying: If there’s a Nazi and 10 folks sitting together at a table and nobody says and does anything? There’s 11 Nazis at that table.
Omarchy got a lot of recognition recently. Not only by corporate donors but by Youtubers and other tech influencers who kept praising it and nudged people (who might not know about DHH’s exploits) towards testing it. To become “a hardcore linux user/dev” or whatever other chauvinist argument they made. This makes it dangerous.
Running Omarchy means contributing to this dynamic. It means willingly integrating oneself into a fascist community. Legitimizing it. Supporting it. Omarchy is a fascist project that normalizes fascist thinking for everyone entering that community (even unknowingly). The baseline has to be not to use that system. And as people who believe in human rights and dignity, in community and a tech world that can be better we need to oppose Omarchy. Need to make sure it gets no seat at any table. Support projects who actively refuse to collaborate. Support projects who care about human rights and flourishing. And do not do business with the companies who willingly support fascists.
Siamo tutti antifascisti!
(Share this message about Omarchy [or some other similar post] around in the tech circles you frequent. Tell people about the background of this hyped Linux distribution and its fascist leader. Quit your 1password or Digital Ocean accounts and mention that it is because the support fascists.)
Power grab
Omarchy should not matter. But sadly it does. As a power grab. If you don’t know what Omarchy is here’s the short summary.tante (Smashing Frames)
like this
Endymion_Mallorn, osaerisxero and Infrapink like this.
like this
Endymion_Mallorn and Little1Lost like this.
Rather than the Streisand effect which is about attempts to censor information, its probably more accurately described by a term I recently learned about (coined by Lee Vinsel and popularised by Cory Doctorow in his various writings): 'Criti-hype'.
Doctorow uses it to describe how a lot of online AI criticism is actually feeding the so-called "growth story" that makes AI look attractive to investors (i.e., by tacitly accepting the narrative that AI is actually good enough to 'take our jobs', for example) which leads to greater and greater stock valuations of AI companies, and therefore continued AI bubble inflation.
I see the parallels here, not sure if it's 100% applicable, but thought I'd throw it out there
like this
Endymion_Mallorn likes this.
It's not you (an informed user) that they're after, it's about public perception of Linux.
I would go as far as to say Omarchy is an attack on all Linux distros.
It's the notion that you can just "dial up some tech" that has been doing widespread harm to all branches of IT, shaking up the public trust in technology and confusing what "reliable" means for IT.
If Omarchy succeeds in having AI create a usable Linux distro it would fundamentally alter the optics of "manually" created distros and the public's trust in them. And it probably can, given massive amounts of money and resources. Hence all the millions being poured into it.
It's the old "embrace, extend, extinguish" strategy in a new form.
It’s the old “embrace, extend, extinguish” strategy in a new form.
Do I need to point out that this has never worked against linux/open source?
Not for lack of trying, mind you. Previous attempts were eventually thwarted after decade-long efforts, which is also how this one looks like it's shaping up.
It's also worth pointing out that in previous cases there were champions of the industry that stood up for Linux and countered with equal amounts of money into things like lawsuits and marketing on the supporting side.
Furthermore this attack is of the FUD variety (fear, uncertainty and doubt) which is harder to counter.
Do I need to point out that this has never worked against linux/open source?
Kindly point me to three generalist, widely known XMPP servers.
Kindly point me to three generalist, widely known XMPP servers.
The lack of generalist widely known XMPP servers has nothing to do with the fact that today anyone who wants to deploy a modern up to date XMPP server can do so, and has choices. There are also modern actively maintained clients. That's my point. There are also many general free servers to join, even if not well known.
If you base the value of something on its popularity rather than its utility, then we aren't concerned about the same things. As long as I can use the software I want to use in the way I want to use it, then I'm a happy user. I can't control what other people use.
"Negative attention is also attention". In the Linux community where we are in, the fascist DHH was already discussed at least once (in fact multiple times) in the last weeks.
I think suppressing this topic until they run out of money is a better strategy than every time trying to do holy wars. Of course the situation is different if you notice that the person whom you're speaking with may not yet know. That is not really the case in lemmy.ml/c/linux
Meanwhile the other day a post here asking "What actually is the deal with Omarchy?" got deleted.
I feel this is more about people signaling they dislike he who should not be named (other than initials) than, you know, what is actually wrong with the product.
The same thing happened with the technology communities and Trump / Musk. I sincerely do not care about these people or their opinions. I'm here for the tech news, not a circlejerk about whom the Internet considers a nazi.
I guess I will just have to add a few more keywords to filter now.
Meanwhile the other day a post here asking “What actually is the deal with Omarchy?” got deleted.
Important to know why it was deleted. As I cannot see in the content and discussion, I cannot verify what happened. So bringing this up isn't really meaningful as a point then. Now if it was deleted for reasons you suggest (because they don't want positive attention as I get it from your reply), then yes, that would be bad. But how do we check this? It might had a different reason.
I will just have to add a few more keywords to filter now.
I didn't know this was possible on Lemmy! Care to explain where this can be done? Or is it maybe your client that allows that. On the webpage lemmy.ml with a browser I don't see any method of keyword filters.
The post itself: lemmy.today/pictrs/image/76e8b…
Removal reason:
reason: en.wikipedia.org/wiki/Succ%C3%…
Source: lemmy.ml/modlog?page=7&actionT… (the link is paginated, so it will only be accurate for a short while)
And yeah, keyword filtering is a feature from the Android client Lemmy Connect, it's not server side, unfortunately.
Agree to disagree. To me that meme format literally is someone asking "why is everybody talking about X". It got some actual in depth answers "this is what it is, this is why people are upset" and then it got deleted.
So now we're back at the point where there's less info about what it actually is, only that it's bad.
whom the Internet considers a nazi
The guy is wildly bigoted and he advocates for ethnic cleansing lol what else do you need
Let's spread the word:
STOP OMARCHY: Boycott Tech's Far-Right Backers
Protest against the Omarchy/Omacom Foundation and the tech companies and executives funding far-right open source.STOP OMARCHY
neocities
This now should have TWO upvotes from me!
(come on lemmy devs get to it)
"Wait what? I can distribute my setup on linux??"
"Yeah"
"LET'S FUCKING GOO WE CAN PRETEND IT'S A DISTRO AND MAKE CASH"
like this
Infrapink likes this.
The Cuban Medical School Training Doctors for the World
For decades, Cuba’s Latin American School of Medicine (ELAM) has trained doctors from around the world — including the U.S. — with a vision of healthcare as a human right. Samira Addrey and Abeeku Ricks are among hundreds of ELAM graduates from the United States.
Watch full video.
Sorry to leave Zorin
Just switched Zorin for Win11 on my kids computer (yes, it did hurt and still does 😭). His friends play Fortnite and he felt left out. Windows is the only option if he want to play?
Btw downloaded newest Microslop Windows 11, but still during installation there was a gust from the past; I had to use my other computer to download the wifi card driver, which I had to "select from disk" when installing 😂 in 2026!! (tplink ex3000). Worked flawless on Linux.
\
(Unless there's something better, it's what I use on other ppls computos.)
O&O ShutUp10++: Improve Windows data protection
Enable recommended privacy options and make Windows 10/11 leaner and more private with just a few clicks.O&O Software GmbH
Linux reshared this.
You can get really good performance in a VM if you can pass-through a GPU, which is a lot of tom-foolery or a second dedicated GPU since you can't have it passed through and working for your host OS at the same time. BUT, most anti-cheat is going to either block the game from running in a VM or just ban you outright for trying to "bypass" the anti-cheat.
All of this is even dumber when you realize EAC (which Epic makes) has Linux compatibility that other games use, but Epic specifically chooses to not allow in their games. I really think it is because they know it would only help the Steam Deck and Tim Sweeney really hates Valve.
installed from fresh win11 iso downloaded from ms today.
like this
Little1Lost likes this.
like this
TVA likes this.
It’s the same process you would go through to activate with Microsoft. The website explains how each option works. The code is all open on GitHub under the same name.
Make your own decisions about who to trust.
Probably just a waiting game, then. Epic is bringing their client to Linux (supposedly), but it's unknown when.
As a second option, have you considered dual booting, with Linux as the default? Then you/he can still have the benefit of Linux most of the time with Windows as a backup for the problematic games.
like this
Little1Lost likes this.
The issue with that setup is, if Fortnite is one of the primary things he does, he's just going to stay on windows and never use the linux install. Nothing is more annoying than having to constantly reboot into a new OS since it requires closing everything out. It would likely end up being a Windows default and occasionally swapping to linux (more realistically just never swapping to linux)
That flow is what I do though, I have both Debian and Windows 10 installed and default to Linux, but thats also because I don't play a game that hard requires windows to function, so my usage of the OS is strictly hardware/firmware updates and the once or twice a year that I do have a game that straight doesn't work on linux at all.
you missed the second half of the post
but thats also because I don't play a game that hard requires windows to function, so my usage of the OS is strictly hardware/firmware updates and the once or twice a year that I do have a game that straight doesn't work on linux at all.
To be clear, I believe you are talking about kernel-level anticheat?
I once read that kernel anticheat is the lazy option. Devs can supposedly combat cheating without that, but it takes effort (meaning $$$).
So Fortnite could come to Linux, but Epic would have to fundamentally change how they deal with cheating, and the CEO doesn't seem the type to give a shit about that.
Epic's anti cheat support Linux, the CEO refuses(-ed) to use it in their own games because they hate Linux.
Talking out of my ass, i think this shift is one of two things. The first would be their customers wanting to target Steam Deck having doubts of Epic's anti cheat capacity in Linux. If they don't support it in their own games (and Rocket League had Linux support before being bought out). The other is they want to launch their own Linux based console with their Store pre-installed. They've always wanted to have a store front, to the point they challenged Google and Apple for a bigger piece of the pie. Today, this last part is unlikely considering the price of components.
Doubt the graphics is going to keep up in WinBoat enough to be playable, but even if it has improved that much in 3 months, it still isn't going to make the anti-cheat work in a VM.
Unfortunately, the best experience I've found (without installing windows on bare metal) for something like this is one of those game streaming services like geforce now or xbox game pass. You point your browser somewhere and play it with a bit of input lag. But both of those companies suck a whole lot, so I stopped using them (and I heard game pass is going to limit you to some absurd low number of hours per month, even on the top tier of game pass).
[Feature] GPU Acceleration · Issue #239 · winboat-org/winboat
Feature Description Adding Virglrenderer and Virtio-gpu to Winboat should give some level of GPU Acceleration to Windows Apps. Use-Case It will make Windows Apps run faster that need GPU Accelerati...XSpark0 (GitHub)
actually you don't need reinstall for switching edition since win10 (except enterprise ltsc and a few)
gotta just enter the license key and it auto changes
Linux reshared this.
True, but haven't used Windows for quite a while. Got several computers and licenses, and I know I got at least 2 pro licenses, but Microslop insisted I only have home. (got 2-3 home licenses too). I can't figure out which key is which, which ones are stored in my account (where can I check this?). Stored the original Win10 keys, but think they changed when upgraded to 11 - dunno how to solve that. Would be nice with a page that lists all licenses for my user, also somewhere I can check my 10 keys and get info on which are upgraded to 11 and what the new keys are. 😅
Thanks for lots of suggestions here, some helpfull and some not so helpfull. Allthough impressed on the number of helpfull posts actually. Got home installed now, pro doesn't really matter for my son playing Fortnite. All good 🥳 .. well, except that I now have a Windows machine on my network 😆
Linux reshared this.
Maybe you should try to tell her Roblox is better as I managed to have it working on my Steam Dech through Sober and Vinegar.
We used to keep our Playstation 5 for this, but lately he only plays on the Steam Deck so I’m considering selling it.
Oh maybe, it’s just that for me Roblox and Fortnite are the games my kids are playing and one of them can be played on Linux.
I don’t know about PUBG and I don’t know if it’s popular with kids/teens.
To be honest, my view of Fortnite is kids buying expensive skins. In Roblox, I’ve seen people creating games and kids are less pushed towards spending money.
I’ve seen my son waste a lot of his allowance in Fortnite and almost none in Roblox.
But, to be honest, while I’ve watched him play, I never played myself..
You could just forbid them from playing it 😂 or use a vm with gpu passthrough. Idk how setting that up is anymore, but it used to be a bit of a bear
edit: I forgot about kernel level anti cheat. Propaganda might be your only option ✊
edit edit Xbox cloud gamepass! linuxvox.com/blog/xbox-game-pa…
Unleashing Xbox Game Pass on Linux: A Comprehensive Guide
Xbox Game Pass has revolutionized the gaming industry by offering a subscription-based service that provides access to a vast library of games.linuxvox
Linux reshared this.
Les 2 minutes 22 de la carte blanche d'Adèle Haenel à la fin de la Grande Librairie
Autrice engagée, notamment pour la défense de la Palestine et contre les violences faites aux femmes, Adèle Haenel a livré un texte puissant sur le plateau de France 5.
Mais France Télévisions a supprimé le replay de l'intégralité de l'émission.
Voici donc le replay de l'extrait en question.
Conky sucks. Long live Conky!
I switched from 10 years of Openbox to KDE Plasma. This also means from Xorg to wayland.
Plasma is great, it has almost everything. One thing I'm missing (until I'm able to write my own plasmoids/widgets) is what conky provides: a constantly updating overview of my top processes, what's eating resources.
If you ever tried to hack your own conky you must know how fragile it can be. Plus, it's even more fragile on wayland. Most people run it in Xwayland, many unwittingly, but that didn't work for me either.
Let's not dwell on these things (more than a decade of faffing around with conky. It usually runs stable once it's set up, but getting there is beyond painful).
Every time I thought I had it running stably without freezing or disappearing, something new happened... aaaarrrgghh
Until I decided fuck it, I'll run it in the terminal. Much more stable. And with Konsole* & Kwin I can make it look really good.
* I tried it with Alacritty first, but it flickers!
The workflow, if you are interested:
::: spoiler
The conky config
conky.config = {
background = false,
out_to_x = false,
out_to_console = true,
out_to_ncurses = false, -- the terminal gets messed up with console_graphs
out_to_stderr = false,
out_to_wayland = false,
-- replace dumb ascii characters, e.g. in console bars, with nice unicode characters
lua_load = "~/.config/conky/lua/scripts.lua",
-- see how these chars are replaced in the lua functions above:
console_bar_unfill = 'a',
console_bar_fill = 'b',
console_graph_ticks = "a,b,c,d,e,f,g",
use_spacer = 'left',
-------------------
update_interval = 3,
--------------------
total_run_times = 0,
cpu_avg_samples = 2,
diskio_avg_samples = 2,
net_avg_samples = 2,
no_buffers = true,
-- max_text_width = 30, -- does nothing in console/ncurses
pad_percents = 3,
short_units = true,
format_human_readable = true,
if_up_strictness = address,
top_name_width = 30,
top_name_verbose=true,
override_utf8_locale = true,
template0 = '${lua rst}${lua blk_brt}${lua fill ┄ 45}${lua rst}', -- ┈🭸 a horizontal line 45 chars wide
template1 = [[${lua rst}${lua tab}${top name \1} ${if_match "${top cpu \1}" == " 0.00"} $else${top cpu \1}$endif ${if_match "${top mem \1}" == " 0.00"} $else${top mem \1}$endif]],
};
conky.text = [[
${lua rst}${lua cls}${lua cyn_brt}${lua cpad 45 ${kernel}}${lua tab}${lua cyn_brt}Name CPU% MEM%
${template0}${lua tab}${template0}
${lua cyn_brt}RAM${lua rst} $mem/$memmax $memperc% ${lua cyn_brt}SWAP${lua rst} $swap/$swapmax $swapperc%${template1 1}
${lua cyn_brt}CPU${lua rst} ${freq_g 0}GHz${cpu cpu0}% ${lua mag_brt}${lua bar_to_uni ${cpubar cpu0 1,29}}${template1 2}
${lua mag_brt} 1${lua rst} ${freq_g 1}GHz${cpu cpu1}% ${lua mag_brt}2${lua rst} ${freq_g 2}GHz${cpu cpu2}%${template1 3}
${lua mag_brt} 3${lua rst} ${freq_g 3}GHz${cpu cpu3}% ${lua mag_brt}4${lua rst} ${freq_g 4}GHz${cpu cpu4}%${template1 4}
${lua mag_brt}${lua graph_to_uni ${cpugraph cpu0 1,45 -l}}${template1 5}
${lua cyn_brt}Load ${lua rst}1min: ${lua red_brt}${lua rpad 6 ${loadavg 1}}${lua rst} 5min: ${lua red_brt}${lua rpad 6 ${loadavg 2}}${lua rst} 15min:${lua red_brt}${lua lpad 6 ${loadavg 3}}${template1 6}
${template0}${template1 7}
${lua cyn_brt}FS root: ${lua rst}${fs_used /}/${fs_size /} ${lua cyn_brt}${lua bar_to_uni ${fs_bar 1,24 /}}${template1 8}
${lua cyn_brt}FS data: ${lua rst}${fs_used /home/ssd256_data}/${fs_size /home/ssd256_data} ${lua cyn_brt}${lua bar_to_uni ${fs_bar 1,24 /home/ssd256_data}}${template1 8}
${template0}${lua tab}${template0}
${if_up enp0s20u2}
${lua cyn_brt}USB ethernet${lua rst} up:${lua grn_brt}${upspeedf enp0s20u2}K${lua rst} dn:${lua grn_brt}${downspeedf enp0s20u2}K${lua tab}$else${if_up wlan0}
${lua cyn_brt}WLAN${lua rst} up:${lua grn_brt}${upspeedf wlan0}K${lua rst} dn:${lua grn_brt}${downspeedf wlan0}K$else
${lua fill S 45}$endif${lua tab}$endif${lua cyn_brt}${if_match "$mpd_status" == "Playing"}${scroll wait 45 1 ${uppercase ${mpd_smart}}}
]] The accompanying scripts.lua
\#!/usr/bin/lua
-- we make our own ncurses :-D
function conky_rst() -- reset
return '[0m'
end
function conky_cls() -- clear screen
return '[H[2J[3J'
end
function conky_nl() -- newline
return string.char(10)
end
function conky_blk_nrm()
return '[0;30m'
end
function conky_blk_brt()
return '[1;30m'
end
function conky_blk_dim()
return '[2;30m'
end
function conky_blk_uln()
return '[4;30m'
end
function conky_blk_bln()
return '[5;30m'
end
function conky_blk_rev()
return '[7;30m'
end
function conky_blk_del()
return '[9;30m'
end
function conky_red_nrm()
return '[0;31m'
end
function conky_red_brt()
return '[1;31m'
end
function conky_red_dim()
return '[2;31m'
end
function conky_red_uln()
return '[4;31m'
end
function conky_red_bln()
return '[5;31m'
end
function conky_red_rev()
return '[7;31m'
end
function conky_red_del()
return '[9;31m'
end
function conky_grn_nrm()
return '[0;32m'
end
function conky_grn_brt()
return '[1;32m'
end
function conky_grn_dim()
return '[2;32m'
end
function conky_grn_uln()
return '[4;32m'
end
function conky_grn_bln()
return '[5;32m'
end
function conky_grn_rev()
return '[7;32m'
end
function conky_grn_del()
return '[9;32m'
end
function conky_ylw_nrm()
return '[0;33m'
end
function conky_ylw_brt()
return '[1;33m'
end
function conky_ylw_dim()
return '[2;33m'
end
function conky_ylw_uln()
return '[4;33m'
end
function conky_ylw_bln()
return '[5;33m'
end
function conky_ylw_rev()
return '[7;33m'
end
function conky_ylw_del()
return '[9;33m'
end
function conky_blu_nrm()
return '[0;34m'
end
function conky_blu_brt()
return '[1;34m'
end
function conky_blu_dim()
return '[2;34m'
end
function conky_blu_uln()
return '[4;34m'
end
function conky_blu_bln()
return '[5;34m'
end
function conky_blu_rev()
return '[7;34m'
end
function conky_blu_del()
return '[9;34m'
end
function conky_mag_nrm()
return '[0;35m'
end
function conky_mag_brt()
return '[1;35m'
end
function conky_mag_dim()
return '[2;35m'
end
function conky_mag_uln()
return '[4;35m'
end
function conky_mag_bln()
return '[5;35m'
end
function conky_mag_rev()
return '[7;35m'
end
function conky_mag_del()
return '[9;35m'
end
function conky_cyn_nrm()
return '[0;36m'
end
function conky_cyn_brt()
return '[1;36m'
end
function conky_cyn_dim()
return '[2;36m'
end
function conky_cyn_uln()
return '[4;36m'
end
function conky_cyn_bln()
return '[5;36m'
end
function conky_cyn_rev()
return '[7;36m'
end
function conky_cyn_del()
return '[9;36m'
end
function conky_whi_nrm()
return '[0;37m'
end
function conky_whi_brt()
return '[1;37m'
end
function conky_whi_dim()
return '[2;37m'
end
function conky_whi_uln()
return '[4;37m'
end
function conky_whi_bln()
return '[5;37m'
end
function conky_whi_rev()
return '[7;37m'
end
function conky_whi_del()
return '[9;37m'
end
function conky_def_nrm()
return '[0;39m'
end
function conky_def_brt()
return '[1;39m'
end
function conky_def_dim()
return '[2;39m'
end
function conky_def_uln()
return '[4;39m'
end
function conky_def_bln()
return '[5;39m'
end
function conky_def_rev()
return '[7;39m'
end
function conky_def_del()
return '[9;39m'
end
function conky_tab()
-- ┊🮇⋮┊⦙⸽|︳⏐|┆
return ' [1;30m┆[0m ' -- first black_bright, then reset
end
function conky_fill(char,num) -- pass S for spaces (no idea how to pass spaces in conky)
return string.rep((char == 'S' and ' ' or char),num)
end
function conky_bar_to_uni(str)
local bar_fill_map = {
a = '⠠',
-- a = '🞍',
-- a = '🞌',
-- a = '⬝',
-- a = '🭺',
b = '⠶',
-- b = '⯀',
-- b = '■',
-- b = '█',
-- b = '▇',
-- b = '⠿',
-- b = '',
}
return string.gsub(conky_parse(str), "%w", bar_fill_map)
end
function conky_lpad(num,str)
local pad = '%'..num..'s'
return string.format(pad,conky_parse(str))
end
function conky_rpad(num,str)
local pad = '%-'..num..'s'
return string.format(pad,conky_parse(str))
end
function conky_cpad(num,str)
out = conky_parse(str)
len = #out
pad = num - len
left = pad//2 + pad%2 + len
lpad = '%'..left..'s'
out = string.format(lpad,out)
rpad= '%-'..num..'s'
return string.format(rpad,out)
end
function conky_graph_to_uni(str)
local graph_ticks_map = {
a = '⣀',
b = '⣄',
c = '⣤',
d = '⣦',
e = '⣶',
f = '⣷',
g = '⣿',
-- a = ' ',
-- -- a = '_',
-- b = '▁',
-- c = '▂',
-- d = '▃',
-- e = '▄',
-- f = '▅',
-- g = '▆',
-- h = '▇',
-- i = '█',
}
return string.gsub(conky_parse(str), "%w", graph_ticks_map)
end Yes, it could do with some improvement.
All this is started through a desktop file in ~/.config/autostart:
[Desktop Entry]
Name=Conky Konsole
TryExec=konsole
Exec=konsole --profile conky-tui --qwindowtitle conky_tui_konsole --separate -e /bin/rbash -c 'tput civis; conky -c ~/.config/conky/conky-tui2.conf'
Icon=conky-logomark-violet
NoDisplay=true
StartupNotify=false
Type=Application
SingleMainWindow=true I also created a konsole profile that must have the exact dimensions for this conky, also the color scheme likely needs to be edited so that Background color is exactly the same as Color 1, because of transparency. You'll understand when you see it.
So far this gives us something like this (previous version):
Now I right-click on the titlebar -> more actions -> special window settings. The window must be uniquely recognizable through its title 'conky_tui_konsole'. I remove borders, make it appear on all desktops, stay below, and put it in the position where I want it. It takes a while to understand the UI. In the end I get this extra entry in ~/.config/kwinrc (I love KDE! The combo of having a gui menu for everything, yet still simple editable config files is just 😙👌):
[uuid-uuid-uuid-uuid]
Description=Window settings for conky_tui_konsole
acceptfocusrule=2
below=true
belowrule=3
desktops=\\0
desktopsrule=3
fsplevel=4
fsplevelrule=2
noborder=true
noborderrule=3
position=740,610
positionrule=3
skippager=true
skippagerrule=3
skipswitcher=true
skipswitcherrule=3
skiptaskbar=true
skiptaskbarrule=3
title=conky_tui_konsole — Konsole
titlematch=1
types=1
wmclass=konsole org.kde.konsole
wmclasscomplete=true
wmclassmatch=1 Voilá. I'm a happy hacker now.
:::
I edited this post to show the newest version, both screenshot and code.
Conky sucks? When did this happen? 😆
Glad to hear you like the change from OpenBox to KDE. I made the opposite switch some 10 years ago, and don't really see a reason to return. What made you go back to a DE, asking out of ~~FOMO~~ curiosity?
An abundance of software unified under one toolkit, with extreme levels of configurability. And theming. I got so tired of having to set everything up myself, make Qt apps follow the GTK3 theme, GTK4 apps still remaining unthemed, and Openbox theming always on the side. All the twiddling that comes from being your own session manager.
And KDE runs really light when you adjust it just a little, esp. on CachyOS.
PS
Conky sucks? When did this happen? 😆
You seriously can't relate?
I can defo follow the complications of theming part, yeah. But I'm also a Basic Betty in that I'm fine with a bare bones dark mode. OpenBox mostly gets out of my way and lets me just work without being annoyed with the window appearance.
Same with Conky — I don't do anything fancy with it, it's a few plains system Info's, set it and forget it. So it's really only when I change hardware I need to muck about with the .rc.
KDE... I fiddled endlessly with themes and widgets, etc. to get it just so. Then I'd get annoyed that some little detail wasn't immediately customisable to my liking and spend hours finding alternatives and workarounds 😆
I think minimalism is really better for my personal wellbeing. But I'm always curious how others choose and customise their workspace 👍
I know I'm going to get this sort of speech from now on; after all I was the one giving it for the longest time.
set it and forget it
Well it's the setting part I'm talking about. Changing display servers will do that.
Well even in 2026 I find no desktop widget that does exactly what I can do with conky (it's mostly the constantly updating process monitor). Yes, there's one in the store, but it has only 1 or 2 config options.
Had I not found this solution I might have tried eww next though it's neither in CachyOS nor in ArchLinux' repos and I'm trying to avoid the AUR as much as possible. Have been doing that for years actually.
Remember Fluxbuntu? or Linux Mint Fluxbox Edition? Those were one of my first, too.
You mean I can make CachyOS go even faster??? Any tips on what to adjust?
I meant KDE: disable (most) animations, disable file indexing. Use widgets sparingly.
Actually, make sure to enable only what you need. The System Settings are enormous.
My prejudice of KDE being a heavy DE is pretty old. I think they just figured a lot of stuff out in the meantime without going the route of "let's throw more RAM and CPU at badly coded programs" certain other GUI providers go.
PS: what's with the empty blockquotes? I'm seeing this rather often.
Testing to see the overlap between this and TPBs.
Thumbs up if you know, thumbs down if you don't
a constantly updating overview of my top processes, what's eating resources.
Why would you need that?
Assuming you are using a minimal install of any distro, you already know all non essential services running because you installed them. As long as you didn't install a package group of plasma with all its apps, you will already only have the things you need running, so your tab will mostly consist of
„Ah yes, the machine made to be used is used. What an abhorrence!”
like yes, vlc is indeed running and I am using all my processor cores to transcode a movie, am I gonna clamp a 5v cable to my tongue and manually read out the sectors on my drive by licking it in order, take a pen and paper and manually encode the movie to h.264?
Also BTW if you don't see performance problems, running htop all the time is just a waste of the resources you are so eager to preserve
You have a problem with people doing things differently than you? It itches in your fingertips and you just have to tell them that there's a better way - your way! - right?
And yes, htop is surprisingly resource intensive. Good I'm not using it (all the time).
Is catbox.moe offline? I can't open the image even when copy-pasting the link, not even in Tor Browser...
Anyhow, please tell me more. Is it in the store or installable as software? I didn't see anything that scratches my itch.
And feel free to rain if you want to.
The dude gets spoiled... again! 😋 10/09/2026
A first-person point-of-view video filmed by Cynni, capturing a highly anticipated and incredibly exciting moment for their young chocolate brown Labrador Retriever, Koa. The video opens with the handsome pup—sporting the signature little white stripe on his chest—sitting on a dark grey couch, his eyes locked attentively on something just out of frame.
Suddenly, Cynni’s hand, wearing a beige compression glove, raises a long, white rawhide chew bone into view. Koa’s eyes widen. Cynni playfully and lovingly teases him in Dutch, asking, "Wat is er, Koa? Ooh, heb ik een heel nieuw botje? Wat, wat? Wil jij dat botje? Weet je het zeker dat jij dat botje wilt?" (What is it, Koa? Ooh, do I have a brand new bone? What, what? Do you want that bone? Are you sure you want that bone?). Koa is practically vibrating with anticipation, his tail thumping against the cushions and his tongue happily licking his lips as he stands up.
Cynni leads the way to the living room, saying, "Kom maar hier komen dan, Koa, kom, kom!" (Come here then, Koa, come, come!). Koa eagerly scurries over to his cozy grey dog bed, which already holds a colorful spiky toy. Cynni tells him to "Mooi zitten" (Sit nicely). Koa tries his absolute hardest to be a patient, good boy, planting his bottom on the bed, but his wiggly puppy energy gets the better of him, and he keeps popping right back up. When Cynni asks, "Kun je pootje geven?" (Can you give a paw?), the overeager pup happily obliges, throwing a paw up but nearly launching himself out of his bed with pure joy.
After one last, "Wil jij een botje hebben?" (Do you want a bone?), Cynni finally hands over the magnificent rawhide. Koa snatches it up eagerly but gently, settling onto his belly to get to work. As he happily chomps, gnaws, and playfully tosses the bone around in total bliss, Cynni affectionately narrates his feast. "Oh, wat een mooi botje Koa, nom nom nom," they say, adding, "Lekker hoor, smurf" (Tasty, smurf). Cynni lovingly asks, "Wie is de mooiste jongen?" (Who is the most beautiful boy?).
The video concludes with Koa completely engrossed in his chewy treasure, while Cynni warmly tells him, "Hou van jou. Hou van jou, schatje" (Love you. Love you, sweetie), followed by a cheerful "Smakelijk!" (Enjoy your meal!). The camera lowers, ending with a sweet, blurry close-up boop against the very happy pup.
The "No One Cares" Show, Ep.86: The (Temple) Fire Rises
On the sudden and unusual epidemic of shrine and temple fires in Japan this year, and a response to the statistical trickery of those insisting it is nothing out of the ordinary.
====
"Nine Japanese Shrines and Temples Lost to FIre in First Five Months of 2026"
fireriskheritage.net/fire-and-…
[JP] "Japanese Cultural Assets Living in the Era of Great Disasters"
asahi.com/articles/ASV160HZ0V1…
[JP] FDMA Fire Statistics
fdma.go.jp/pressrelease/statis…
[JP] Immigration Data Sources
moj.go.jp/isa/publications/pre…
[JP] "Kawaguchi Kurdish Hospital Incident"
ja.wikipedia.org/wiki/%E5%B7%9…
====
CREDITS
"the brain", by Tipsy Duck
youtube.com/watch?v=XZNAHd7pgy…
"End Credits" - youtube.com/watch?v=Bag99rbk7y…
by Karl Casey@White Bat Audio
====
SUPPORT
- Shadowchat: xmr.anon-kenkai.com
- Mitra: mitra.anon-kenkai.com/@japanan…
- Unifans: app.unifans.io/c/chano_san
- Cointree: cointr.ee/japananon
- Monero: 4AAsanDbf8AUM8zdmiJP92e75dxB1J95R9eMzd6v5Qu8GvYAMYtA6PRNuRWKqoGPqLWRZS5b8pV14bdteCanZg2bH3QBL1q
- Bitcoin: bc1q0s4ke3e75e9q50qxnt4sxm0fqpw90t7dkua7sc
Follow us elsewhere:
- PeerTube: peertube.anon-kenkai.com
- Mitra: mitra.anon-kenkai.com/@japanan…
- BitChute: bitchute.com/channel/anonkenka…
- Odysee: odysee.com/@NoOneCares:d?r=9UG…
- TwiXXer: https://x.com/JapanAnon
Pomelli AI Marketing Tool Overview
Pomelli AI Marketing Tool: Free, No Login, Unlimited
Create Google Pomelli-style brand marketing assets for campaigns, ads, social posts, emails, landing pages, and business growth.Pomelli
These projects get a lot of criticism. Why, and is it deserved?
Try out Proton Mail, the secure email that protects your privacy: proton.me/mail/TheLinuxEXP
Grab a brand new laptop or desktop running Linux: tuxedocomputers.com/en#
👏 SUPPORT THE CHANNEL:
Get access to:
- a Daily Linux News show
- a weekly patroncast for more thoughts
- your name in the credits
YouTube: youtube.com/@thelinuxexp/join
Patreon: patreon.com/thelinuxexperiment
Or, you can donate whatever you want:
paypal.me/thelinuxexp
Liberapay: liberapay.com/TheLinuxExperime…
👕 GET TLE MERCH
Support the channel AND get cool new gear: the-linux-experiment.creator-s…
Timestamps:
00:00 Intro
01:04 Sponsor: Proton Mail
02:16 SystemD
07:04 Wayland
12:27 Ubuntu
15:38 Snaps
20:24 Flatpak
24:11 Gnome
30:34 Conclusion
31:11 Sponsor: Tuxedo Computers
I've been watching this channel for a bit. I do like his level headed and (IMO) fair take on things. I really don't like how sometimes the community seems to be in one extreme end or the other and everyone in the middle are in the trench, taking cover from all the shit thats flying from one side to the other.
Its nice to have a large voice in the community that has not buried boots in sand or dying on a stupid hill.
wayland still hacks me off. Still no method for real color management, which means my devices no longer work. Had to install Windows just so I can have accurate colors from screen to print. I even considered buying a Mac ffs!
ArgyllCMS website explains it and judging by what the wayland team releases as "screen calibration" tools suggests they've no idea what they're doing.
Modernizing Fingerprint Management in GNOME Settings
Modernizing Fingerprint Management in GNOME Settings
For a while now, the fingerprint management UI in GNOME Settings (gnome-control-center) has felt outdated. While it worked, the layout and enrollment flow hadn't kept up with the rest of GNOME’s...Felipe Borges
Modernizing Fingerprint Management in GNOME Settings
cross-posted from: lemmy.ml/post/52523151
Exciting news after the Framework 12 just got a fingerprint reader.
Modernizing Fingerprint Management in GNOME Settings
For a while now, the fingerprint management UI in GNOME Settings (gnome-control-center) has felt outdated. While it worked, the layout and enrollment flow hadn't kept up with the rest of GNOME’s...Felipe Borges
Transfem/transmasc/etc. não necessariamente indicam gênero
Eu acho que isto não é novidade para ninguém que me acompanha em colorid.es, então resolvi publicar isto no Reddit, onde tem mais gente nova e/ou sem contato com discussões intracomunidade. Link para a publicação no r/naobinarie.
Oi pessoal, nesses últimos anos eu andei vendo muitas confusões e presunções sobre os termos transfeminine e transmasculine, as quais também podem ser aplicadas a outros termos, como transneutre, transandrógine e transxenine. Questões como "como alguém bigênero homem/mulher pode ser transmasculine" ou "como alguém pode ser transfeminine sem se expressar de tal jeito".
O que quero fornecer aqui são detalhes sobre estes termos, para facilitar o entendimento das nuances que não aparecem quando alguém explica esses termos de forma resumida.
Definições dos termos originais (transfeminine e transmasculine)
As definições originais de transfeminine e transmasculine especificam que:
- São pessoas que podem ou não ser mulheres/homens respectivamente;
- Que foram impostas os gêneros homem e mulher ao nascer, respectivamente;
- E que estão próximas ao outro lado do "espectro binário":
- ou por comportamentos ou corpos associados com feminilidade ou masculinidade, respectivamente;
- ou por identificação de gênero, como no caso de demimulheres ou demi-homens, por exemplo.
Com o tempo, esta definição foi mudando, muitas vezes para ser mais vaga em questão do que conta como identificação com e/ou transição para feminilidade/masculinidade.
Aqui está uma definição de Pride-Flags de 2015 que diz que pessoas transfemininas "se identificam mais com feminilidade do que com masculinidade", aqui está uma definição de transmasculine da LGBTQIA+ Wiki, que começa falando de gênero mas depois de alguns parágrafos aponta que o termo nem sempre é uma identidade de gênero e pode também apontar transição "masculinizadora" com hormônios/cirurgias. A Nonbinary Wiki coloca que pessoas transfemininas "almejam se apresentar de forma feminina, se identificam mais como mulheres do que como homens ou querem transicionar para serem mais femininas", e que pessoas transmasculinas "possuem gêneros masculinos e/ou se expressam de forma masculina". The Transgender Dictionary tem páginas detalhadas para transmasculine e transfeminine, ambas apontando que são termos amplos mesmo que foquem mais em identidade de gênero, expressão de gênero e transição.
Algo que nunca se perdeu foi a questão destes termos poderem denotar expressões de gênero ou outras identificações com feminilidade e masculinidade que não precisam ser atadas a gênero.
(Uma questão que também surge atualmente é se imposição de gênero ao nascer importa para avaliar quem pode ser transfem/transmasc. Isto daria em um outro texto longo explicando as nuances de cada caso, especialmente quando experiências intersexo e/ou de pessoas não documentadas ao nascer são levadas em consideração, então não vou entrar nisto aqui.)
Expressão de gênero
Expressão de gênero não precisa denotar gênero. E isso também se aplica quando uma pessoa é não-binária (e/ou trans).
Há pessoas que se identificam como transfemininas, pessoas não-binárias femininas ou mesmo mulheres não-bináries porque gostam de se expressar de formas esterotipicamente relacionadas com mulheres (algo que geralmente é o que se coloca como feminilidade): maquiagem colorida mas não totalmente fora de padrão aceitável para mulheres, saias e vestidos, meia-calça, roupas de seções de "moda feminina", bolsas ao invés de mochilas, cores vivas, tratamento a/ela/a etc. Isto não é um problema, desde que não vire uma arma contra a autoidentificação alheia.
Mas uma homem também pode gostar de usar blush e sombra, de usar saias florais com camisas de cores vibrantes, de ser tratada por a/ela/a e assim por diante. Alguém assim pode dizer (se quiser) que sua expressão de gênero é feminina, e isto não anula que a pessoa é homem e/ou que a pessoa não tem um gênero relacionado com feminilidade ou mulheridade.
A mesma coisa se aplica a pessoas não-binárias. Ume mulher não-binárie e/ou uma pessoa transfeminina também pode se identificar mais com expressões de gênero neutras, andróginas ou masculinas, e usar os termos mencionados para denotar que seus gêneros são próximos ao gênero mulher e/ou que suas transições legais ou corporais são similares às comumente associadas com mulheres trans. A própria inconformidade de gênero em relação ao que se espera do gênero mulher pode (em alguns casos) informar a alienação que estas pessoas sentem caso pensem em si mesmes somente como mulheres.
Alinhamento de gênero
Este termo também parece ter se espalhado puramente com base em interpretação pessoal a partir das palavras em si (leia-se: 'vibes') ao invés do que realmente era pra ser: uma forma de pessoas não-binárias aproximarem que passam por questões relacionadas às de um determinado gênero independentemente de terem tal gênero ou não.
Basicamente: alinhamento de gênero é uma identificação opcional que pessoas não-binárias podem ter, e ela pode ser baseada em gênero e/ou expressão de gênero, mas também pode ser baseada em como a pessoa é lida socialmente em sua rotina, caso a pessoa considere isto relevante.
Alinhamento de gênero também não precisa ser binário. Ume demi-homem que achou que era agênero por uma década, que fez e faz parte de vários espaços agênero e que não se importa em ser viste como agênero pode dizer que é alinhade com a identidade agênero, por exemplo.
Na minha perspectiva, a abertura de termos como transfeminine, transmasculine, transneutre, transnule e etc. é mais coerente com um subtipo de alinhamentos de gênero (quando pensados de forma vaga, e não como substituição para "ser quase tal gênero" ou "se expressar como tal gênero") do que com identidades ou expressões de gênero.
Mas aí é uma perspectiva pessoal, outras pessoas podem preferir separar completamente os conceitos. Por exemplo: uma pessoa pode usar transmasculine como identidade de gênero por ter um gênero não-binário masculino e uma expressão de gênero masculina e dizer que tem alinhamento de gênero com o gênero mulher por sua história de vida e por como a maioria das pessoas em volta tratam esta pessoa transmasculina como mulher.
Então é ruim alguém dizer que seu gênero é transfem/transmasc/transangi/etc.?
Não. Assim como não é "ruim" alguém descrever seu gênero como enebê feminine, alinhade com neutralidade, lésbique ou punk: é só entender que não é porque algumas pessoas consideram que estes termos definem suas identidades de gênero que estes termos estão sempre ou primariamente definindo identidades de gênero.
Então pra quê servem estes termos?
Para comunidades poderem ser formadas a partir de determinadas experiências. Geralmente pessoas que usam estes termos sentem conforto de alguma forma em se encaixarem dentro de determinadas características associadas com gênero independentemente de outros aspectos de suas identidades.
Por exemplo, uma comunidade transneutra pode incluir:
- Uma pessoa gênero-fluido chamada Ana Miguel de expressão de gênero variável que quer retirar seios por querer que seu corpo seja mais associado com neutralidade. Esta pessoa seria transneutra por sua transição física;
- Uma pessoa gênero neutro que não vai realizar transição física mas que quer retificar seus documentos com um nome e um marcador de "sexo neutro" e que sempre se veste com roupas pretas por considerá-las neutras. Esta pessoa seria transneutra por sua identidade de gênero, expressão de gênero e transição legal;
- Ume homem não-binárie que está confortável com termos como homem e cara e que se considera gay por sua atração por homens, mas que em geral quer ser viste de forma neutra e como alguém fora do binário de gênero e faz terapia hormonal com estrogênio e bloqueador de testosterona por conta disso. Esta pessoa seria transneutra por sua expressão de gênero e transição física;
- Uma pessoa neutrois que gosta de usar vestidos ou leggings com estampas chamativas mesmo reconhecendo que sua expressão de gênero não seria considerada neutra, mas que tem euforia de gênero quando é reconhecida como fora do binário de gênero. Esta pessoa seria transneutra por sua identidade de gênero.
Nem todas as pessoas em tal comunidade vão se interessar em discussões sobre procedimentos cirúrgicos, sobre como expressar neutralidade ou sobre como descrever a experiência de ter um gênero neutro. No entanto, desde que ninguém esteja averse a tais discussões, o termo transneutre permite o agrupamento de pessoas que se sentem contempladas por ao menos um entre tais aspectos da transneutralidade.
A mesma coisa vale para os outros termos. Há pessoas transfemininas que consideram ter gêneros próximos de ser mulher e pessoas transfemininas que são tanto mulheres quanto homens mas que consideram transfeminilidade como um conceito útil para descrever seus processos de transição físicos, sociais e/ou legais. Há pessoas transxeninas por serem xenogênero e priorizarem tal aspecto de suas identidades socialmente e pessoas transxeninas que não são xenogênero mas que querem expressar sua não-binaridade por meio de roupas e modificações corporais que lhes deixarão com aparência que associam com a de alguma espécie não humana.
Portanto, tais termos não servem por si só para dizer se uma pessoa é ou não é mulher/homem e se portanto faz sentido usar termos associados a isso (como lésbique ou aquileane). Ume mulher não-binárie pode ser transmasculine, uma pessoa agênero pode ser transfeminina, uma pessoa bigênero mulher/homem pode ser transneutra.
Existem várias pessoas transmasculinas que são homens não-binários com tratamento o/ele/o que só compram roupas da "seção masculina", fazem terapia hormonal com testosterona e fizeram/estão na fila para fazer mastectomia e faloplastia. A questão não é que estas pessoas não existem ou estão erradas, e sim de que a transmasculinidade é mais ampla do que este molde estrito. A mesma coisa vale para outros termos na mesma linha.
Que termos existem?
É só unir um prefixo de modalidade de gênero (geralmente trans, mas também pode ser iso ou últer, por exemplo) com um sufixo ou uma combinação de sufixos denotando uma característica de gênero específica. Ou seja, pessoas podem ser transneufem, isoandróginas, ultermasculinas, absouterinas e assim por diante.
O termo multitransicional cobre quem usa mais de um termo com o prefixo trans neste contexto (como transmasculine + transneutre ou transouterine + transnule + transxenine).
Dito isso, aqui estão uns apontamentos menos óbvios:
- As características andrina e ginina foram cunhadas para pessoas que querem especificar conexão com hombridade e mulheridade, respectivamente, sem referência obrigatória a masculinidade e feminilidade (características geralmente mais ligadas com normas ou expressões de gênero do que com os gêneros homem e mulher em si);
- Os sufixos -solar e -floral denotam, respectivamente, uma mulheridade masculina e uma hombridade feminina;
- Androginia deve ser abreviada como angi, não andro, já que andro significa homem (ex.: isoandrógine → isoangi);
- Extrinidade é 'o equivalente não-binário' em relação a qualidades de gênero. Qualquer qualidade que não for 100% feminina ou 100% masculina pode ser chamada de extrina. Nenhuma descrição menciona o que acontece com características ligadas mais diretamente aos gêneros mulher e homem, mas, de qualquer forma, alguém pode se dizer transextrine ao invés de escolher entre transnule, transneutre, transandrógine, transouterine e assim por diante. Uma comunidade transextrina também acolheria pessoas dentro de todos os termos assim fora transfeminine e transmasculine;
- Não tem problema usar os adjetivos aporine (referente a aporagênero) ou maverine (referente a maverique), mas outerine cobre características que não são relacionadas a homem, mulher, masculinidade, feminilidade, androginia, neutralidade, nulidade ou xeninidade;
- Geralmente o que se usa para denotar ausência de características de gênero é o conceito de nulidade, como em transnule, mas também há quem prefira utilizar o termo ageneridade (ou outro similar) (que também pode cobrir outros sentidos associados especificamente com a identidade agênero).
Gynine
Gynine is a gender quality related to women and girls, which includes most genderera identities. It is not the same as feminine, an ideo-quality that can overlap with any kind of gender.Contributors to YB3 Wiki (YB3 Wiki)
Alinhamento de gênero e como essa terminologia se tornou inadequada
Uma postagem marcante na discussão sobre alinhamento de gênero definiu a ideia desta forma:Por conta da forma que [identidades não-binárias] se cruzam com o binário de gênero, há vezes que é útil nos categorizarmos como pessoas com experiências comuns com homens ou com mulheres. Se existe uma sobreposição muito grande, como quando alguém é exclusivamente percebide como homem/mulher e então está sujeite a problemas sociais que afetam tais classes, pode haver valor em "nos alinharmos" com essas classes, para ter discussões significativas sobre como opressão funciona.Há valor em poder dizer "sou negativamente afetade por esse conjunto específico de preconceitos de gênero, mesmo que eu não seja deste gênero".
Esse era o propósito inicial de termos como "alinhade com homem" e de "alinhade com mulher". Identificar sobreposições fortes em pressões externas e experiências, ou identificar sobreposições de identidade pessoal com as experiências de outro gênero.
Os exemplos dados foram de ume proxvir racializade poder ter uma narrativa similar a de um homem racializado quanto a racismo específico contra homens, e de ume ambonec com TEPT complexo viste como mulher poder ser sujeite a um monte de misoginia médica em relação à sua diagnose e ao seu tratamento da mesma forma que uma mulher cis seria.Esta mesma postagem também fala de como esses termos foram cooptados para significar "basicamente binárie" ou até mesmo "basicamente cis", e sugere então termos novos para que pessoas não tenham que se associar com essas ideias.
Tais termos são lunariane ("alguém que tem similaridades em identidade ou experiência com mulheres"), solariane ("alguém que tem similaridades em identidade ou experiência com homens") e estelariane ("alguém que não possui alinhamento forte com o binário de gênero, ou que rejeita tal alinhamento").
Acho interessante que esta postagem fala de alinhamento quase que exclusivamente como uma questão de uma pessoa ser injustamente colocada na mesma categoria que um gênero binário e sofrer algum tipo de opressão por isso.
Não acho que todas as pessoas usavam alinhamento só por isso, também. Mesmo as pessoas que não usavam esse tipo de identidade por conta de opressão baseada em gênero ou para serem exorsexistas (apagando as identidades individuais de pessoas não-binárias para dizer "mas você na verdade é homem/mulher" sem dizer isso de forma explícita) às vezes queriam expressar conexão com algum gênero binário por conta de expressão de gênero, sentimento interno ou transição desejada, motivos pelos quais algumas pessoas também usam termos como homem/mulher não-binárie, transmasculine e transfeminine.
Eu não sei dizer se isso seria um problema para o propósito de descrever opressão por gênero. Eu diria que não. Em ambos os casos, alinhamento seria uma forma de uma pessoa não-binária dizer que tem algum tipo de experiência/sentimento/vivência em comum com alguém de algum gênero binário, caso queira sinalizar algo do tipo.
Mas, mesmo nos círculos com a melhor das intenções, isso deu errado.
Problema 1: Misturar alinhamento de gênero com definições/categorizações de identidades de gênero
Logo quando os termos estelariane, lunariane e solariane foram cunhados, pessoas já aparentemente não pegaram a ideia disso ser algo opcional e pessoal, e começaram a associar certas identidades com certos alinhamentos.Postagens apareciam colocando zenina, juxera, demimulher, libramulher e mulher-fluxo como identidades lunarianas, por exemplo.
Algumas pessoas também começaram a cunhar termos e, ao invés de dizer que eram associados com tal gênero, diziam que eram alinhados com tal gênero.
Eu entendo que alguém que sente alguma similaridade com a identidade mulher pode se identificar como lunariane. Mas se o exemplo original de uma pessoa alinhada com o gênero mulher na postagem que cunhou lunariane é de ume ambonec, dizer que gêneros específicos são de alinhamentos específicos não pode acabar deixando pessoas que não possuem gêneros relacionados aos binários desconfortáveis demais para usar termos como lunariane ou solariane por conta da opressão que sofrem?
Isso também é presumir sobre as identidades/vivências das pessoas. E se alguém for demimulher, mas for uma pessoa transmasculina que só se identifica como parcialmente mulher por isso fazer parte do seu gênero e não vê isso como uma parte relevante da sua identidade a ponto de ser seu alinhamento? E se algume juxera achar mais relevante a confusão que as pessoas têm com seu gênero por conta de sua expressão genderfuck do que a proximidade do seu gênero com mulher?
Cunhar termos com base em alinhamentos não é um problema tão grande, porque se alguém se identificar com o resto do termo mas não se ver como alinhade com algo, é só não usar. Ainda assim, não vejo porque não seria melhor deixar o gênero só relacionado com algo, e então deixar pessoas decidirem seus próprios alinhamentos de gênero separadamente.
Pessoas também começaram a perguntar, em blogs de ajuda, por "gêneros alinhados com tal coisa". Sendo que, se alinhamento de gênero não é associado com gênero, qualquer identidade de gênero pode ter qualquer alinhamento. Ume ambonec pode ser lunariane, uma pessoa agênero pode ser solariana, ume zenina pode ser estelariane, etc. Eu entendo que provavelmente o que querem dizer é que querem saber mais sobre gêneros associados/parecidos com certo gênero, mas isso não ajuda pessoas cujas identidades de gênero não deixam seus alinhamentos "óbvios" a se sentirem seguras em compartilhar/ir atrás de comunidades para tal alinhamento.
Um exemplo de como isso é ruim: Ume maverique é viste como homem e participou de espaços para homens por um longo tempo, antes de se perceber não-binárie. Tal maverique não se sente confortável com pessoas presumindo que elu é homem, mas isso de qualquer forma acontece com frequência e afeta suas experiências de vida. Solariane poderia ser um rótulo confortável para elu, porém grande parte das coisas disponíveis para pessoas solarianas presume que a maioria delas é de algum gênero parecido com homem, ou que são parcialmente homens, ou que são homens parte do tempo. Alguém que está tentando se afastar da ideia de que "na verdade é homem" vai se sentir confortável adotando esse alinhamento de gênero?
Problema 2: Misturar alinhamento com gêneros binários com feminilidade/masculinidade
Como já falei em outro texto, feminilidade e masculinidade são termos usados de duas formas que, ainda que façam sentido com suas definições básicas, são bem distintas na prática:
- Ser uma pessoa feminina ou masculina significa se dizer ao menos "meio mulher" ou "meio homem", respectivamente;
- Ser uma pessoa feminina ou masculina significa aderir a arquétipos relacionados a estereótipos de gêneros binários.
O que acontece é que, muitas vezes, pessoas passaram a usar "alinhamento com feminilidade/masculinidade" ao invés de "alinhamento com mulher/homem". Talvez isso seja por acharem que, por exemplo, alinhamento com feminilidade seja uma forma mais abrangente de falar de alinhamentos relacionadas com ser mulher, ao invés de ser um alinhamento estrito com ser mulher.
Mas isso acaba alienando as pessoas que rejeitam a ideia de que feminilidade/masculinidade precisa ter a ver com estar perto de um gênero binário (1), e que são mais acostumadas com a ideia de que ser uma pessoa feminina/masculina tem só a ver com se identificar com certos arquétipos/estereótipos, independentemente do gênero (2).
Um exemplo: Imaginem ume femil - uma pessoa cujo gênero é mulher, mas com 0% de feminilidade e ao menos alguma identificação com masculinidade - que passou boa parte da vida se identificando como bofinho. Que sempre foi criticade por não ser feminine, e que enfrenta violência por ser viste como "mulher que se veste de homem". Essa pessoa tem um gênero relacionado com mulher, e passa por questões enfrentadas por mulheres binárias, então faz sentido dizer que possui um alinhamento de gênero com mulher. Mas será que alguém assim se identificaria com um alinhamento com feminilidade?
Esse exemplo pode ser fictício, mas a pessoa que cunhou femil e melle é melle e já falou que não consegue usar o sistema de alinhamento de gênero por conta das pessoas juntarem feminilidade com ser mulher e masculinidade com ser homem, ainda que seja uma pessoa que se vê como alguém que tem alinhamento com ser homem e com feminilidade, mas não com ser mulher ou com masculinidade.
Problema 3: A obrigação de alinhamento
Isso não é algo tão presente em círculos mais inclusivos, e nunca cheguei a ver isso na lusosfera, mas acho que é uma questão importante pra apontar, já que é relacionada com o assunto.Para não ignorar a existência de pessoas não-binárias que se identificam com termos vistos como binários, e também não ignorar que pessoas que usam os termos vistos como binários não querem que tais termos sejam deturpados, é comum haverem definições como:
Lésbica: Uma mulher ou pessoa alinhada com o gênero mulher que sente atração somente por mulheres ou por pessoas alinhadas com o gênero mulher.
Eu não acho que essa definição é necessariamente problemática, porque pela maior parte ela está certa. E não acho que adicionar todas as exceções possíveis a definições é um processo muito útil, já que sempre vão haver mais delas.Mas, tipo assim, já não tem um monte de casos lá em cima no texto sobre um monte de casos onde pessoas não são (completamente, sempre, etc.) mulheres e não se sentem/talvez não se sintam confortáveis se dizendo lunarianas/alinhadas com o gênero mulher?
Fora que, se é comum que pessoas relacionem pessoa alinhada com o gênero mulher com pessoa com identidade de gênero relacionada com ser mulher, isso não poderia causar problemas para lunarianes que são agênero, maveriques, ou de outras identidades que não possuem mulher no nome ou na definição?
Ou pior: Como pessoas vão se sentir confortáveis adotando ou mantendo essa identidade se, mesmo que sintam alguma conexão ou relação forte com ser mulher, não possuem identidade de gênero com mulher no nome ou na definição, e não se sentem confortáveis se dizendo lunarianes/alinhades com o gênero mulher por conta das questões listadas acima?
Os problemas que isso causa não são apenas teóricos: existem pessoas que se afastam de espaços para homens com atração por homens/mulheres com atração por mulheres por medo de invadir mesmo que se identifiquem com os termos usados, e existem pessoas tratadas como "invasoras" por não se identificarem com os termos de identidade e/ou alinhamento de gênero "certos" para que possam ser aceitas em tais espaços.
Existem sim termos como feminamórique e viramórique, mas muita gente gosta de ter um termo "que a maioria entende" como identidade, e as comunidades femínicas, mascúlicas, feminamóricas, viramóricas, dóricas e trízicas não são muitas nem grandes.
Problema 4: Falta de comunicação entre "desalinhades" e pessoas com alinhamentos não-tradicionais
Não é à toa que foquei muito mais em alinhamentos com homem e com mulher neste texto; são os alinhamentos mais discutidos e destacados.Mas até mesmo estelariane foi um termo cunhado junto a lunariane e solariane. Se lunariane significa que a pessoa tem alinhamento com ser mulher, e solariane significa que a pessoa tem alinhamento com ser homem, estelariane aponta, pra mim, um alinhamento com não-binaridade.
Isso pode parecer desnecessário: pra quê ter um alinhamento com não-binaridade, se a pessoa já é não-binária?
Eu acredito que a intenção tenha sido de oferecer um termo que explicitamente diz "não, eu não me vejo como alguém próxime de um gênero binário, ou como alguém mais próxime de um gênero binário do que do outro". Que diz "não importa a minha identidade de gênero ou como as pessoas me veem, eu não me sinto confortável em dizer que tenho experiências em comum com um dos gêneros binários".
Que diz "não, eu não tenho um alinhamento binário". Então, é, um alinhamento com qualquer coisa que não seja binária.
Eu acredito que a ideia tenha sido que estes três termos fossem absolutos; ou você se identifica como alguém que tem algo em comum com algum gênero binário, ou não (seja por ter coisas em comum com ambos, seja por não não ter nada em comum com ambos, seja por rejeitar a ideia de ter algo em comum com um ou outro).
Mas, é, quando a comunidade gosta de termos e começa a usá-los, buracos começam a aparecer.
Surgiram alinhamentos que são combinações desses três termos; surgiram alinhamentos que são parcialmente cada um desses três termos; surgiu o termo singulariane para quem não tem alinhamento nenhum.
Muita gente também começou a ver estelariane como um alinhamento com neutralidade.
Mais tarde, também surgiu xênique, um termo para quem tem alinhamento com um ou mais xenogêneros. Também surgiram termos mais específicos para conceitos xenogênero específicos (como alinhamentos com luz, com animais, com cristais, etc).
Mas, o que importa aqui, é que parte da comunidade ignorou todo esse desenvolvimento, e agiu como se só houvessem pessoas alinhadas com mulheres, com homens, ou sem alinhamento.
Eu não acho que há algo de errado em falar que existem pessoas sem alinhamento de gênero. Porém, em muitos textos, era como se não ter alinhamento de gênero fosse sinônimo com não ter um alinhamento de gênero puramente binário. Por exemplo, a falta de espaços para pessoas que não são mulheres ou homens ou alinhadas com esses gêneros não é uma questão que só é relevante para quem não tem alinhamento, quando pessoas estelarianas, xênicas ou eclipsianas (que são lunarianas e solarianas) também enfrentam problemas com essas divisões.
Quando alguns termos e espaços surgiram para pessoas sem alinhamento de gênero, algumas pessoas tiveram que perguntar se a ideia era para pessoas sem alinhamento ou sem alinhamento binário, especialmente quando eram coisas acompanhadas por alternativas que eram apenas para pessoas com alinhamentos binários.
Mas e então, o que fazer?
Eu sinceramente não sei se há como "consertar" todas as impressões erradas sobre os sistemas de alinhamento de gênero. Ao menos não tão cedo e se cada pessoa continuar usando esses termos de forma diferente.Não acho que é um problema que alinhamentos de gênero ainda existam. Mas pessoas precisam certamente parar de fazer presunções baseadas em conhecimentos limitados (como gêneros relacionados com mulher = gêneros femininos = "gêneros lunarianos" ou pessoas que não são alinhadas com homem ou com mulher = pessoas sem alinhamento), se querem parar de machucar ou afastar pessoas de termos que acham úteis.
Acho que estelariane e xênique me contemplam bastante, mas não são termos que faço questão de usar.
O sistema alibinário foi feito para poder ter termos que falam de questões diferentes sem elas serem divididas por que tipo de identidade de gênero a pessoa tem, mas ele não fala sobre questões de gênero enfrentadas especificamente por homens e pessoas solarianas ou por mulheres e pessoas lunarianas, ou qualquer equivalente disso.
A ideia de elementos de gênero foi cunhada para que pessoas possam expressar alguma relação com tais elementos independentemente de gênero, mas eles não possuem nenhum propósito político (de falar de questões específicas enfrentadas por certos grupos).
Também existem os termos proxmenina e proxmenino (e, sim, como qualquer outra identidade com esse tipo de nome, dá pra usar proxmulher, proxguri e afins). Eles podem servir como alinhamento, mas eu não sei o quanto os termos seriam confundidos com identidades de gênero, e/ou o quanto teriam o problema 1 descrito lá em cima.
Eu não sei se chamaria esses conceitos de alternativas, porque eles podem existir independentes de alinhamento de gênero. Mas se alguém quer apenas complementar sua identidade com outras coisas que a descrevem, esses sistemas podem ser usados. De qualquer forma, eu não acho que pessoas que usem o conceito de alinhamento de gênero precisem parar.
Também acho que a concepção do conceito foi importante para que pessoas pudessem se dar conta de como não é só porque uma pessoa é não-binária, ou mesmo porque tem um gênero completamente alheio a homem/mulher, que uma pessoa não pode "se alinhar" por ver que tem experiências em comum com pessoas binárias. E a cunhagem de alinhamentos parciais, mistos ou com identidades não-binárias também indica que pessoas podem sentir esse tipo de conexão com identidades fora do binário também.
O que mais quero que aconteça é que pessoas confiem mais nas experiências alheias sem precisar de rótulos. Alguém que é não-binárie e que quer usar um rótulo como aquileane deveria poder fazer isso sem ter que explicitar que é homem não-binárie, solariane, proxmenino, transmasculine ou qualquer outra coisa assim. Também seria legal confiar que, por exemplo, alguém bigênero homem/mulher não está invadindo ou traindo qualquer comunidade caso queira participar tanto de espaços de mulheres quanto de espaços de homens. Deixem que cada pessoa se descubra ou se identifique com o que achar melhor, ainda que "não faça sentido" para pessoas binárias.
Reblog by @temp-nb-blog
💬 3 🔁 458 ❤️ 721 · Describing Alignment · A guest post by @vergess. What is a nonbinary person’s “Gender Alignment”? You may have seen terms such as “male aligned” and “female aligned” floating…Tumblr
Ikey Doherty vs Omarchy: Why He’s Building Barney Instead of Another Distro
Ikey Doherty, the creator of Solus and AerynOS, is back with Barney, a Rust tool that builds Linux distros from source. So that you can easily create your own Omarchy.In a video posted on YouTube, the creator of Solus and AerynOS called the money behind DHH's distro absurd and promised to do it better with nothing. His answer is Barney, a Rust-based tool for building Linux distros from source.
Of course, that's why I go open source, that's what brought me here to Lemmy.
Maybe I am wrong to mix music into it, although you might be able to pick up the glove in that aspect too: Morrissey is a narcissistic/racist asshole, yet his music brings me joy. Am I a bad person for that? Should I stop listening to him? I've never really bought an album, and I don't listen to interviews, but his music. Wouldn't having a nazi OS be the same (mind you not this one, but something without the slop)? Using Temple OS would make me weird, sure, but would that mean I am platforming the mentally deranged?
There's no ethical consumption under Capitalism. I get it, too. It could be easily said that this very Internet that's connecting us has some Nazi fingerprint since the DARPA.
Your bootleged tracks won't make a penny to Morrissey nor bring more awareness to him. However, with FOSS, we have a choice. Don't hatch this serpent's egg
I can see how propogating their product would intensify their reach, but the problem I am having is that I cannot differentiate a good app based on ideology.
Now that I come to think of it, I might not run into that problem. Maybe nazis cannot make wholesome code, because they are not wholesome themselves. That would make my point moot. Thank you for the gentle comment.
No need to throw punches, comrade.
If you feel you wanna toe my line, we can get into the merits and blind spots of positivism, but please try to see me arguing in good faith about something I either don't understand or find questionable.
I wouldn't want to install anything unvetted. But doesn't open source mean it's fully transparent? So if the system had tracking and whatnot (which regimes usually like), I wouldn't install it.
If it's a good fit and there is no fallout for me downloading it (I'm not funding them, not giving them info), I think there is no moral problem with me downloading the software.
In this specific case I guess it's moot, cuz it's full of slop, but this is the same vein as pop culture consumption: do I hate myself for liking Michael Jackson's and Morrissey's music? Should I not pirate it, if it brings me joy? Am I a bad person for liking that music?
Being Open Source doesn't solve the issue here. First, as you say yourself, you even do not trust a project that is Open Source because of Ai slop. And you cannot verify every line of code with every update on every application. Do you understand every security issue by just looking at it? Even if you would, which is impossible, do you build everything from source? No normal people does that (sorry Gentoo users, this sentence was just for you guys 😁).
Omarchy is a good example of that we should not trust everything, just because it is Open Source. I personally would have moral problems AND fear of incompetence and intentional malware. The actual software, the operating system itself, would have been very nice if there were not these trust issues.
I would say its not the same as liking pop culture. That comparison doesn't hold up, because listening to music does not execute stuff on your system, you do not depend on it, and there is no trust issue here involved. As for the moral problem of liking something, where the creator is a bad person, well that is something you can do in art. I personally can differentiate from media consumption and its creator, which is not possible with operating systems and software.
But if we start talking about media or even food, that is all a different thing and would just distract us from our original topic.
The reason I brought up the comparison is because I think it at least tangentially relates to ethical software usage as well.
I came to a similar conclusion from another comment: nazis are not wholesome people, so they cannot produce wholesome code (I guess music doesn't need wholesomeness to hit deep). This is my practical stance on the matter. Nazis have not produced a good enough operating system for me to switch to it.
But going back to nitpick, I don't have a blink of understanding about machine languages (or coding in general for that), but I do have trust in the community, and the community has freaks that speak machine language and can inform me about any hidden malware. But I guess by now I'm just advocating for the devil. Thanks for engaging, it did provide extra gradients in my view.
I also have to trust the community in order to trust the system. But no community can help you, if the maintainers doesn't do their job well, after you got pawned. There are lot of Open Source projects and operating systems I do not trust.
And yes I also get what you were saying with the media comparison, I did not try to invalidate your personal opinion by claiming the comparison wasn't valid. I understand you were trying to make a point by that. I just didn't want to go too far away from the topic, as this happens too often. So my apologies for the tone it may had (not sure how to put this into words). Also thanks for staying productive in the discussions, with political stuff involved this gets heated up very quickly.
apologies for the tone it may had
Right back at ya. But for what it's worth, I didn't feel any animosity coming from you, and most of the answers have been pretty tame compared to the weight of the topic.
I do understand now why I shouldn't trust my data to a bad-faith player. I know where my misunderstanding stems from and appreciate all the input I got from this community. Another big thanks for keeping things on track (re:music).
It's worth mentioning something in order to point out why it's bad? It's in the news right now and people are currently discussing it, and it's not like someone is going to read this article and be more likely to go support it
This article is saying that Omarchy isn't doing anything that novel or special, and that this developer is trying to create a tool that will allow anyone to do the same thing without millions of dollars of funding
Let's talk about Barney in every Omarchy thead form now on.
Actually, mods, a bot is all we need.
Forgejo Scraping Protection: Nginx and Anubis
AYO - AI and Sofware solutions
AYO provides customized AI solution for comapnies to improve their process. We take inspiration in the latest research in machine learning : deep learning, probabilistic models, neuroscience and physics.ayo.tokyo
runtimewire.com/article/anubis…
news.ycombinator.com/item?id=4…
news.ycombinator.com/item?id=4…
Anubis bypass shows bot proof-of-work mostly catches low-effort scrapers
Farid Zakaria's anubis-fetch automates Anubis challenges, testing whether proof-of-work stops AI crawlers or mainly adds friction for human visitors.Ryan Merket (RuntimeWire)
Thanks for the sources, reading them make me realize : MAYBE I have been protected so far because my website is built using InfernoJS and I didn't realize Forgejo doesn't requires Javascript.
So the spams are more likely to appear from the "low-effort" bots that don't run a Javascript engine. The problem is that the website has only 5 static pages (the JS framework allows better server efficiency and language/theme switch) so spam were never an issue (you can get the whole websites in 10 requests).
I am thinking about adding a fail2ban rule on the 503 answers triggered by nginx rate limit. This should but this would once again only protected against low-effort bot that don't calculate the rate limit.
Experience will tell how good of a protection this is.
Let me add that the website is still not using Anubis, this is only for the public forgejo instance. Also any published software is mirrored on codeberg. I think visitors of the self-host git repository is very niche and specialized, for any one but me looking at this forgejo instance should be more of looking my work or backup of the published work than anything, so very niche.
PS : loving the runtimewire article concluding "instead of repeatedly charging the humans trying to read the page" when they have this
For me, every single request is coming from a different random IP address (different ASN, different country, etc.) using a random plausible User-Agent. There's no way to discern them as bot requests. And since every request is coming from a random source, things like fail2ban or CrowdSec don't really work. You can block a few major ASNs but there will still be lots of requests making it through.
And these things work by going through a list of URLs previously collected. About a week ago I've configured a redirect for ALL requests to my personal Gitea instance to a zip bomb. It's been 7 days now where the website was inaccessible and I still see requests for deep links, e.g. specific commits or lists of pull requests. These things are relentless. That's also one of the arguments against Anubis - those scrapers just don't care.
I've found some comments that at least a few ISPs check AbuseIPDB.com and cancel their customer's contracts if their IP appears in that database. So, I've now resorted to occasionally collect those IPs hammering my poor Raspberry Pi and reporting them to the AbuseIPDB. If people are unknowingly running a "residential proxy" (why don't we call them "open proxies" anymore?) somebody needs to let them know, I guess.
The option to Block Large Media Elements in uBlock Origin(in Firefox) is nice. Saves net and speeds up loading
Remembered about this a Lemmy convo.
It is good. Animations or pictures beyond the selected size are replaced by a red border. Clicking it will load that image. Or you can temporarily turn it off for the website and reload the tab.
There is an option to exclude Websites from from it too. e.g. You can exclude Lemmy instances where you want to see images by default.
github.com/gorhill/uBlock/wiki…
Sharing it here since I had heard that uBo with full capabilities is now only available in Firefox
Per site switches
uBlock Origin - An efficient blocker for Chromium and Firefox. Fast and lean. - gorhill/uBlockGitHub
like this
Oofnik and Endymion_Mallorn like this.
Replaced the window regulators in my car.
I got super lucky at a U-pull-it and found a 100% complete exact match for my car, it was at the lot cause it got front-end totaled. But everything I needed was interior and convertible related. (unfortunately it wasn't leather so the seats were worthless to me) My current regulators were super busted and I had 2 windows held up by zip-ties
Borrowed a friend and ripped the thing apart, and when it got cooler last night I swapped all the new regulators in. This car is special and a new regulator is like $350, so getting all 4 w/ a new cloth top for only $200 was a steal, it just needs some repairs but the cloth is in WAY better shape than the one that's on there atm.
The hardest part was getting the windows lined up correctly, first issue was fitting the glass to the sleds, I kept my original glass cause the tinting is different, they have to be installed out of the car, but need to be aligned while installed. After doing that there's a whole process with setting 3 different standoffs in a Stewart platform like arrangement. until it puts slight pressure on the seals both in front of and behind the glass.
And then there was the front left window, which didn't need the whole regulator, but the track it mounts too... at least I thought.
After installing the new track I noticed the entire mechanism flexes about 1/4" side-to-side when moving. And upon closer inspection, the nylon bushings that ride on the tracks are completely wore out on the new-to-me and old ones. At least the window works now though.
But it paid off and now I don't look stupid driving down the road with 2 rear windows jutting out when converted.
Next is replacing the hydraulic lifts with linear actuators and a brain. Those cursed Chrysler cylinders fail so often it was a miracle this one worked for the 2 months before a seal exploded and filled the back seats with stinky goo
DRM from Korean eBook service Kyobo
So I caved and bought some books from Kyobo that were definitely not on thé usual channels and they have them in such a way that you can only read them from the app. So I downloaded them to my phone using the mobile app (the app doesn't support Linux and is basically a Rootkit anyway) and copied the files from Android/data. They're OEBPS by structure but come in regular folders, is it feasible to just zip them and import to Calibre?
Edit: I found a Calibre plugin for the DRM itself, so it's more "How to make this folder a file"
Edit: so you can just zip them up and import as epub BUT the DRM plugin only goes as far as the metadata, the content itself shows up garbled. Don't know how to get around that one...
GitHub - leoincedo/KyoboKr: KyoboKr is carlibre metadata plugin
KyoboKr is carlibre metadata plugin. Contribute to leoincedo/KyoboKr development by creating an account on GitHub.GitHub
#CrossBorderRail live stream - 9/7/2026, 7:55:07 PM
#CrossBorderRail live stream - 9/8/2026, 6:21:33 AM
#CrossBorderRail live stream - 9/8/2026, 7:51:13 PM
#CrossBorderRail live stream - 9/9/2026, 5:13:40 AM
How Urban Building Projects Influence Concrete Equipment Investment in Ethiopia
Urban building projects can significantly influence how contractors invest in concrete production equipment. As cities expand, construction activity often includes residential buildings, commercial properties, public facilities, mixed-use developments, and supporting infrastructure. These projects create different patterns of concrete demand. Some require continuous production for structural work, while others involve smaller and intermittent batches for foundations, columns, slabs, and auxiliary structures. As a result, equipment investment is increasingly shaped by the practical requirements of individual projects rather than by machine size alone.
For contractors evaluating a concrete mixer in Ethiopia, urban construction conditions can affect decisions about capacity, mobility, automation, and long-term operating costs. Limited site space, changing work schedules, labor availability, material supply, and transportation conditions all influence which equipment configuration is appropriate. The investment decision therefore extends beyond the initial purchase. Contractors must consider how efficiently the equipment can support concrete production throughout different stages of an urban building project.
Urban Building Growth Changes Concrete Production Requirements
Different Building Types Create Different Demand Patterns
Urban construction does not create a uniform demand for concrete. A multi-story residential building may require substantial volumes during foundation and structural stages, followed by lower concrete consumption as finishing work progresses. Commercial buildings can have different schedules, while smaller developments may need concrete only at specific intervals.
This variation affects equipment investment. Contractors working on repeated medium-scale projects may prefer equipment that can provide consistent production without the infrastructure requirements of a large batching facility. Larger contractors managing several simultaneous projects may require more substantial production capacity.
Foundation Work Often Creates an Early Production Peak
Excavation and foundation construction can generate intensive concrete demand during the early phase of a building project. Footings, foundation beams, retaining structures, columns, and base slabs may require significant quantities within a relatively short period.
Equipment must be capable of responding to this concentrated demand. However, purchasing a large production system solely for the foundation stage may not always be economical if concrete consumption decreases significantly later in the project.
Restricted Urban Sites Influence Equipment Size
Construction sites in growing urban areas are often surrounded by existing buildings, roads, commercial activity, and residential developments. Available working space may be limited.
A large concrete production installation can compete with aggregate storage, reinforcement preparation, formwork, cranes, material deliveries, and worker access. Consequently, contractors may place greater value on compact equipment that can fit into a restricted site layout.
The physical footprint of a concrete mixer can therefore become an important investment factor. A machine does not operate in isolation. It must coexist with the entire construction ecosystem around it.
How Project Conditions Influence Concrete Mixer Investment
Production Capacity Must Match Actual Project Demand
One of the most important investment decisions involves selecting the appropriate production capacity. Higher output may appear advantageous, but unused capacity can increase equipment costs without producing a corresponding benefit.
Contractors need to examine average daily concrete demand, peak pouring periods, working hours, and the expected duration of each construction phase. A properly matched self loading mixer concrete can provide sufficient output while avoiding excessive investment in oversized equipment.
Capacity should therefore be viewed as a functional requirement rather than a simple indicator of machine quality.
Mobility Can Improve Equipment Utilization
Urban contractors may complete projects at different locations over relatively short periods. Once concrete work is finished at one site, the equipment may be required elsewhere.
Mobile or easily transportable equipment can improve asset utilization by allowing contractors to move the production system between projects. This reduces the risk of purchasing equipment that remains inactive after a single construction phase is completed.
Relocation Costs Should Be Considered
Mobility is not simply a technical feature. It has economic consequences. Equipment that requires extensive dismantling, transportation, and reinstallation can generate additional labor and time costs whenever a project changes.
For contractors managing multiple urban developments, easier relocation can become a meaningful advantage over the equipment's operating life.
Labor Availability Also Affects Equipment Selection
Concrete production traditionally depends on several repetitive activities, including loading aggregates, adding cement, measuring water, mixing, and transporting fresh concrete.
Equipment that integrates or simplifies some of these functions can reduce the number of manual operations required. This does not eliminate the need for skilled operators and quality control, but it can make the production process more organized and less dependent on fragmented manual work.
As construction schedules become tighter, predictable production processes may become increasingly valuable.
Why Concrete Mixer Price and Operating Costs Shape Investment Decisions
The Initial Purchase Price Is Only One Part of the Investment
When contractors compare concrete mixer price in Ethiopia, the machine's purchase price is naturally an important consideration. However, the lowest quotation does not necessarily represent the lowest long-term cost.
Fuel or electricity consumption, maintenance requirements, spare parts, transportation, labor, and equipment utilization can all influence the actual economic value of the investment. A cheaper machine that requires frequent repairs or consumes excessive fuel may become more expensive during its operating life.
For this reason, contractors should compare total ownership costs rather than focusing exclusively on the initial equipment price.
Material Handling Can Affect Overall Productivity
Concrete production depends on a continuous flow of aggregates, cement, water, and other materials. If material handling is inefficient, the mixer may spend significant periods waiting rather than producing concrete.
Urban building projects can make this issue more pronounced because delivery schedules and storage areas may be restricted. Equipment investment should therefore consider how easily materials can be supplied to the mixer within the available site layout.
A Balanced System Reduces Operational Bottlenecks
The mixer is only one part of the production process. Aggregate supply, cement storage, loading equipment, water availability, and concrete transportation must operate at compatible rates.
A highly productive mixer cannot compensate for an inefficient material supply system. Similarly, additional supporting equipment may provide little value if the project's concrete demand remains modest. Investment decisions should consider the complete production sequence.
Future Project Use Influences the Value of the Equipment
A contractor purchasing a large concrete mixer should also consider future applications. Equipment selected for one urban building project may later be used for housing developments, commercial structures, infrastructure works, or other concrete-intensive activities.
Versatility can improve long-term utilization. A machine that can adapt to different project sizes and operating conditions may provide greater value than equipment designed around a single narrowly defined application.
Urban Construction Encourages More Strategic Equipment Investment
Urban building development in Ethiopia influences concrete equipment investment by creating a combination of practical demands. Contractors need adequate production capacity, but they may also face limited site space. They require reliable concrete supply, yet demand can fluctuate between construction stages. Equipment may need to remain at one site for months or move between multiple projects.
These variables encourage a more selective approach to machinery investment. The appropriate concrete mixer in Ethiopia depends on the contractor's typical project profile, expected concrete volume, available labor, site conditions, and future equipment utilization.
Price remains important, but it should be evaluated alongside productivity and operating requirements. When comparing concrete mixer price in Ethiopia, contractors can achieve a clearer investment decision by examining capacity, fuel consumption, maintenance, mobility, material handling, and after-sales support together.
Ultimately, urban construction does not necessarily require the largest concrete production equipment. It requires equipment that fits the construction environment. A properly matched mixer can support foundation work, structural concrete production, and multiple future projects without creating unnecessary operational complexity. As urban building activity continues to diversify, the most valuable equipment investment is likely to be the one that balances production capability with the realities of the jobsite.
```
Self Loading Concrete Mixer in Ethiopia - Local Distritutor&Support
You can buy AIMIX self loading concrete mixer in Ethiopia from the local authorized dealer. Ready stocky, best price, local support!aimixblock (AIMIX Concrete Solutions - Concrete Production & Pumping & Paving)
Festplatten und SSDs unter Linux mit Smartmontools prüfen – SMART und Selbsttests
Überarbeitet am 9. September 2026.
Bei einem Server gehören Festplatten und SSDs für mich zu den Dingen, die ich lieber kontrolliere, bevor sie sich mit einem Totalausfall melden. Dafür sind die Smartmontools unter Linux weiterhin eines der wichtigsten Werkzeuge.
Das Paket enthält vor allem smartctl für manuelle Prüfungen und smartd für die laufende Überwachung im Hintergrund. Aktuell ist Smartmontools 7.5.
Table of Contents
Toggle
Installation unter Debian und Ubuntu
sudo apt update
sudo apt install smartmontoolsVersion prüfen:
smartctl --versionUnter Debian Trixie ist Smartmontools 7.5 beispielsweise auch über die Backports verfügbar.
Welche Laufwerke sind vorhanden?
Für einen schnellen Überblick:
lsblk -o NAME,MODEL,SERIAL,SIZE,TYPE,FSTYPE,MOUNTPOINTSTypische Gerätenamen sind:
/dev/sdafür SATA/SAS-Laufwerke,/dev/nvme0beziehungsweise/dev/nvme0n1für NVMe.
Smartmontools kann unterstützte Geräte auch selbst suchen:
sudo smartctl --scanKompletten SMART-Bericht anzeigen
Bei einer SATA-Festplatte oder SSD:
sudo smartctl -a /dev/sdaFür ausführlichere Informationen:
sudo smartctl -x /dev/sdaBei NVMe funktioniert entsprechend:
sudo smartctl -a /dev/nvme0Smartmontools 7.5 unterstützt auch aktuelle NVMe-SMART-/Health-Informationen und Selbsttests.
Nicht nur auf „PASSED“ schauen
Ein globales SMART-Ergebnis wie PASSED ist hilfreich, aber kein Freifahrtschein. Ein Laufwerk kann bereits auffällige Werte zeigen, bevor der Gesamtstatus endgültig auf Fehler springt.
Bei klassischen HDDs achte ich besonders auf:
- Reallocated Sector Count – bereits ersetzte problematische Sektoren,
- Current Pending Sector – aktuell verdächtige, noch nicht stabil lesbare Sektoren,
- Offline Uncorrectable – nicht korrigierbare Sektoren,
- Fehler- und Selbsttestprotokolle.
Ein einzelner herstellerspezifischer Rohwert sollte allerdings nicht ohne Kontext interpretiert werden. SMART-Attribute unterscheiden sich zwischen Herstellern und Laufwerkstypen.
Bei SSD und NVMe zählen andere Werte
Bei SSDs interessieren zusätzlich Verschleiß und verfügbare Reserve. Smartmontools 7.5 kann in der JSON-Ausgabe unter anderem Werte wie endurance_used und spare_available für unterstützte Geräte liefern.
Für Automatisierung ist JSON praktisch:
sudo smartctl -j -a /dev/nvme0Damit können Monitoring-Skripte Werte verarbeiten, ohne die normale Textausgabe zerlegen zu müssen.
Kurzen Selbsttest starten
sudo smartctl -t short /dev/sdaSmartctl nennt anschließend normalerweise, wie lange der Test ungefähr dauert. Danach Ergebnis anzeigen:
sudo smartctl -l selftest /dev/sdaLangen Selbsttest durchführen
sudo smartctl -t long /dev/sdaAuch hier danach:
sudo smartctl -l selftest /dev/sdaDer lange Test kann je nach Größe des Laufwerks deutlich länger dauern. Er läuft normalerweise intern im Laufwerk; trotzdem starte ich so etwas auf einem Produktivserver lieber bewusst und nicht zufällig während einer ohnehin hohen Lastphase.
NVMe-Selbsttests
Aktuelle Smartmontools-Versionen unterstützen Selbsttests auch bei passenden NVMe-Geräten:
sudo smartctl -t short /dev/nvme0
sudo smartctl -l selftest /dev/nvme0Nicht jedes Laufwerk unterstützt jede Funktion. Wenn Smartctl einen Test ablehnt, sollte man nicht mit irgendwelchen erzwungenen Optionen herumprobieren, sondern zuerst die Fähigkeiten des Geräts prüfen.
smartd für laufende Überwachung
Statt nur gelegentlich manuell hineinzusehen, kann smartd Laufwerke regelmäßig überwachen.
Status prüfen:
systemctl status smartmontoolsJe nach Distribution heißt die Unit auch
smartd. Die zentrale Konfiguration liegt normalerweise unter:/etc/smartd.confBevor ich Benachrichtigungen aktiviere, kontrolliere ich dort genau, welche Geräte automatisch erkannt werden und wohin Warnungen gehen.
SMART ersetzt kein Backup
Das ist mir wichtig: SMART ist Frühwarnung, keine Versicherung. Ein Laufwerk kann auch ohne lange Vorwarnung sterben.
Deshalb kombiniere ich Laufwerksüberwachung mit echten Backups. Dazu passen meine Artikel BorgBackup unter Debian/Ubuntu und Backup richtig planen.
Bei RAID jedes physische Laufwerk prüfen
Ein Software-RAID schützt vor dem Ausfall eines einzelnen Datenträgers, macht SMART aber nicht überflüssig. Im Gegenteil: Bei einem RAID möchte ich wissen, ob ein Mitglied bereits Fehler entwickelt, bevor noch ein zweites Laufwerk Probleme bekommt.
Darum prüfe ich RAID-Status und SMART-Werte getrennt.
Fazit
Smartmontools gehört für mich auf jeden Linux-Server mit lokalen Laufwerken. Ein gelegentliches smartctl -a, regelmäßige Selbsttests und eine funktionierende Backup-Strategie geben wesentlich mehr Sicherheit als erst dann auf die Platte zu schauen, wenn das System bereits I/O-Fehler meldet.
Quellen: Debian Manpages: smartctl 7.5 und Smartmontools 7.5 Release.
Meine Backupmethoden zum Worldbackupday | Das Netz und ich
Gestern, also bis vor 38 Minuten war der World Backup Day. Ein Tag um daran zu erinnern das Backups sehr wichtig sind. Ein gutes/oder schlechtes Beispiel ist der Brand im Ovh Rechenzentrum in Straßburg. Wer da keins hatte, war verloren.lars (Das Netz und ich)
Webserver mit Security-Headern absichern – sinnvoll statt blind kopieren
Überarbeitet am 8. September 2026.
Security-Header sind eine schöne zusätzliche Schutzschicht für Webseiten. Mein alter Artikel hatte allerdings genau das Problem, vor dem ich heute warnen würde: Ich hatte mehrere Header global auf sämtliche Websites gesetzt, ohne die Folgen für jede Anwendung einzeln zu prüfen.
Das ging sogar einmal schief. Eine globale Regel, die jedes Set-Cookie nachträglich mit HttpOnly; Secure versehen sollte, sorgte bei mir dafür, dass ein Cookie-Banner nicht mehr richtig funktionierte. Seitdem gilt für mich: Security-Header nicht nach Punkteliste einschalten, sondern verstehen, testen und passend zur Anwendung setzen.
Table of Contents
Toggle
1. X-Content-Type-Options: nosniff
Dieser Header ist ein guter und meist unkomplizierter Anfang:
X-Content-Type-Options: nosniffEr weist den Browser an, die vom Server angegebenen MIME-Typen zu respektieren, statt den Inhalt selbst anders zu interpretieren.
Nginx:
add_header X-Content-Type-Options "nosniff" always;Apache:
Header always set X-Content-Type-Options "nosniff"2. Referrer-Policy
Mit der Referrer-Policy lässt sich begrenzen, welche Informationen eine aufgerufene Fremdseite über die Herkunft eines Besuchers erhält.
Ein vernünftiger allgemeiner Wert ist:
Referrer-Policy: strict-origin-when-cross-originDas ist inzwischen auch der Browser-Standard. Wer noch weniger Informationen nach außen geben möchte, kann beispielsweise
strict-origin, same-origin oder no-referrer prüfen. Die strengste Einstellung ist aber nicht automatisch die beste, wenn Anwendungen Referrer-Informationen benötigen.3. HSTS – sehr sinnvoll, aber nicht leichtfertig mit preload
HTTP Strict Transport Security teilt dem Browser mit, dass eine Domain künftig nur über HTTPS angesprochen werden soll:
Strict-Transport-Security: max-age=31536000Nginx:
add_header Strict-Transport-Security "max-age=31536000" always;Apache:
Header always set Strict-Transport-Security "max-age=31536000"Wichtig: Den Header nur über HTTPS ausliefern. Browser ignorieren HSTS über eine unverschlüsselte HTTP-Verbindung ohnehin.
Mit includeSubDomains gilt die Regel zusätzlich für sämtliche Subdomains. Das sollte man erst aktivieren, wenn wirklich jede aktuelle und zukünftige Subdomain per HTTPS funktioniert.
Und preload würde ich nicht mehr wie früher einfach in eine Beispielkonfiguration schreiben. Wer seine Domain in eine Browser-Preload-Liste eintragen lässt, bindet sich sehr stark an HTTPS. Vorher unbedingt alle Subdomains prüfen und die Folgen verstehen.
4. Schutz vor Einbettung: CSP frame-ancestors
Früher wurde dafür häufig nur X-Frame-Options gesetzt. Dieser Header funktioniert weiterhin, moderner und flexibler ist aber die CSP-Direktive frame-ancestors.
Wenn eine Seite überhaupt nicht in Frames eingebettet werden soll:
Content-Security-Policy: frame-ancestors 'none';Wenn Einbettung aus derselben Origin erlaubt sein soll:
Content-Security-Policy: frame-ancestors 'self';Bei Nextcloud, Office-Anwendungen, Payment-Diensten oder eingebetteten Inhalten sollte man so eine Regel aber nicht blind setzen. Genau dort können Frames legitim benötigt werden.
5. Content-Security-Policy: mächtig, aber individuell
CSP kann unter anderem verhindern, dass unerwartete Skripte, Styles oder andere Ressourcen geladen werden. Sie gehört aber nicht in eine universelle Copy-and-Paste-Zeile für WordPress, Nextcloud und jede andere Anwendung.
Mein alter Artikel hatte beispielsweise eine lange CSP mit 'unsafe-inline' und 'unsafe-eval' sowie fest verdrahteten Fremddomains. So etwas altert schnell und kann entweder Funktionen blockieren oder ein falsches Gefühl von Sicherheit erzeugen.
Mein heutiger Weg wäre:
- prüfen, welche Ressourcen die Anwendung tatsächlich benötigt,
- eine CSP zunächst mit
Content-Security-Policy-Report-Onlytesten, - Verstöße auswerten,
- danach schrittweise eine wirksame CSP aktivieren.
Bei fertigen Anwendungen wie Nextcloud würde ich außerdem zuerst deren offizielle Dokumentation beziehungsweise bereits gesetzte Header prüfen, statt darüber global eine eigene Richtlinie zu legen.
6. X-XSS-Protection nicht mehr als modernen Schutz empfehlen
In meinem alten Beispiel stand:
X-XSS-Protection: 1; mode=blockDiesen Header würde ich heute nicht mehr als moderne Sicherheitsmaßnahme aufnehmen. Die entsprechenden alten Browser-XSS-Filter sind veraltet. Moderne Anwendungen sollten XSS vor allem durch korrektes Escaping, sichere Frameworks und eine sinnvoll gestaltete Content Security Policy verhindern.
7. CORS nicht global mit * freigeben
Ebenfalls problematisch war mein altes Beispiel:
Access-Control-Allow-Origin: *CORS ist keine allgemeine „Webseite sicherer machen“-Option. Damit wird festgelegt, welche fremden Origins Browser auf bestimmte Ressourcen zugreifen lassen. Ein Wildcard-Wert kann für öffentliche APIs oder statische öffentliche Ressourcen sinnvoll sein, gehört aber nicht pauschal auf jede Website.
Wenn eine Anwendung CORS benötigt, sollte die erlaubte Origin gezielt passend zu genau diesem Anwendungsfall gesetzt werden.
8. Cookies nicht global im Webserver umschreiben
Genau damit hatte ich mir damals selbst Probleme gebaut:
Header always edit Set-Cookie ^(.*)$ $1;HttpOnly;SecureDie Absicht war gut: Cookies sollten nur über HTTPS übertragen und vor JavaScript geschützt werden. Aber nicht jedes Cookie darf
HttpOnly sein. Ein Cookie, das clientseitiges JavaScript bewusst lesen muss, funktioniert danach möglicherweise nicht mehr.Cookie-Eigenschaften wie Secure, HttpOnly und SameSite sollten deshalb vorzugsweise von der Anwendung beziehungsweise dem Framework passend zum jeweiligen Cookie gesetzt werden – nicht per globalem Such-und-Ersetzen im Webserver.
9. Permissions-Policy nur gezielt verwenden
Mit Permissions-Policy können Browserfunktionen wie Kamera, Mikrofon oder Geolocation eingeschränkt werden. Die Browserunterstützung ist allerdings je nach Direktive unterschiedlich. Auch hier gilt: Nicht wahllos alles abschalten, wenn eine Anwendung beispielsweise Videotelefonie oder Standortzugriff benötigt.
Für eine einfache Webseite ohne solche Funktionen könnte man einzelne Features bewusst sperren, beispielsweise:
Permissions-Policy: geolocation=(), camera=(), microphone=()Vor dem Produktiveinsatz immer die tatsächlich benötigten Funktionen und Browserkompatibilität prüfen.
Meine kleine Basis für normale Webseiten
Für eine klassische HTTPS-Webseite ohne besondere Anforderungen könnte eine vorsichtige Nginx-Basis beispielsweise so beginnen:
add_header X-Content-Type-Options "nosniff" always;
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
add_header Strict-Transport-Security "max-age=31536000" always;Bei Apache entsprechend:
Header always set X-Content-Type-Options "nosniff"
Header always set Referrer-Policy "strict-origin-when-cross-origin"
Header always set Strict-Transport-Security "max-age=31536000"CSP,
frame-ancestors, CORS und Permissions Policy würde ich anschließend pro Anwendung ergänzen und testen.Header überprüfen
Nach Änderungen zunächst Webserver-Konfiguration testen:
sudo nginx -tbeziehungsweise:
sudo apachectl configtestDie tatsächlichen Response-Header lassen sich beispielsweise mit
curl ansehen:curl -I https://example.deZusätzlich sind Browser-Entwicklertools und der Mozilla Observatory hilfreich.
Fazit
Security-Header sind sinnvoll – aber mehr Header bedeutet nicht automatisch mehr Sicherheit. Mein größter Lernpunkt aus der alten Konfiguration ist, globale Regeln nur dann zu setzen, wenn ich sicher bin, dass sie zu allen darunter laufenden Anwendungen passen.
Für Nextcloud habe ich die wichtigsten Servermaßnahmen separat beschrieben: Nextcloud richtig absichern. Und falls Nginx selbst einmal nicht startet: Nginx „Unit is masked“ beheben.
Quellen: MDN: HSTS, MDN: X-Content-Type-Options, MDN: Referrer-Policy und MDN: CSP frame-ancestors.
Nginx-Fehler „Unit nginx.service is masked“ beheben – systemd richtig prüfen | Das Netz und ich
Nginx startet nicht und systemd meldet „Unit nginx.service is masked“? So prüfst du den Status, findest die Ursache und entmaskierst den Dienst sauber.lars (Das Netz und ich)
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung:includeSubDomainssolltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind
trusted_proxiesund die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus demnextcloud.logerkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen
nextcloud.logkorrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie/var/www.Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der
config.phpändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud solltedebugnicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
Android-Smartphone mit scrcpy am PC spiegeln und steuern
Überarbeitet am 8. September 2026.
scrcpy gehört für mich zu diesen kleinen Open-Source-Werkzeugen, die unglaublich praktisch sein können. Damit lässt sich der Bildschirm eines Android-Smartphones auf Linux, Windows oder macOS spiegeln und das Gerät mit Maus und Tastatur bedienen.
Das kann beispielsweise helfen, wenn der Touchscreen Probleme macht oder man das Smartphone bequem vom Rechner aus bedienen möchte.
Table of Contents
Toggle
Was scrcpy 2026 kann
Die aktuelle scrcpy-Reihe kann deutlich mehr als die Version aus meinem ursprünglichen Artikel:
- Bildschirm über USB oder TCP/IP spiegeln,
- Steuerung mit Tastatur und Maus,
- bis zu 120 fps je nach Gerät,
- Audio-Weiterleitung ab Android 11,
- Bildschirmaufnahme,
- Zwischenablage zwischen PC und Smartphone,
- virtuelle Displays,
- HID-Tastatur/-Maus und Gamepads,
- kein Root und kein dauerhaft installiertes Android-Programm nötig.
Unterstützt wird Android ab Version 5.0. Für die normale Spiegelung und Steuerung muss USB-Debugging auf dem Gerät aktiviert sein.
Eine wichtige Grenze
Wenn USB-Debugging auf dem Smartphone nicht aktiviert beziehungsweise die Verbindung zum Computer nicht bestätigt wurde, kann die normale scrcpy-Verbindung nicht genutzt werden. Wer scrcpy als Notfallwerkzeug im Hinterkopf hat, sollte es deshalb einmal einrichten und testen, solange das Smartphone normal bedienbar ist.
Unter Linux installieren
Auf vielen Linux-Distributionen ist scrcpy direkt paketiert. Unter Debian/Ubuntu beispielsweise:
sudo apt update
sudo apt install adb scrcpyDie Distributionspakete können hinter der aktuellen Projektversion zurückliegen. Das scrcpy-Projekt weist ausdrücklich darauf hin, dass Genymobile/scrcpy die einzige offizielle Projektquelle ist. Für die neueste Version sollte man deshalb die dort dokumentierten Installationswege nutzen.
Verbindung testen und starten
Smartphone per USB verbinden. Anschließend:
scrcpyWenn alles eingerichtet ist, öffnet sich ein Fenster mit dem Smartphone-Bild. Das Gerät lässt sich direkt mit Maus und Tastatur bedienen.
Praktische Befehle
Auflösung reduzieren:
scrcpy --max-size=1280Audio deaktivieren:
scrcpy --no-audioSmartphone-Bildschirm während der PC-Steuerung ausschalten:
scrcpy --turn-screen-offSitzung aufnehmen:
scrcpy --record=aufnahme.mp4Drahtlose Verbindung
scrcpy kann auch über TCP/IP arbeiten. Für den normalen Einstieg würde ich trotzdem zuerst USB nutzen, weil dabei weniger zusätzliche Fehlerquellen entstehen.
OTG-Modus
scrcpy unterstützt auch einen OTG-Modus, bei dem Eingabegeräte per USB-HID simuliert werden können. Dieser Modus benötigt kein USB-Debugging, ist aber nicht dasselbe wie die normale Bildschirmspiegelung.
Fazit
scrcpy ist 2026 noch deutlich vielseitiger als bei meinem ersten Artikel. Es ist schnell, quelloffen, werbefrei und benötigt weder Cloudkonto noch Root-Zugriff. Für Android-Nutzer ist es ein richtig schönes Werkzeug für die tägliche Bedienung und Fehlersuche.
Quelle: Offizielles scrcpy-Projekt von Genymobile.
GitHub - Genymobile/scrcpy: Display and control your Android device
Display and control your Android device. Contribute to Genymobile/scrcpy development by creating an account on GitHub.GitHub
Nextcloud mit Plesk und Nginx betreiben – PHP-FPM, Proxy-Modus und wichtige Einstellungen
Überarbeitet am 8. September 2026.
Dieser Artikel war ursprünglich eine Mischung aus Plesk-, Nextcloud- und Collabora-Konfigurationen. Das war irgendwann kaum noch wartbar: Nextcloud hat seine Nginx-Regeln mehrfach angepasst und Collabora verwendet heute andere Pfade als früher. Deshalb trenne ich die Themen inzwischen sauber.
Hier geht es nur noch darum, Nextcloud unter Plesk Obsidian mit Nginx und PHP-FPM sinnvoll zu betreiben. Für Office gibt es eine eigene aktuelle Anleitung: Nextcloud Office mit Collabora einrichten.
Table of Contents
Toggle
1. Nginx in Plesk aktivieren
Bei einer aktuellen Plesk-Installation ist Nginx normalerweise bereits vorhanden. Prüfen kannst du das unter Tools & Einstellungen → Service-Verwaltung. Dort sollte der Reverse-Proxy-Service Nginx laufen.
Falls Nginx als PHP-Handler nicht angeboten wird, prüfe außerdem unter Tools & Einstellungen → Updates → Komponenten hinzufügen/entfernen → Webhosting, ob der Nginx-Webserver installiert ist.
2. Apache für diese Domain wirklich umgehen?
Plesk arbeitet standardmäßig mit Nginx vor Apache. Eine einzelne Domain kann aber auch nur über Nginx ausgeliefert werden.
Dazu gehst du bei der Nextcloud-Domain auf:
Websites & Domains → Einstellungen für Apache & Nginx
und deaktivierst im Nginx-Bereich den Proxymodus.
Wichtig: Bei nginx-only steht für PHP nur ein von Nginx bedienter PHP-FPM-Handler zur Verfügung. In den PHP-Einstellungen der Domain muss deshalb ein passender FPM-Handler, bedient von Nginx, ausgewählt sein.
3. Nicht meine alte Nginx-Konfiguration kopieren
Im alten Artikel stand eine komplette Nextcloud-Konfiguration aus einer längst vergangenen Version. Darin waren Pfade und Regeln enthalten, die heute nicht mehr dem offiziellen Beispiel entsprechen.
Nextcloud veröffentlicht eine gepflegte Referenzkonfiguration für Nginx. Diese sollte immer Ausgangspunkt sein:
Nextcloud Administration Manual: NGINX configuration
Plesk generiert allerdings selbst den Server-Block der Domain. Deshalb würde ich nicht einfach den kompletten offiziellen server { ... }-Block in „Zusätzliche Nginx-Anweisungen“ kopieren. Stattdessen müssen die für die eigene Installation nötigen Direktiven in die von Plesk erzeugte Struktur integriert werden.
4. .well-known für CalDAV und CardDAV
Ein Klassiker in der Nextcloud-Adminübersicht sind Warnungen zu CalDAV/CardDAV. Bei einer Installation direkt unter der Domain verweist die aktuelle Nextcloud-Dokumentation unter anderem auf folgende Weiterleitungen am vorgeschalteten Nginx:
location = /.well-known/carddav {
return 301 $scheme://$host/remote.php/dav;
}
location = /.well-known/caldav {
return 301 $scheme://$host/remote.php/dav;
}Weitere
/.well-known-Pfade sollten nicht pauschal blockiert werden. Die aktuelle Nextcloud-Nginx-Doku enthält dafür die jeweils passende Regel.5. Client-IP bei Reverse Proxies richtig behandeln
Falls vor Nextcloud noch ein weiterer Reverse Proxy, Load Balancer oder Container-Proxy sitzt, müssen trusted_proxies und gegebenenfalls forwarded_for_headers in der config.php korrekt gesetzt sein.
Das ist nicht nur Kosmetik: Erkennt Nextcloud alle Besucher als dieselbe Proxy-IP, kann die eingebaute Brute-Force-Erkennung plötzlich völlig normale Nutzer drosseln. Umgekehrt darf Nextcloud auch nicht beliebige vom Client gelieferte Forwarded-Header vertrauen, weil sich sonst IP-Adressen fälschen lassen.
Die aktuelle Dokumentation dazu: Nextcloud: Reverse proxy.
6. Nach Änderungen testen
Nach Anpassungen kontrolliere ich mindestens:
nginx -tund anschließend die Nextcloud-Adminübersicht unter Verwaltung → Übersicht. Zusätzlich sollte man Anmeldung, Datei-Upload, WebDAV sowie Kalender- und Kontakte-Synchronisation testen.
Wenn Nginx selbst mit Unit nginx.service is masked nicht startet, habe ich dafür ebenfalls eine eigene aktuelle Anleitung: Nginx „Unit is masked“ beheben.
7. Nextcloud-Härtung nicht vergessen
Der Webserver ist nur ein Teil des Setups. HTTPS, Updates, 2FA, Brute-Force-Schutz, Backups und eine korrekte Proxy-Konfiguration gehören ebenfalls dazu. Mehr dazu in Nextcloud richtig absichern.
Fazit
Plesk und Nextcloud funktionieren auch 2026 gut zusammen, wenn man Plesk seine Webserver-Konfiguration verwalten lässt und die Nextcloud-spezifischen Regeln gezielt ergänzt. Was ich heute vermeiden würde: eine jahrealte komplette Nginx-Konfiguration aus einem Blogbeitrag blind in Plesk einzufügen.
Quellen: Plesk Obsidian: Apache- und Nginx-Einstellungen, Nextcloud: NGINX configuration und Nextcloud: Reverse proxy.
Einstellungen für Apache und nginx
Plesk verwendet standardmäßig den Apache Webserver (https://de.wikipedia.org/wiki/Apache_HTTP_Server), um die Seiten ...docs.plesk.com
Nextcloud Office mit Collabora einrichten: Docker, Reverse Proxy und Tests
Überarbeitet am 8. September 2026.Diese Anleitung ist einer der Artikel, bei denen das Alter besonders deutlich geworden ist. Meine ursprüngliche Version brauchte noch einen speziellen Ubuntu-16.04-Kernel und hantierte mit AUFS. Das ist heute Geschichte. Nextcloud Office basiert weiterhin auf Collabora Online beziehungsweise CODE, lässt sich aber inzwischen wesentlich entspannter einrichten.
Für kleine private Installationen gibt es sogar einen eingebauten CODE-Server. Wer etwas mehr Leistung möchte, betreibt Collabora separat – zum Beispiel als Docker-Container hinter einem Reverse Proxy. Genau diesen Weg zeige ich hier.
Falls Docker auf deinem Server noch fehlt, findest du hier meine aktualisierte Anleitung: Docker und Docker Compose unter Debian und Ubuntu installieren.
Table of Contents
ToggleWas ist Nextcloud Office eigentlich?
Nextcloud Office ist die Office-Integration innerhalb von Nextcloud. Die eigentliche Bearbeitung übernimmt Collabora Online. Damit lassen sich unter anderem DOCX-, XLSX-, PPTX- und OpenDocument-Dateien direkt im Browser öffnen und gemeinsam bearbeiten.Wenn du erstmal nur ausprobieren möchtest, ob dir das gefällt, reicht für eine kleine Installation oft der Built-in CODE Server. Er lässt sich als Nextcloud-App installieren und funktioniert in vielen Setups ohne zusätzlichen Container. Nextcloud weist allerdings selbst darauf hin, dass ein separater Collabora-Server für bessere Performance sinnvoller ist.
1. Eigene Subdomain für Collabora vorbereiten
Für einen separaten Collabora-Server würde ich eine eigene Subdomain verwenden, zum Beispiel:
office.example.deCode-Sprache: CSS (css)
Die Subdomain zeigt auf deinen Server und bekommt ein gültiges TLS-Zertifikat. Auch deine Nextcloud sollte natürlich über HTTPS erreichbar sein. Nextcloud und Collabora sollten dasselbe Protokoll verwenden – praktisch also beide HTTPS.Mehr zu den grundlegenden Sicherheitsmaßnahmen findest du in Nextcloud richtig absichern.
2. Collabora CODE als Docker-Container starten
Das offizielle CODE-Image heißt weiterhincollabora/code. Zuerst laden wir es:
docker pull collabora/code
Danach starten wir Collabora nur auf localhost. So ist Port 9980 nicht direkt aus dem Internet erreichbar:
docker run -t -d \
-p 127.0.0.1:9980:9980 \
-e 'aliasgroup1=https://cloud.example.de:443' \
--restart always \
--cap-add MKNOD \
--name collabora \
collabora/codeCode-Sprache: JavaScript (javascript)cloud.example.deersetzt du durch die Domain deiner Nextcloud. Der Container lauscht anschließend nur auf127.0.0.1:9980. Von außen kommt man später ausschließlich über den Reverse Proxy an Collabora heran.3. Reverse Proxy vor Collabora setzen
Collabora benötigt einen Reverse Proxy, der die öffentliche Adressehttps://office.example.deauf den lokalen Dienst an Port 9980 weiterleitet. Anders als in sehr alten Anleitungen heißen die wichtigen Pfade heute unter anderem:
/browser/hosting/discovery/hosting/capabilities/cool- WebSocket-Verbindungen unter
/cool/.../wsWer noch eine alte Konfiguration mit
/loolund/loleaflethat, sollte sie deshalb überprüfen. Die aktuellen Collabora-Komponenten verwendencoolwsd,/coolund/browser.Da ich selbst Nginx nutze, würde ich dafür die aktuelle Reverse-Proxy-Vorlage von Collabora beziehungsweise Nextcloud als Ausgangspunkt nehmen. Besonders wichtig ist, dass die WebSocket-Verbindung mit durchgereicht wird. Eine reine normale HTTP-Weiterleitung reicht nicht.
4. Erst Collabora testen
Bevor ich Nextcloud konfiguriere, teste ich den Office-Server separat. Diese beiden Adressen sollten über den Browser erreichbar sein:
office.example.de/hosting/capa…
office.example.de/hosting/disc… JavaScript (javascript)
Auch direkt vom Nextcloud-Server aus kann man testen:
curl office.example.de/hosting/capa…
curl office.example.de/hosting/disc… JavaScript (javascript)
Wenn das schon nicht funktioniert, braucht man in Nextcloud noch gar nicht weiterzusuchen. Dann liegt das Problem eher bei DNS, Zertifikat, Firewall oder Reverse Proxy.5. Nextcloud Office installieren und verbinden
In Nextcloud gehst du zu Apps → Office & Text und installierst beziehungsweise aktivierst Nextcloud Office.Anschließend findest du unter Administrationseinstellungen → Office die Verbindung zum Collabora-Server. Dort trägst du ein:
office.example.deCode-Sprache: JavaScript (javascript)
Wenn alles stimmt, sollte Nextcloud die Verbindung erkennen. Danach kannst du direkt eine neue Textdatei oder Tabelle erstellen und testen.6. WOPI-Zugriffe einschränken
Ein Punkt, den es in meiner alten Anleitung noch gar nicht gab: Nextcloud empfiehlt ausdrücklich, WOPI-Anfragen auf die erwarteten Collabora-Server zu begrenzen. Die entsprechende Allow-Liste findest du in den Office-Administrationseinstellungen.Dort sollte möglichst nur die IP beziehungsweise das Netz eingetragen werden, aus dem dein Collabora-Server Nextcloud tatsächlich erreicht. Das verhindert, dass beliebige andere Systeme WOPI-Anfragen an deine Nextcloud stellen können.
7. Typische Fehler
Wenn Nextcloud Office nicht verbindet, prüfe ich in dieser Reihenfolge:
- Kann der Browser Nextcloud und Collabora über HTTPS erreichen?
- Kann Nextcloud
office.example.deerreichen?- Kann Collabora wiederum die Nextcloud-Domain erreichen?
- Ist das TLS-Zertifikat gültig?
- Werden die
/cool-WebSockets vom Reverse Proxy korrekt weitergeleitet?- Ist die WOPI-Allow-Liste korrekt?
Für den Container selbst helfen die Logs:
docker logs --tail 100 collabora
Die Nextcloud-Logs sollte man parallel ebenfalls ansehen. Sehr häufig ist es kein Office-Fehler, sondern schlicht eine nicht funktionierende Verbindung in eine der beiden Richtungen.8. Collabora aktualisieren
Da CODE regelmäßig aktualisiert wird, sollte auch der Container nicht jahrelang unangetastet bleiben:
docker pull collabora/code
Anschließend wird der Container mit demselben Startbefehl neu erstellt. Wer stattdessen Docker Compose verwendet, kann das entsprechend mitdocker compose pullunddocker compose up -derledigen.Mein Fazit nach der Überarbeitung
Der Unterschied zu meiner ersten Collabora-Anleitung ist schon ziemlich absurd: Kein Xenial-Proposed, kein Kernel 4.4, kein AUFS-Gefrickel mehr. Für kleine Instanzen reicht heute sogar der eingebaute CODE-Server. Wer es etwas sauberer und performanter möchte, stellt einen separaten Collabora-Container hinter eine eigene HTTPS-Subdomain.Wenn du noch am Anfang mit Nextcloud bist, findest du in Was bietet Nextcloud 2026? einen Überblick darüber, was die Cloud inzwischen alles kann.
Weiterführend: Nextcloud Office installieren, Collabora per Docker und Troubleshooting.
Was bietet Nextcloud 2026? Mehr als nur eine private Cloud | Das Netz und ich
Nextcloud ist längst mehr als Datei-Sync: Files, Kalender, Kontakte, Talk, Office, Fotos, Aufgaben, RSS und viele Apps – ein Überblick für Einsteiger.lars (Das Netz und ich)
aria2 mit Docker Compose sicher betreiben – RPC-Token und WebUI nur lokal
Überarbeitet am 8. September 2026.
aria2 ist auch 2026 noch ein praktischer Download-Client für HTTP/HTTPS, FTP/SFTP, BitTorrent und Metalink. Meine alte Docker-Anleitung hatte allerdings einen ziemlich unschönen Haken: Die RPC-Schnittstelle und die WebUI wurden direkt auf öffentliche Serverports gelegt. Das würde ich heute nicht mehr so machen.
In dieser aktualisierten Variante laufen WebUI und RPC deshalb ausschließlich auf 127.0.0.1. Für die RPC-Schnittstelle wird zusätzlich ein Secret verwendet.
Table of Contents
Toggle
Voraussetzungen
Docker und Docker Compose sollten bereits installiert sein. Falls nicht: Docker und Docker Compose unter Debian/Ubuntu installieren.
Eine Erklärung zum Aufbau von Compose-Dateien findest du hier: Docker Compose erklärt.
Projektordner anlegen
sudo mkdir -p /opt/aria2/{downloads,config}
cd /opt/aria2Für den RPC-Schlüssel verwenden wir eine
.env-Datei:nano .envARIA2_SECRET=hier-ein-langes-zufaelliges-secret-eintragenDie Datei sollte nicht unnötig für andere Benutzer lesbar sein:
chmod 600 .envcompose.yaml erstellen
services:
aria2:
image: abcminiuser/docker-aria2-with-webui:latest-ng
container_name: aria2
restart: unless-stopped
ports:
- "127.0.0.1:6800:6800"
- "127.0.0.1:6880:80"
volumes:
- ./downloads:/data
- ./config:/conf
environment:
SECRET: ${ARIA2_SECRET}
PUID: 1000
PGID: 1000PUID und PGID müssen zu dem Benutzer passen, der auf die Download-Verzeichnisse zugreifen soll. Die Werte kannst du beispielsweise mit id BENUTZERNAME prüfen.Container starten
docker compose up -d
docker compose ps
docker compose logs --tail=100 aria2Warum die Ports nur auf localhost liegen
Die aria2-RPC-Schnittstelle ist eine administrative Schnittstelle. Wer Zugriff darauf bekommt, kann Downloadaufträge steuern. Deshalb öffne ich Port 6800 nicht mehr mit ufw allow 6800 ins Internet.
Auch die WebUI braucht bei mir keinen öffentlichen Port. Für einen gelegentlichen administrativen Zugriff reicht ein SSH-Tunnel:
ssh -L 6880:127.0.0.1:6880 -L 6800:127.0.0.1:6800 user@serverDanach kann die WebUI lokal im Browser über
http://127.0.0.1:6880 geöffnet werden. In der WebUI muss für die RPC-Verbindung das gleiche Secret eingetragen werden.Updates
cd /opt/aria2
docker compose pull
docker compose up -dVor einem Update sollte man bei produktiv genutzten Downloads natürlich prüfen, ob die verwendete Container-Version oder Konfiguration Änderungen mitbringt.
Nextcloud: heute nicht mehr über ocDownloader
Der ursprüngliche Artikel war eng mit ocDownloader für Nextcloud verbunden. Diese Kombination empfehle ich heute nicht mehr. Für Nextcloud habe ich inzwischen modernere Lösungen im Blog, unter anderem meine eigene App MediaFetch.
Fazit
aria2 selbst ist weiterhin ein nützliches Werkzeug. Der entscheidende Unterschied zu meiner alten Installation ist die Absicherung: kein offener RPC-Port, kein öffentliches Webinterface und ein RPC-Secret. Genau solche Kleinigkeiten machen bei einem Server im Internet einen großen Unterschied.
Quellen: aria2-Projekt und Docker-Image mit WebUI.
Erste eigene Nextcloud App – Mediafetch | Das Netz und ich
Effizienter Download-Manager für Nextcloud gesucht? Entdecke MediaFetch – deine erste eigene App für einfache Downloads direkt in Nextcloud!lars (Das Netz und ich)
Docker-Container 2026 sicher aktualisieren: Compose, Diun und Renovate statt Watchtower
Überarbeitet am 8. September 2026.
Docker-Container automatisch zu aktualisieren klingt erstmal perfekt: neues Image verfügbar, Container wird neu erstellt, fertig. Genau deshalb habe ich früher Watchtower eingesetzt. Heute würde ich das auf einem produktiven Server deutlich vorsichtiger angehen.
Der wichtigste Grund: Das ursprüngliche Projekt containrrr/watchtower wurde am 17. Dezember 2025 archiviert und wird nicht mehr gepflegt. Meine alte Watchtower-Anleitung ist damit selbst zu einem guten Beispiel dafür geworden, warum Infrastruktur nicht blind jahrelang automatisch weiterlaufen sollte.
Mein heutiger Ansatz ist einfacher: Updates erkennen, kurz prüfen, Backup im Blick haben und dann mit Docker Compose bewusst aktualisieren. Wer mehr Automatisierung möchte, kann sich über neue Images benachrichtigen lassen oder Änderungen über Git verwalten.
Table of Contents
Toggle
Warum ich nicht mehr alles blind automatisch aktualisiere
Ein neues Container-Image ist nicht automatisch ein risikoloses Update. Es können sich Umgebungsvariablen ändern, Datenbankmigrationen nötig werden oder Konfigurationsoptionen verschwinden. Genau das haben wir beispielsweise bei Pi-hole v6 gesehen.
Wenn ein Update nachts automatisch durchläuft und danach Nextcloud, Mailcow oder eine Datenbank nicht mehr sauber startet, ist „immer aktuell“ plötzlich kein Vorteil mehr.
Variante 1: Docker Compose bewusst aktualisieren
Für meinen privaten Server ist das oft schon die beste Lösung. Im Verzeichnis des jeweiligen Compose-Projekts:
docker compose pull
docker compose up -d
docker compose pspull lädt die aktuellen Images der in der Compose-Datei verwendeten Tags. up -d erstellt betroffene Container bei Bedarf neu und lässt unveränderte Dienste in Ruhe.
Danach schaue ich kurz in die Logs:
docker compose logs --tail 100
Bei wichtigen Diensten teste ich zusätzlich die Anwendung selbst: Login funktioniert? Datenbank erreichbar? Upload oder Schreibzugriff okay? Erst dann ist das Update für mich wirklich erledigt.
Die Grundlagen zu diesen Befehlen findest du in Docker Compose erklärt und in Docker-Container für Einsteiger.
Nicht überall latest verwenden
Ein großer Teil der Update-Sicherheit beginnt schon in der compose.yaml. Statt überall nur latest einzutragen, kann man bei kritischen Diensten bewusst eine Haupt- oder konkrete Version verwenden.
image: mariadb:11.8Code-Sprache: CSS (css)
Damit entscheidet nicht irgendein zukünftiger Major-Sprung automatisch, wann die Datenbank auf eine völlig neue Generation wechselt.
Noch reproduzierbarer sind Images, die zusätzlich auf einen Digest festgelegt werden. Das ist vor allem interessant, wenn Compose-Dateien in Git liegen und Updates über Renovate verwaltet werden.
Variante 2: Diun meldet neue Images, aktualisiert aber nichts
Diun steht für Docker Image Update Notifier. Genau der Name beschreibt den Unterschied zu Watchtower ziemlich gut: Diun beobachtet Container-Images und benachrichtigt mich, wenn sich etwas geändert hat. Das eigentliche Update entscheide ich anschließend selbst.
Das gefällt mir für einen produktiven Homeserver deutlich besser als ein Dienst, der mit Zugriff auf den Docker-Socket eigenständig jeden Container ersetzt.
Ein kleines Diun-Compose-Beispiel
services:
diun:
image: crazymax/diun:latest
command: serve
restart: unless-stopped
volumes:
- ./data:/data
- /var/run/docker.sock:/var/run/docker.sock:ro
environment:
TZ: Europe/Berlin
DIUN_PROVIDERS_DOCKER: "true"
DIUN_PROVIDERS_DOCKER_WATCHBYDEFAULT: "false"
DIUN_WATCH_SCHEDULE: "0 */6 * * *"Code-Sprache: PHP (php)
In den Containern, die beobachtet werden sollen, wird anschließend ein Label gesetzt:
labels:
- "diun.enable=true"Code-Sprache: JavaScript (javascript)
Diun unterstützt verschiedene Benachrichtigungswege. Welche davon sinnvoll sind, hängt vom eigenen Setup ab. Der entscheidende Punkt für mich ist: Benachrichtigen und Aktualisieren sind zwei getrennte Schritte.
Achtung: Auch Diun braucht Zugriff auf Docker
Damit Diun laufende Container erkennen kann, benötigt der Docker-Provider Zugriff auf den Docker-Socket. Dieser Socket ist sicherheitstechnisch mächtig und sollte nicht gedankenlos an beliebige Container durchgereicht werden.
Ich würde deshalb nur vertrauenswürdige Images einsetzen und den Zugriff nicht als harmlose Kleinigkeit betrachten. Wer seine Compose-Dateien ohnehin in Git verwaltet, kann komplett auf diese lokale Docker-Erkennung verzichten und stattdessen Renovate verwenden.
Variante 3: Renovate aktualisiert die Compose-Datei per Pull Request
Renovate kann Docker-Images direkt in Compose-Dateien erkennen. Liegt meine Serverkonfiguration beispielsweise in einem privaten Git-Repository, kann Renovate bei einer neuen Version einen Pull Request erzeugen.
Das hat einen großen Vorteil: Ich sehe die Änderung, kann Release Notes prüfen und entscheide erst danach, ob sie übernommen wird. Das ist kontrollierter als ein nächtlicher Container-Tausch ohne Review.
Renovate unterstützt dabei auch Docker-Digests. Ein Image kann lesbar mit Tag eingetragen und gleichzeitig auf einen konkreten SHA256-Digest festgelegt werden. Renovate aktualisiert diesen Digest anschließend über einen Pull Request.
image: nginx:1.29-alpine@sha256:...Code-Sprache: HTTP (http)
Für einen einzelnen kleinen Server ist das vielleicht mehr GitOps als nötig. Wer seine Docker-Konfigurationen aber ohnehin versioniert, bekommt damit einen sehr nachvollziehbaren Updateprozess.
Was ich nicht mehr empfehlen würde: Ouroboros als Watchtower-Ersatz
In einer früheren Version dieses Artikels hatte ich Ouroboros als Alternative genannt. Das nehme ich wieder heraus. Nur weil ein Werkzeug einmal eine Watchtower-Alternative war, heißt das nicht, dass es Jahre später noch die beste Empfehlung ist.
Genau das ist übrigens auch der Grund, warum ich solche alten Infrastrukturartikel gerade Stück für Stück überarbeite.
Backups vor kritischen Updates
Container selbst sind schnell neu erstellt. Die wichtigen Dinge liegen aber in Datenbanken und Volumes. Vor einem größeren Update von Nextcloud, MariaDB, PostgreSQL oder einem anderen zustandsbehafteten Dienst möchte ich deshalb ein aktuelles Backup haben.
Für meine Serverdaten nutze ich unter anderem Borg. Die aktuelle Einrichtung habe ich hier beschrieben: BorgBackup unter Debian und Ubuntu einrichten.
Nach dem Update alte Images aufräumen
Wenn ein Update erfolgreich läuft und kein schneller Rollback auf das alte Image mehr nötig ist, sammeln sich mit der Zeit ungenutzte Images an.
Vor dem Löschen schaue ich zuerst:
docker image ls
Ungenutzte Images lassen sich später gezielt mit den normalen Docker-Prune-Funktionen bereinigen. Dabei sollte man genauso wenig blind löschen wie bei Volumes.
Mein heutiger Workflow
Für einen kleinen selbst gehosteten Server würde ich es heute ungefähr so halten:
- Neue Version erkennen – beispielsweise über Diun oder Renovate.
- Release Notes beziehungsweise Breaking Changes prüfen.
- Bei wichtigen Diensten Backup kontrollieren.
docker compose pullausführen.docker compose up -dausführen.- Status, Logs und die Anwendung selbst testen.
- Alte Images erst später aufräumen.
Das sind ein paar Schritte mehr als „Watchtower macht das nachts automatisch“. Dafür weiß ich am nächsten Morgen aber auch ziemlich genau, warum meine Dienste noch laufen.
Weiterführend: Diun-Dokumentation, Renovate für Docker Compose und die Docker-Compose-Dokumentation.
Docker Compose
Learn how to use Docker Compose to define and run multi-container applications with this detailed introduction to the tool.Docker Inc (Docker Documentation)
Raises rent, offers no additional value to the proposition. Pay it or vacate. By the way, rent has been raised across the board in the are, so fuck you. Coincidentally your paltry COLA raises that are below the actual cost of living do not compensate to match the rent hike.
Also, you can call any time, and they will return your call as soon as possible, or more likely never. Good luck to you, and don’t even dream of receiving your full security deposit back, as those door hinges and 5 year old carpet looks nothing like it did when you moved in and must be replaced.
Pi-hole v6 mit Docker Compose installieren – DNS-Werbeblocker im Heimnetz
Überarbeitet am 8. September 2026.
Pi-hole ist für mich nach wie vor eine der angenehmsten Möglichkeiten, Werbung und Tracking bereits auf DNS-Ebene für ein komplettes Heimnetz zu filtern. Meine alte Docker-Anleitung war allerdings dringend fällig: Sie verwendete noch ein uraltes Image, alte Umgebungsvariablen und war ursprünglich sogar auf einem öffentlich erreichbaren Root-Server entstanden.
Ganz wichtig: Einen Pi-hole-DNS-Server würde ich nicht offen ins Internet stellen. Port 53 gehört nur in das eigene LAN beziehungsweise in ein bewusst abgesichertes VPN. Ein öffentlicher rekursiver DNS-Resolver kann missbraucht werden und unnötig viel Traffic verursachen.
Falls Docker und Docker Compose noch fehlen, habe ich dafür eine aktuelle Anleitung: Docker und Docker Compose unter Debian und Ubuntu installieren.
Table of Contents
Toggle
Pi-hole v6: Was hat sich geändert?
Seit Pi-hole v6 sieht die Docker-Konfiguration deutlich anders aus. Fast alle alten Environment-Variablen aus v5 wurden durch die neuen FTLCONF_...-Variablen ersetzt.
Ein paar Beispiele:
WEBPASSWORD→FTLCONF_webserver_api_passwordDNSMASQ_LISTENING→FTLCONF_dns_listeningModePIHOLE_DNS_→FTLCONF_dns_upstreamsDNSSEC→FTLCONF_dns_dnssec
Wer eine alte v5-Konfiguration übernimmt, sollte deshalb nicht einfach das Image aktualisieren und hoffen, dass alle alten Variablen weiter gelten.
1. Verzeichnis anlegen
sudo mkdir -p /opt/pihole/etc-pihole
sudo chown -R $USER:$USER /opt/pihole
cd /opt/piholeCode-Sprache: PHP (php)
Für eine neue Pi-hole-v6-Installation reicht normalerweise das persistente Verzeichnis /etc/pihole. Das früher häufig eingebundene /etc/dnsmasq.d ist laut aktueller Pi-hole-Dokumentation für einen frischen v6-Start normalerweise nicht mehr nötig.
2. Webpasswort in .env ablegen
Das Admin-Passwort schreibe ich nicht direkt in die compose.yml. Ein zufälliges Passwort lässt sich zum Beispiel so erzeugen:
openssl rand -base64 24
Danach:
nano /opt/pihole/.envPIHOLE_PASSWORD=DEIN_LANGES_ZUFAELLIGES_PASSWORTchmod 600 /opt/pihole/.env
Pi-hole unterstützt alternativ auch Docker Secrets über WEBPASSWORD_FILE. Für ein kleines privates Compose-Setup finde ich eine geschützte .env-Datei aber leichter nachvollziehbar.
3. compose.yml für Pi-hole v6
In diesem Beispiel hat der Docker-Host im Heimnetz die feste IP 192.168.178.10. Diese Adresse musst du durch die IP deines eigenen Servers ersetzen.
services:
pihole:
container_name: pihole
image: pihole/pihole:latest
restart: unless-stopped
ports:
- "192.168.178.10:53:53/tcp"
- "192.168.178.10:53:53/udp"
- "192.168.178.10:8080:80/tcp"
environment:
TZ: "Europe/Berlin"
FTLCONF_webserver_api_password: "${PIHOLE_PASSWORD}"
FTLCONF_dns_listeningMode: "ALL"
FTLCONF_dns_upstreams: "9.9.9.9;149.112.112.112"
volumes:
- ./etc-pihole:/etc/piholeCode-Sprache: JavaScript (javascript)
Warum binde ich die Ports ausdrücklich an die LAN-IP? So lauscht der Container nicht automatisch auf sämtlichen Netzwerkschnittstellen des Hosts. Gerade auf einem Server mit mehreren Interfaces ist das wesentlich eindeutiger.
Die offiziellen Pi-hole-Beispiele veröffentlichen zusätzlich Port 443. Für einen einfachen Start im geschützten Heimnetz reicht mir hier zunächst die Weboberfläche auf Port 8080. Wer das Admin-Panel über HTTPS betreiben möchte, kann das anschließend bewusst ergänzen.
4. Pi-hole starten
cd /opt/pihole
docker compose up -d
docker compose ps
Bei Problemen sind die Logs meistens der schnellste Weg:
docker logs -f --tail 100 pihole
Das Admin-Panel ist im Beispiel anschließend erreichbar unter:
192.168.178.10:8080/admin/Code… JavaScript (javascript)
5. Pi-hole als DNS-Server im Heimnetz verteilen
Damit nicht jedes Smartphone und jeder Rechner einzeln konfiguriert werden muss, trage ich die Pi-hole-IP am liebsten im Router als lokalen DNS-Server ein. Dann erhalten die Clients den DNS-Server automatisch per DHCP.
Bei einer FRITZ!Box hängt der genaue Menüpunkt von FRITZ!OS ab. Wichtig ist am Ende nur: Die Clients sollen 192.168.178.10 als DNS-Server verwenden.
6. Funktion testen
Von einem Rechner im LAN kann man direkt prüfen, ob Pi-hole antwortet:
nslookup example.com 192.168.178.10Code-Sprache: CSS (css)
Unter Linux geht alternativ:
dig @192.168.178.10 example.comCode-Sprache: CSS (css)
Wenn eine Antwort kommt und die Anfrage kurz danach im Pi-hole Query Log auftaucht, funktioniert der grundlegende DNS-Weg.
7. Keine wahllosen Blocklisten sammeln
In der alten Anleitung hatte ich eine ganze Sammlung fremder Blocklisten direkt zum Kopieren aufgeführt. Das würde ich heute anders machen. Listen verschwinden, werden nicht mehr gepflegt oder blockieren irgendwann mehr als gewünscht.
Ich würde zunächst mit den vorhandenen Pi-hole-Listen starten und zusätzliche Quellen nur dann ergänzen, wenn ich einen konkreten Grund dafür habe. Lieber wenige gepflegte Listen als eine halbe Million Domains aus irgendwelchen alten GitHub-Repositories.
8. Pi-hole als DHCP-Server?
Das ist möglich, aber für einen Docker-Container etwas aufwendiger. Das offizielle Compose-Beispiel benötigt dafür unter anderem UDP-Port 67 und die Capability NET_ADMIN.
Wenn der vorhandene Router den Pi-hole-DNS-Server sauber per DHCP verteilen kann, würde ich DHCP zunächst dort lassen. Pi-hole als DHCP-Server würde ich erst einrichten, wenn dafür wirklich ein Grund besteht.
9. Pi-hole aktualisieren
Im Docker-Container verwendet man nicht pihole -up. Pi-hole weist ausdrücklich darauf hin, dass Docker-Installationen über ein neues Container-Image aktualisiert werden:
cd /opt/pihole
docker compose pull
docker compose down
docker compose up -d
Die Konfiguration bleibt durch das Volume ./etc-pihole:/etc/pihole erhalten.
Vor größeren Versionssprüngen lohnt sich trotzdem immer ein Blick in die Release Notes. Gerade der Wechsel von Pi-hole v5 auf v6 hat gezeigt, dass sich Environment-Variablen ändern können.
Mein Fazit
Pi-hole im Docker-Container ist 2026 weiterhin unkompliziert – wenn man nicht versucht, eine fünf Jahre alte Compose-Datei unverändert weiterzuverwenden. Für mich sind die wichtigsten Punkte: aktuelle FTLCONF_-Variablen, persistente Daten, ein ordentliches Admin-Passwort und DNS-Port 53 niemals versehentlich öffentlich ins Internet stellen.
Aktuelle Beispiele findest du in der offiziellen Pi-hole-Docker-Dokumentation und in der Migrationsübersicht von v5 auf v6.
Docker & Docker Compose unter Debian und Ubuntu installieren – Schritt für Schritt | Das Netz und ich
Docker und Docker Compose unter Debian oder Ubuntu installieren: aktuelle Repository-Methode, Compose-Plugin, erster Test und wichtige Firewall-Hinweise.lars (Das Netz und ich)
ONLYOFFICE Docs mit Docker Compose und Nextcloud einrichten – sicher hinter Nginx
Überarbeitet am 8. September 2026.
ONLYOFFICE Docs ist weiterhin eine interessante Möglichkeit, Office-Dateien direkt in Nextcloud im Browser zu bearbeiten. Der Nextcloud-Connector wird aktiv gepflegt und unterstützt im September 2026 Nextcloud bis Version 34. Meine alte Anleitung funktioniert in Teilen noch, enthält aber inzwischen ein paar Dinge, die ich so nicht mehr empfehlen würde.
Vor allem würde ich den Document Server heute nicht mehr mit einem offenen Port ins Internet stellen. Stattdessen binde ich ihn nur an 127.0.0.1 und lasse den öffentlichen Zugriff ausschließlich über Nginx und HTTPS laufen.
Falls Docker und das Compose-Plugin noch fehlen, findest du die aktuelle Installation in meiner Anleitung Docker und Docker Compose unter Debian und Ubuntu installieren.
Table of Contents
Toggle
1. Verzeichnis für ONLYOFFICE anlegen
sudo mkdir -p /opt/onlyoffice/{data,logs,lib}
sudo chown -R $USER:$USER /opt/onlyoffice
cd /opt/onlyofficeCode-Sprache: PHP (php)
Die zusätzlichen Verzeichnisse sind nicht zwingend nötig, damit der Container überhaupt läuft. Sie machen Logs und relevante Anwendungsdaten aber leichter zugänglich und verhindern, dass alles ausschließlich im Container liegt.
2. Starkes JWT-Secret erzeugen
Seit ONLYOFFICE Docs 7.2 ist JWT standardmäßig aktiv. Wird kein eigenes Secret gesetzt, generiert ONLYOFFICE einen zufälligen Wert. Für eine feste Nextcloud-Integration ist ein eigenes Secret wesentlich praktischer, weil Nextcloud und Document Server denselben Schlüssel verwenden müssen.
Ein starkes Secret lässt sich so erzeugen:
openssl rand -hex 32
Den ausgegebenen Wert speichere ich in einer .env-Datei:
nano /opt/onlyoffice/.envJWT_SECRET=HIER_DEIN_LANGES_ZUFAELLIGES_SECRET
Danach die Datei nur für den Eigentümer lesbar machen:
chmod 600 /opt/onlyoffice/.env
3. compose.yml erstellen
Eine Versionsangabe wie version: '2.2' ist bei aktuellem Docker Compose nicht mehr nötig. Meine compose.yml sieht so aus:
services:
documentserver:
image: onlyoffice/documentserver:latest
container_name: onlyoffice-documentserver
restart: unless-stopped
ports:
- "127.0.0.1:8833:80"
environment:
JWT_ENABLED: "true"
JWT_SECRET: "${JWT_SECRET}"
volumes:
- ./data:/var/www/onlyoffice/Data
- ./logs:/var/log/onlyoffice
- ./lib:/var/lib/onlyofficeCode-Sprache: JavaScript (javascript)
Der entscheidende Unterschied zu meiner alten Anleitung ist diese Zeile:
127.0.0.1:8833:80Code-Sprache: CSS (css)
Damit lauscht Port 8833 nur auf dem lokalen Host. Ein ufw allow 8833 ist dadurch weder nötig noch gewünscht. Von außen soll ausschließlich Nginx auf Port 443 erreichbar sein.
Hinweis zu latest: Für einen privaten Testserver ist das bequem. Auf einem produktiven System würde ich eher eine zuvor getestete ONLYOFFICE-Version fest pinnen und Updates bewusst durchführen.
4. Container starten und prüfen
cd /opt/onlyoffice
docker compose up -d
docker compose ps
Falls der Container nicht sauber startet, helfen die Logs:
docker logs -f --tail 100 onlyoffice-documentserver
Vom Host aus kann man außerdem testen, ob der Dienst antwortet:
curl -I 127.0.0.1:8833/Code-Sprache: JavaScript (javascript)
5. Nginx als Reverse Proxy einrichten
ONLYOFFICE benötigt hinter einem Proxy unter anderem die korrekten X-Forwarded-Proto– und X-Forwarded-Host-Header. Auch WebSocket-Verbindungen müssen weitergereicht werden.
Die Map für WebSocket-Verbindungen gehört in den http-Kontext von Nginx, beispielsweise in eine Datei unter /etc/nginx/conf.d/:
map $http_upgrade $connection_upgrade {
default upgrade;
'' close;
}Code-Sprache: PHP (php)
Der eigentliche Virtual Host kann anschließend beispielsweise so aussehen. Die Zertifikatspfade musst du natürlich an deine Domain anpassen:
server {
listen 80;
server_name office.example.de;
return 301 https://$host$request_uri;
}
server {
listen 443 ssl;
server_name office.example.de;
ssl_certificate /etc/letsencrypt/live/office.example.de/fullchain.pem;
ssl_certificate_key /etc/letsencrypt/live/office.example.de/privkey.pem;
client_max_body_size 100M;
location / {
proxy_pass 127.0.0.1:8833;
proxy_http_version 1.1;
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection $connection_upgrade;
proxy_read_timeout 3600s;
}
}Code-Sprache: PHP (php)
Die uralte TLS-1.0/1.1- und Cipher-Liste aus meiner früheren Anleitung habe ich bewusst entfernt. TLS-Einstellungen sollten heute zentral und passend zur verwendeten Nginx-Version gepflegt werden, statt jahrelang einen alten Cipher-Block aus einem Blogartikel mitzuschleppen.
Danach wie immer testen und neu laden:
sudo nginx -t
sudo systemctl reload nginx
6. ONLYOFFICE-App in Nextcloud installieren
In Nextcloud wird anschließend die App ONLYOFFICE aus dem App Store installiert. Der Connector unterstützt aktuell Nextcloud bis Version 34.
Unter den ONLYOFFICE-Einstellungen trägst du als Document-Server-Adresse ein:
office.example.de/Code-Sprache… JavaScript (javascript)
Im Feld für den geheimen Schlüssel kommt derselbe JWT-Wert hinein, der in der .env-Datei des Document Servers steht.
7. Wenn öffentliche Adressen intern nicht funktionieren
In manchen Docker- oder Firewall-Setups können Nextcloud und ONLYOFFICE ihre öffentlichen Domains intern nicht erreichen. Dafür bietet der Connector unter den erweiterten Servereinstellungen getrennte interne Adressen an.
Diese Felder würde ich nur verwenden, wenn sie wirklich benötigt werden. In einer normalen Installation, in der beide Seiten ihre öffentlichen HTTPS-Adressen erreichen können, ist das nicht nötig.
8. Verbindung testen
Nach dem Speichern der Einstellungen lege ich in Nextcloud eine kleine DOCX-Datei an beziehungsweise öffne eine vorhandene Datei. Wenn der Editor erscheint und Änderungen gespeichert werden, funktioniert die grundlegende Integration.
Wenn Nextcloud stattdessen einen Verbindungsfehler zeigt, prüfe ich in dieser Reihenfolge:
- Ist
docker compose psgrün? - Antwortet
curl http://127.0.0.1:8833/lokal? - Ist
https://office.example.deöffentlich erreichbar? - Ist das Zertifikat gültig?
- Stimmt das JWT-Secret auf beiden Seiten exakt überein?
- Kann ONLYOFFICE die Nextcloud-Adresse selbst erreichen?
9. Updates bewusst durchführen
cd /opt/onlyoffice
docker compose pull
docker compose up -d
Auf einem produktiven System würde ich Document Server und Nextcloud-Connector nicht blind automatisch aktualisieren. Gerade bei Office-Integrationen lohnt es sich, vor einem Versionssprung kurz die Kompatibilität zu prüfen und die Konfiguration zu sichern.
ONLYOFFICE oder Collabora?
Beide Lösungen funktionieren mit Nextcloud und haben ihre eigenen Stärken. Wenn du statt ONLYOFFICE lieber die LibreOffice-nahe Variante einsetzen möchtest, habe ich auch die Anleitung Nextcloud Office mit Collabora einrichten aktualisiert.
Weiterführend: ONLYOFFICE Docs per Docker installieren, ONLYOFFICE mit Nextcloud verbinden und ONLYOFFICE hinter einem Reverse Proxy.
ONLYOFFICE Docs Community Edition für Docker auf einem lokalen Server installieren - ONLYOFFICE
ONLYOFFICE Docs Community Edition für Docker auf einem lokalen Server installierenONLYOFFICE Docs Community Edition für Docker auf einem lokalen Server installieren - ONLYOFFICE
Nextcloud Office mit Collabora einrichten: Docker, Reverse Proxy und Tests
Überarbeitet am 8. September 2026.Diese Anleitung ist einer der Artikel, bei denen das Alter besonders deutlich geworden ist. Meine ursprüngliche Version brauchte noch einen speziellen Ubuntu-16.04-Kernel und hantierte mit AUFS. Das ist heute Geschichte. Nextcloud Office basiert weiterhin auf Collabora Online beziehungsweise CODE, lässt sich aber inzwischen wesentlich entspannter einrichten.
Für kleine private Installationen gibt es sogar einen eingebauten CODE-Server. Wer etwas mehr Leistung möchte, betreibt Collabora separat – zum Beispiel als Docker-Container hinter einem Reverse Proxy. Genau diesen Weg zeige ich hier.
Falls Docker auf deinem Server noch fehlt, findest du hier meine aktualisierte Anleitung: Docker und Docker Compose unter Debian und Ubuntu installieren.
Table of Contents
ToggleWas ist Nextcloud Office eigentlich?
Nextcloud Office ist die Office-Integration innerhalb von Nextcloud. Die eigentliche Bearbeitung übernimmt Collabora Online. Damit lassen sich unter anderem DOCX-, XLSX-, PPTX- und OpenDocument-Dateien direkt im Browser öffnen und gemeinsam bearbeiten.Wenn du erstmal nur ausprobieren möchtest, ob dir das gefällt, reicht für eine kleine Installation oft der Built-in CODE Server. Er lässt sich als Nextcloud-App installieren und funktioniert in vielen Setups ohne zusätzlichen Container. Nextcloud weist allerdings selbst darauf hin, dass ein separater Collabora-Server für bessere Performance sinnvoller ist.
1. Eigene Subdomain für Collabora vorbereiten
Für einen separaten Collabora-Server würde ich eine eigene Subdomain verwenden, zum Beispiel:
office.example.deCode-Sprache: CSS (css)
Die Subdomain zeigt auf deinen Server und bekommt ein gültiges TLS-Zertifikat. Auch deine Nextcloud sollte natürlich über HTTPS erreichbar sein. Nextcloud und Collabora sollten dasselbe Protokoll verwenden – praktisch also beide HTTPS.Mehr zu den grundlegenden Sicherheitsmaßnahmen findest du in Nextcloud richtig absichern.
2. Collabora CODE als Docker-Container starten
Das offizielle CODE-Image heißt weiterhincollabora/code. Zuerst laden wir es:
docker pull collabora/code
Danach starten wir Collabora nur auf localhost. So ist Port 9980 nicht direkt aus dem Internet erreichbar:
docker run -t -d \
-p 127.0.0.1:9980:9980 \
-e 'aliasgroup1=https://cloud.example.de:443' \
--restart always \
--cap-add MKNOD \
--name collabora \
collabora/codeCode-Sprache: JavaScript (javascript)cloud.example.deersetzt du durch die Domain deiner Nextcloud. Der Container lauscht anschließend nur auf127.0.0.1:9980. Von außen kommt man später ausschließlich über den Reverse Proxy an Collabora heran.3. Reverse Proxy vor Collabora setzen
Collabora benötigt einen Reverse Proxy, der die öffentliche Adressehttps://office.example.deauf den lokalen Dienst an Port 9980 weiterleitet. Anders als in sehr alten Anleitungen heißen die wichtigen Pfade heute unter anderem:
/browser/hosting/discovery/hosting/capabilities/cool- WebSocket-Verbindungen unter
/cool/.../wsWer noch eine alte Konfiguration mit
/loolund/loleaflethat, sollte sie deshalb überprüfen. Die aktuellen Collabora-Komponenten verwendencoolwsd,/coolund/browser.Da ich selbst Nginx nutze, würde ich dafür die aktuelle Reverse-Proxy-Vorlage von Collabora beziehungsweise Nextcloud als Ausgangspunkt nehmen. Besonders wichtig ist, dass die WebSocket-Verbindung mit durchgereicht wird. Eine reine normale HTTP-Weiterleitung reicht nicht.
4. Erst Collabora testen
Bevor ich Nextcloud konfiguriere, teste ich den Office-Server separat. Diese beiden Adressen sollten über den Browser erreichbar sein:
office.example.de/hosting/capa…
office.example.de/hosting/disc… JavaScript (javascript)
Auch direkt vom Nextcloud-Server aus kann man testen:
curl office.example.de/hosting/capa…
curl office.example.de/hosting/disc… JavaScript (javascript)
Wenn das schon nicht funktioniert, braucht man in Nextcloud noch gar nicht weiterzusuchen. Dann liegt das Problem eher bei DNS, Zertifikat, Firewall oder Reverse Proxy.5. Nextcloud Office installieren und verbinden
In Nextcloud gehst du zu Apps → Office & Text und installierst beziehungsweise aktivierst Nextcloud Office.Anschließend findest du unter Administrationseinstellungen → Office die Verbindung zum Collabora-Server. Dort trägst du ein:
office.example.deCode-Sprache: JavaScript (javascript)
Wenn alles stimmt, sollte Nextcloud die Verbindung erkennen. Danach kannst du direkt eine neue Textdatei oder Tabelle erstellen und testen.6. WOPI-Zugriffe einschränken
Ein Punkt, den es in meiner alten Anleitung noch gar nicht gab: Nextcloud empfiehlt ausdrücklich, WOPI-Anfragen auf die erwarteten Collabora-Server zu begrenzen. Die entsprechende Allow-Liste findest du in den Office-Administrationseinstellungen.Dort sollte möglichst nur die IP beziehungsweise das Netz eingetragen werden, aus dem dein Collabora-Server Nextcloud tatsächlich erreicht. Das verhindert, dass beliebige andere Systeme WOPI-Anfragen an deine Nextcloud stellen können.
7. Typische Fehler
Wenn Nextcloud Office nicht verbindet, prüfe ich in dieser Reihenfolge:
- Kann der Browser Nextcloud und Collabora über HTTPS erreichen?
- Kann Nextcloud
office.example.deerreichen?- Kann Collabora wiederum die Nextcloud-Domain erreichen?
- Ist das TLS-Zertifikat gültig?
- Werden die
/cool-WebSockets vom Reverse Proxy korrekt weitergeleitet?- Ist die WOPI-Allow-Liste korrekt?
Für den Container selbst helfen die Logs:
docker logs --tail 100 collabora
Die Nextcloud-Logs sollte man parallel ebenfalls ansehen. Sehr häufig ist es kein Office-Fehler, sondern schlicht eine nicht funktionierende Verbindung in eine der beiden Richtungen.8. Collabora aktualisieren
Da CODE regelmäßig aktualisiert wird, sollte auch der Container nicht jahrelang unangetastet bleiben:
docker pull collabora/code
Anschließend wird der Container mit demselben Startbefehl neu erstellt. Wer stattdessen Docker Compose verwendet, kann das entsprechend mitdocker compose pullunddocker compose up -derledigen.Mein Fazit nach der Überarbeitung
Der Unterschied zu meiner ersten Collabora-Anleitung ist schon ziemlich absurd: Kein Xenial-Proposed, kein Kernel 4.4, kein AUFS-Gefrickel mehr. Für kleine Instanzen reicht heute sogar der eingebaute CODE-Server. Wer es etwas sauberer und performanter möchte, stellt einen separaten Collabora-Container hinter eine eigene HTTPS-Subdomain.Wenn du noch am Anfang mit Nextcloud bist, findest du in Was bietet Nextcloud 2026? einen Überblick darüber, was die Cloud inzwischen alles kann.
Weiterführend: Nextcloud Office installieren, Collabora per Docker und Troubleshooting.
Was bietet Nextcloud 2026? Mehr als nur eine private Cloud | Das Netz und ich
Nextcloud ist längst mehr als Datei-Sync: Files, Kalender, Kontakte, Talk, Office, Fotos, Aufgaben, RSS und viele Apps – ein Überblick für Einsteiger.lars (Das Netz und ich)
Brother MFC-J4625DW unter Linux installieren: Drucker und Scanner einrichten
Überarbeitet am 8. September 2026.
Der Brother MFC-J4625DW ist inzwischen kein neues Gerät mehr, aber genau deshalb wollte ich diese Anleitung nicht einfach löschen. Brother bietet für das Modell auch 2026 noch offizielle Linux-Downloads für DEB- und RPM-Systeme an. Die alte Anleitung war allerdings mit vielen Paketnamen, 32-Bit-Resten und manuellen Schritten ziemlich unübersichtlich geworden.
Ich konzentriere mich hier deshalb auf Debian- und Ubuntu-basierte Systeme. Für Arch Linux beziehungsweise Garuda stellt Brother auf der offiziellen Downloadseite keine eigenen Arch-Pakete bereit.
Table of Contents
Toggle
1. Erst prüfen, ob Linux den Drucker schon erkennt
Bevor ich zusätzliche Treiber installiere, würde ich den Drucker zunächst über USB oder Netzwerk verbinden und prüfen, ob CUPS ihn bereits automatisch findet. Bei manchen Distributionen funktioniert Drucken heute direkt über vorhandene Treiber beziehungsweise treiberlose Druckverfahren.
Wenn Drucken funktioniert, der Scanner aber fehlt, muss nicht zwangsläufig das komplette Brother-Paket neu installiert werden.
2. Offizielle Brother-Downloadseite verwenden
Brother führt für den MFC-J4625DW weiterhin Linux (deb) und Linux (rpm) als Betriebssysteme. Für Debian, Ubuntu, Linux Mint und ähnliche Systeme ist die DEB-Variante normalerweise die passende Wahl.
Am bequemsten ist das von Brother angebotene Driver Install Tool. Laut Brother installiert es LPR-, CUPS-Wrapper- und bei Multifunktionsgeräten auch Scanner-Treiber. Das Tool wurde für dieses Modell zuletzt im September 2025 aktualisiert.
Download: Brother Support für den MFC-J4625DW.
3. Driver Install Tool ausführen
Nach dem Download liegt normalerweise eine komprimierte Datei im Download-Ordner. Der genaue Dateiname kann sich mit neuen Versionen ändern. Deshalb verwende ich hier bewusst Platzhalter statt einer fest verdrahteten Versionsnummer.
cd ~/Downloads
gunzip linux-brprinter-installer-*.gz
chmod +x linux-brprinter-installer-*
sudo ./linux-brprinter-installer-* MFC-J4625DW
Die Rückfragen des Installers hängen davon ab, ob der Drucker per USB oder Netzwerk verbunden ist. Bei einem Netzwerkdrucker sollte die IP-Adresse des Geräts bekannt sein beziehungsweise möglichst fest vergeben werden.
4. Prüfen, ob CUPS den Drucker kennt
lpstat -p -d
Wenn der Drucker dort auftaucht, würde ich direkt eine Testseite drucken. Bei Problemen lohnt sich zusätzlich ein Blick in die CUPS-Weboberfläche unter http://localhost:631, sofern sie auf dem System aktiviert ist.
5. Scanner prüfen
Brother bietet für dieses Modell weiterhin einen 64-Bit-DEB-Scannertreiber an. Die aktuelle Supportseite führt dafür brscan4-basierte Pakete.
Nach der Installation kann man zuerst prüfen, ob SANE das Gerät findet:
scanimage -L
Wenn dort ein Scanner erscheint, sollten Programme wie Document Scanner beziehungsweise Simple Scan oder gscan2pdf ebenfalls darauf zugreifen können.
6. Netzwerk-Scanner manuell eintragen
Wird der Drucker über das Netzwerk gefunden, der Scanner aber nicht, kann bei brscan4-Geräten ein manueller Eintrag helfen:
sudo brsaneconfig4 -a name=MFC-J4625DW model=MFC-J4625DW ip=192.168.1.50
Die IP-Adresse musst du natürlich durch die Adresse deines Druckers ersetzen. Danach erneut testen:
scanimage -L
7. Scan-Key-Funktion ist ein eigenes Paket
Wer direkt am Brother-Gerät die Taste „Scan to PC“ verwenden möchte, benötigt zusätzlich das Scan-Key-Tool. Interessanterweise stellt Brother dafür auch 2026 noch aktualisierte Linux-Pakete bereit. Für reines Scannen aus einer Linux-Anwendung ist dieses Zusatzpaket nicht zwingend nötig.
Und unter Arch Linux oder Garuda?
Brother selbst bietet für dieses Modell offiziell DEB- und RPM-Pakete an, aber keine nativen Arch-Pakete. Unter Arch/Garuda würde ich deshalb zuerst prüfen, ob Drucken über CUPS beziehungsweise treiberlos funktioniert. Für Herstellertreiber gibt es teilweise Community-/AUR-Pakete, deren Aktualität aber separat geprüft werden sollte.
Mein Fazit
Der MFC-J4625DW ist alt, aber unter Linux keineswegs unbrauchbar. Dass Brother selbst 2026 noch das Driver Install Tool, Scanner-Pakete und sogar ein aktualisiertes Scan-Key-Tool anbietet, ist für so ein älteres Multifunktionsgerät ziemlich angenehm. Ich würde heute nur nicht mehr jedes einzelne Paket manuell zusammensuchen, sondern zuerst den offiziellen Installer verwenden und danach gezielt den Scanner prüfen.
Nextcloud Desktop und getaktete Verbindung: Synchronisierung 2026 weiterhin beachten
Überarbeitet am 8. September 2026.
Manchmal überlebt ein alter Blogartikel erstaunlich lange. Diesen hier hatte ich ursprünglich 2020 geschrieben, weil der Nextcloud-Desktop-Client eine getaktete Verbindung unter Windows nicht automatisch berücksichtigt. Ich hätte ehrlich gesagt erwartet, dass das Thema inzwischen erledigt ist.
Ist es aber nicht. Das zugehörige GitHub-Issue #39 „Stop Sync on mobile connection“ stammt aus November 2017 und ist im September 2026 weiterhin offen. Es ist als bestätigtes Thema markiert, steht laut Projekt aber derzeit nicht auf der Roadmap.
Table of Contents
Toggle
Warum das überhaupt wichtig ist
Wer den Laptop unterwegs über den Smartphone-Hotspot ins Internet bringt, möchte normalerweise nicht, dass im Hintergrund plötzlich mehrere Gigabyte Nextcloud-Daten synchronisiert werden.
Windows kann WLAN-Verbindungen selbst als getaktete Verbindung kennzeichnen. Viele Programme reduzieren dann automatisch ihren Datenverkehr. Der Nextcloud-Desktop-Client nutzt diese Information bislang aber nicht zuverlässig als automatische Sync-Sperre.
Vor dem Hotspot: Synchronisierung pausieren
Die einfachste Lösung ist deshalb weiterhin ziemlich banal: Bevor ich mich mit einem mobilen Hotspot verbinde, pausiere ich die Nextcloud-Synchronisierung manuell.
Nach dem Wechsel zurück ins normale WLAN oder LAN kann die Synchronisierung wieder aktiviert werden.
Windows-Verbindung trotzdem als getaktet markieren
Auch wenn Nextcloud selbst die Einstellung nicht automatisch auswertet, würde ich einen Smartphone-Hotspot unter Windows trotzdem als getaktet konfigurieren. Andere Windows-Dienste und Programme können dadurch ihren Hintergrundverkehr reduzieren.
Große Ordner bewusst auswählen
Wer häufig mobil arbeitet, sollte außerdem überlegen, ob wirklich die komplette Nextcloud lokal synchronisiert werden muss. Große Foto-, Video- oder Backup-Verzeichnisse brauche ich unterwegs normalerweise nicht ständig auf dem Notebook.
Eine schlankere Synchronisationsauswahl reduziert nicht nur mobilen Datenverbrauch, sondern spart auch lokalen Speicherplatz.
Ein überraschend langlebiges Feature-Request
Dass dieses Thema nach so vielen Jahren noch offen ist, hätte ich beim Schreiben der ursprünglichen Version wirklich nicht erwartet. Wer die Funktion ebenfalls vermisst, kann den aktuellen Stand im GitHub-Issue verfolgen.
Mehr rund um meine eigene Cloud findest du auch in Was bietet Nextcloud 2026? und in meiner Anleitung Nextcloud richtig absichern.
Aktueller Stand des Feature-Requests: Nextcloud Desktop Issue #39.
Stop Sync on mobile connection · Issue #39 · nextcloud/desktop
Hi everyone, I am using the windows desktop client with several nextcloud instances so there is a lot of synching going on. At the same time I'm on the move a lot and use a mobile connection to sta...goddib (GitHub)
Was bietet Nextcloud 2026? Mehr als nur eine private Cloud
Überarbeitet am 8. September 2026.Als ich Nextcloud vor Jahren zum ersten Mal installiert habe, war mein Hauptgedanke ziemlich simpel: Ich wollte meine Dateien nicht bei Google Drive oder einem anderen großen Cloud-Anbieter ablegen. Inzwischen ist daraus deutlich mehr geworden. Nextcloud ist heute eher ein kompletter digitaler Arbeitsplatz, den man auf dem eigenen Server betreiben kann.
Das Schöne daran: Man muss nicht alle Funktionen benutzen. Wer nur Dateien synchronisieren möchte, kann genau das tun. Wer später Kalender, Kontakte, Videochat, Office oder einen RSS-Reader ergänzen möchte, installiert die passenden Apps dazu.
Table of Contents
ToggleDateien synchronisieren und teilen
Der Kern von Nextcloud ist weiterhin Nextcloud Files. Dateien können über den Browser, Desktop-Clients und die Apps für Smartphones erreicht und synchronisiert werden. Damit bekommt man im Alltag etwas Ähnliches wie Dropbox, OneDrive oder Google Drive – nur eben auf dem eigenen Server oder bei einem selbst gewählten Anbieter.Dateien und Ordner lassen sich außerdem per Link teilen. Solche Freigaben können je nach Bedarf mit Passwort, Ablaufdatum und weiteren Einschränkungen versehen werden. Auch Freigaben zwischen Nextcloud-Servern sind möglich.
Kalender und Kontakte
Kalender und Kontakte gehören für mich zu den Funktionen, die eine eigene Cloud erst richtig nützlich machen. Nextcloud verwendet dafür offene Standards wie CalDAV und CardDAV. Dadurch lassen sich Kalender und Adressbücher mit vielen Programmen und Betriebssystemen synchronisieren.Damit liegt nicht nur die Dateiablage auf dem eigenen Server, sondern auf Wunsch auch das persönliche Adressbuch und der Kalender.
Nextcloud Talk für Chat und Videotelefonie
Mit Nextcloud Talk gibt es Chats, Sprach- und Videoanrufe direkt innerhalb der eigenen Nextcloud. Das funktioniert im Browser und über mobile Apps. Gerade für kleine Teams, Familien oder Vereine ist das interessant, weil Dateien und Gespräche nicht auf mehrere Plattformen verteilt werden müssen.Dokumente direkt im Browser bearbeiten
Auch Office gehört inzwischen fest zum Nextcloud-Ökosystem. Dokumente, Tabellen und Präsentationen können direkt im Browser bearbeitet und gemeinsam genutzt werden. Welche Office-Lösung zum Einsatz kommt, hängt von der eigenen Installation ab.Für mich ist genau das einer der Punkte, an denen Nextcloud über eine reine Dateiablage hinausgeht: Eine Datei muss nicht erst heruntergeladen, lokal bearbeitet und anschließend wieder hochgeladen werden.
Fotos und Videos
Fotos vom Smartphone können automatisch zur Nextcloud hochgeladen werden. Für die Anzeige gibt es die integrierten Funktionen von Nextcloud sowie zusätzliche Apps aus dem App Store. Gerade bei großen Fotosammlungen lohnt es sich, unterschiedliche Lösungen auszuprobieren, weil die Anforderungen sehr verschieden sein können.Notizen, Aufgaben, Projekte und RSS
Der Nextcloud App Store ist für mich einer der größten Vorteile. Dort findet man Erweiterungen für sehr unterschiedliche Einsatzzwecke. Beispiele sind:
- Notes für einfache Notizen
- Tasks für Aufgaben
- Deck für Kanban-Boards und Projektplanung
- News als RSS-Feedreader
- Mail für E-Mail
- Bookmarks für Lesezeichen
- External Storage für zusätzliche Speicherziele
Man sollte trotzdem nicht jeden Fund aus dem App Store installieren. Weniger ist bei einer produktiven Nextcloud oft mehr. Ich schaue vorher, ob eine App aktiv gepflegt wird und zur verwendeten Nextcloud-Version passt.
Versionierung und Papierkorb
Nextcloud kann ältere Dateiversionen aufbewahren und gelöschte Dateien zunächst im Papierkorb behalten. Das ersetzt natürlich kein richtiges Backup, ist im Alltag aber enorm praktisch. Eine Datei versehentlich überschrieben oder gelöscht? Oft lässt sie sich mit wenigen Klicks zurückholen.Nextcloud ist keine automatische Datensicherung
Das ist ein Punkt, den ich heute deutlicher schreiben würde als früher: Nur weil Dateien in Nextcloud liegen, sind sie noch nicht automatisch sicher. Wird der Server beschädigt, verschlüsselt oder versehentlich gelöscht, kann auch die Cloud weg sein.Zu einer selbst gehosteten Nextcloud gehört deshalb ein externes Backup der Daten, der Datenbank und der Konfiguration. Wer die Cloud selbst betreibt, bekommt Kontrolle – übernimmt dafür aber eben auch Verantwortung.
Datenschutz und Kontrolle als größter Vorteil
Der für mich wichtigste Unterschied zu vielen klassischen Cloud-Diensten ist bis heute derselbe: Ich entscheide, wo die Daten liegen. Bei einem eigenen Server kenne ich den Speicherort, kann Backups selbst organisieren und bestimme, welche Erweiterungen installiert werden.Natürlich bedeutet das auch Arbeit. Updates, Backups und Sicherheit gehören dazu. Wer damit gar nichts zu tun haben möchte, kann Nextcloud auch bei einem Anbieter mieten und muss den Server nicht selbst administrieren.
Für wen lohnt sich Nextcloud?
Nextcloud lohnt sich aus meiner Sicht besonders für Leute, die ihre Daten nicht auf mehrere Dienste verteilen möchten. Dateien bei Anbieter A, Kalender bei B, Kontakte bei C und Videotelefonie bei D – das kann Nextcloud zumindest teilweise unter einem Dach zusammenführen.Man muss dafür kein Unternehmen sein. Auch für eine einzelne Person oder eine Familie kann eine kleine Nextcloud sinnvoll sein. Und wer Spaß am Selfhosting hat, findet im App-Ökosystem ziemlich schnell das nächste Projekt.
Wenn du Nextcloud selbst betreibst, solltest du dir auch meinen aktualisierten Beitrag Nextcloud richtig absichern ansehen.
Mehr Informationen gibt es direkt bei Nextcloud und im Nextcloud App Store.
All apps - App Store - Nextcloud
The Nextcloud App Store - Upload your apps and install new apps onto your Nextcloudapps.nextcloud.com
Nextcloud News 2026: RSS-Feeds synchronisieren und passende Clients nutzen
Überarbeitet am 8. September 2026.
RSS gehört für mich immer noch zu den angenehmsten Wegen, Nachrichten und Blogs zu verfolgen. Keine fünfzig einzelnen Apps, keine algorithmische Timeline – ich entscheide selbst, welche Quellen ich lesen möchte.
Wenn sowieso eine eigene Nextcloud läuft, liegt es nahe, die Feed-Abos dort zentral zu speichern. Genau dafür gibt es die App Nextcloud News. Die wird auch 2026 aktiv gepflegt und bietet neben der Weboberfläche eine API, über die externe Reader die Feeds, gelesenen Artikel und Markierungen synchronisieren können.
Wer noch einen allgemeinen Überblick über die Möglichkeiten der Plattform sucht: Was bietet Nextcloud 2026?
Table of Contents
Toggle
Nextcloud News installieren
Die App lässt sich direkt über den Nextcloud App Store installieren. Danach erscheint News in der App-Leiste und Feeds können über ihre RSS- oder Atom-Adresse hinzugefügt werden.
Die eigentliche Stärke ist für mich aber die Synchronisierung mit externen Readern. Dadurch bleibt Nextcloud die zentrale Datenbasis, während ich auf jedem Gerät die Oberfläche nutzen kann, die mir am besten gefällt.
Desktop: RSS Guard
Für Windows, Linux und macOS ist RSS Guard weiterhin eine der interessantesten Optionen. Die offizielle Nextcloud-News-Dokumentation führt RSS Guard als empfohlenen Desktop-Client.
Damit bekommt man einen klassischen Desktop-Feedreader, während gelesene Artikel und Abos mit Nextcloud News synchronisiert werden.
iPhone und Mac: Fiery Feeds
Mein alter Artikel drehte sich fast ausschließlich um Fiery Feeds. Die App existiert weiterhin und wird auch in der aktuellen Client-Liste von Nextcloud News für iOS und macOS aufgeführt.
Ich würde den Artikel heute aber nicht mehr auf genau eine App reduzieren. Der große Vorteil von Nextcloud News ist ja gerade, dass der Server unabhängig vom verwendeten Reader bleibt.
Android: Nextcloud News Reader und Readrops
Unter Android ist die Auswahl größer. Die Nextcloud-News-Dokumentation empfiehlt den Nextcloud News Reader und führt zusätzlich Readrops als kompatiblen Sync-Client auf.
Linux-Terminal: Newsboat
Wer viel im Terminal arbeitet, kann sogar Newsboat verwenden. Auch dieser Client wird von der Nextcloud-News-Dokumentation gelistet. Das ist vielleicht etwas nerdiger, aber genau solche Möglichkeiten mag ich an offenen Schnittstellen.
Weitere Desktop-Clients
Neben RSS Guard nennt die aktuelle Dokumentation unter anderem Fluent Reader, Communique und NewsFlash. Wichtig ist immer, dass der Client ausdrücklich die Nextcloud-News-API unterstützt – ein beliebiger RSS-Reader kann nicht automatisch mit der eigenen Nextcloud synchronisieren.
Warum überhaupt über Nextcloud synchronisieren?
- Feed-Abos liegen zentral auf dem eigenen Server.
- Gelesen/Ungelesen wird zwischen Geräten synchronisiert.
- Markierte Artikel bleiben überall gleich.
- Man kann den Client wechseln, ohne die komplette Feed-Sammlung neu aufzubauen.
- Die Feeds lassen sich direkt im Browser lesen, wenn gerade kein Client vorhanden ist.
Updates der Feeds müssen zuverlässig laufen
Nextcloud News aktualisiert Feeds im Hintergrund. Damit das zuverlässig funktioniert, sollte eine produktive Nextcloud generell mit echten Cronjobs betrieben werden und nicht nur auf AJAX-Aufrufe im Browser angewiesen sein.
Wenn sehr viele Feeds hinzukommen, lohnt es sich außerdem, die Datenbank- und Cache-Konfiguration im Blick zu behalten. Dazu passt meine Anleitung Nextcloud mit Redis und APCu beschleunigen.
Mein Fazit
Meine Empfehlung ist heute weniger „nimm genau diesen einen Reader“ als früher. Ich würde Nextcloud News als zentrale Basis verwenden und anschließend pro Gerät den Client auswählen, der am besten passt. Genau dafür ist die offene API gedacht.
Aktuelle kompatible Programme findest du in der offiziellen Client-Liste von Nextcloud News.
Was bietet Nextcloud 2026? Mehr als nur eine private Cloud
Überarbeitet am 8. September 2026.Als ich Nextcloud vor Jahren zum ersten Mal installiert habe, war mein Hauptgedanke ziemlich simpel: Ich wollte meine Dateien nicht bei Google Drive oder einem anderen großen Cloud-Anbieter ablegen. Inzwischen ist daraus deutlich mehr geworden. Nextcloud ist heute eher ein kompletter digitaler Arbeitsplatz, den man auf dem eigenen Server betreiben kann.
Das Schöne daran: Man muss nicht alle Funktionen benutzen. Wer nur Dateien synchronisieren möchte, kann genau das tun. Wer später Kalender, Kontakte, Videochat, Office oder einen RSS-Reader ergänzen möchte, installiert die passenden Apps dazu.
Table of Contents
ToggleDateien synchronisieren und teilen
Der Kern von Nextcloud ist weiterhin Nextcloud Files. Dateien können über den Browser, Desktop-Clients und die Apps für Smartphones erreicht und synchronisiert werden. Damit bekommt man im Alltag etwas Ähnliches wie Dropbox, OneDrive oder Google Drive – nur eben auf dem eigenen Server oder bei einem selbst gewählten Anbieter.Dateien und Ordner lassen sich außerdem per Link teilen. Solche Freigaben können je nach Bedarf mit Passwort, Ablaufdatum und weiteren Einschränkungen versehen werden. Auch Freigaben zwischen Nextcloud-Servern sind möglich.
Kalender und Kontakte
Kalender und Kontakte gehören für mich zu den Funktionen, die eine eigene Cloud erst richtig nützlich machen. Nextcloud verwendet dafür offene Standards wie CalDAV und CardDAV. Dadurch lassen sich Kalender und Adressbücher mit vielen Programmen und Betriebssystemen synchronisieren.Damit liegt nicht nur die Dateiablage auf dem eigenen Server, sondern auf Wunsch auch das persönliche Adressbuch und der Kalender.
Nextcloud Talk für Chat und Videotelefonie
Mit Nextcloud Talk gibt es Chats, Sprach- und Videoanrufe direkt innerhalb der eigenen Nextcloud. Das funktioniert im Browser und über mobile Apps. Gerade für kleine Teams, Familien oder Vereine ist das interessant, weil Dateien und Gespräche nicht auf mehrere Plattformen verteilt werden müssen.Dokumente direkt im Browser bearbeiten
Auch Office gehört inzwischen fest zum Nextcloud-Ökosystem. Dokumente, Tabellen und Präsentationen können direkt im Browser bearbeitet und gemeinsam genutzt werden. Welche Office-Lösung zum Einsatz kommt, hängt von der eigenen Installation ab.Für mich ist genau das einer der Punkte, an denen Nextcloud über eine reine Dateiablage hinausgeht: Eine Datei muss nicht erst heruntergeladen, lokal bearbeitet und anschließend wieder hochgeladen werden.
Fotos und Videos
Fotos vom Smartphone können automatisch zur Nextcloud hochgeladen werden. Für die Anzeige gibt es die integrierten Funktionen von Nextcloud sowie zusätzliche Apps aus dem App Store. Gerade bei großen Fotosammlungen lohnt es sich, unterschiedliche Lösungen auszuprobieren, weil die Anforderungen sehr verschieden sein können.Notizen, Aufgaben, Projekte und RSS
Der Nextcloud App Store ist für mich einer der größten Vorteile. Dort findet man Erweiterungen für sehr unterschiedliche Einsatzzwecke. Beispiele sind:
- Notes für einfache Notizen
- Tasks für Aufgaben
- Deck für Kanban-Boards und Projektplanung
- News als RSS-Feedreader
- Mail für E-Mail
- Bookmarks für Lesezeichen
- External Storage für zusätzliche Speicherziele
Man sollte trotzdem nicht jeden Fund aus dem App Store installieren. Weniger ist bei einer produktiven Nextcloud oft mehr. Ich schaue vorher, ob eine App aktiv gepflegt wird und zur verwendeten Nextcloud-Version passt.
Versionierung und Papierkorb
Nextcloud kann ältere Dateiversionen aufbewahren und gelöschte Dateien zunächst im Papierkorb behalten. Das ersetzt natürlich kein richtiges Backup, ist im Alltag aber enorm praktisch. Eine Datei versehentlich überschrieben oder gelöscht? Oft lässt sie sich mit wenigen Klicks zurückholen.Nextcloud ist keine automatische Datensicherung
Das ist ein Punkt, den ich heute deutlicher schreiben würde als früher: Nur weil Dateien in Nextcloud liegen, sind sie noch nicht automatisch sicher. Wird der Server beschädigt, verschlüsselt oder versehentlich gelöscht, kann auch die Cloud weg sein.Zu einer selbst gehosteten Nextcloud gehört deshalb ein externes Backup der Daten, der Datenbank und der Konfiguration. Wer die Cloud selbst betreibt, bekommt Kontrolle – übernimmt dafür aber eben auch Verantwortung.
Datenschutz und Kontrolle als größter Vorteil
Der für mich wichtigste Unterschied zu vielen klassischen Cloud-Diensten ist bis heute derselbe: Ich entscheide, wo die Daten liegen. Bei einem eigenen Server kenne ich den Speicherort, kann Backups selbst organisieren und bestimme, welche Erweiterungen installiert werden.Natürlich bedeutet das auch Arbeit. Updates, Backups und Sicherheit gehören dazu. Wer damit gar nichts zu tun haben möchte, kann Nextcloud auch bei einem Anbieter mieten und muss den Server nicht selbst administrieren.
Für wen lohnt sich Nextcloud?
Nextcloud lohnt sich aus meiner Sicht besonders für Leute, die ihre Daten nicht auf mehrere Dienste verteilen möchten. Dateien bei Anbieter A, Kalender bei B, Kontakte bei C und Videotelefonie bei D – das kann Nextcloud zumindest teilweise unter einem Dach zusammenführen.Man muss dafür kein Unternehmen sein. Auch für eine einzelne Person oder eine Familie kann eine kleine Nextcloud sinnvoll sein. Und wer Spaß am Selfhosting hat, findet im App-Ökosystem ziemlich schnell das nächste Projekt.
Wenn du Nextcloud selbst betreibst, solltest du dir auch meinen aktualisierten Beitrag Nextcloud richtig absichern ansehen.
Mehr Informationen gibt es direkt bei Nextcloud und im Nextcloud App Store.
All apps - App Store - Nextcloud
The Nextcloud App Store - Upload your apps and install new apps onto your Nextcloudapps.nextcloud.com
Was bietet Nextcloud 2026? Mehr als nur eine private Cloud
Überarbeitet am 8. September 2026.
Als ich Nextcloud vor Jahren zum ersten Mal installiert habe, war mein Hauptgedanke ziemlich simpel: Ich wollte meine Dateien nicht bei Google Drive oder einem anderen großen Cloud-Anbieter ablegen. Inzwischen ist daraus deutlich mehr geworden. Nextcloud ist heute eher ein kompletter digitaler Arbeitsplatz, den man auf dem eigenen Server betreiben kann.
Das Schöne daran: Man muss nicht alle Funktionen benutzen. Wer nur Dateien synchronisieren möchte, kann genau das tun. Wer später Kalender, Kontakte, Videochat, Office oder einen RSS-Reader ergänzen möchte, installiert die passenden Apps dazu.
Table of Contents
Toggle
Dateien synchronisieren und teilen
Der Kern von Nextcloud ist weiterhin Nextcloud Files. Dateien können über den Browser, Desktop-Clients und die Apps für Smartphones erreicht und synchronisiert werden. Damit bekommt man im Alltag etwas Ähnliches wie Dropbox, OneDrive oder Google Drive – nur eben auf dem eigenen Server oder bei einem selbst gewählten Anbieter.
Dateien und Ordner lassen sich außerdem per Link teilen. Solche Freigaben können je nach Bedarf mit Passwort, Ablaufdatum und weiteren Einschränkungen versehen werden. Auch Freigaben zwischen Nextcloud-Servern sind möglich.
Kalender und Kontakte
Kalender und Kontakte gehören für mich zu den Funktionen, die eine eigene Cloud erst richtig nützlich machen. Nextcloud verwendet dafür offene Standards wie CalDAV und CardDAV. Dadurch lassen sich Kalender und Adressbücher mit vielen Programmen und Betriebssystemen synchronisieren.
Damit liegt nicht nur die Dateiablage auf dem eigenen Server, sondern auf Wunsch auch das persönliche Adressbuch und der Kalender.
Nextcloud Talk für Chat und Videotelefonie
Mit Nextcloud Talk gibt es Chats, Sprach- und Videoanrufe direkt innerhalb der eigenen Nextcloud. Das funktioniert im Browser und über mobile Apps. Gerade für kleine Teams, Familien oder Vereine ist das interessant, weil Dateien und Gespräche nicht auf mehrere Plattformen verteilt werden müssen.
Dokumente direkt im Browser bearbeiten
Auch Office gehört inzwischen fest zum Nextcloud-Ökosystem. Dokumente, Tabellen und Präsentationen können direkt im Browser bearbeitet und gemeinsam genutzt werden. Welche Office-Lösung zum Einsatz kommt, hängt von der eigenen Installation ab.
Für mich ist genau das einer der Punkte, an denen Nextcloud über eine reine Dateiablage hinausgeht: Eine Datei muss nicht erst heruntergeladen, lokal bearbeitet und anschließend wieder hochgeladen werden.
Fotos und Videos
Fotos vom Smartphone können automatisch zur Nextcloud hochgeladen werden. Für die Anzeige gibt es die integrierten Funktionen von Nextcloud sowie zusätzliche Apps aus dem App Store. Gerade bei großen Fotosammlungen lohnt es sich, unterschiedliche Lösungen auszuprobieren, weil die Anforderungen sehr verschieden sein können.
Notizen, Aufgaben, Projekte und RSS
Der Nextcloud App Store ist für mich einer der größten Vorteile. Dort findet man Erweiterungen für sehr unterschiedliche Einsatzzwecke. Beispiele sind:
- Notes für einfache Notizen
- Tasks für Aufgaben
- Deck für Kanban-Boards und Projektplanung
- News als RSS-Feedreader
- Mail für E-Mail
- Bookmarks für Lesezeichen
- External Storage für zusätzliche Speicherziele
Man sollte trotzdem nicht jeden Fund aus dem App Store installieren. Weniger ist bei einer produktiven Nextcloud oft mehr. Ich schaue vorher, ob eine App aktiv gepflegt wird und zur verwendeten Nextcloud-Version passt.
Versionierung und Papierkorb
Nextcloud kann ältere Dateiversionen aufbewahren und gelöschte Dateien zunächst im Papierkorb behalten. Das ersetzt natürlich kein richtiges Backup, ist im Alltag aber enorm praktisch. Eine Datei versehentlich überschrieben oder gelöscht? Oft lässt sie sich mit wenigen Klicks zurückholen.
Nextcloud ist keine automatische Datensicherung
Das ist ein Punkt, den ich heute deutlicher schreiben würde als früher: Nur weil Dateien in Nextcloud liegen, sind sie noch nicht automatisch sicher. Wird der Server beschädigt, verschlüsselt oder versehentlich gelöscht, kann auch die Cloud weg sein.
Zu einer selbst gehosteten Nextcloud gehört deshalb ein externes Backup der Daten, der Datenbank und der Konfiguration. Wer die Cloud selbst betreibt, bekommt Kontrolle – übernimmt dafür aber eben auch Verantwortung.
Datenschutz und Kontrolle als größter Vorteil
Der für mich wichtigste Unterschied zu vielen klassischen Cloud-Diensten ist bis heute derselbe: Ich entscheide, wo die Daten liegen. Bei einem eigenen Server kenne ich den Speicherort, kann Backups selbst organisieren und bestimme, welche Erweiterungen installiert werden.
Natürlich bedeutet das auch Arbeit. Updates, Backups und Sicherheit gehören dazu. Wer damit gar nichts zu tun haben möchte, kann Nextcloud auch bei einem Anbieter mieten und muss den Server nicht selbst administrieren.
Für wen lohnt sich Nextcloud?
Nextcloud lohnt sich aus meiner Sicht besonders für Leute, die ihre Daten nicht auf mehrere Dienste verteilen möchten. Dateien bei Anbieter A, Kalender bei B, Kontakte bei C und Videotelefonie bei D – das kann Nextcloud zumindest teilweise unter einem Dach zusammenführen.
Man muss dafür kein Unternehmen sein. Auch für eine einzelne Person oder eine Familie kann eine kleine Nextcloud sinnvoll sein. Und wer Spaß am Selfhosting hat, findet im App-Ökosystem ziemlich schnell das nächste Projekt.
Wenn du Nextcloud selbst betreibst, solltest du dir auch meinen aktualisierten Beitrag Nextcloud richtig absichern ansehen.
Mehr Informationen gibt es direkt bei Nextcloud und im Nextcloud App Store.
All apps - App Store - Nextcloud
The Nextcloud App Store - Upload your apps and install new apps onto your Nextcloudapps.nextcloud.com
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung:includeSubDomainssolltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind
trusted_proxiesund die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus demnextcloud.logerkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen
nextcloud.logkorrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie/var/www.Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der
config.phpändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud solltedebugnicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
Nextcloud Office mit Collabora einrichten: Docker, Reverse Proxy und Tests
Überarbeitet am 8. September 2026.
Diese Anleitung ist einer der Artikel, bei denen das Alter besonders deutlich geworden ist. Meine ursprüngliche Version brauchte noch einen speziellen Ubuntu-16.04-Kernel und hantierte mit AUFS. Das ist heute Geschichte. Nextcloud Office basiert weiterhin auf Collabora Online beziehungsweise CODE, lässt sich aber inzwischen wesentlich entspannter einrichten.
Für kleine private Installationen gibt es sogar einen eingebauten CODE-Server. Wer etwas mehr Leistung möchte, betreibt Collabora separat – zum Beispiel als Docker-Container hinter einem Reverse Proxy. Genau diesen Weg zeige ich hier.
Falls Docker auf deinem Server noch fehlt, findest du hier meine aktualisierte Anleitung: Docker und Docker Compose unter Debian und Ubuntu installieren.
Table of Contents
Toggle
Was ist Nextcloud Office eigentlich?
Nextcloud Office ist die Office-Integration innerhalb von Nextcloud. Die eigentliche Bearbeitung übernimmt Collabora Online. Damit lassen sich unter anderem DOCX-, XLSX-, PPTX- und OpenDocument-Dateien direkt im Browser öffnen und gemeinsam bearbeiten.
Wenn du erstmal nur ausprobieren möchtest, ob dir das gefällt, reicht für eine kleine Installation oft der Built-in CODE Server. Er lässt sich als Nextcloud-App installieren und funktioniert in vielen Setups ohne zusätzlichen Container. Nextcloud weist allerdings selbst darauf hin, dass ein separater Collabora-Server für bessere Performance sinnvoller ist.
1. Eigene Subdomain für Collabora vorbereiten
Für einen separaten Collabora-Server würde ich eine eigene Subdomain verwenden, zum Beispiel:
office.example.deCode-Sprache: CSS (css)
Die Subdomain zeigt auf deinen Server und bekommt ein gültiges TLS-Zertifikat. Auch deine Nextcloud sollte natürlich über HTTPS erreichbar sein. Nextcloud und Collabora sollten dasselbe Protokoll verwenden – praktisch also beide HTTPS.
Mehr zu den grundlegenden Sicherheitsmaßnahmen findest du in Nextcloud richtig absichern.
2. Collabora CODE als Docker-Container starten
Das offizielle CODE-Image heißt weiterhin collabora/code. Zuerst laden wir es:
docker pull collabora/code
Danach starten wir Collabora nur auf localhost. So ist Port 9980 nicht direkt aus dem Internet erreichbar:
docker run -t -d \
-p 127.0.0.1:9980:9980 \
-e 'aliasgroup1=https://cloud.example.de:443' \
--restart always \
--cap-add MKNOD \
--name collabora \
collabora/codeCode-Sprache: JavaScript (javascript)cloud.example.de ersetzt du durch die Domain deiner Nextcloud. Der Container lauscht anschließend nur auf 127.0.0.1:9980. Von außen kommt man später ausschließlich über den Reverse Proxy an Collabora heran.
3. Reverse Proxy vor Collabora setzen
Collabora benötigt einen Reverse Proxy, der die öffentliche Adresse https://office.example.de auf den lokalen Dienst an Port 9980 weiterleitet. Anders als in sehr alten Anleitungen heißen die wichtigen Pfade heute unter anderem:
/browser/hosting/discovery/hosting/capabilities/cool- WebSocket-Verbindungen unter
/cool/.../ws
Wer noch eine alte Konfiguration mit /lool und /loleaflet hat, sollte sie deshalb überprüfen. Die aktuellen Collabora-Komponenten verwenden coolwsd, /cool und /browser.
Da ich selbst Nginx nutze, würde ich dafür die aktuelle Reverse-Proxy-Vorlage von Collabora beziehungsweise Nextcloud als Ausgangspunkt nehmen. Besonders wichtig ist, dass die WebSocket-Verbindung mit durchgereicht wird. Eine reine normale HTTP-Weiterleitung reicht nicht.
4. Erst Collabora testen
Bevor ich Nextcloud konfiguriere, teste ich den Office-Server separat. Diese beiden Adressen sollten über den Browser erreichbar sein:
office.example.de/hosting/capa…
office.example.de/hosting/disc… JavaScript (javascript)
Auch direkt vom Nextcloud-Server aus kann man testen:
curl office.example.de/hosting/capa…
curl office.example.de/hosting/disc… JavaScript (javascript)
Wenn das schon nicht funktioniert, braucht man in Nextcloud noch gar nicht weiterzusuchen. Dann liegt das Problem eher bei DNS, Zertifikat, Firewall oder Reverse Proxy.
5. Nextcloud Office installieren und verbinden
In Nextcloud gehst du zu Apps → Office & Text und installierst beziehungsweise aktivierst Nextcloud Office.
Anschließend findest du unter Administrationseinstellungen → Office die Verbindung zum Collabora-Server. Dort trägst du ein:
office.example.deCode-Sprache: JavaScript (javascript)
Wenn alles stimmt, sollte Nextcloud die Verbindung erkennen. Danach kannst du direkt eine neue Textdatei oder Tabelle erstellen und testen.
6. WOPI-Zugriffe einschränken
Ein Punkt, den es in meiner alten Anleitung noch gar nicht gab: Nextcloud empfiehlt ausdrücklich, WOPI-Anfragen auf die erwarteten Collabora-Server zu begrenzen. Die entsprechende Allow-Liste findest du in den Office-Administrationseinstellungen.
Dort sollte möglichst nur die IP beziehungsweise das Netz eingetragen werden, aus dem dein Collabora-Server Nextcloud tatsächlich erreicht. Das verhindert, dass beliebige andere Systeme WOPI-Anfragen an deine Nextcloud stellen können.
7. Typische Fehler
Wenn Nextcloud Office nicht verbindet, prüfe ich in dieser Reihenfolge:
- Kann der Browser Nextcloud und Collabora über HTTPS erreichen?
- Kann Nextcloud
office.example.deerreichen? - Kann Collabora wiederum die Nextcloud-Domain erreichen?
- Ist das TLS-Zertifikat gültig?
- Werden die
/cool-WebSockets vom Reverse Proxy korrekt weitergeleitet? - Ist die WOPI-Allow-Liste korrekt?
Für den Container selbst helfen die Logs:
docker logs --tail 100 collabora
Die Nextcloud-Logs sollte man parallel ebenfalls ansehen. Sehr häufig ist es kein Office-Fehler, sondern schlicht eine nicht funktionierende Verbindung in eine der beiden Richtungen.
8. Collabora aktualisieren
Da CODE regelmäßig aktualisiert wird, sollte auch der Container nicht jahrelang unangetastet bleiben:
docker pull collabora/code
Anschließend wird der Container mit demselben Startbefehl neu erstellt. Wer stattdessen Docker Compose verwendet, kann das entsprechend mit docker compose pull und docker compose up -d erledigen.
Mein Fazit nach der Überarbeitung
Der Unterschied zu meiner ersten Collabora-Anleitung ist schon ziemlich absurd: Kein Xenial-Proposed, kein Kernel 4.4, kein AUFS-Gefrickel mehr. Für kleine Instanzen reicht heute sogar der eingebaute CODE-Server. Wer es etwas sauberer und performanter möchte, stellt einen separaten Collabora-Container hinter eine eigene HTTPS-Subdomain.
Wenn du noch am Anfang mit Nextcloud bist, findest du in Was bietet Nextcloud 2026? einen Überblick darüber, was die Cloud inzwischen alles kann.
Weiterführend: Nextcloud Office installieren, Collabora per Docker und Troubleshooting.
Was bietet Nextcloud 2026? Mehr als nur eine private Cloud | Das Netz und ich
Nextcloud ist längst mehr als Datei-Sync: Files, Kalender, Kontakte, Talk, Office, Fotos, Aufgaben, RSS und viele Apps – ein Überblick für Einsteiger.lars (Das Netz und ich)
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung:includeSubDomainssolltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind
trusted_proxiesund die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus demnextcloud.logerkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen
nextcloud.logkorrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie/var/www.Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der
config.phpändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud solltedebugnicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
Gesichtserkennung in Nextcloud: Face Recognition 2026 einrichten und testen
Überarbeitet am 8. September 2026.
Gesichter direkt auf dem eigenen Nextcloud-Server erkennen lassen – genau das fand ich an der Face-Recognition-App schon vor Jahren spannend. Meine alte Anleitung dazu war allerdings inzwischen kaum noch brauchbar: PHP 7.3, dlib und pdlib von Hand kompilieren, mehrere Gigabyte PHP-Memory-Limit und ein Hintergrundjob per disown.
Die App gibt es weiterhin und sie wird sogar noch entwickelt. Der Aufbau hat sich aber deutlich verändert. Deshalb geht es hier nicht mehr darum, irgendwelche uralten Build-Befehle zu kopieren, sondern darum, wie Face Recognition heute grundsätzlich eingerichtet und getestet wird.
Wenn du Nextcloud gerade grundsätzlich einrichtest, findest du in Was bietet Nextcloud 2026? einen aktuellen Überblick über die Möglichkeiten der Cloud.
Table of Contents
Toggle
Was macht die Face-Recognition-App?
Face Recognition analysiert Bilder innerhalb der Nextcloud, erkennt Gesichter und gruppiert ähnliche Gesichter zu Personen. Die Verarbeitung läuft auf dem eigenen Server. Die Fotos müssen dafür nicht zu Google, Apple oder einem anderen externen Dienst geschickt werden.
Die gefundenen Personen tauchen unter anderem in den persönlichen Einstellungen, in der Seitenleiste der Dateien-App und in der Fotos-App auf. Dort können Gesichter benannt und zusammengeführt werden.
Stand September 2026: auf die Version achten
Beim Schreiben dieser Aktualisierung gibt es eine Besonderheit: Das Upstream-Projekt dokumentiert mit Version 0.9.94 Unterstützung für Nextcloud 34 und mindestens PHP 8.2. Im offiziellen Nextcloud App Store wird aktuell dagegen noch eine ältere Veröffentlichung mit maximal Nextcloud 31 angezeigt.
Deshalb würde ich vor der Installation immer zuerst die aktuelle Projektversion und deren Anforderungen prüfen. Eine alte App-Version sollte nicht mit Gewalt in eine neuere Nextcloud installiert werden.
Voraussetzungen
Das aktuelle Projekt nennt für die neue Generation unter anderem diese Anforderungen:
- eine unterstützte Nextcloud-Version,
- Dlib-PHP-Bindings beziehungsweise PDlib,
- PHP-Bzip2,
- ausreichend Arbeitsspeicher.
Die Gesichtserkennung ist CPU- und speicherintensiv. Gerade bei zehntausenden Fotos würde ich die Analyse nicht während der Hauptnutzungszeit mit maximaler Parallelität starten.
Warum ich die alten dlib-Build-Befehle entfernt habe
In meiner früheren Anleitung wurde dlib aus GitHub kompiliert und pdlib mit Befehlen wie phpize7.3 gebaut. Das war schon damals empfindlich gegenüber PHP-Versionen und Distributionen.
Heute würde ich zuerst die Installationsdokumentation des Projekts für das eigene Betriebssystem verwenden und – wenn verfügbar – vorkompilierte Pakete bevorzugen. Wer eine abweichende PHP-Version oder ein ungewöhnliches Container-Image verwendet, muss PDlib unter Umständen weiterhin selbst bauen. Das ist aber kein sinnvoller Copy-and-Paste-Schritt für eine allgemeine Nextcloud-Anleitung.
1. App installieren und Voraussetzungen prüfen
Wenn die zu deiner Nextcloud passende App-Version verfügbar ist, installierst und aktivierst du Face Recognition. Danach würde ich zunächst prüfen, ob alle Abhängigkeiten erkannt werden, bevor irgendwelche echten Fotos analysiert werden.
Das Projekt stellt dafür inzwischen einen eigenen Setup-Befehl bereit:
sudo -E -u www-data php /var/www/nextcloud/occ face:setupCode-Sprache: JavaScript (javascript)
Damit werden die grundlegende Konfiguration und das benötigte Erkennungsmodell eingerichtet.
2. Erst mit einem Testbenutzer ausprobieren
Diesen Tipp finde ich aus der aktuellen Projektdokumentation besonders sinnvoll: Nicht sofort die komplette private Fotosammlung loslaufen lassen. Stattdessen zuerst einen Testbenutzer anlegen und ein paar unkritische Testbilder hochladen.
Dann kann die Analyse gezielt für diesen Benutzer gestartet werden:
sudo -E -u www-data php /var/www/nextcloud/occ face:background_job -u TESTBENUTZER -t 900Code-Sprache: JavaScript (javascript)
So sieht man relativ schnell, ob PDlib funktioniert, ob die Modelle geladen werden und ob das Ergebnis für die eigene Installation brauchbar ist.
3. Nutzer müssen die Analyse erlauben
Face Recognition analysiert nicht einfach ungefragt sämtliche Bilder aller Benutzer. In den persönlichen Einstellungen gibt es einen eigenen Bereich für die Gesichtserkennung. Dort kann der Nutzer die Analyse aktivieren und später gefundene Personen verwalten.
Das ist gerade bei einer Mehrbenutzer-Nextcloud wichtig: Gesichtserkennung ist nicht nur ein technisches Feature, sondern verarbeitet biometrisch interessante Informationen. Entsprechend bewusst sollte man die Funktion einsetzen.
4. Hintergrundanalyse sauber planen
Die App ist für einen regelmäßig laufenden Hintergrundjob ausgelegt. Der zentrale Befehl ist heute:
sudo -E -u www-data php /var/www/nextcloud/occ face:background_jobCode-Sprache: JavaScript (javascript)
Auf einem Server mit mehreren CPU-Kernen kann parallel gearbeitet werden:
sudo -E -u www-data php /var/www/nextcloud/occ face:background_job --workers=4Code-Sprache: JavaScript (javascript)
Mehr Worker bedeuten aber auch mehr Speicherverbrauch, weil jeder Worker sein eigenes Modell lädt. Ich würde deshalb klein anfangen und die Last beobachten, statt direkt alle Kerne freizugeben.
5. Fortschritt anzeigen
Statt wie früher anhand irgendwelcher Prozesslisten zu rätseln, gibt es inzwischen einen eigenen Fortschrittsbefehl:
sudo -E -u www-data php /var/www/nextcloud/occ face:progressCode-Sprache: JavaScript (javascript)
Für eine Zusammenfassung von Bildern, Gesichtern und Personen gibt es außerdem:
sudo -E -u www-data php /var/www/nextcloud/occ face:statsCode-Sprache: JavaScript (javascript)
Alben nach Personen synchronisieren
Die App kann erkannte Personen auch mit der Nextcloud-Fotos-App verknüpfen. Dafür existiert inzwischen:
sudo -E -u www-data php /var/www/nextcloud/occ face:sync-albumsCode-Sprache: JavaScript (javascript)
Das ist deutlich näher an dem, was man von modernen Fotoverwaltungen kennt, als die sehr frühe Version der App, über die ich ursprünglich geschrieben hatte.
Serverlast nicht unterschätzen
Gesichtserkennung kann eine Menge Rechenzeit fressen. Besonders der erste Durchlauf über eine große Bildersammlung ist kein Job, den ich ungeplant zur Mittagszeit starten würde. Sinnvoller ist ein Zeitfenster, in dem der Server wenig genutzt wird.
Auch das restliche Nextcloud-Setup sollte sauber laufen. Für das normale Memory Caching habe ich meinen Artikel Nextcloud mit Redis und APCu beschleunigen aktualisiert.
Datenschutz nicht vergessen
Der große Charme dieser Lösung ist für mich weiterhin, dass die Bilder auf der eigenen Nextcloud bleiben. Trotzdem sollte man Gesichtserkennung nicht einfach als gewöhnliches Thumbnail-Plugin betrachten. Wer eine Nextcloud für mehrere Menschen betreibt, sollte transparent machen, dass und wie Gesichtsdaten analysiert werden.
Die allgemeine Absicherung des Servers habe ich hier zusammengefasst: Nextcloud richtig absichern.
Weiterführend: Face Recognition auf GitHub und Face Recognition im Nextcloud App Store.
GitHub - matiasdelellis/facerecognition: Nextcloud app that implement a basic facial recognition system.
Nextcloud app that implement a basic facial recognition system. - matiasdelellis/facerecognitionGitHub
Nextcloud mit Redis und APCu beschleunigen: Caching richtig einrichten
Überarbeitet am 8. September 2026.Redis gehört bei vielen Nextcloud-Installationen inzwischen fast zur Grundausstattung. Früher hatte ich Redis vor allem eingebaut, weil die Galerie und andere Bereiche gefühlt schneller reagieren sollten. Heute würde ich das genauer formulieren: Für den lokalen Cache ist APCu normalerweise die bessere Wahl, Redis spielt seine Stärke vor allem beim verteilten Cache und beim Transactional File Locking aus.
Gerade das File Locking ist wichtig. Ohne Redis kann Nextcloud dafür die Datenbank verwenden, was unnötig Last erzeugt. Bei einer größeren oder stärker genutzten Instanz lohnt sich Redis deshalb sehr schnell.
Wenn du Nextcloud gerade erst aufsetzt, findest du in meinem Beitrag Was bietet Nextcloud 2026? einen Überblick. Für die Absicherung des Servers habe ich außerdem Nextcloud richtig absichern aktualisiert.
Table of Contents
ToggleWas macht APCu und was macht Redis?
APCu ist ein sehr schneller lokaler Cache innerhalb von PHP. Nextcloud empfiehlt ihn fürmemcache.local. Redis eignet sich dagegen besonders fürmemcache.distributedundmemcache.locking.Auf einem typischen einzelnen Linux-Server sieht eine sinnvolle Kombination deshalb so aus:
'memcache.local' => '\OC\Memcache\APCu',
'memcache.distributed' => '\OC\Memcache\Redis',
'memcache.locking' => '\OC\Memcache\Redis',Code-Sprache: PHP (php)
Für einen sehr kleinen privaten Server reicht laut Nextcloud auch nur APCu. Wer Redis aber ohnehin installiert hat oder die Datenbank beim File Locking entlasten möchte, kann Redis zusätzlich verwenden.1. Redis und APCu unter Debian oder Ubuntu installieren
sudo apt update
sudo apt install redis-server php-redis php-apcu
Danach prüfe ich zuerst, ob Redis läuft:
systemctl status redis-server
Die PHP-Module kannst du ebenfalls kontrollieren:
php -m | grep -Ei 'redis|apcu'Code-Sprache: JavaScript (javascript)
Je nach Setup muss anschließend PHP-FPM oder der Webserver neu gestartet werden, damit die neu installierten PHP-Module geladen werden.2. Redis lokal besser per Unix-Socket anbinden
Läuft Redis auf demselben Server wie Nextcloud, empfiehlt die aktuelle Nextcloud-Dokumentation einen Unix-Socket. Dadurch muss Redis nicht über TCP angesprochen werden.In
/etc/redis/redis.confsollten die Socket-Einstellungen vorhanden beziehungsweise aktiviert sein:
unixsocket /run/redis/redis-server.sock
unixsocketperm 770
Damit der Webserver auf den Socket zugreifen darf, wird der typische Debian-Webserver-Nutzerwww-datazur Redis-Gruppe hinzugefügt:
sudo usermod -a -G redis www-data
sudo systemctl restart redis-server
Danach muss auch der PHP-/Webserver-Prozess neu gestartet werden, damit die neue Gruppenmitgliedschaft greift.3. Nextcloud config.php anpassen
Die Datei liegt bei einer klassischen Installation meistens unter:
/var/www/nextcloud/config/config.phpCode-Sprache: JavaScript (javascript)
Innerhalb des bestehenden Konfigurationsarrays ergänze ich:
'memcache.local' => '\OC\Memcache\APCu',
'memcache.distributed' => '\OC\Memcache\Redis',
'memcache.locking' => '\OC\Memcache\Redis','redis' => [
'host' => '/run/redis/redis-server.sock',
'port' => 0,
],Code-Sprache: PHP (php)
Wichtig: Nicht einfach einen zweiten'redis' => [...]-Block anlegen, wenn bereits einer existiert. Dann muss der vorhandene Eintrag angepasst werden.Alternative: Redis über 127.0.0.1
Wenn du keinen Unix-Socket nutzen möchtest, kann Redis lokal auch über TCP angesprochen werden:
'redis' => [
'host' => '127.0.0.1',
'port' => 6379,
],Code-Sprache: PHP (php)
Redis sollte dabei nicht ungeschützt am öffentlichen Netzwerk lauschen. Für eine reine lokale Nextcloud gibt es normalerweise keinen Grund, Port 6379 ins Internet freizugeben.Brauche ich noch requirepass?
In meiner alten Anleitung hatte ich für Redis zwingend ein Passwort überrequirepasseingerichtet. Das ist bei einer ausschließlich lokalen Verbindung über einen korrekt berechtigten Unix-Socket nicht zwingend erforderlich. Wer Redis über TCP oder zwischen mehreren Servern betreibt, sollte die Redis-Authentifizierung und Netzwerkkonfiguration dagegen bewusst absichern.Ein festes Beispielpasswort gehört ohnehin nicht in eine Anleitung – und erst recht nicht in eine produktive
config.php.4. Konfiguration testen
Zuerst prüfe ich Redis selbst:
redis-cli ping
Bei einer TCP-Konfiguration sollte als AntwortPONGerscheinen. Beim Unix-Socket kannst du direkt den Socket angeben:
redis-cli -s /run/redis/redis-server.sock ping
Danach kontrolliere ich Nextcloud:
sudo -E -u www-data php /var/www/nextcloud/occ statusCode-Sprache: JavaScript (javascript)
Zusätzlich lohnt sich ein Blick unter Administrationseinstellungen → Übersicht. Ist kein lokaler Cache konfiguriert oder stimmt etwas mit der Einrichtung nicht, meldet Nextcloud das dort normalerweise ziemlich deutlich.APCu nicht zu klein dimensionieren
Ein Punkt, der bei größeren Instanzen schnell auffällt: Der Standardwert für den APCu-Speicher kann zu klein sein. Nextcloud nennt 128 MB als sinnvollen Startwert, wenn der Standard nicht reicht. Die Einstellung erfolgt in der passenden PHP-Konfiguration zum Beispiel über:
apc.shm_size=128M
Ob mehr nötig ist, hängt von Anzahl der Benutzer, Apps und PHP-Worker ab. Einfach blind auf mehrere Gigabyte hochdrehen würde ich nicht.Was Redis nicht automatisch schneller macht
Redis ist kein Wunderknopf für eine langsame Nextcloud. Wenn PHP-FPM falsch dimensioniert ist, die Datenbank hängt, die Platte langsam ist oder Vorschaubilder den Server beschäftigen, wird Redis diese Probleme nicht plötzlich verschwinden lassen.Seine größten Vorteile liegen in sauberem Caching und vor allem darin, die Datenbank beim Transactional File Locking zu entlasten. Zusammen mit APCu ergibt das für viele selbst gehostete Installationen eine sehr sinnvolle Kombination.
Wenn du deine Nextcloud generell überarbeitest, lohnt sich auch mein Artikel zum sicheren Verschieben des Nextcloud-Datenverzeichnisses per Bind Mount.
Weiterführend: Nextcloud-Dokumentation zu Memory Caching und Transactional File Locking.
Was bietet Nextcloud 2026? Mehr als nur eine private Cloud | Das Netz und ich
Nextcloud ist längst mehr als Datei-Sync: Files, Kalender, Kontakte, Talk, Office, Fotos, Aufgaben, RSS und viele Apps – ein Überblick für Einsteiger.lars (Das Netz und ich)
Bestehende Nextcloud in Docker umziehen: Datenbank, Daten und Konfiguration übernehmen
Überarbeitet am 8. September 2026.
Meine Nextcloud von einer klassischen Serverinstallation in Docker umzuziehen war damals eines meiner größeren Projekte. Die alte Anleitung funktioniert heute aber nur noch teilweise: Docker Compose wurde noch als einzelne Binärdatei installiert, Containernamen waren fest eincodiert und nebenbei wurde sogar eine längst veraltete Collabora-Konfiguration mit umgezogen.
Heute würde ich den Umzug deutlich sauberer machen: erst sichern, dann auf exakt derselben Nextcloud-Hauptversion in Docker wiederherstellen und erst danach über Updates nachdenken.
Wenn Docker auf dem Zielserver noch nicht eingerichtet ist, findest du hier meine aktuelle Anleitung: Docker und Docker Compose unter Debian und Ubuntu installieren.
Table of Contents
Toggle
Was muss bei einer Nextcloud wirklich mit?
Für eine vollständige Migration reicht es nicht, nur den Nextcloud-Datenordner zu kopieren. Zu einer bestehenden Installation gehören mindestens:
- die Datenbank,
- das Nextcloud-Datenverzeichnis,
config/config.phpund die übrige relevante Konfiguration,- eigene beziehungsweise zusätzliche Apps,
- eigene Themes, falls vorhanden.
Gerade Kalender, Kontakte, Freigaben, App-Einstellungen und viele Metadaten liegen in der Datenbank. Ein reines Kopieren der Dateien wäre deshalb keine vollständige Migration.
1. Quell- und Zielversion müssen zusammenpassen
Das ist einer der wichtigsten Punkte. Wenn auf dem alten Server beispielsweise Nextcloud Hauptversion X läuft, würde ich auf dem Docker-Ziel zunächst ebenfalls ein Image dieser Hauptversion verwenden.
Ich würde einen Serverumzug nicht gleichzeitig als Sprung über mehrere Nextcloud-Hauptversionen benutzen. Das offizielle Docker-Image unterstützt Upgrades nur jeweils um eine Hauptversion. Erst die Migration sauber abschließen, anschließend kontrolliert aktualisieren.
2. Vollständiges Backup erstellen
Bevor irgendetwas verändert wird, kommt ein vollständiges Backup. Ich schalte Nextcloud dafür zuerst in den Wartungsmodus:
sudo -E -u www-data php /var/www/nextcloud/occ maintenance:mode --onCode-Sprache: JavaScript (javascript)
Danach sichere ich Datenbank, Konfiguration und Datenverzeichnis. Bei MariaDB/MySQL kann ein Dump beispielsweise so erstellt werden:
mysqldump --single-transaction --routines --triggers \
-u nextcloud -p nextcloud > nextcloud.sqlCode-Sprache: CSS (css)
Zusätzlich sichere ich mindestens:
/var/www/nextcloud/config/
/DEIN/NEXTCLOUD-DATENVERZEICHNIS/
/var/www/nextcloud/custom_apps/
/var/www/nextcloud/themes/Code-Sprache: JavaScript (javascript)
Wo dein Datenverzeichnis tatsächlich liegt, siehst du in der config.php beim Eintrag datadirectory. Falls du Daten auf eine andere Platte verschieben möchtest, habe ich dafür inzwischen eine separate Anleitung: Nextcloud-Datenverzeichnis sicher per Bind Mount verschieben.
3. Docker-Umgebung aufbauen
Auf dem Zielsystem definiere ich die komplette Infrastruktur in einer compose.yaml. Für eine typische Installation sind das mindestens Nextcloud und eine Datenbank; Redis würde ich ebenfalls direkt mit einplanen.
Ein stark vereinfachtes Grundgerüst kann so aussehen:
services:
db:
image: mariadb:11.8
restart: unless-stopped
env_file:
- db.env
volumes:
- ./db:/var/lib/mysql
redis:
image: redis:alpine
restart: unless-stopped
app:
image: nextcloud:DEINE_HAUPTVERSION-apache
restart: unless-stopped
depends_on:
- db
- redis
ports:
- "127.0.0.1:8080:80"
volumes:
- ./nextcloud:/var/www/htmlCode-Sprache: JavaScript (javascript)DEINE_HAUPTVERSION ersetzt du bewusst durch die Version, die zu deiner bestehenden Installation passt. Für produktive Setups würde ich außerdem Passwörter und Secrets nicht direkt in die Compose-Datei schreiben.
Die genaue Struktur kann natürlich anders aussehen – etwa mit externem Datenverzeichnis, separaten Volumes oder FPM statt Apache. Entscheidend ist, dass die persistenten Daten nicht nur im flüchtigen Container liegen.
4. Basis einmal erstellen
Das offizielle Nextcloud-Docker-Projekt empfiehlt bei der Migration, die neue Infrastruktur zunächst einmal mit Compose aufzubauen. Dadurch entstehen die benötigten Volumes und die Datenbankumgebung:
docker compose up -d
Anschließend stoppe ich die App wieder beziehungsweise verhindere, dass parallel schon Benutzer mit der leeren Installation arbeiten, während die alten Daten eingespielt werden.
5. Datenbank wiederherstellen
Die vorhandene Nextcloud-Datenbank muss jetzt in den neuen Datenbankcontainer. Das offizielle Docker-Projekt zeigt dafür einen robusten Weg: Dump in den Container kopieren und dort importieren.
docker compose cp ./nextcloud.sql db:/nextcloud.sql
Der eigentliche Import hängt von Benutzername, Datenbankname und Datenbanktyp ab. Bei MariaDB/MySQL wird der Dump anschließend mit dem Datenbank-Client in die vorbereitete Nextcloud-Datenbank eingelesen. Passwörter würde ich dabei nicht als Beispielwert in die Shell-History schreiben, sondern aus der eigenen sicheren Konfiguration verwenden.
6. config.php übernehmen und Docker-Pfade anpassen
Jetzt kommt die bestehende config.php in die Docker-Installation. Besonders der Datenbankhost ändert sich häufig. Wenn der Compose-Dienst db heißt, sieht der Eintrag beispielsweise so aus:
'dbhost' => 'db:3306',Code-Sprache: PHP (php)
Außerdem prüfe ich trusted_domains, Reverse-Proxy-Einstellungen, Redis und datadirectory. Die Pfade müssen aus Sicht des Containers stimmen – nicht aus Sicht des Hosts.
7. Daten und Custom Apps übernehmen
Die Nutzerdaten werden jetzt in das vorgesehene persistente Volume beziehungsweise den eingebundenen Host-Pfad kopiert. Dateirechte und Zeitstempel sollten erhalten bleiben.
Eigene Apps kopiere ich nur dann mit, wenn ich sie wirklich noch brauche. Normale Apps aus dem Nextcloud App Store lassen sich oft sauber neu installieren. Alte, seit Jahren ungepflegte Apps möchte ich nicht automatisch in die neue Umgebung mitschleppen.
8. Nextcloud starten und mit OCC prüfen
docker compose up -d
Danach kontrolliere ich zuerst die Container:
docker compose ps
docker compose logs --tail 100 app
OCC wird im Container ausgeführt:
docker compose exec -u www-data app php occ status
Wenn alles stimmt, kann der Wartungsmodus in der neuen Installation beendet werden:
docker compose exec -u www-data app php occ maintenance:mode --offCode-Sprache: CSS (css)
9. Cron richtig einrichten
Meine alte Anleitung hatte für einzelne Apps mehrere selbstgebastelte Cronjobs. Das würde ich heute nicht mehr als Standard empfehlen. Nextcloud selbst braucht einen regelmäßig ausgeführten cron.php-Job.
Je nach Docker-Aufbau kann dafür ein separater Cron-Container oder ein Host-Cronjob verwendet werden. Entscheidend ist, dass in Nextcloud unter den Grundeinstellungen Cron als Hintergrundjob ausgewählt ist und der Job zuverlässig läuft.
10. Reverse Proxy erst danach sauber anbinden
Ich lasse Nextcloud im Beispiel nur auf 127.0.0.1:8080 lauschen und setze davor meinen normalen Nginx-Reverse-Proxy mit HTTPS. So muss der Container nicht selbst öffentlich Port 80 oder 443 übernehmen.
Bei einem Reverse Proxy müssen insbesondere Host, Protokoll und echte Client-IP korrekt an Nextcloud weitergereicht werden. Mehr dazu steht auch in meiner aktualisierten Anleitung Nextcloud richtig absichern.
Collabora nicht mehr in diese Migration quetschen
Früher hatte ich in diesem Artikel gleich noch eine Collabora-Nginx-Konfiguration angehängt. Das machte die Anleitung unnötig unübersichtlich und die verwendeten /lool-Pfade sind längst veraltet. Nextcloud Office gehört deshalb in eine eigene Anleitung: Nextcloud Office mit Collabora einrichten.
Erst wenn alles läuft: alte Installation abschalten
Ich würde das alte System nicht sofort löschen. Erst anmelden, Dateien öffnen, Upload testen, Kalender und Kontakte prüfen, Hintergrundjobs kontrollieren und einen neuen Backup-Lauf durchführen.
Wenn die Docker-Installation einige Zeit sauber gelaufen ist und ein Restore-fähiges Backup existiert, kann die alte Installation endgültig außer Betrieb gehen.
Weiterführend: offizielles Nextcloud-Docker-Image und Docker-Dokumentation inklusive Migration bestehender Installationen.
Docker & Docker Compose unter Debian und Ubuntu installieren – Schritt für Schritt | Das Netz und ich
Docker und Docker Compose unter Debian oder Ubuntu installieren: aktuelle Repository-Methode, Compose-Plugin, erster Test und wichtige Firewall-Hinweise.lars (Das Netz und ich)
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung:includeSubDomainssolltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind
trusted_proxiesund die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus demnextcloud.logerkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen
nextcloud.logkorrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie/var/www.Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der
config.phpändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud solltedebugnicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
Nextcloud Full Text Search einrichten: Dateien durchsuchen mit Elasticsearch oder SQL
Überarbeitet am 8. September 2026.
Meine alte Anleitung für die Nextcloud-Volltextsuche war inzwischen ein ziemliches Museum: Java 8, Elasticsearch 7.12, ReadonlyREST, ein separat installiertes ingest-attachment-Plugin und Hinweise auf PHP 7.4. Die gute Nachricht ist: Full Text Search gibt es weiterhin und wird aktiv gepflegt. Der Aufbau ist aber heute deutlich klarer.
Das Wichtigste zuerst: Nextcloud Full Text Search besteht nicht aus nur einer App. Es ist ein kleines Baukastensystem aus einer Kern-App, einem Inhalts-Provider und einer Suchplattform.
Wenn du erstmal wissen möchtest, was Nextcloud sonst noch kann, findest du hier meinen aktuellen Überblick: Was bietet Nextcloud 2026?.
Table of Contents
Toggle
Die drei Bausteine der Volltextsuche
Für die Suche in Dateien brauchst du normalerweise diese Komponenten:
- Full text search – die Kern-App und das Such-Framework
- Full text search – Files – liest Inhalte und Metadaten aus Dateien
- eine Platform-App – dort wird der Suchindex gespeichert
Als Plattform gibt es unter anderem Full text search – Elasticsearch Platform. Inzwischen existiert außerdem eine SQL Platform, die den Index in der Nextcloud-Datenbank speichert und ohne separaten Elasticsearch-Server auskommt.
Welche Plattform würde ich nehmen?
Für eine kleine Installation würde ich mir zuerst die SQL Platform ansehen. Sie spart einen zusätzlichen Dienst und damit auch RAM, Updates und Wartung.
Bei vielen Dateien, mehreren Benutzern oder einer größeren Installation bleibt Elasticsearch interessant. Dafür läuft ein zusätzlicher Suchserver, der speziell für solche Indizes gebaut ist.
Wichtig: Die aktuelle Nextcloud-App Full text search – Elasticsearch Platform ist seit Version 26 nur noch mit Elasticsearch 8 kompatibel. Meine alten Elasticsearch-7-Beispiele gehören deshalb nicht mehr in eine heutige Anleitung.
1. Die Nextcloud-Apps installieren
Im Nextcloud App Store installierst du für die Elasticsearch-Variante:
- Full text search
- Full text search – Files
- Full text search – Elasticsearch Platform
Alternativ kannst du als Plattform Full text search – SQL Platform verwenden.
Wer lieber mit OCC arbeitet, kann die App-IDs auch darüber aktivieren. Die eigentliche Konfiguration erledige ich anschließend aber gern in der Administrationsoberfläche, weil dort sofort sichtbar ist, welcher Provider und welche Plattform ausgewählt sind.
2. Elasticsearch nur intern erreichbar machen
Wenn du Elasticsearch nutzt, braucht Nextcloud Zugriff auf dessen HTTP-Schnittstelle. Port 9200 sollte aber nicht einfach offen im Internet hängen.
Auf einem einzelnen Docker-Host binde ich solche Dienste lieber nur an localhost oder lasse Nextcloud und Elasticsearch direkt über ein internes Docker-Netz miteinander sprechen.
127.0.0.1:9200:9200Code-Sprache: CSS (css)
Damit ist Elasticsearch vom Host erreichbar, aber nicht automatisch aus dem Internet. Wie Docker und Docker Compose aktuell installiert werden, habe ich hier beschrieben: Docker und Docker Compose installieren.
Ich pinne in dieser Anleitung bewusst keine konkrete Elasticsearch-Patchversion fest. Vor der Installation würde ich immer die Kompatibilitätsangabe der aktuellen Nextcloud-Elasticsearch-App prüfen. Alte Blogposts mit Elasticsearch 6 oder 7 sollte man nicht einfach nachbauen.
3. Full Text Search in Nextcloud konfigurieren
Unter den Administrationseinstellungen der Volltextsuche wählst du den Datei-Provider und deine Suchplattform aus.
Bei einem lokal auf dem Host laufenden Elasticsearch könnte die Adresse beispielsweise so aussehen:
127.0.0.1:9200Code-Sprache: JavaScript (javascript)
Laufen Nextcloud und Elasticsearch beide in Docker, ist stattdessen meist der interne Servicename sinnvoll, zum Beispiel:
http://elasticsearch:9200Code-Sprache: JavaScript (javascript)
Zusätzlich wird ein Indexname festgelegt, zum Beispiel nextcloud. Zugangsdaten oder TLS hängen davon ab, wie du deinen Elasticsearch-Server abgesichert hast.
4. Erst testen, dann indexieren
Einer der praktischsten Befehle ist inzwischen der eingebaute Test:
sudo -E -u www-data php /var/www/nextcloud/occ fulltextsearch:testCode-Sprache: JavaScript (javascript)
Der Test prüft unter anderem, ob Provider und Suchplattform geladen werden können, ob sich Dokumente indexieren lassen und ob Suchanfragen Ergebnisse zurückgeben.
Erst wenn dieser Test sauber durchläuft, starte ich den eigentlichen Index:
sudo -E -u www-data php /var/www/nextcloud/occ fulltextsearch:indexCode-Sprache: JavaScript (javascript)
Bei vielen Dateien kann der erste Lauf ziemlich lange dauern. Dann gehört der Prozess in eine stabile SSH-Sitzung wie tmux oder screen – nicht in ein Terminal, das man versehentlich nach zehn Minuten schließt.
5. Konfiguration kontrollieren
Für eine schnelle Übersicht gibt es:
sudo -E -u www-data php /var/www/nextcloud/occ fulltextsearch:checkCode-Sprache: JavaScript (javascript)
Damit sieht man, welche Plattform ausgewählt ist und welche Provider aktiv sind. Bei Fehlern ist das oft hilfreicher als direkt den ganzen Index zu löschen und neu aufzubauen.
6. Laufende Indexierung
Für fortlaufende Indexierung gibt es außerdem:
sudo -E -u www-data php /var/www/nextcloud/occ fulltextsearch:liveCode-Sprache: JavaScript (javascript)
Das ist ein dauerhaft laufender Prozess und gehört deshalb nicht einfach in eine normale SSH-Sitzung. Je nach Installation kann man ihn beispielsweise über systemd oder einen Prozessmanager betreiben. Wer nur gelegentlich indexiert, kann auch bewusst mit normalen Indexläufen arbeiten.
Was ist mit OCR?
Hier war meine alte Anleitung zu pauschal. Volltextsuche und OCR sind nicht dasselbe. Die Full-Text-Search-Apps können Inhalte unterstützter Dateien indexieren, aber aus jedem beliebigen Foto oder Scan wird nicht automatisch zuverlässig durchsuchbarer Text.
Wenn dein Hauptziel gescannte Dokumente sind, würde ich zuerst prüfen, ob die Dateien bereits eine OCR-Textebene besitzen – beispielsweise weil sie aus Paperless-ngx oder einer Scanner-Software kommen. Dann kann die Volltextsuche diesen Text wesentlich einfacher indexieren.
Und Nextant mit Solr?
Nextant war der Vorgänger, über den ich hier früher viel geschrieben habe. Die App ist aber nur bis Nextcloud 13 freigegeben und seit Jahren nicht mehr gepflegt. Meine alten Solr-/Nextant-Installationsanleitungen sind deshalb keine sinnvolle Empfehlung mehr.
Für eine aktuelle Nextcloud würde ich heute beim aktiv gepflegten Full-Text-Search-Framework bleiben und eine aktuelle Platform-App auswählen.
Auch Caching und Serverleistung im Blick behalten
Volltextindexierung erzeugt ordentlich Last auf CPU, RAM und Datenträger. Wenn die Nextcloud ohnehin schon langsam ist, sollte man nicht nur am Suchdienst drehen. Für das normale Nextcloud-Caching habe ich deshalb auch Redis und APCu für Nextcloud aktualisiert.
Weiterführend: Full text search, Full text search – Files, Elasticsearch Platform und SQL Platform.
Docker & Docker Compose unter Debian und Ubuntu installieren – Schritt für Schritt | Das Netz und ich
Docker und Docker Compose unter Debian oder Ubuntu installieren: aktuelle Repository-Methode, Compose-Plugin, erster Test und wichtige Firewall-Hinweise.lars (Das Netz und ich)
Nextcloud mit Redis und APCu beschleunigen: Caching richtig einrichten
Überarbeitet am 8. September 2026.Redis gehört bei vielen Nextcloud-Installationen inzwischen fast zur Grundausstattung. Früher hatte ich Redis vor allem eingebaut, weil die Galerie und andere Bereiche gefühlt schneller reagieren sollten. Heute würde ich das genauer formulieren: Für den lokalen Cache ist APCu normalerweise die bessere Wahl, Redis spielt seine Stärke vor allem beim verteilten Cache und beim Transactional File Locking aus.
Gerade das File Locking ist wichtig. Ohne Redis kann Nextcloud dafür die Datenbank verwenden, was unnötig Last erzeugt. Bei einer größeren oder stärker genutzten Instanz lohnt sich Redis deshalb sehr schnell.
Wenn du Nextcloud gerade erst aufsetzt, findest du in meinem Beitrag Was bietet Nextcloud 2026? einen Überblick. Für die Absicherung des Servers habe ich außerdem Nextcloud richtig absichern aktualisiert.
Table of Contents
ToggleWas macht APCu und was macht Redis?
APCu ist ein sehr schneller lokaler Cache innerhalb von PHP. Nextcloud empfiehlt ihn fürmemcache.local. Redis eignet sich dagegen besonders fürmemcache.distributedundmemcache.locking.Auf einem typischen einzelnen Linux-Server sieht eine sinnvolle Kombination deshalb so aus:
'memcache.local' => '\OC\Memcache\APCu',
'memcache.distributed' => '\OC\Memcache\Redis',
'memcache.locking' => '\OC\Memcache\Redis',Code-Sprache: PHP (php)
Für einen sehr kleinen privaten Server reicht laut Nextcloud auch nur APCu. Wer Redis aber ohnehin installiert hat oder die Datenbank beim File Locking entlasten möchte, kann Redis zusätzlich verwenden.1. Redis und APCu unter Debian oder Ubuntu installieren
sudo apt update
sudo apt install redis-server php-redis php-apcu
Danach prüfe ich zuerst, ob Redis läuft:
systemctl status redis-server
Die PHP-Module kannst du ebenfalls kontrollieren:
php -m | grep -Ei 'redis|apcu'Code-Sprache: JavaScript (javascript)
Je nach Setup muss anschließend PHP-FPM oder der Webserver neu gestartet werden, damit die neu installierten PHP-Module geladen werden.2. Redis lokal besser per Unix-Socket anbinden
Läuft Redis auf demselben Server wie Nextcloud, empfiehlt die aktuelle Nextcloud-Dokumentation einen Unix-Socket. Dadurch muss Redis nicht über TCP angesprochen werden.In
/etc/redis/redis.confsollten die Socket-Einstellungen vorhanden beziehungsweise aktiviert sein:
unixsocket /run/redis/redis-server.sock
unixsocketperm 770
Damit der Webserver auf den Socket zugreifen darf, wird der typische Debian-Webserver-Nutzerwww-datazur Redis-Gruppe hinzugefügt:
sudo usermod -a -G redis www-data
sudo systemctl restart redis-server
Danach muss auch der PHP-/Webserver-Prozess neu gestartet werden, damit die neue Gruppenmitgliedschaft greift.3. Nextcloud config.php anpassen
Die Datei liegt bei einer klassischen Installation meistens unter:
/var/www/nextcloud/config/config.phpCode-Sprache: JavaScript (javascript)
Innerhalb des bestehenden Konfigurationsarrays ergänze ich:
'memcache.local' => '\OC\Memcache\APCu',
'memcache.distributed' => '\OC\Memcache\Redis',
'memcache.locking' => '\OC\Memcache\Redis','redis' => [
'host' => '/run/redis/redis-server.sock',
'port' => 0,
],Code-Sprache: PHP (php)
Wichtig: Nicht einfach einen zweiten'redis' => [...]-Block anlegen, wenn bereits einer existiert. Dann muss der vorhandene Eintrag angepasst werden.Alternative: Redis über 127.0.0.1
Wenn du keinen Unix-Socket nutzen möchtest, kann Redis lokal auch über TCP angesprochen werden:
'redis' => [
'host' => '127.0.0.1',
'port' => 6379,
],Code-Sprache: PHP (php)
Redis sollte dabei nicht ungeschützt am öffentlichen Netzwerk lauschen. Für eine reine lokale Nextcloud gibt es normalerweise keinen Grund, Port 6379 ins Internet freizugeben.Brauche ich noch requirepass?
In meiner alten Anleitung hatte ich für Redis zwingend ein Passwort überrequirepasseingerichtet. Das ist bei einer ausschließlich lokalen Verbindung über einen korrekt berechtigten Unix-Socket nicht zwingend erforderlich. Wer Redis über TCP oder zwischen mehreren Servern betreibt, sollte die Redis-Authentifizierung und Netzwerkkonfiguration dagegen bewusst absichern.Ein festes Beispielpasswort gehört ohnehin nicht in eine Anleitung – und erst recht nicht in eine produktive
config.php.4. Konfiguration testen
Zuerst prüfe ich Redis selbst:
redis-cli ping
Bei einer TCP-Konfiguration sollte als AntwortPONGerscheinen. Beim Unix-Socket kannst du direkt den Socket angeben:
redis-cli -s /run/redis/redis-server.sock ping
Danach kontrolliere ich Nextcloud:
sudo -E -u www-data php /var/www/nextcloud/occ statusCode-Sprache: JavaScript (javascript)
Zusätzlich lohnt sich ein Blick unter Administrationseinstellungen → Übersicht. Ist kein lokaler Cache konfiguriert oder stimmt etwas mit der Einrichtung nicht, meldet Nextcloud das dort normalerweise ziemlich deutlich.APCu nicht zu klein dimensionieren
Ein Punkt, der bei größeren Instanzen schnell auffällt: Der Standardwert für den APCu-Speicher kann zu klein sein. Nextcloud nennt 128 MB als sinnvollen Startwert, wenn der Standard nicht reicht. Die Einstellung erfolgt in der passenden PHP-Konfiguration zum Beispiel über:
apc.shm_size=128M
Ob mehr nötig ist, hängt von Anzahl der Benutzer, Apps und PHP-Worker ab. Einfach blind auf mehrere Gigabyte hochdrehen würde ich nicht.Was Redis nicht automatisch schneller macht
Redis ist kein Wunderknopf für eine langsame Nextcloud. Wenn PHP-FPM falsch dimensioniert ist, die Datenbank hängt, die Platte langsam ist oder Vorschaubilder den Server beschäftigen, wird Redis diese Probleme nicht plötzlich verschwinden lassen.Seine größten Vorteile liegen in sauberem Caching und vor allem darin, die Datenbank beim Transactional File Locking zu entlasten. Zusammen mit APCu ergibt das für viele selbst gehostete Installationen eine sehr sinnvolle Kombination.
Wenn du deine Nextcloud generell überarbeitest, lohnt sich auch mein Artikel zum sicheren Verschieben des Nextcloud-Datenverzeichnisses per Bind Mount.
Weiterführend: Nextcloud-Dokumentation zu Memory Caching und Transactional File Locking.
Was bietet Nextcloud 2026? Mehr als nur eine private Cloud | Das Netz und ich
Nextcloud ist längst mehr als Datei-Sync: Files, Kalender, Kontakte, Talk, Office, Fotos, Aufgaben, RSS und viele Apps – ein Überblick für Einsteiger.lars (Das Netz und ich)
Nextcloud mit LDAP/OpenLDAP verbinden: Benutzer und Gruppen einbinden
Überarbeitet am 8. September 2026.
Nextcloud kann Benutzer und Gruppen direkt aus einem LDAP-Verzeichnis oder Microsoft Active Directory übernehmen. Das ist praktisch, wenn mehrere Dienste dieselben Benutzerkonten verwenden sollen und man nicht für jede Anwendung eigene Accounts pflegen möchte.
Meine alte Anleitung ging noch einen Schritt weiter und beschrieb gleichzeitig den Aufbau eines OpenLDAP-Servers inklusive phpLDAPadmin. Das war inzwischen zu viel auf einmal und enthielt ein paar Dinge, die ich heute aus Sicherheitsgründen nicht mehr so empfehlen würde. Diese Anleitung konzentriert sich deshalb auf das, was sie eigentlich leisten soll: einen vorhandenen LDAP-Server sauber mit Nextcloud verbinden.
Wer seine Nextcloud generell absichern möchte, findet die wichtigsten Punkte in Nextcloud richtig absichern.
Table of Contents
Toggle
Was Nextcloud mit LDAP macht
Das LDAP User and Group Backend liest Benutzer und Gruppen aus dem Verzeichnis ein. Die Nutzer melden sich anschließend mit ihren LDAP-Zugangsdaten an Nextcloud an. Separate Nextcloud-Benutzerkonten müssen dafür nicht angelegt werden.
Nextcloud verwendet das LDAP-Verzeichnis dabei grundsätzlich lesend für Benutzer- und Gruppeninformationen. Quoten, Freigaben und andere Nextcloud-spezifische Einstellungen werden weiterhin in Nextcloud verwaltet.
1. PHP-LDAP installieren
Für die LDAP-Anbindung benötigt PHP das LDAP-Modul. Unter Debian und Ubuntu lässt sich das normalerweise so installieren:
sudo apt update
sudo apt install php-ldap
Danach muss der verwendete PHP-FPM- beziehungsweise Webserver-Dienst neu gestartet werden, damit das Modul geladen wird.
Prüfen kannst du das zum Beispiel mit:
php -m | grep -i ldap
2. LDAP User and Group Backend aktivieren
Die benötigte Nextcloud-App heißt LDAP user and group backend und hat die App-ID user_ldap. Sie kann in der App-Verwaltung aktiviert werden.
Alternativ geht es über OCC:
sudo -E -u www-data php /var/www/nextcloud/occ app:enable user_ldapCode-Sprache: JavaScript (javascript)
Danach erscheint in den Administrationseinstellungen die LDAP-Konfiguration.
3. Verbindung zum LDAP-Server eintragen
Im ersten Reiter wird die eigentliche Serververbindung eingerichtet. Benötigt werden mindestens Host, Port und Base-DN.
Ein typisches Beispiel könnte so aussehen:
Host: ldaps://ldap.example.de
Port: 636
Base DN: dc=example,dc=deCode-Sprache: JavaScript (javascript)
Läuft LDAP auf demselben Server und ausschließlich lokal, kann das Setup natürlich anders aussehen. Bei einer Verbindung über das Netzwerk würde ich die LDAP-Anmeldedaten aber nicht unverschlüsselt quer durchs Netz schicken.
Nextcloud kann für die Suche einen eigenen LDAP-Systembenutzer verwenden. Genau das ist sinnvoller als ein vollwertiges Administratorkonto. Dieser Bind-Benutzer benötigt nur die Rechte, die Nextcloud zum Lesen der benötigten Benutzer- und Gruppeninformationen braucht.
uid=nextcloudsystemuser,ou=service,dc=example,dc=de
Port 389 nicht einfach ins Internet öffnen
In meiner alten Anleitung stand pauschal:
sudo ufw allow 389
Das würde ich heute so nicht mehr empfehlen. Wenn Nextcloud und LDAP auf demselben Server laufen, muss dafür überhaupt kein öffentlicher Port geöffnet werden. Laufen sie auf unterschiedlichen Servern, sollte die Firewall nur die tatsächlich beteiligten Systeme miteinander kommunizieren lassen.
Bei LDAPS wird üblicherweise Port 636 verwendet. Entscheidend ist nicht die Portnummer allein, sondern dass die Verbindung verschlüsselt ist, Zertifikate geprüft werden und der Dienst nicht unnötig für das gesamte Internet erreichbar ist.
4. Benutzerfilter festlegen
Im Reiter Benutzer legst du fest, welche LDAP-Konten überhaupt in Nextcloud erscheinen sollen. Nextcloud erkennt viele typische Objektklassen automatisch.
Bei einem klassischen OpenLDAP ist inetOrgPerson häufig ein passender Ausgangspunkt. Noch besser ist es, nur eine bestimmte Gruppe für Nextcloud freizugeben.
(&(objectClass=inetOrgPerson)(memberOf=cn=nextcloudusers,ou=groups,dc=example,dc=de))
Ob ein solcher memberOf-Filter funktioniert, hängt von der Konfiguration des LDAP-Servers ab. Deshalb würde ich zuerst die grafische Auswahl in Nextcloud verwenden und nur bei Bedarf mit eigenen LDAP-Filtern arbeiten.
5. Login-Attribute auswählen
Im Reiter für die Login-Attribute stellst du ein, womit sich Benutzer anmelden dürfen. Häufig ist das der LDAP-Benutzername, je nach Verzeichnis zum Beispiel uid oder bei Active Directory sAMAccountName.
Optional kann auch die E-Mail-Adresse als Login erlaubt werden. Ich würde nur die Attribute freischalten, die tatsächlich gebraucht werden.
6. Gruppen auswählen
Im Gruppen-Reiter wird festgelegt, welche LDAP-Gruppen in Nextcloud sichtbar sein sollen. Typische Objektklassen sind beispielsweise group oder posixGroup.
Auch hier gilt: lieber gezielt die benötigten Gruppen auswählen, statt das komplette Verzeichnis unnötig nach Nextcloud zu spiegeln.
7. LDAP-Konfiguration mit OCC prüfen
Nextcloud bringt inzwischen sehr brauchbare LDAP-Kommandos mit. Zuerst kannst du dir die vorhandene Konfiguration anzeigen lassen:
sudo -E -u www-data php /var/www/nextcloud/occ ldap:show-configCode-Sprache: JavaScript (javascript)
Nach einem Benutzer suchen:
sudo -E -u www-data php /var/www/nextcloud/occ ldap:search BENUTZERNAMECode-Sprache: JavaScript (javascript)
Und einen konkreten LDAP-Benutzer prüfen:
sudo -E -u www-data php /var/www/nextcloud/occ ldap:check-user BENUTZERNAMECode-Sprache: JavaScript (javascript)
Das ist deutlich angenehmer, als bei jedem Fehler nur in der Weboberfläche herumzuklicken.
Zertifikatsprüfung nicht abschalten
Wenn LDAPS oder TLS wegen eines Zertifikatsfehlers nicht funktioniert, sollte die Ursache behoben werden. Nextcloud bietet zwar eine Möglichkeit, die Zertifikatsprüfung für Tests abzuschalten, die Dokumentation kennzeichnet das aber ausdrücklich als Testoption.
Sauberer ist es, die CA beziehungsweise das Serverzertifikat auf dem Nextcloud-Server korrekt bekannt zu machen.
LDAP und Caching
LDAP-Abfragen werden von Nextcloud gecacht. Gerade bei vielen Benutzern und Gruppen hilft deshalb eine vernünftige Memory-Cache-Konfiguration. Dazu passt meine aktualisierte Anleitung Nextcloud mit Redis und APCu beschleunigen.
Mein Fazit
LDAP mit Nextcloud zu verbinden ist heute deutlich komfortabler als bei meinem ersten Versuch vor vielen Jahren. Nextcloud erkennt viele Attribute selbst, bietet Filter für Benutzer und Gruppen und bringt inzwischen umfangreiche OCC-Kommandos zur Diagnose mit.
Der wichtigste Unterschied zu meiner alten Anleitung: Ich würde LDAP nicht mehr nebenbei mit einem frei erreichbaren phpLDAPadmin-Webpanel und pauschal geöffnetem Port aufbauen. Erst ein sauber abgesichertes LDAP-Verzeichnis, dann Nextcloud als Client anbinden.
Weiterführend: Nextcloud-Dokumentation zur LDAP-Authentifizierung und LDAP-Kommandos mit OCC.
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung:includeSubDomainssolltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind
trusted_proxiesund die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus demnextcloud.logerkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen
nextcloud.logkorrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie/var/www.Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der
config.phpändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud solltedebugnicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
ocDownloader für Nextcloud nicht mehr nutzen: aktuelle Alternativen
Überarbeitet am 8. September 2026.
Wichtig vorweg: ocDownloader wird nicht mehr gepflegt und sollte auf einer aktuellen Nextcloud nicht mehr neu eingerichtet werden.
Diese Seite bleibt bewusst als Hinweis bestehen, weil ältere Anleitungen und Suchtreffer noch darauf verweisen können. Die eigentliche Installationsanleitung habe ich aus dem veröffentlichten Bestand genommen.
Table of Contents
Toggle
Warum ocDownloader heute keine gute Wahl mehr ist
- keine verlässlichen Sicherheitsupdates,
- Probleme mit aktuellen Nextcloud-Versionen möglich,
- alte Abhängigkeiten wie youtube-dl und historische aria2-Setups,
- keine gute Basis für eine öffentlich erreichbare Nextcloud.
Gerade bei einer App, die Downloads aus dem Internet direkt auf den eigenen Server holt, möchte ich keine ungepflegte Altsoftware einsetzen.
Meine heutige Alternative: MediaFetch
Inzwischen habe ich selbst an einer moderneren Lösung gearbeitet. MediaFetch ist mein eigener Ansatz für Downloads direkt innerhalb von Nextcloud.
Wer sich für die Entwicklung und den Hintergrund interessiert, findet dort auch den aktuellen Stand des Projekts.
Auch Net Loader ist aus diesem Thema entstanden
Ein weiterer Ansatz ist Net Loader. Das Projekt ist aus der Idee entstanden, die alten Downloader-Konzepte für eine heutige Nextcloud neu zu denken, statt immer weiter an längst überholten Installationsanleitungen festzuhalten.
Alte ocDownloader-Anleitungen besser nicht mehr nachbauen
Im Netz finden sich noch Anleitungen mit offenen aria2-RPC-Ports, deaktivierter Zertifikatsprüfung oder sehr alten Abhängigkeiten. Solche Setups würde ich heute nicht mehr übernehmen.
Wenn deine Nextcloud öffentlich erreichbar ist, solltest du außerdem die grundlegende Absicherung prüfen. Dazu habe ich den Artikel Nextcloud richtig absichern komplett aktualisiert.
Kurz gesagt: ocDownloader darf in meinem Blog als historischer Hinweis bleiben – für eine neue Installation würde ich aber eine aktuell gepflegte Lösung verwenden.
Net Loader: Warum ich NcDownloader als Nextcloud-App weiterentwickeln will | Das Netz und ich
**"Net Loader: Nextcloud-App für direkte Web-Downloads – Warum ich NcDownloader weiterentwickle und wie du mithelfen kannst."** (120 Zeichen)lars (Das Netz und ich)
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung:includeSubDomainssolltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind
trusted_proxiesund die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus demnextcloud.logerkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen
nextcloud.logkorrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie/var/www.Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der
config.phpändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud solltedebugnicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
Nextcloud mit 2FA absichern: TOTP, Backup-Codes und App-Passwörter
Überarbeitet am 8. September 2026.
Die Zwei-Faktor-Authentifizierung gehört für mich bei einer öffentlich erreichbaren Nextcloud inzwischen zu den wichtigsten Schutzmaßnahmen. Ein Passwort allein kann gestohlen, wiederverwendet oder durch Phishing abgegriffen werden. Mit einem zweiten Faktor reicht das Passwort allein nicht mehr aus.
In meiner alten Version dieses Artikels ging es noch um WinAuth auf dem PC. Das ist heute nicht mehr der Punkt. Nextcloud unterstützt verschiedene 2FA-Verfahren und bringt mehrere Provider bereits mit. Für viele private Installationen ist TOTP weiterhin der einfachste Einstieg.
Wenn du deine Nextcloud insgesamt absichern möchtest, findest du die wichtigsten Punkte gesammelt in Nextcloud richtig absichern.
Table of Contents
Toggle
Welche 2FA-Verfahren unterstützt Nextcloud?
Nextcloud ist bei der Zwei-Faktor-Authentifizierung modular aufgebaut. Zu den typischen Möglichkeiten gehören:
- TOTP-Codes aus einer Authenticator-App,
- Bestätigung über bereits angemeldete Nextcloud-Geräte,
- Hardware- beziehungsweise FIDO-basierte Faktoren über passende Provider,
- Backup-Codes für den Notfall.
Der Administrator muss mindestens einen passenden 2FA-Provider aktivieren. Danach kann der Benutzer den zweiten Faktor in seinen persönlichen Sicherheitseinstellungen einrichten. 2FA kann vom Administrator auch für alle Nutzer oder nur bestimmte Gruppen verpflichtend gemacht werden.
1. TOTP-Provider aktivieren
Für TOTP benötigt Nextcloud den Two-Factor TOTP Provider. Er ist bei aktuellen Nextcloud-Versionen vorhanden, kann aber deaktiviert sein. Als Administrator findest du ihn unter den Apps bei den deaktivierten Apps beziehungsweise im Bereich Sicherheit.
Alternativ lässt sich der Provider über OCC installieren:
sudo -E -u www-data php /var/www/nextcloud/occ app:install twofactor_totpCode-Sprache: JavaScript (javascript)
Ist die App bereits installiert, aber deaktiviert, genügt:
sudo -E -u www-data php /var/www/nextcloud/occ app:enable twofactor_totpCode-Sprache: JavaScript (javascript)
2. TOTP im Benutzerkonto einrichten
Im eigenen Nextcloud-Konto öffnest du die persönlichen Einstellungen und gehst in den Bereich Sicherheit. Dort lässt sich TOTP aktivieren.
Nextcloud zeigt anschließend einen QR-Code beziehungsweise ein geheimes TOTP-Secret an. Diesen QR-Code scannst du mit einer kompatiblen Authenticator-App. Nextcloud verwendet den üblichen TOTP-Standard, sodass du nicht an eine bestimmte App gebunden bist.
Danach gibst du den aktuell erzeugten Code einmal zur Bestätigung in Nextcloud ein. Ab dem nächsten Login werden Passwort und TOTP-Code verlangt.
Die Uhrzeit muss stimmen
TOTP-Codes sind zeitabhängig. Wenn die Uhr auf dem Nextcloud-Server oder dem Gerät deutlich falsch läuft, können eigentlich richtige Codes abgelehnt werden. Deshalb sollte die Systemzeit auf dem Server sauber per NTP synchronisiert werden.
3. Unbedingt Backup-Codes erzeugen
Das ist der Teil, den man gern auf später verschiebt und dann genau im falschen Moment vermisst. Nextcloud kann einmalig verwendbare Backup-Codes erzeugen. Diese sind für den Fall gedacht, dass das Smartphone verloren geht, kaputt ist oder der normale zweite Faktor nicht mehr funktioniert.
Die Backup-Codes gehören an einen sicheren Ort, aber nicht auf dasselbe Smartphone, auf dem auch der Authenticator liegt. Ein Passwortmanager oder eine sicher verwahrte Offline-Kopie ist sinnvoller.
4. App-Passwörter für Joplin, DAV und andere Clients
Sobald 2FA aktiviert ist, können viele klassische Clients nicht mehr einfach mit Benutzername und normalem Nextcloud-Passwort auf das Konto zugreifen. Dafür gibt es gerätespezifische App-Passwörter.
Ein eigenes App-Passwort ist zum Beispiel sinnvoll für:
- WebDAV-Programme,
- CalDAV- und CardDAV-Clients,
- ältere Synchronisationsprogramme,
- Joplin mit Nextcloud-Synchronisation.
Der Vorteil: Du musst dein eigentliches Kontopasswort nicht an jede Anwendung weitergeben. Außerdem kann einem einzelnen Gerät der Zugriff später wieder entzogen werden.
Ein praktisches Beispiel findest du in meiner aktualisierten Anleitung Joplin mit Nextcloud synchronisieren.
5. 2FA als Administrator erzwingen
Wer mehrere Benutzer verwaltet, kann 2FA auch verpflichtend machen. Das geht unter Administrationseinstellungen → Sicherheit. Nextcloud kann die Pflicht systemweit oder nur für ausgewählte Gruppen setzen.
Per OCC lässt sich der aktuelle Zustand ebenfalls prüfen:
sudo -E -u www-data php /var/www/nextcloud/occ twofactorauth:state BENUTZERNAMECode-Sprache: JavaScript (javascript)
Für alle Nutzer lässt sich die Pflicht beispielsweise so aktivieren:
sudo -E -u www-data php /var/www/nextcloud/occ twofactorauth:enforce --onCode-Sprache: JavaScript (javascript)
Bevor ich so etwas für alle erzwinge, würde ich allerdings testen, ob die benötigten Clients und Wiederherstellungswege funktionieren.
Was tun, wenn der zweite Faktor verloren geht?
Als Benutzer sind die Backup-Codes die beste Rückfallebene. Hat man keine mehr, kann ein Administrator bei unterstützten Providern die 2FA-Methode eines Benutzers über OCC deaktivieren.
sudo -E -u www-data php /var/www/nextcloud/occ twofactorauth:disable BENUTZERNAME PROVIDER_IDCode-Sprache: JavaScript (javascript)
Das sollte natürlich nur nach einer sauberen Identitätsprüfung passieren. Sonst würde aus der Wiederherstellungsfunktion selbst eine Sicherheitslücke.
2FA ist wenig Aufwand für deutlich mehr Schutz
Im Alltag ist der zusätzliche Schritt beim Login schnell Gewohnheit. Dafür bringt 2FA einen echten Sicherheitsgewinn: Ein gestohlenes Passwort reicht nicht mehr aus, um sich direkt an der Nextcloud anzumelden.
Für mein eigenes Setup würde ich mindestens für Administratorkonten TOTP oder einen vergleichbaren zweiten Faktor aktivieren, Backup-Codes sicher ablegen und für externe Programme konsequent App-Passwörter verwenden.
Weiterführend: Nextcloud Benutzerhandbuch zu 2FA und Nextcloud Admin-Dokumentation zu 2FA.
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung:includeSubDomainssolltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind
trusted_proxiesund die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus demnextcloud.logerkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen
nextcloud.logkorrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie/var/www.Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der
config.phpändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud solltedebugnicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
Joplin mit Nextcloud synchronisieren: aktuelle WebDAV-Anleitung
Überarbeitet am 8. September 2026.
Joplin nutze ich bis heute gern für Notizen, weil die App nicht an einen bestimmten Cloud-Anbieter gebunden ist. Besonders praktisch: Die Synchronisation funktioniert weiterhin direkt mit Nextcloud. Damit bleiben Notizen, Anhänge und Aufgaben auf dem eigenen Server, während Joplin die eigentliche Notizverwaltung übernimmt.
Wer Nextcloud noch nicht kennt, findet in meinem Artikel Was bietet Nextcloud 2026? einen aktuellen Überblick. Und wenn deine Nextcloud öffentlich erreichbar ist, lohnt sich zusätzlich der Beitrag Nextcloud richtig absichern.
Table of Contents
Toggle
Was wird eigentlich synchronisiert?
Joplin ist eine lokale Notiz-App mit eigener Synchronisation. Die Notizen liegen also zunächst auf dem jeweiligen Gerät. Über Nextcloud werden anschließend Notizen, Notizbücher, Tags und Ressourcen wie Bilder oder Dateianhänge zwischen den Geräten abgeglichen.
Das ist ein wichtiger Unterschied zur normalen Nextcloud-Notes-App: Joplin verwaltet seine Daten selbst. Der Ordner auf der Nextcloud ist deshalb nicht dafür gedacht, die dortigen Dateien direkt von Hand zu bearbeiten.
1. Einen eigenen Joplin-Ordner in Nextcloud anlegen
Ich lege in Nextcloud zuerst einen eigenen Ordner an, zum Beispiel:
Joplin
Der Ordner sollte ausschließlich von Joplin für die Synchronisation verwendet werden. Die offizielle Joplin-Dokumentation empfiehlt ausdrücklich, diesen Sync-Ordner nicht zusätzlich mit dem Nextcloud-Desktop-Client zu synchronisieren. Sonst arbeiten zwei Synchronisationsmechanismen auf denselben Daten.
2. Die richtige WebDAV-Adresse herausfinden
In Nextcloud findest du die WebDAV-Adresse in der Dateien-App unter den Einstellungen. Je nach Installation kann sie zum Beispiel so aussehen:
cloud.example.de/remote.php/da… JavaScript (javascript)
Joplin unterstützt weiterhin auch die ältere Form:
cloud.example.de/remote.php/we… JavaScript (javascript)
Am einfachsten ist es, die von deiner eigenen Nextcloud angezeigte WebDAV-Adresse zu kopieren und den Ordner Joplin anzuhängen.
3. Nextcloud in Joplin als Synchronisationsziel auswählen
In Joplin öffnest du die Einstellungen und wählst als Synchronisationsziel Nextcloud. Danach werden WebDAV-Adresse, Benutzername und Passwort eingetragen.
Wenn alles stimmt, sollte die Verbindung getestet werden können. Anschließend startet die Synchronisation automatisch beziehungsweise lässt sich manuell anstoßen.
Wichtig bei aktivierter Zwei-Faktor-Authentifizierung
Wenn du für dein Nextcloud-Konto 2FA aktiviert hast, solltest du für Joplin ein eigenes App-Passwort verwenden. Das normale Kontopasswort gehört dann nicht in Joplin.
App-Passwörter kannst du in Nextcloud in den persönlichen Sicherheitseinstellungen erzeugen. So lässt sich der Zugriff für Joplin später auch gezielt wieder entziehen, ohne dein normales Passwort ändern zu müssen.
Typische Fehler bei der Einrichtung
Wenn Joplin nicht synchronisiert, sind es erstaunlich oft dieselben Ursachen:
- die WebDAV-Adresse ist nicht vollständig,
- der Ordner
Joplinwurde vorher nicht angelegt, - Benutzername oder Passwort sind falsch,
- bei aktivierter 2FA wird statt eines App-Passworts das normale Passwort verwendet,
- ein Reverse Proxy oder eine Webserver-Regel blockiert WebDAV-Anfragen.
Joplin führt eigene Logs. Wenn die Synchronisation scheitert, lohnt sich deshalb zuerst ein Blick in das Protokoll der App. Dort steht meist deutlich mehr als nur „Synchronisation fehlgeschlagen“.
Nicht im Nextcloud-Ordner herumeditieren
Ein Punkt aus meiner alten Version des Artikels war missverständlich: Die Dateien im Joplin-Sync-Ordner sehen zwar teilweise nach Textdateien aus, bilden aber zusammen mit weiteren Metadaten den Synchronisationsbestand von Joplin. Dieser Ordner ist kein normales Markdown-Archiv zum manuellen Bearbeiten.
Wenn du einzelne Notizen außerhalb von Joplin brauchst, solltest du die Exportfunktionen von Joplin verwenden, statt im Synchronisationsordner Dateien zu verändern.
Joplin und Nextcloud passen weiterhin gut zusammen
Für mich ist die Kombination weiterhin interessant: Joplin kümmert sich um Notizen, Aufgaben, Anhänge und die lokale Arbeit auf den Geräten; Nextcloud stellt lediglich den selbst gehosteten Synchronisationsspeicher bereit.
Damit muss ich weder Dropbox noch OneDrive nur für meine Notizen verwenden. Gleichzeitig bleibt Joplin flexibel: Sollte ich das Synchronisationsziel irgendwann wechseln wollen, bin ich nicht dauerhaft an Nextcloud gebunden.
Weiterführend: Joplin-Dokumentation zur Nextcloud-Synchronisation und Übersicht der Joplin-Synchronisationsziele.
Nextcloud-Synchronisation | Joplin
Nextcloud ist eine selbst gehostete, private Cloud-Lösung. Es kann Dokumente, Bilder und Videos, aber auch Kalender, Passwörter und unzählige andere Dinge speichern und sie mit Ihrem Laptop oder Te...joplinapp.org
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung:includeSubDomainssolltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind
trusted_proxiesund die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus demnextcloud.logerkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen
nextcloud.logkorrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie/var/www.Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der
config.phpändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud solltedebugnicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
Nextcloud mit Redis und APCu beschleunigen: Caching richtig einrichten
Überarbeitet am 8. September 2026.
Redis gehört bei vielen Nextcloud-Installationen inzwischen fast zur Grundausstattung. Früher hatte ich Redis vor allem eingebaut, weil die Galerie und andere Bereiche gefühlt schneller reagieren sollten. Heute würde ich das genauer formulieren: Für den lokalen Cache ist APCu normalerweise die bessere Wahl, Redis spielt seine Stärke vor allem beim verteilten Cache und beim Transactional File Locking aus.
Gerade das File Locking ist wichtig. Ohne Redis kann Nextcloud dafür die Datenbank verwenden, was unnötig Last erzeugt. Bei einer größeren oder stärker genutzten Instanz lohnt sich Redis deshalb sehr schnell.
Wenn du Nextcloud gerade erst aufsetzt, findest du in meinem Beitrag Was bietet Nextcloud 2026? einen Überblick. Für die Absicherung des Servers habe ich außerdem Nextcloud richtig absichern aktualisiert.
Table of Contents
Toggle
Was macht APCu und was macht Redis?
APCu ist ein sehr schneller lokaler Cache innerhalb von PHP. Nextcloud empfiehlt ihn für memcache.local. Redis eignet sich dagegen besonders für memcache.distributed und memcache.locking.
Auf einem typischen einzelnen Linux-Server sieht eine sinnvolle Kombination deshalb so aus:
'memcache.local' => '\OC\Memcache\APCu',
'memcache.distributed' => '\OC\Memcache\Redis',
'memcache.locking' => '\OC\Memcache\Redis',Code-Sprache: PHP (php)
Für einen sehr kleinen privaten Server reicht laut Nextcloud auch nur APCu. Wer Redis aber ohnehin installiert hat oder die Datenbank beim File Locking entlasten möchte, kann Redis zusätzlich verwenden.
1. Redis und APCu unter Debian oder Ubuntu installieren
sudo apt update
sudo apt install redis-server php-redis php-apcu
Danach prüfe ich zuerst, ob Redis läuft:
systemctl status redis-server
Die PHP-Module kannst du ebenfalls kontrollieren:
php -m | grep -Ei 'redis|apcu'Code-Sprache: JavaScript (javascript)
Je nach Setup muss anschließend PHP-FPM oder der Webserver neu gestartet werden, damit die neu installierten PHP-Module geladen werden.
2. Redis lokal besser per Unix-Socket anbinden
Läuft Redis auf demselben Server wie Nextcloud, empfiehlt die aktuelle Nextcloud-Dokumentation einen Unix-Socket. Dadurch muss Redis nicht über TCP angesprochen werden.
In /etc/redis/redis.conf sollten die Socket-Einstellungen vorhanden beziehungsweise aktiviert sein:
unixsocket /run/redis/redis-server.sock
unixsocketperm 770
Damit der Webserver auf den Socket zugreifen darf, wird der typische Debian-Webserver-Nutzer www-data zur Redis-Gruppe hinzugefügt:
sudo usermod -a -G redis www-data
sudo systemctl restart redis-server
Danach muss auch der PHP-/Webserver-Prozess neu gestartet werden, damit die neue Gruppenmitgliedschaft greift.
3. Nextcloud config.php anpassen
Die Datei liegt bei einer klassischen Installation meistens unter:
/var/www/nextcloud/config/config.phpCode-Sprache: JavaScript (javascript)
Innerhalb des bestehenden Konfigurationsarrays ergänze ich:
'memcache.local' => '\OC\Memcache\APCu',
'memcache.distributed' => '\OC\Memcache\Redis',
'memcache.locking' => '\OC\Memcache\Redis',
'redis' => [
'host' => '/run/redis/redis-server.sock',
'port' => 0,
],Code-Sprache: PHP (php)
Wichtig: Nicht einfach einen zweiten 'redis' => [...]-Block anlegen, wenn bereits einer existiert. Dann muss der vorhandene Eintrag angepasst werden.
Alternative: Redis über 127.0.0.1
Wenn du keinen Unix-Socket nutzen möchtest, kann Redis lokal auch über TCP angesprochen werden:
'redis' => [
'host' => '127.0.0.1',
'port' => 6379,
],Code-Sprache: PHP (php)
Redis sollte dabei nicht ungeschützt am öffentlichen Netzwerk lauschen. Für eine reine lokale Nextcloud gibt es normalerweise keinen Grund, Port 6379 ins Internet freizugeben.
Brauche ich noch requirepass?
In meiner alten Anleitung hatte ich für Redis zwingend ein Passwort über requirepass eingerichtet. Das ist bei einer ausschließlich lokalen Verbindung über einen korrekt berechtigten Unix-Socket nicht zwingend erforderlich. Wer Redis über TCP oder zwischen mehreren Servern betreibt, sollte die Redis-Authentifizierung und Netzwerkkonfiguration dagegen bewusst absichern.
Ein festes Beispielpasswort gehört ohnehin nicht in eine Anleitung – und erst recht nicht in eine produktive config.php.
4. Konfiguration testen
Zuerst prüfe ich Redis selbst:
redis-cli ping
Bei einer TCP-Konfiguration sollte als Antwort PONG erscheinen. Beim Unix-Socket kannst du direkt den Socket angeben:
redis-cli -s /run/redis/redis-server.sock ping
Danach kontrolliere ich Nextcloud:
sudo -E -u www-data php /var/www/nextcloud/occ statusCode-Sprache: JavaScript (javascript)
Zusätzlich lohnt sich ein Blick unter Administrationseinstellungen → Übersicht. Ist kein lokaler Cache konfiguriert oder stimmt etwas mit der Einrichtung nicht, meldet Nextcloud das dort normalerweise ziemlich deutlich.
APCu nicht zu klein dimensionieren
Ein Punkt, der bei größeren Instanzen schnell auffällt: Der Standardwert für den APCu-Speicher kann zu klein sein. Nextcloud nennt 128 MB als sinnvollen Startwert, wenn der Standard nicht reicht. Die Einstellung erfolgt in der passenden PHP-Konfiguration zum Beispiel über:
apc.shm_size=128M
Ob mehr nötig ist, hängt von Anzahl der Benutzer, Apps und PHP-Worker ab. Einfach blind auf mehrere Gigabyte hochdrehen würde ich nicht.
Was Redis nicht automatisch schneller macht
Redis ist kein Wunderknopf für eine langsame Nextcloud. Wenn PHP-FPM falsch dimensioniert ist, die Datenbank hängt, die Platte langsam ist oder Vorschaubilder den Server beschäftigen, wird Redis diese Probleme nicht plötzlich verschwinden lassen.
Seine größten Vorteile liegen in sauberem Caching und vor allem darin, die Datenbank beim Transactional File Locking zu entlasten. Zusammen mit APCu ergibt das für viele selbst gehostete Installationen eine sehr sinnvolle Kombination.
Wenn du deine Nextcloud generell überarbeitest, lohnt sich auch mein Artikel zum sicheren Verschieben des Nextcloud-Datenverzeichnisses per Bind Mount.
Weiterführend: Nextcloud-Dokumentation zu Memory Caching und Transactional File Locking.
Was bietet Nextcloud 2026? Mehr als nur eine private Cloud | Das Netz und ich
Nextcloud ist längst mehr als Datei-Sync: Files, Kalender, Kontakte, Talk, Office, Fotos, Aufgaben, RSS und viele Apps – ein Überblick für Einsteiger.lars (Das Netz und ich)
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung:includeSubDomainssolltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind
trusted_proxiesund die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus demnextcloud.logerkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen
nextcloud.logkorrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie/var/www.Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der
config.phpändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud solltedebugnicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
Shitty hard right rich douche put together dotfiles for arch, called it a distro, and was given lots of money from 1password.
DHH being a hard right rich douche is not news, but 1password giving $300k to aforementioned hard right asswipe is recent news.
Thats a reasonable summary IMO.
It's a new pre-configured hyprland/arch distro, that raised $15 million dollars somehow. The founder of Omarchy is DHH, the creator of Ruby-on-rails.
The distro is probably AI/vibe-coding, setup to give LLM agents easy access to the system. Some of the previously mentioned $15 million is actually in the form of donated AI credits to code the distro with.
The distro has some controversial decisions like bundling Spotify and Zoom into the install, when Linux (and especially arch) is known for low bloat and user choice.
Some of the money they've raised is going to Vaxry the dev of Hyprland. There are various opinions on this, a lot of people like hyprland but Vaxry is kinda insane polish dude obsessed with anime porn.
Overall I think most people care because it's a lot of money raised for a distro, especially when people disagree with the developmental decisions and goals. People would rather see that money go to other places, and are questioning why so many companies were willing to sponsor Omarchy specifically.
The founder of Omarchy is DHH, the creator of Ruby-on-rails.
Oh, I remember that guy. He sucks. Of course big tech is giving him money to make a dodgy linux.
Now I feel so learned. Thanks!
Cant find the post on Twitter. This seems fake
Edit: Seems he deleted it, obviously
Omarchy’s Kitty Config Exposed Users to Remote Code Execution
Omarchy has changed its Kitty configuration after a security issue was identified with allow_remote_control yes.
That setting allows Kitty’s remote-control protocol to accept commands from terminal output, meaning untrusted output could potentially execute commands as the current user. Kitty itself defaults this setting to no; the exposure came from Omarchy explicitly enabling it so other parts of the desktop could query the active terminal’s working directory.
The change disables remote control by default and migrates existing explicit yes settings to no. Users affected by the migration need to fully close and reopen Kitty, as existing processes remain exposed until they exit.
There is a small trade-off: Omarchy can no longer reliably determine the active Kitty tab/pane’s working directory via its socket, so new terminal or Files launches may occasionally fall back to the home directory.
The associated migration tests reportedly pass, although no live Kitty test was run in the test environment.
Disable unrestricted Kitty remote control by ErikMelton · Pull Request #10527 · omacom/omarchy
Kitty currently ships with allow_remote_control yes, allowing untrusted terminal output to issue commands through Kitty's remote-control protocol. Set the default to no and migrate existing exp...GitHub
like this
bretton.dev likes this.
In Kitty’s defense, the docs mention the risks involved with full remote control, and there several ways to control the scope of permitted actions.
It’s tricky though. I’d like my coding agent to be able to control the terminal, but I’ve found it harder to sandbox kitty than, say, a multiplexer like tmux/zellij. Herdr is a bit less obvious.
Omarchy can no longer reliably determine the active Kitty tab/pane’s working directory via its socket
Imagine this as the reason to allow remote access without questions. I watched an interview and he is proud to fix those issues (there were a few more security issues of this stupidity class) and thinks this is totally normal. And over time after fix after fix, Omarchy will become secure. He admits Omarchy is unsecure at this time. Edit: I should probably link to the interview in question: Invidious or YouTube
The users are just beta testers, risking getting hacked. I could not trust this project. Even if all issues are fixed, who says no new security issues will make into the project? Omarchy is worse than Ubuntu and Manjaro combined.
Omarchy Is A Security Mess... But
Since Omarchy popped off there have been a bunch of people spending a ton of time trying to find security issues with the distro but that's not a surprise.Fu...Tech Over Tea (YouTube)
Nextcloud richtig absichern: praktische Sicherheitstipps für den eigenen Server
Überarbeitet am 8. September 2026.
Eine eigene Nextcloud ist praktisch, aber sie hängt bei vielen von uns direkt am Internet. Damit reicht es nicht, Nextcloud einmal zu installieren und danach jahrelang nicht mehr anzufassen. Zum Glück bringt Nextcloud inzwischen schon viele sinnvolle Schutzmechanismen mit. Ein paar Dinge muss man als Administrator trotzdem selbst sauber einstellen.
Ich gehe hier bewusst nicht in Richtung Hochsicherheits-Rechenzentrum. Es geht um die Maßnahmen, die bei einer selbst gehosteten Nextcloud auf einem Linux-Server wirklich etwas bringen und die man auch dauerhaft pflegen kann.
Table of Contents
Toggle
1. Nextcloud, Apps und Server aktuell halten
Der wichtigste Punkt ist gleichzeitig der langweiligste: Updates. Nextcloud selbst, installierte Apps, PHP, der Webserver und das Betriebssystem sollten regelmäßig aktualisiert werden. Gerade bei öffentlich erreichbaren Diensten werden Sicherheitslücken früher oder später auch automatisiert gescannt.
Nach einem Nextcloud-Update schaue ich deshalb immer in Administrationseinstellungen → Übersicht. Dort meldet Nextcloud fehlende Datenbankindizes, Sicherheitsheader oder andere Probleme, die nach einem Versionswechsel auftauchen können.
2. HTTPS ist Pflicht
Eine Nextcloud sollte öffentlich ausschließlich über HTTPS erreichbar sein. Ein gültiges TLS-Zertifikat gibt es zum Beispiel kostenlos über Let’s Encrypt. Unverschlüsseltes HTTP sollte auf HTTPS umgeleitet werden.
Zusätzlich empfiehlt Nextcloud HSTS. Bei Nginx kann das zum Beispiel so aussehen:
add_header Strict-Transport-Security "max-age=15552000; includeSubDomains" always;Code-Sprache: JavaScript (javascript)
Achtung: includeSubDomains solltest du nur verwenden, wenn wirklich alle Subdomains deiner Domain per HTTPS funktionieren. Das optionale HSTS-Preloading würde ich erst aktivieren, wenn du genau weißt, welche Folgen das hat – ein Zurücknehmen kann lange dauern.
3. Zwei-Faktor-Authentifizierung aktivieren
Ein starkes Passwort ist gut. Noch besser ist ein zweiter Faktor. Nextcloud unterstützt unter anderem TOTP-Apps und je nach Einrichtung auch WebAuthn beziehungsweise Sicherheitsschlüssel.
Für Administratorkonten würde ich 2FA auf jeden Fall aktivieren. Für Apps oder ältere Clients, die keinen zweiten Faktor abfragen können, verwendet Nextcloud eigene App-Passwörter. Damit muss das normale Kontopasswort nicht in jedem Client hinterlegt werden.
4. Brute-Force-Schutz nicht abschalten
Nextcloud bringt bereits einen eingebauten Brute-Force-Schutz mit. Wiederholte fehlerhafte Anmeldungen werden gedrosselt beziehungsweise blockiert. Dieser Schutz ist standardmäßig aktiv und sollte auch aktiv bleiben.
Wichtig wird das bei einem Reverse Proxy: Nextcloud muss die echte IP-Adresse des Besuchers erkennen. Sind trusted_proxies und die Weiterleitung der Client-IP falsch eingerichtet, sieht Nextcloud möglicherweise nur die Adresse des Reverse Proxys. Im schlechtesten Fall wird dann der gesamte Verkehr so behandelt, als käme er von einer einzigen IP.
5. Fail2ban als zusätzliche Schutzschicht
Zusätzlich zum eingebauten Schutz kann Fail2ban sinnvoll sein. Dabei werden wiederholte fehlgeschlagene Anmeldungen aus dem nextcloud.log erkannt und die betreffende IP bereits auf Betriebssystemebene geblockt. Dadurch müssen Webserver, PHP und Nextcloud diese Verbindungen gar nicht erst weiterverarbeiten.
Die offizielle Nextcloud-Dokumentation enthält dafür inzwischen ein eigenes Filter- und Jail-Beispiel. Wichtig ist, den Pfad zum eigenen nextcloud.log korrekt einzutragen und den Filter nach der Einrichtung wirklich zu testen.
6. Datenverzeichnis außerhalb des Webroots
Nextcloud empfiehlt, das Datenverzeichnis außerhalb des Webroots zu platzieren. Bei einer neuen Installation sollte man das direkt berücksichtigen. So liegen die eigentlichen Nutzerdaten nicht irgendwo unterhalb eines öffentlich ausgelieferten Webverzeichnisses wie /var/www.
Bei einer bestehenden Installation sollte man allerdings nicht einfach den Pfad in der config.php ändern und die Dateien verschieben. Dafür habe ich meine alte Anleitung inzwischen ebenfalls überarbeitet: Nextcloud-Datenverzeichnis sicher verschieben.
7. Debug-Modus auf Produktivsystemen ausschalten
In einer produktiven Nextcloud sollte debug nicht aktiviert sein. Der Debug-Modus ist für gezielte Fehlersuche und Entwicklungsumgebungen gedacht, nicht für den Dauerbetrieb eines öffentlich erreichbaren Servers.
8. SSH und den Linux-Server absichern
Auch die beste Nextcloud-Konfiguration bringt wenig, wenn der Server darunter offen wie ein Scheunentor ist. Für SSH nutze ich deshalb lieber Schlüssel statt Passwort-Anmeldung. Direkter Root-Login sollte deaktiviert werden, sobald ein funktionierender Benutzer mit sudo-Rechten vorhanden und getestet ist.
Eine Firewall sollte nur die Ports freigeben, die tatsächlich benötigt werden. Bei einem typischen öffentlich erreichbaren Server sind das beispielsweise HTTPS und gegebenenfalls SSH. Datenbank-Ports gehören normalerweise nicht offen ins Internet.
9. Backups gehören zur Sicherheit dazu
Ein Backup verhindert keinen Angriff, aber es entscheidet oft darüber, ob ein Fehler oder kompromittiertes System eine Katastrophe wird. Zu einer vollständigen Nextcloud-Sicherung gehören mindestens die Konfiguration, das Datenverzeichnis und die Datenbank. Bei eigenen Apps und Themes müssen auch diese berücksichtigt werden.
Wichtig ist nicht nur, dass irgendein Backup-Job grün leuchtet. Eine Wiederherstellung sollte zumindest gelegentlich getestet werden. Sonst merkt man den Fehler im Sicherungskonzept ausgerechnet dann, wenn man die Daten wirklich braucht.
10. Die Admin-Übersicht regelmäßig ansehen
Mein einfachster Tipp zum Schluss: Öffne regelmäßig die Administrationsübersicht deiner Nextcloud. Die dortigen Sicherheits- und Einrichtungswarnungen sind keine Dekoration. Nextcloud erkennt inzwischen erstaunlich viele typische Fehlkonfigurationen selbst und sagt ziemlich genau, was noch fehlt.
Wer diese Punkte umsetzt, hat schon eine ziemlich solide Basis: aktuelle Software, HTTPS, 2FA, funktionierender Brute-Force-Schutz, ein abgesicherter Server und brauchbare Backups. Viel wichtiger als zwanzig exotische Härtungstricks ist, dass diese Grundlagen dauerhaft gepflegt werden.
Weiterführend: Nextcloud Hardening and Security Guidance und Nextcloud Backup-Dokumentation.
Nextcloud-Datenverzeichnis verschieben: sicherer Weg mit Bind Mount | Das Netz und ich
Nextcloud-Daten auf eine andere Platte oder Partition verschieben, ohne den datadirectory-Pfad zu ändern: sicherer Ablauf mit Wartungsmodus, rsync und Bind Mount.lars (Das Netz und ich)
SlowTVStitchery - Episode19
When Worlds COLLIDE (Outer Wilds RANDOMIZER ANY% Playthrough)
0:00 Coming Up/Intro
0:58 Timber Hearth/Attlerock
8:00 Brittle Hollow
14:17 White Hole Station and Beyond
15:27 A Fool Out of Air!
16:30 Timber Hearth/Attlerock
17:38 Hourglass Twins
22:01 Go With God
23:07 Giant's Deep
30:32 Twin Impact!
30:55 Timber Hearth
31:58 Hourglass Twins
36:49 Why Does This Keep Happening to Me?
37:27 Timber Hearth
37:49 Hollow's Lantern/Brittle Hollow
40:17 Giant's Deep
41:25 Moon
42:42 Sun Station Smash
44:04 Deep Space Impact!
44:48 Dark Bramble
46:41 Giant's Deep (Whoa...)
49:25 When Worlds Collide
53:59 Interloper (Success!)
56:16 Status Check
56:42 Brittle Hollow
59:55 Brittle Bash!
1:00:13 Timber Hearth
1:01:24 Giant's Deep
1:02:15 Hourglass Twins
1:02:55 Moonscan
1:03:30 Home Stretch (Watch for Fishies)
!SPOILER WARNING!
If you haven't played Outer Wilds or its associated DLC "Echoes of the Eye," please do NOT watch this video (or any other) until you have. Outer Wilds is a game of discovery in the most rewarding way. Once you have that knowledge, a core part of the game can never be experienced again. It's such a blast to play, and I guarantee you'll thank yourself for doing so.
With that out of the way, welcome to my Archipelago Randomizer challenge! The aim with this attempt is to complete enough of the 87 randomized checks scattered throughout the solar system to help me warp to the Eye of the universe and finish it off, all in one session! These checks cover virtually every location within the base game. To clarify, the items/abilities obtained from the checks are random (as are other aspects of the game, such as shuffled ghost matter), but the locations of the checks are not (e.g. a random item/ability is always found* when reading the second scroll in the Construction Yard on Giant's Deep).
*There can also be traps laid in a check, such as sudden ship damage or a suit puncture.
So, what's an Archipelago Randomizer? From the mod page:
"Randomizers in the Archipelago sense—which are sometimes called 'Metroidvania-style' or 'progression-based' randomizers—rely on the base game having several progression-blocking items you must find in order to complete the game. In Outer Wilds progression is usually blocked by player knowledge, so to make a good randomizer we take away some of your starting equipment (Translator, Scout, Signalscope, etc), and turn much of that player knowledge into items (using warp platforms now requires a 'Nomai Warp Codes' item, using the special GD tornado now requires a 'Tornado Aerodynamic Adjustments' item, etc.). These 'items' are then placed at randomly selected 'locations' while ensuring the game can still be completed."
I normally incorporate the following rules: no map, no hints, no ship log, no meditation, and no velocity matching. However, this time all is fair game, as this is an "ANY%" run. In addition to that, I'll have specific mods applied, such as a certain "strange" large structure now visible in the sky so I don't accidentally run into it (again).
Finally, a big thank you to the great minds at Mobius Digital for developing such a stellar game and to the many contributors in the modding community for creating the perfect excuse for me to revisit the fun physics of this clockwork solar system! Check out the links below for more info on the game and mods:
The Influence of Tire Typology on Pyrolysis Efficiency and Product Yield Dynamics
Scrap tire recycling via thermal pyrolysis represents a critical engineering frontier for mitigating global elastomer waste. However, industrial operators frequently encounter operational inefficiencies when processing heterogeneous feedstock streams. Scrap tires are far from uniform; they vary dramatically by vehicle classification, manufacturing origin, structural reinforcement, and chemical compounding. Passenger car tires, commercial truck tires, and specialized off-the-road tires possess distinct morphological and chemical profiles that directly dictate pyrolytic heat transfer rates, volatile matter evolution, and the ultimate yield distribution of pyrolytic oil, recovered carbon black, and steel wire.
Elastomer Blends and Macromolecular Pyrolysis Kinetics
The core of any tire matrix comprises a complex blend of synthetic and natural elastomers, primarily natural rubber, styrene-butadiene rubber, and polybutadiene. Each polymeric constituent exhibits distinct thermal degradation kinetics and volatilization thresholds. Natural rubber undergoes thermal cleavage at lower temperature intervals, yielding high initial volatile fractions, whereas synthetic styrene-butadiene copolymers require elevated thermal plateaus to achieve complete depolymerization.
Consequently, tires with high natural rubber content decompose more rapidly under initial heating in pyrolysis machine, whereas heavy-duty truck tires—which heavily utilize synthetic blends for enhanced tread wear resistance—demand extended residence times and higher peak reactor temperatures to prevent incomplete thermal cracking and residual heavy tar accumulation.
Reinforcement Architecture and Thermal Conduction
Beyond polymer chemistry, the internal physical architecture of a tire exerts a profound influence on reactor thermodynamics. Passenger car tires typically feature high textile cord content and lighter steel belts, whereas heavy commercial vehicle tires incorporate dense, multi-ply steel wire matrices.
Steel Content and Thermal Conductivity Variations
The presence of substantial steel fractions alters the bulk thermal conductivity of the charge. Steel acts as a localized thermal conductor, accelerating heat penetration into the center of the shredded tire matrix. However, an excessive accumulation of unseparated steel wire inside a continuous tyre pyrolysis plant can cause mechanical wear, bridge feeding mechanisms, and interfere with uniform bed temperatures. Furthermore, the metal fraction absorbs thermal energy without undergoing volatilization, shifting the mass balance calculations and requiring careful calibration of the energy inputs supplied to the primary pyrolytic reactor.
Compounding Additives and Mineral Filler Impacts
Tire manufacturing involves intensive chemical compounding, incorporating reinforcing fillers such as commercial carbon black, mineral silica, sulfur vulcanizing agents, and metallic oxides like zinc oxide. These inorganic additions do not vaporize during the thermal degradation phase; instead, they concentrate entirely within the solid residue, fundamentally altering the quality of the recovered carbon black.
High-silica passenger tires yield a solid residue contaminated with amorphous silicon dioxide, which limits its direct reinjection into high-performance rubber compounding without prior acid leaching or chemical beneficiation. Conversely, heavy truck tires with high carbon black loadings produce a more structurally robust solid residue that, with proper mechanical milling and pelletization, achieves high market valorization.
Volatile Fraction Condensation and Liquid Oil Specification
The chemical composition of the input tire type directly dictates the boiling range and heteroatom concentration of the resulting pyrolytic oil. Passenger tires, containing varied plasticizers and synthetic rubber formulations, generate a highly complex liquid condensate rich in aromatic hydrocarbons, sulfur compounds, and nitrogenated molecules. This requires sophisticated multi-stage fractional distillation and catalytic hydrotreatment to remove contaminants before the oil can be co-processed in conventional refineries. Heavy truck tires, dominated by different vulcanization packages, yield distinct boiling curve distributions that necessitate precise dew-point control within the condensation train to prevent pipe fouling and coking.
Tailoring Operational Parameters for Feedstock Variability
The inherent variability among tire typologies necessitates flexible, highly responsive operational parameters within commercial pyrolysis facilities. Operators cannot apply a static temperature profile or uniform residence time to a mixed batch of passenger and truck tires. Optimizing thermal efficiency requires rigorous pre-sorting, mechanical size reduction, and feed-stream homogenization. By categorizing incoming scrap tires by vehicle classification and structural composition, facility managers can fine-tune reactor heating ramps, optimize syngas recovery trains, and maximize the commercial value of both liquid condensates and solid carbonaceous outputs, securing long-term economic resilience in the competitive chemical recycling sector.
Continuous Tyre Pyrolysis Plant | 24 Hours*5 Days
Continuous tyre pyrolysis plant is an excellent choice for investors seeking a sustainable and profitable recycling method.bestonmachinery (Beston Group)
Bluefin Server — Cloud-native home infrastructure from Project Bluefin
Bluefin Server — Cloud-native home infrastructure from Project Bluefin
The Bluefin experience for your homelab. Image-based, auto-updating, zero maintenance. One management suite for every node, every service, and every container you run at home.Project Bluefin
Lots. Immich, Jellyfin, Ollama, Homeassistant, Frigate, Nextcloud, Navidrome, *arr stack, Find my Device Server, various monitoring/logging tools (mainly Grafana stack), etc.
Totally overkill for my use case but it's for learning as well since I'm starting to use K8s at work.
Find my Device Server
is there a project page for this? is this the one that using the android app?
Yes is is.
fmd-foss.org/docs/fmd-server/o…
They have a public instance you can use but if you're going to have things like location tracking and device wipe enabled then it's probably better to self host.
Bluefin Dakota Alpha 1
Bluefin Dakota Alpha 1 | Bluefin
Today we celebrate a nice milestone for the project. Thanks to some awesome work by the team we have a mostly daily-driveable Alpha 1. GNOME 50 too!Jorge O. Castro (docs.projectbluefin.io)
Community Camp 4 Palestine 06.09.2026
Thermodynamic and Harmless Valorization of Municipal Sludge via Pyrolytic Treatment
Municipal wastewater treatment facilities generate astronomical volumes of dewatered sludge daily, presenting an escalating logistical and ecological challenge. Comprising complex organic matrices, pathogenic microorganisms, heavy metals, and persistent trace pollutants, raw sludge resists safe long-term containment. Traditional management pathways, including direct agricultural application, landfilling, and conventional incineration, face tightening regulatory constraints due to groundwater contamination risks, greenhouse gas emissions, and toxic ash management burdens. In response to these vulnerabilities, industrial pyrolysis—defined as the thermal degradation of carbonaceous matter in an oxygen-depleted environment—emerges as a premier engineering paradigm for harmless disposal and resource valorization.
The Imperative of Advanced Municipal Sludge Sanitization
Ensuring total pathogen destruction and the elimination of emerging organic contaminants is the foundational requirement for any municipal sludge management protocol. Conventional biological stabilization techniques frequently fail to eradicate resilient pharmaceutical residues, endocrine-disrupting chemicals, and pathogenic spores completely. Thermochemical processing bridges this critical performance gap. Exposing the sludge matrix to elevated temperatures eradicates biological activity entirely, instantly decomposing volatile organic compounds and thermal-sensitive pollutants. This complete sanitization shifts the operational framework from hazardous waste containment to sustainable material transformation.
Thermochemical Mechanisms and Reactor Kinetics
The execution of sewage sludge treatment plant with pyrolysis technology relies on precise thermodynamic control within specialized industrial equipment, such as indirect-fired rotary kilns, fluidized beds, or continuous screw conveyors. Operating typically within a temperature threshold of 450 degrees Celsius to 850 degrees Celsius, these reactors supply the necessary thermal energy to drive the endothermic cleavage of high-molecular-weight polymers, including proteins, lipids, and humic substances. Because the reactor operates under sub-stoichiometric or completely inert conditions, complete combustion is prevented. Instead, the reaction kinetics favor devolatilization, carbonization, and structural aromatization, yielding three distinct product streams: a stable solid carbonaceous residue, condensable bio-oil, and non-condensable syngas.
Volatilization and Carbon Matrix Encapsulation
As thermal energy transfers through the moist sludge matrix, interstitial water is rapidly vaporized, paving the way for thermal cracking of organic fractions. The volatile gases escape the solid phase and are subsequently captured or condensed, while the remaining solid fraction undergoes severe volumetric shrinkage. This process forms a dense, highly stable pyrolytic char. Crucially, inorganic mineral phases and heavy metals—such as chromium, nickel, lead, and cadmium—are chemically and physically encapsulated within the expanding carbon lattice. This structural entrapment drastically suppresses their environmental mobility and leachability, neutralizing the primary ecological hazard associated with raw sludge disposal.
Environmental Abatement and Heavy Metal Stabilization
Atmospheric protection and leachate mitigation represent core advantages of pyrolytic treatment over traditional incineration. Because pyrolysis avoids the oxygen-rich combustion environment characteristic of incinerators, the formation of noxious sulfur dioxide and nitrogen oxides is profoundly suppressed. Furthermore, volatile inorganic compounds and condensable tars are routinely captured within integrated scrubbing systems or thermally destroyed inside secondary reaction chambers. This inherent emission control architecture bypasses the requirement for capital-intensive flue gas cleaning trains, offering municipal authorities a compliant, streamlined operational profile. The resulting solid residue, exhibiting negligible leachability under standardized testing protocols, eliminates long-term sub-surface liabilities.
Energetic Autonomy and Resource Recovery
Beyond environmental decontamination, industrial pyrolysis achieves exceptional thermodynamic efficiency through internal energy recovery loops. The non-condensable gases generated during thermal cracking—comprising hydrogen, carbon monoxide, methane, and light hydrocarbons—possess significant calorific value. By scrubbing and recirculating this syngas to feed the primary thermal reactor or power auxiliary mechanical drives, the facility achieves operational energetic autonomy. This closed-loop configuration neutralizes the massive thermal energy penalties typically incurred during the preliminary drying of high-moisture municipal sludge. By converting a persistent environmental liability into a secure geomaterial and a reliable energy source, pyrolysis establishes an indispensable foundation for advanced municipal resource recovery.
Sewage Sludge Treatment Plant - Sludge Pyrolysis to Biochar
A sewage sludge pyrolysis treatment plant reduces waste volume by up to 90%, harmlessly eliminates pollutants, and produces biochar.Beston Group
Latin American Local Assembly vs Chinese Import Which Model Truly Reduces Your Initial Procurement Price
In the competitive road and bridge construction industry across Latin American markets, securing reliable machinery while controlling capital expenditure is a constant challenge. Project contractors and equipment dealers frequently face a tough decision when sourcing new production units: should you invest in a equipment locally assembled within Latin America, or should you import a complete plant directly from Chinese manufacturers? While both options have distinct advantages, understanding how each model affects your upfront capital output is essential for making a sound financial investment.
To make an informed purchasing decision, contractors must carefully evaluate every factor that contributes to the final price tag. The initial acquisition cost encompasses not just the factory base quote, but also international shipping rates, import duties, assembly labor, and regional supply chain factors. By breaking down these cost components, contractors can accurately determine which sourcing strategy delivers the best value for their specific operational needs and budgetary limits.
Analyzing the Base Asphalt Plant Price Breakdown
When comparing local assembly against direct imports, the base asphalt plant price(precio de planta de asfalto) remains the primary benchmark for budget planning. Chinese manufacturers benefit from massive economies of scale, extensive supply chain networks, and lower raw material procurement costs. As a result, direct factory quotes for complete imported systems often come in significantly lower than local assembly alternatives.
Local assembly facilities in Latin America typically import key technological components—such as burners, control software, and high-precision sensors—from global suppliers, while fabricating heavier structural elements like aggregate bins, dryer drums, and frame supports locally. Although this hybrid approach reduces international freight volume, higher local steel prices and smaller production runs can elevate the base production cost. Consequently, the ex-factory asphalt plant price for locally assembled units often reflects higher manufacturing overhead compared to direct Chinese imports.
Import Tariffs and Custom Duties Impact
Customs duties and trade agreements play a pivotal role in shaping the final landed equipment cost across Latin American countries.
- Trade agreements: Regional trade pacts can make locally assembled machinery more appealing if components move tax-free between partner nations.
- Tariff variations: Direct imports from China may face varying tariff brackets depending on the destination country, sometimes adding a noticeable percentage to the total outlay.
- Tax incentives: Certain infrastructure initiatives offer temporary import tax exemptions for complete machinery, offsetting potential tariff penalties.
Understanding these trade dynamics helps contractors calculate whether local assembly tax perks outweigh the lower base price of direct imports.
Total Investment for Compact and Portable Systems
For short-term projects, urban road repairs, or remote bridge access roads, contractors often prefer smaller or movable setups. Evaluating the mobile asphalt plant price(planta de asfalto móvil precio) requires looking beyond the sticker price to account for freight and logistics complexities.
| Cost Factor | Chinese Direct Import | Latin American Local Assembly |
|---|---|---|
| Base Manufacturing Cost | Lower due to scale | Higher due to component imports |
| Shipping & Logistics | Higher overseas freight fees | Lower local transportation fees |
| Delivery Timetable | Longer transit time | Faster regional delivery |
| Customization Options | Standardized modular designs | Tailored regional adaptations |
Mobile Units Freight and Mobility Logistics
Transporting fully mobile equipment involves shipping multi-axle chassis, towing mechanisms, and compact mixing units across ocean routes. While Chinese suppliers offer highly competitive initial machinery costs, long-distance maritime freight and heavy-lift handling fees can inflate the final delivered mobile asphalt plant price. Conversely, local assembly plants can deliver portable units directly by road, cutting down international shipping expenses and simplifying overall transport logistics.
Mini Units for Targeted Projects
For niche applications requiring modest output, a mini asphalt plant(mini planta de asfalto) provides an economical entry point for small-to-midsize contractors.
- Reduced capital expenditure: Small-capacity mixing units require significantly less initial capital, lowering the barrier to market entry.
- Faster installation: Compact designs mean minimal foundation work and rapid setup times on bridge decks or narrow site paths.
- Lower shipping volume: Small footprints allow a mini asphalt plant to fit inside standard container units, drastically cutting ocean transport costs for Chinese imports.
Because smaller equipment fits standard ocean containers, buying a compact system from overseas often preserves the low base price advantage without incurring excessive heavy-cargo shipping surcharges.
Key Considerations Beyond the Initial Price Tag
While upfront cost is a decisive factor, equipment long-term value depends on operational reliability, spare parts availability, and technical support.
Component Quality and Engineering Standards
Chinese machinery producers have made substantial advancements in build quality, leveraging automated welding, precise laser cutting, and standardized modular manufacturing. Meanwhile, regional Latin American assemblers often tailor structural designs specifically for local aggregate conditions and rugged terrain, which can enhance equipment longevity in demanding environments.
After-Sales Service and Spare Parts Availability
- Local support: Regional assembly plants usually offer faster technician response times and immediate access to replacement parts stocked domestically.
- Digital support: Leading export suppliers provide 24/7 remote diagnostic assistance and maintain regional distribution hubs to dispatch critical components quickly.
Contractors must weigh the convenience of immediate local service against the overall cost savings offered by direct overseas purchasing.
Making the Final Sourcing Determination for Your Project
Choosing between local assembly and direct importing ultimately comes down to your project timeline, overall budget, and logistics capabilities. Importing directly from Chinese manufacturers generally yields a lower base asphalt plant price, especially for containerized units and small-scale machinery where shipping costs remain manageable. On the other hand, local assembly models offer advantages in delivery speed and local regulatory compliance, though often at a higher initial capital outlay.
By analyzing the full picture—including the mobile asphalt plant price, freight logistics, customs tariffs, and site requirements—contractors can choose the model that delivers maximum cost efficiency for their asphalt production operations. For contractors looking to maximize profitability on limited bridge and road construction budgets, opting for a high-efficiency mini asphalt plant or standard imported unit remains one of the most effective strategies to lower initial procurement expenses.
Planta de Asfalto Precio | Guía de Inversión y Costos - Macroad
¿Busca planta de asfalto precio en LatAm? Desde $60k a $1.2M. Vea costos de envío, consumo de combustible y pida su cotización directa aquí.AIMIXgrupo (AIMIX GROUP)
When Living the Dream Becomes a Nightmare
Beautiful wife, two kids, family pet. All gone because she went back to college.
#Redonkulas #ModernWomen #CultureWar
To donate to this content, see our list of channels, purchase merchandise or join Popp’s Preppers, click here: linktr.ee/redonkulas
Send physical donations to:
Redonkulas.com Productions
29488 Woodward Avenue, Unit 407
Royal Oak, MI 48073
If you write a check, make it out to Second Class Citizen, 501c3
All donations are tax deductible
And be sure to tune in to see the Redonkulas Regiment Live!
Tuesday and Thursday at 8pm Eastern time!
And
Supporter Sunday streams for Locals, Odysee, and SubscribeStar members only!
All sources available on Redonkulas.com!
Is there a way to hide/remove categories shown in the categories tab of the app?
like this
Auster likes this.
Breaking News (Sun May 28 16:38:01 GMT 2023)
- Iraq's National Security Advisor due in Tehran
- Russian troops thwart Ukrainian offensive in South Donetsk
- IGAD Condemns Attack on Ugandan Peacekeepers in Somalia
- Cuban President praises attitude in the face of adversities in the central province of Villa Clara
- White House & Republicans Reach Debt Ceiling Deal in Principle
- Erdogan leads presidential race: Anadolu
- Belgorod Oblast Governor Gladkov: Poles and Americans were among the attackers on Belgorod Oblast
- Moscow Warns West Against ‘Playing with Fire’
- Texas House Impeaches Attorney General Over Corruption
- Ukraine Open Thread 2023-129
- The MoA Week In Review - (Not Ukraine) OT 2023-128
Wordle Hint Today
Wordle Hint Today offers gradual clues and letter reveals for faster solving progress to keep the Wordle streak alive. Explore hints without spoilers!Wordle Hint Today
Koa's little mud bath 😂 06/09/2026
Because the pond is quite low from a dry summer, the recent rains have created a gloriously thick, squishy border of mud along the water's edge. Unable to resist the allure of the muck and an abandoned ball, he enthusiastically marches right off the dry sand and plunges his paws straight into the deep, wet mud, his tail wagging with pure delight. Yolande carefully navigates the slippery bank, keeping pace with the eager pup while jokingly calling him a "smeerkees". Koa happily splooshes through the shallows, thoroughly investigating the mud and treating himself to a very enthusiastic, messy spa day. Cynni follows along, making sure this hilarious adventure is perfectly documented for the memories.
Koa's snack attack! 05/09/2026
Suddenly, his attention shifts. Koa looks up directly at the camera, his bright, loving eyes locking onto Cynni. With the giant chew stick still held proudly in his mouth like a prized trophy, he scrambles up from his bed. He trots enthusiastically straight toward the camera. The video ends in a hilarious and heartwarming "snack attack" as Koa shoves his sweet, goofy face and his beloved chew stick directly into the camera lens, playfully showering Cynni with puppy love and giving them a very close-up view of his new treasure.
I changed my license
cross-posted from: feddit.org/post/35110129
This year I decided to switch my “default license” to EUPL-1.2. This is an OSI-approved free software license created and published by the European Union. And it is quite a divergence from the licenses I’ve used in the past. EUPL is a strong copyleft license that closes the “SaaS loophole” by requiring reciprocal licensing regardless of how the software is distributed.Over the years it has been clear that we in the “open source” camp (as opposed to the “free software” camp) were wrong all along.
We won the debate, and gained little for users or developers. All that our efforts did was to make it easier for big corporations build things more cheaply and for billionaires to become trillionaires.
And so it is time to stop messing about with permissive licenses. If corporations don’t want to use our software under our terms, they are free to spend the effort or tokens to build their own.
I changed my license
In the last 28 years of publishing software, I’ve had three distinct eras of software licensing. All of my recent stuff is available under the European Union Public License 1.2, and I thought to explain why.Henri Bergius
like this
bretton.dev likes this.
don't like this
bretton.dev doesn't like this.
Personally, I also think that much of the hate which one would find e.g. on reddit or the orange site against copyleft licenses in general, and the GPL specifically was probably astroturfing from corporations for which it was just an obstacle to appropiate more unpaid volunteer work for the commons for free.
For the Linux kernel - and for GNU/Linux as an OS - the GPL was never a problem. On the contrary: Without it, the kernel would not be what it is (the historic Torvalds - Tanenbaum debate shows the reasons quite clearly).
The same is true, by the way for the GNU Guix project: Very few arguments against it are logical or really hold water. It is, for example, perfectly possile to publish a Guix channel for a commercial game or proprietary software on ones own web site - just as you can do with a docker image. And the way Guix takes care of dependencies and updates makes it probably the easiest way to do such. Because you can use Guix as a package manager on most distros - I use it both on Debian and Arch - I find it more reasonable than using snaps, docker, or flatpaks.
The reason for the hate is likely something else: That you can't commercialise and embrace the whole, source-based ecosystem.
For example, you can't use the Guix infrastructure (e.g. their mailing list or download server) to promote or advertise commercial, non-free stuff.
But expecting or demanding to be able to do that is just ridiculous: Nobody expects from Microsoft or Apple that they feel obliged to promote or market Adobe or Oracle products. Alone the idea that companies could demand that shows how entitled the corporations behave in respect to free software.
like this
Infrapink likes this.
don't like this
bretton.dev doesn't like this.
was probably astroturfing from corporations
Could be. At least when I still was on r/linux a few years ago there were about three usual suspects who would pop up every time a topic even went in the general direction of licensing and spewed their toxicity. To me these people had less of a corporate shill vibe and more of a undiagnosed mental health issues vibe, but I obviously can't say for sure.
EUPL
Why should a FREE software license have colonizer finger print?
Not good enough. Companies are still allowed to use this software freely, make massive profits without anything going to the developer. It is truly free labor.
They are even allowed to modify it, even make derivative work, without open sourcing it, as long as they don't distribute said derivative work.
How about
The Anti-Capitalist Software License
A software license towards a world beyond capitalism.anticapitalist.software
#lisp1 and #lisp2, reading Kent's #halfbaked, moo.el #lambdaMOO (and you). #lispyGopherClimate
nhplace.com/kent/Half-Baked/in…
yduJ's moo.el git:
codeberg.org/nosrednayduj/moo-…
Lisdude's cache of a page about moo.el:
lisdude.com/moo/mud_el_tutoria…
KDE is firing on all cylinders, Brave says they're the best browser, CERN moves to Debian
Check out TuxCare's Endless Lifecycle Support for Debian 11 (and other Open Source projects): tuxcare.com/endless-lifecycle-…
Grab a brand new laptop or desktop running Linux: tuxedocomputers.com/en#
👏 SUPPORT THE CHANNEL:
Get access to:
- a Daily Linux News show
- a weekly patroncast for more thoughts
- your name in the credits
YouTube: youtube.com/@thelinuxexp/join
Patreon: patreon.com/thelinuxexperiment
Or, you can donate whatever you want:
paypal.me/thelinuxexp
Liberapay: liberapay.com/TheLinuxExperime…
👕 GET TLE MERCH
Support the channel AND get cool new gear: the-linux-experiment.creator-s…
Timestamps:
00:00 Intro
00:44 Sponsor: TuxCare
01:45 Brave say they outperform every other major browser
04:49 Firefox 155 should load pages faster
06:36 CERN leaves Red Hat for Debian
09:42 Debian says yes to AI
12:14 GNOME 51 will improve hybrid GPU support
13:52 Plasma 6.8 adds more accessibility features to Wayland
15:19 KDE's theme engine supports more KDE apps now
16:39 Artix drops XLibre after it pushes a maintainer to resign
18:59 KDE Connect redesign ready for testing
20:29 FOSS Minecraft Luanti taken down by Microsoft
23:25 KDE Linux makes more progress towards its beta
25:24 Grab bag of gaming news
28:45 Sponsor: Tuxedo Computers
Links:
Brave say they outperform every other major browser
brave.com/blog/brave-outperfor…
Firefox 155 should load pages faster
itsfoss.com/news/firefox-155-f…
CERN leaves Red Hat for Debian
phoronix.com/news/CERN-Goes-De…
Debian says yes to AI
lists.debian.org/debian-devel-…
GNOME 51 will improve hybrid GPU support
gitlab.gnome.org/GNOME/mutter/…
phoronix.com/news/GNOME-Shell-…
Plasma 6.8 adds more accessibility features to Wayland
saueseb.wordpress.com/2026/09/…
KDE's theme engine supports more KDE apps now
blogs.kde.org/2026/08/28/this-…
Artix drops XLibre after it pushes a maintainer to resign
artixlinux.org/news.php#XLibre…
forum.artixlinux.org/index.php…
KDE Connect redesign ready for testing
tintotint.eu/programming/kde-c…
FOSS Minecraft Luanti taken down by Microsoft
blog.luanti.org/2026/08/27/lua…
microsoft.com/en-us/research/p…
KDE Linux makes more progress towards its beta
blogs.kde.org/2026/08/31/this-…
Grab bag of gaming news
gamingonlinux.com/2026/08/stea…
gamingonlinux.com/2026/08/game…
arstechnica.com/gaming/2026/08…
This is my kind of "Apple Event" 😀 Thank you for the news.
Kinda makes me want to have a higher budget "Linux Event" event, with fake graphs, paid actors and one last thing. /hj
There's a Dutch commercial from the 1980s with a tagline that's widely recognised in the Netherlands to this day and used as an expression to refer to conflicts of interest:
We of Toilet Duck recommend... Toilet Duck.
Anyway, while Firefox can hardly be described as being blessed by brilliant leadership today, whenever I look at Brave, I can't help but feel it dodged a bullet.
WC-Eend reclame uit de jaren 80 (Nederlands)
WC-Eend commercial from the 80s (Dutch)oonai5000 (YouTube)
Linux distro for remote access via Citrix and RDP?
Looking for advice on which distro to try out for what I suspect is not a common use case.
I want to use my personal laptop to connect to my work PC running windows 11.
My laptop is a pugged in to a couple of screens via a dock.
The company I work for uses Citrix workspace and RDP for this purpose.
So far I have had a go with Mint 22.3 / Cinnamon and had a lot of trouble with Multi monitors.
Best I can do is run the remote session windowed and have it dragged over two screens. This is not adequate by any means. Even getting the connection bar to appear in cinnamon is a nightmare of hitting atl and F10 and hoping it happens.
I've also added KDE plasma to my mint install. So far it is more reliable at getting RDP window to restore so I can drag it over 2 screens, however still no luck with full screen across all screens.
Does anyone else use citrix workspace from linux over multiple screens in full screen mode successfully?
Looking for an AI Responder for Text Messages and Other Features
Hands off AI programs, where for example if I get a text message, without using my hands it read it to me, and I can use my voice to reply.
And any of other features like reading notifications, emails, whatever else! 😀
like this
Auster likes this.
Thank you! I like to live a busy multitasking lifestyle. But still would be useful for folks with disability issues.
A lot of downvotes for me. I should maybe mention to those folks that I'm guessing most of the AI direction humans have gone, but I'm not against all AI.
like this
Auster likes this.
Check the modern apps ecosystem.
There is an ai assistant and it has links to the other apps.
I'm in the process of making a distro that combines the way SteamOS makes Arch Linux stable and user-friendly WITH the performance optimizations of CachyOS
As the title and the website say, I'm currently making a distro with the goal that you don't have to compromise between ease of use + safety and bleeding-edge + performance optimizations.
As I will likely be able to publish the 0.0.1 source code to the GitHub link and the ISO to the website sometime next week, I would like people to be aware of my project so I can have some feedback for further improvements when I release the first version. I have not posted this anywhere else yet, as I value the opinion of this community more than Reddit or whatever.
If you have any questions or any criticism, please voice it, I would love to hear it, good or bad, in the end I want to make a proper OS. (I'll go to bed now so expect replies to take a few hours from posting.)
Pu-239
Pu-239 is an atomic Arch Linux distribution: sealed read-only root, ostree A/B deployments with automatic rollback, and the 1000 Hz linux-cachyos kernel.pu-239.org
like this
opossumtriceps likes this.
Yeah you shouldn't recommend Arch to a beginner.
If you actually interacted with beginners you'd immediately understand why people choose mint or Ubuntu for that purpose instead.
my intention was for this to be the short version of Plutonium-239 so it matches better with the logo. I kind of hope for this to be colloquially refered to as just Plutonium
My first thought when I saw your domain was not plutonium-239, it was P U 239, your website doesn’t reference plutonium until 8-9 paragraphs in.
However if you still insist on the shorthand, what I saw people do, have a paragraph explaining what the shortcut means and how to call the os. Something like "the p-239 stands for plutonium and that is what we call the os - Plutonium" or variant of that. Maybe have it on the homepage even as a part of some baner or simly as second or third element under header. And it can also link to the full story (that it was a codename at first..)
Please let people have fun with computers, thank you. This doesn't sound like the 100th Arch reskin and doesn't sound like "just a bunch of config files" either.
If you need to start a flamewar, please do it with that far-right LLM slopfest grift that is Omarchy.
bought an Intel B70 to run stuff locally
You spent 1700€ for that? Jesus, how rich are your parents?!?! 😄
I'll just mostly copy the comment above because it answers my intentions:
I have NEVER had less issues with an OS ever since running Arch and/or CachyOS, however issues COULD arise and that is enough for the usual Reddit dickhead to talk someone who’s asking for their first distro out of using anything Arch based. I’m tired of hearing these fucking “no you can’t recommend CachyOS, a new user should not touch Arch”, “CachyOS will break three times within your first week of using it”, “it has the AUR so you will contract HIV instantly by using it”, I just can’t hear it anymore which is why I want to provide people with an option that still has them on an Arch based distro but with added peace of mind and speed optimizations out of the box. You know, that’s the thing, I personally find Arch easy and intuitive and don’t get where people get the idea that it breaks all the time from, but that IS the perception however.
like this
Sickday likes this.
You know, that’s the thing, I personally find Arch easy and intuitive and don’t get where people get the idea that it breaks all the time from
I've been using Arch since 2008 or 2010, idk. I find it easy and intuitive but I still managed to fuck it up multiple times by now. All of those major fuckups I can remember could probably have been solved by what you're trying to do with Pu-239.
List of major fuckups off the top of my head, chronologically:
Once it had suddenly contracted some kind of computer AIDS which made the windows pink and caused other graphical errors. Never figured out why, a reinstall solved it.
Another time I installed a bunch of packages without doing a full repo sync before (pacman -S instead of -Syu), which left the system in an inconsistent state. Had snapshots of the root partition I could roll back to.
The third time happened only recently and made my desktop unusable for half a year because I couldn't be bothered to fix the fucking bootloader. Huge update (4-5GiB in size, didn't update for a few weeks or months even) slowed down the whole system due to btrfs having some exhausted inodes or sth, which made the system crash and the bootloader disappear.
This even fucked up my firmware so for whatever reason the system can't boot from /boot, only from the EFI system partition. My current workaround is copying the files from /boot to the ESP until I can be arsed to figure out the issue.
Exactly why I found your idea very cool 😀
With Multi-Kernel Linux you could even try booting it before you try booting it, haha 😄
I see. When I wrote that out it was more of a "Why would some one pick this over CachyOS or plain Arch?" and I think you've adequately answered that.
I have NEVER had less issues with an OS ever since running Arch and/or CachyOS
I can say the same, except I've never had a real issue with Arch in the 15(+) years I've known of it and used it. Every issue I've had with it was my own fault and was just part of learning of how package managers work. Nothing unique to Arch is inherently confusing or prone to user error in my opinion. But that's just my own bias.
Good luck with this distro. My only bit of feedback is that distros with a bus-factor of 1 usually die out quickly (burn out is real). I would say if you're planning to have any support channels look into on-boarding some trustworthy comrades to assist you with this. Other than that wish you the best homie!
like this
Sickday likes this.
I have no idea what people keep talking about when they say Arch/CachyOS is "unstable". I have had so many more issues with running Debian (usually on servers) over the years. Since I swapped my desktop to CachyOS over a year ago, I have basically no issues at all. Just one very minor thing that fixed itself after a few days (bug in kde on new version released). For like 15 months of use, that's spectacular compared to any other system I've ever used (especially including Debian and of course Windows, obviously).
What exactly is the goal? How do you make "no issues" and "it just works" more stable?
I have no idea what people keep talking about when they say Arch/CachyOS is “unstable”.
a) stable in the sense of not changing, or more specific not changing dramatically the user experience and not breaking compatibility, so you can rely on being the same, and b) stable in the sense of not breaking by bugs and issues. Those are two different topics sharing the same wording of stable/unstable. It's a similar issue of the word "Free", which could mean either Open Source or no cost in money.
Archlinux is unstable, in the sense that it changes frequently, without warning for most of the time, and this can break compatibility or user experience. Compare the other extreme Debian, which is very stable.
Compare the other extreme Debian, which is very stable.
In the sense that is unchanging, sure. But that's one hell of a bad word to describe that in this context. In my experience the incompatibilities caused by only ancient versions of things available in the repo of even a newly released Debian are not helpful. Stable wouldn't be the word I choose to describe the situation, or the fiddling and tinkering that results from that. Often having to go outside of the repo to solve, defeating the whole point of said repo.
Arch in my limited experience is much more stable, in the sense of "just works" and always having up to date software. If I want to use something, I can just install it (from the repo), the chance of it not being the current release are slim.
I didn't claim anything is bad, anywhere.
Also I didn't "try to use Debian in a way it wasn't inteded to be used". I am using debian on 90% of my servers/vms/containers to this day. Have been for literally decades. To give a specific example: I was running a nextcloud, which required PHP, and wanted to update that. The newer version reuqired a higher PHP version, because the currently installed PHP version was EoL and not supported anymore (by PHP maintainers or Nextcloud). So updating required removing the debian-provided PHP version and installing one from other sources (external repo or compile from source), which honestly defeats the point of a "stable" distribution if the software provided is EoL, doesn't it?
And to be clear this is just one example I can specifically remember. The "issues" I encouter when using debian are usually of that general type. And to be clear, that's mostly the point of using it on a server, where I use it, but even there it sometimes goes a bit too far.
And finally: I was originally arguing the semantics of calling debian stable and arch UNstable, which it is not. It is rolling, it might be bleeding edge. It's also isn't the same as having a stable and unstable release branch (within the same distro) when applying the label to the most stable release of different distros.
which honestly defeats the point of a "stable" distribution if the software provided is EoL, doesn't it?
Again, the point of a stable release model is that its packaged software doesn't have breaking changes for the lifetime of the release. Install something from those repos and it's guaranteed to run in the same way for the full lifecycle while still getting minor and security updates. So if the software you're externally layering on top of that suddenly requires new dependencies that you have to install externally too, and you don't like that, that's more a problem based on a misunderstanding of Debian than a problem with Debian.
Stable vs Unstable does not mean anything to do with bugginess or prone to breakage.
It literally just means package version changes.
Stable meaning packages update slowly and only minor versions or security.
Unstable means packages update frequently including major versions
Inherently rolling releases are unstable.
My personal experience too isn't Arch has been the best distro for lack of bugs and issues on my machines than Fedora or Debian etc.
Stable vs Unstable does not mean anything to do with bugginess or prone to breakage
It would be great if that's how the words were actually used, but in most discussions I've seen it is certainly not the case. Also, when talking to new users, they are supposed to magically understand and know the word is used in a niche way in this context? It certainly won't be what they take from it when hearing or reading it.
Unstable means packages update frequently including major versions
That's what we have rolling or bleeding edge for. Sure, unstable can mean that when used within the same project/context. So having different releases be stable and unstable for the same thing, but across projects/distros that's just confusing, especially for new people. Yes I'm aware of the historic reasons and the roots in software development, but I'd argue it isn't helpful to convey the practical reality of the differences.
I don't disagree that it causes confusion and that people conflate the two meanings especially for those unaware of what it is supposed to mean.
And inherently as well being an unstable distro as far as package updates goes likely leads to it being "unstable" in day to day use as far as bugs etc obviously goes hand in hand which further conflates the meaning.
I didn't say "it suddenly breaks". I said I have more issues with it, which is decided different from "it just works", which has been my experience on CachyOS. Specifically I mean issues with installing (up to date) software, or using software that has requirements that I just can't install the required version cause the repo has a version from 3+ years ago. Not everything has to be "bleeding edge", but being so stable that everything is utterly outdated is also a kind of unstable.
Sometimes this goes so far that the "stable" version shipped by debian is already unsupported upstream with all the security implications that entails (I had that once with PHP, I think).
it’s illegal to have the same distro on two different machines
Shit. Gotta go, have to do something about that. Glad you mentioned it.
Why OpenSUSE specifically? What do you like better about it?
Why OpenSUSE specifically?
Firstly, my general rule is "upstream or Mint (because screw snaps)". CachyOS was a decision I made prior to this rule but otherwise I have 6 options (Arch, Debian, Ubuntu, Mint, Fedora, and OpenSUSE).
- A rolling release is out of the question, so Arch's out.
- Ubuntu's always out.
- Based on what I've heard, Fedora and OpenSUSE are the two leaders when it comes to desktop security on Linux. I value security so Mint and Debian are out.
- Fedora tends to adopt new technologies fast, which isn't really what I want.
So by process of elimination, OpenSUSE it is.
Another part of it is nostalgia. I used it briefly when I was first switching to Linux full-time. I ran into various issues and moved off it. Private internet access wouldn't install, I didn't even know what proprietary media codecs were at the time, and tumbleweed had a few bugs that caused me trouble. Despite all that, I'm nostalgic for it partly because of the themes I ended up installing.
I value security so Mint and Debian are out.
Why is that? I never had security issues with Debian.
Based on what I’ve heard, Fedora and OpenSUSE are the two leaders when it comes to desktop security on Linux.
I love the idea, apart from "user applications are flatpaks". I'd love to install non flatpak applications.
Plus points for my perceived lack of AI sloppiness.
Sounds great and exactly how I'd want it! So you basically have a base set of packages which are guaranteed to be stable, but you can still layer stuff on top?
Maybe you can also have multiple boot entries like a "safe mode" or a way to boot different combinations of packages.
I'd really like to have a somewhat declarative way to manage the software on my laptop and desktop both, the latter being a superset as I need gaming and LLM related software there (which I don't need on my laptop).
I'll certainly play around with your distro as soon as it's out. Don't know when though, as I need to take a few precautions to not fuck up my data first 😅
Seconding that. I've just read through the website. Got interested. Then my eyes went to the top panel again finally, I've read "GitHub", and my thoughts are "Huh? But this mismatches the rest of the page, especially with the AI stance and some push for simplicity combined with competence.". Went back here to write about it.
\/me a ~10 year old ArchLinux user (using Arch for this long, my Earth age nobody cares about including me anyway). I'm thinking if I wanna actually try this for real. I currently have manually written packages that define the OS dependencies and configuration, and I don't like the mutability of everything, the default update handling of no-longer-dependencies, the .pacnew... I still like and appreciate Arch obviously, but the pain points connect.
-Suy process to the pain points. It alters the local database even when downloads haven't fully finished yet (as it is out-of-the-box at least), so if downloads fail mid-ways you have to remember to not dare installing any particular package before a full upgrade still. If you forget, you're toast.
This is very cool! I like the idea of atomic distros although I haven't really gotten into them much, if you keep
on working on this project I might join it.
Question:
I'm a bit confused about the package management system you talked about. Flatpaks for user level packages? What about the official arch repo and the AUR? I know other atomic distro's don't really work with traditional package managers, what does this mean for Pu-239? If there's no AUR then there is no Arch Linux at least for me.
Also that name could probably do with some work lol. Maybe work on a shorthand way of spelling it and a better way to pronounce it? I'm not sure.
Thank you a lot for your interest! So as I pointed out in the other comments, out of the box and for the 0.0.1 release it's intended to keep the system itself atomically updated through pacman and the user is advised to use flatpaks to install his applications. This is the most user friendly way of going about it, however I'm absolutely on your side and wouldn't use it that way myself. 0.0.2 will have a way to "unlock" it so you can use the distro like vanilla Arch BUT you get peace of mind from knowing that you have a failsafe way of knowing the system will not break.
For the name, I did want Arch-Atomic at first but noticed this would violate the Arch Linux trademark policy and just went with my favorite isotope as a placeholder that unfortunately grew onto me. I will get off the couch now and edit the website so it's apparent that Pu-239 is just the shorthand and people will refer to it as Plutonium-239 or just plain Plutonium in the future!
Very interesting approach, please keep us posted and best of luck!
Edit: just thought, have you ever heard of RakuOS ? They seem to have similar ideas, about the unlocking while still atomic.
UPDATE
I took your suggestions to heart and updated the website to reflect the changes I implemented today. The big change is that I found a way to keep pacman fully intact and functioning, but make it apply the changes atomically. So now this isn't just limited to Flatpaks, but LITERALLY Arch Linux but made atomic.
The new intro reads:
"Plutonium-239 is Arch Linux, made atomic. It combines the rolling release model of Arch Linux with an atomically updated root filesystem inspired by SteamOS on top of the heavily optimized CachyOS performance kernel. Unlike immutable distributions that lock you out of the native package manager and force you into sandboxes, Pu-239 keeps the core Arch experience intact. You still get the full power of pacman and the official Arch repositories, with the peace of mind of an unbreakable safety net underneath."
For more information, please check out the updated "How it works" section. Thank you all a lot for the feedback!
Can't speak much about OP's distro or CachyOS, but I can talk about how Fedora Atomic differs from simply doing btrfs backups before every update.
First, updates are not the only thing that can modify the base system. Installing packages, installing plugins or extensions, manual user modifications, etc, can all end up bricking the system. Fedora Atomic makes the base system immutable so that the only way of making modifications is via rpm-ostree, which ensures that you always have a way to rollback.
Second, one of the issues with traditional update mechanisms is that over time, updates might not do proper clean-up and leave artifacts. This is a harder problem than people realize, because users can have all sorts of permutations of packages and versions installed, and the update mechanism has to account for all of them. Over time, and many updates, a system can accumulate tons of small update errors and finally fall over. I've had this issue myself and heard of this issue from multiple sources. Fedora Atomic solves this by ensuring that every update is like a complete re-install.
Third, since every Fedora Atomic user uses the same base system as their distro maintainers, they can be sure that their base system is well tested. Bugs are more reproducible, and thus can be fixed faster. None of those "works on my system, you're on your own" issues.
Fourth, this one isn't a benefit to the user but the community. Fedora Atomic (and universal blue) distros are easy to fork. This is why there are so many flavors now. Bluefin, Aurora, Bazzite, Secureblue, Wayblue, etc. Instead of one generic distro with a huge community relying on a few maintainers, like Fedora used to have, now you have smaller specialized communities with their own leaders, and users can choose which community they align with more. And you can even switch communities, since rpm-ostree allows you to "rebase" to a different distro (eg Aurora -> Bazzite).
Although I'm on Nobara so I use github.com/rpm-software-manage… -> dnf-plugin-snapper, but the rest is the same.
GitHub - Antynea/grub-btrfs: Include btrfs snapshots at boot options. (Grub menu)
Include btrfs snapshots at boot options. (Grub menu) - Antynea/grub-btrfsGitHub
Will it condone LLM generated / "assisted" programming?
This Week in Plasma: So Many Ways to Click and Scroll
This Week in Plasma: So Many Ways to Click and Scroll
Welcome to a new issue of This Week in Plasma!KDE Blogs
Astro Loop - Roguelike Shooter
f-droid.org/packages/com.astro…
This seems to have come out of nowhere (den has no other repos) but very polished and addictive. Anyone else enjoying this new game?
Astro Loop | F-Droid - Free and Open Source Android App Repository
Open-source roguelike shooter. Simple to play, no ads, no tracking, offline.f-droid.org
like this
Auster likes this.
Looks neat. I'm often skeptical of new games that come out of the blue like this for being vibecoded soon-to-be abandonware, but that doesn't seem (at least in an obvious way to this layman) to be the case here.
Neat find, thank you!
F-Droid reshared this.
F-Droid reshared this.
How to add new item to KDE Application Launcher from terminal?
How do you add new application to this "All Applications" menu (and optionally to some of categories) without using GUI "Edit Applications" menu (named "KDE Menu Editor")?
It may sound like a simple task but I've already spent several hours on this with no success.
When you download an app instead of getting it from package manager, you may want to add it to Application Launcher so it will not get lost.
I have myapp.AppImage file, it's working, I've created .desktop file and tried to place it into some system directories (e.g. ~/.local/share/applications/myapp.desktop) or calling xdg-desktop-menu install myfile.desktop but to no avail. New app doesn't appear in All Applications or specified category, it appears only as a search result, when you start typing its name.
Creating new menu items with GUI "KDE Menu Editor" affects "/home/user/.config/menus/applications-kmenuedit.menu" XML file, but this file doesn't look like it should be edited manually.
Can you please try adding custom executable to this menu yourself and see if you will succeed? Am I trying to do something quirky and is wrong about expecting this task to be simple?
My system is Kubuntu 26.04, KDE Plasma 6.6.6.
did you try update-desktop-database after adding it to .local/share/applications?
That might be an arch command, not sure
Ok, finally I've found solution! Obviously I found it 0.0001 seconds after I publicly asked this question.
Problem is that "Games" menu in mentioned /home/user/.config/menus/applications-kmenuedit.menu XML file does not contain a <Merge type="files"/> tag, that's why KDE Kickoff Application Menu was ignoring .desktop files if they belong to this category. And every sample .desktop file I've created probably belonged to Games category.
I changed this XML file to be like this:
<Menu>
<Name>Games</Name>
<Include/>
<Exclude>
<Filename>Quake.desktop</Filename>
</Exclude>
<Layout>
<Merge type="menus"/>
<Merge type="files"/>Now it seems like everything works as expected. I don't understand why it doesn't work by default.
<Merge type="files"/> a lot of places.
Can you launch the original executable by itself?
So, if you run the command, that you put into the .desktop file, in a terminal, does that work?
cp /usr/share/applications/whatever.desktop ~/.local/share/applications/your-app.desktop
Edit the file, it's a pretty obvious config.
Edit: you may delete all the translation strings.
xdg-desktop-menu install
I had no idea that command exists, I've just been looking up the location of desktop files until i finally remembered lol
.desktop file to ~/.local/share/applications/ directory. Also, there's xdg-desktop-menu uninstall whatever.dekstop which is effectively the same as removing .desktop file from this directory. Probably just copying and removing files is more natural.
GitHub - mijorus/gearlever: Manage AppImages with ease 📦
Manage AppImages with ease 📦. Contribute to mijorus/gearlever development by creating an account on GitHub.GitHub
Noctalia 5 Wayland Desktop Shell Is Now Officially Stable
Noctalia 5 Wayland Desktop Shell Is Now Officially Stable
Noctalia 5 reaches stable status with calendar sync support, improved theming, MRU window switching, and a long list of fixes.Bobby Borisov (Linuxiac)
like this
bretton.dev likes this.
Noctalia - A Family of Native Wayland Projects
Noctalia - a family of native Wayland projects: a desktop shell, a compositor, and a login screen.Noctalia
Debian-Based Grml 2026.09 Rescue Linux Released with Linux Kernel 7.1
Debian-Based Grml 2026.09 Rescue Linux Released with Linux Kernel 7.1
Grml 2026.09 is now available with Linux kernel 7.1.8, a Debian Forky base, exFAT boot support, and updated system administration tools.Bobby Borisov (Linuxiac)
Debian-Based Grml 2026.09 Rescue Linux Released with Linux Kernel 7.1
Debian-Based Grml 2026.09 Rescue Linux Released with Linux Kernel 7.1
Grml 2026.09 is now available with Linux kernel 7.1.8, a Debian Forky base, exFAT boot support, and updated system administration tools.Bobby Borisov (Linuxiac)
Chat Control: Όλες οι επικοινωνίες των Ευρωπαίων στο μικροσκόπιο
Οι «γκρίζες ζώνες» στην νομοθεσία της Ε.Ε. για την προστασία των ανηλίκων γίνονται κερκόπορτα για ολοκληρωτική άλωση της ιδιωτικότητας των επικοινωνιών. Πως ψήφισε η κάθε χώρα – Η στάση της Ελλάδας
- Έρευνα των Data Journalists: Πώς η ΕΕ θα σκανάρει το WhatsApp μας και πώς θα λειτουργεί το Chat Control στις μεγάλες πλατφόρμες. Το «κλειδί», η κρυπτογράφηση και το Dark Web.
- Γιώργος Πλειός στους Data Journalists: «Οι μεγάλες πλατφόρμες εμπορεύονται προσωπικά δεδομένα. Τα μέτρα είναι μέρος μιας παγκόσμιας τάσης καταστολής ελευθεριών».
- Ο ρόλος της Τεχνητής Νοημοσύνης: Όταν ανιχνεύει ένα αρχείο που θα κρίνει ως ύποπτο, θα το αναφέρει στο Κέντρο Δεδομένων κι Αξιολόγησης συμβάντων, το οποίο θα κρίνει αν θα παραπέμψει την υπόθεση στις Αρχές των χωρών της ΕΕ.
- Το περιεχόμενο των επικοινωνιών θα σκανάρεται στις συσκευές των χρηστών (client-side scanning), πριν κρυπτογραφηθεί και αποσταλεί, και θα αφορά ακόμη και τις κρυπτογραφημένες συνομιλίες (end-to-end encryption). Άρα κρυπτογράφηση δεν θα υπάρχει…
- Πως φτάσαμε ως εδώ: Οι ψηφοφορίες και τα στάδια στην μακροχρόνια προσπάθεια επιβολής του μέτρου.
- Κωστής Πιερίδης στους Data Journalists: «Υπάρχουν γκρίζες ζώνες και ζητήματα νομιμότητας. Μετά την 11η Σεπτεμβρίου, η Ασφάλεια υπερίσχυσε της Ελευθερίας».
- Σε ιδιώτες η επιβολή του νόμου – Το SOS των ειδικών κρυπτογράφων.
Chat Control: Όλες οι επικοινωνίες των Ευρωπαίων στο μικροσκόπιο
Έρευνα των Data Journalists: Πώς η ΕΕ θα σκανάρει το WhatsApp μας και πώς θα λειτουργεί το Chat Control στιςDATA JOURNALISTS (Data Journalists)
Sharpening Up Old Photos
I have been testing a few different photo touch-up tools this month.
One that stood out is qualityenhancer.org — it does a good job sharpening up old scanned photos without much manual work.
Sharing in case anyone else is looking for something similar.
Free AI Video Quality Enhancer Online, NO Sign Up, No Login
Enhance, upscale, denoise, and sharpen images and videos online with Quality Enhancer. Built for creators, marketers, and teams.Quality Enhancer
Vivaldi takes a stand: keep browsing human
Just like society, the web moves forward when people think, compare, and discover for themselves. Vivaldi believes the act of browsing is an active one. It is about seeking, questioning, and making up your own mind.
Across the industry, artificial assistants are being embedded directly into browsers, and pitched as a quicker path to answers. Google is bringing Gemini into Chrome to summarize pages and, in future, work across tabs and navigate sites on a user’s behalf. Microsoft is promoting Edge as an AI browser, including new modes that scan what is on screen and anticipate actions.
These moves are reshaping the address bar into an assistant prompt, turning the joy of exploring into inactive spectatorship.
This shift has major consequences for the web as we know it. Independent research shows users are less likely to click through to original sources when an AI summary is present, which means fewer visits for publishers, creators, and communities that keep the web vibrant. A recent study by PewResearch found users clicked traditional results roughly half as often when AI summaries appeared. Publishers warn of dramatic traffic losses when AI overviews sit above links.
The stakes are high. New AI-native browsers and agent platforms are arriving, while regulators debate remedies that could reshape how people reach information online. The next phase of the browser wars is not about tab speed, it is about who intermediates knowledge, who benefits from attention, who controls the pathway to information, and who gets to monetize you.
Today, as other browsers race to build AI that controls how you experience the web, we are making a clear promise:
We’re taking a stand, choosing humans over hype, and we will not turn the joy of exploring into inactive spectatorship. Without exploration, the web becomes far less interesting. Our curiosity loses oxygen and the diversity of the web dies.
Jon von Tetzchner, CEO, Vivaldi
The field of machine learning in general remains an exciting one and may lead to features that are actually useful.
But right now, there is enough misinformation going around to risk adding more to the pile. We will not use an LLM to add a chatbot, a summarization solution or a suggestion engine to fill up forms for you, until more rigorous ways to do those things are available.
Vivaldi is the haven for people who still want to explore. We will continue building a browser for curious minds, power users, researchers, and anyone who values autonomy. If AI contributes to that goal without stealing intellectual property, compromising privacy or the open web, we will use it. If it turns people into passive consumers, we will not.
We will stay true to our identity, giving users control and enabling people to use the browser in combination with whatever tools they want to use. Our focus is on building a powerful personal and private browser for you to explore the web on your own terms. We will not turn exploration into passive consumption.
We’re fighting for a better web.
vivaldi.com/blog/keep-explorin…
Google users are less likely to click on links when an AI summary appears in the results
In a March 2025 analysis, Google users who encountered an AI summary were less likely to click on links to other websites than users who did not see one.Athena Chapekis (Pew Research Center)
Women Would Never Do That
Right? 100 years of “progress” have been thrown out the window in the pursuit of no accountability. Let’s drink to the insanity!
#Redonkulas #LindsayClancy #ModernWomen
To donate to this content, see our list of channels, purchase merchandise or join Popp’s Preppers, click here: linktr.ee/redonkulas
Send physical donations to:
Redonkulas.com Productions
29488 Woodward Avenue, Unit 407
Royal Oak, MI 48073
If you write a check, make it out to Second Class Citizen, 501c3
All donations are tax deductible
And be sure to tune in for Grunt Speak Live
Tuesdays and Thursdays at 8pm Eastern
And
Supporter Sunday streams for Locals, Odysee, and SubscribeStar members only!
All sources are available on Redonkulas.com!
🎙️ New to streaming or looking to level up? Check out StreamYard and get $10 discount! 😍 streamyard.com/pal/d/641301644…
A bicycle for the mind
This is what computer programming means for me. You can build your own tools. You can share them with others. When you build and share such tools, you meet other people that perceive and interact with the world in the same way as you do. You make new friends. I guess this is what I've been trying to do in my life. Get people to understand this process. With computers, you can make your own tools, and so you can augment yourself, and others, to accomplish more things. This is something special about computer and especially open source tools. It costs no money at all to try this.This idea isn't really new, either. Steve Jobs called the Macintosh "a bicycle for the mind", referring to the fact that the human on a bicycle is the most efficient animal on the planet. And before Jobs, you can see similar ideas in Douglas Engelbart's Mother of All Demos, where a whole section is about the human-computer interaction loop, and how their hardware (the mouse, the keyset, the realtime display) was designed to improve this loop and make the tool as transparent as possible (update: actually the segment I was thinking about is in a later talk from Douglas Engelbart in 1986). Just like when you ride a bicycle, and you're not particularly thinking about pedalling and braking and shifting gears and keeping your balance. It's as natural as walking.
But then, there is a limitation on that as soon as you're not the one building the tool. Say you buy a Macintosh or a Windows machine. Someone has designed it to work a certain way. And their design will shape how you perceive and interact with the world.
like this
Maeve likes this.
Immutable distros...
I've got a refurb laptop coming to me soon and I've been wanting to mess with immutable distros for a while... I have no idea what sort of specs the laptop has.
Anyone have any opinions on good immutable distro(s) to try out and why?
Only distros on my list so far are Bluefin and Vanilla (Gnome isn't a favorite these days though).
like this
Mordikan likes this.
The only immutable distro I've tried is Bazzite. It's gaming-oriented, but can work well as a desktop. It also does offer a KDE edition, but for some reason they intentionally ship with some GNOME programs instead of the KDE ones. For example, a fresh KDE edition installation includes Ptyxis instead of Konsole.
Also, DistroWatch's search has the option to only show immutable distros. It's under the Distribution Category option. I figure that might help you find a few more options.
as of bazzite 44, konsole is now the default terminal on kde
(but bazzite kde still defaults to gnome disks)
I run NixOS as a daily driver and on a box for docker containers.
I will say that it is stable to point that since nothing seems to ever really break, I don't feel I really understand the configuration as well as I could (since I'm not having to fix things and learn).
I started with just traditional NixOS but later moved to using flakes. Because of flakes input pinning, it's much more reproducible but also even more stable. The biggest benefit I see to flakes is the use of local git for updating. Since I have git logs for auditing, if something were to go wrong, I'd just find that change in log and revert to before that commit hash (or just revert to different generation).
The biggest problem I've had is how procedurally some tasks change and sometimes are made more difficult. Symlinks is a good example of that. In Arch, symlinking is just a basic one-liner. In NixOS, it's a matter of writing config more verbosely to the configuration.nix file :
(pkgs.writeTextFile {
name = "tst";
destination = "/bin/tst";
executable = true;
text = builtins.readFile ./scripts/tst;
}) That's a good takeaway from NixOS: things are more verbose in setup, but tend to get set once and never again.
I like Fedora Atomic with bootc for this reason. While Nix language is quite confusing and gets even more confusing when you find online advice that has a different setup than you that introduces compatibilities, bootc is just an OCI containers that I can run bash commands in to get stuff set up.
It's still not one-to-one. Generally, I find that using bash to set things up makes more things easier than harder compared to Nix. Though Nix does make some stuff simpler.
That being said, I haven't tried NixOS in a while. I'm sure that with a decent LLMs, today its easier than ever to make a competent NixOS config. I've been meaning to try, but haven't found the time.
like this
Mordikan likes this.
I run Silverblue on 2 devices (my main computer and laptop) for half a year. It works and I didn't have any major issues with it. Though as you might have experienced with other immutable distros, some things like configuring gdm might be a bit more work. But for most things there is a flatpak. The only software that couldn't be installed that wat was my vpn.
If you want to try out something new, NixOS or Guix might be more up your alley
All distros are immutable if you lost your root password.
I think NixOS is the way to go currently, but I personally would not use it due to the extra amount of work for little to no benefit on a single-user home machine.
NixOS is surely what I’d recommend.
I like to tinker with an Arch Linux install using a VM to iterate quickly then translate almost ALL of the home dotfiles and preferences to deterministic nix code that absolutely LOCKS everything into place.
Some essential features/projects to incorporate into a decent nix config:
- nix flakes
- home-manager
- content-addressed and dynamic derivations (Eelco’s original paper writes about CA derivations as the holy grail)
- cachix (local cache) and community substituters
- forgejo (local forge with local CI to test nix flake updates for breakage and warm the local cache) I call it my “update canary”)
- nixos-anywhere/netboot/initrd boot scripting influenced by NixOS-anywhere but extended
- disko
- impermanance (lots of work up front declaring what persists between boots but this one is ESSENTIAL. This module makes it virtually impossible for a compromised package or virus to survive a reboot if things are done right.)
- sops-nix
- nixos-needs-reboot
- devenv/direnv
It’s really powerful.
As a proponent of better, faster, more foolproof, and more elegant, I’m often jealous of some of the features that our brothers in GUIX are building with the benefit of hindsight. Also, I will admit that it really feels like NixOS is doing the hard work exploring a paradigm (and its inherent rough edges) that will effectively obsolete FHS entirely in the Linux world someday.
1Password Just Pledged $300,000 to DHH's Omarchy, and its Own Employees Aren't Happy
Fascism Arch Linux gets more funding.
Omarchy has been on something of a roll now. Funding for its foundation has been climbing fast, from an $8 million launch to $10 million a few weeks later, and now crossing $13 million with the most recent pledge.What's drawn my attention are the first two Corporate Patrons, 1Password and 37signals, both of whom have decided to pitch $100,000 a year for the next three years. Now, 37signals I get; DHH is heavily involved there, but 1Password was a surprise entry.
Naturally, not everyone's onboard with their pledge.
Signs of disagreement
This has not gone well with employees working at 1Password, with company leadership having to take certain damage control measures to assure their staff.
An internal Slack message has surfaced (courtesy of The Verge), which shows cofounder Roustem Karimov downplaying the criticism, telling team members that:
people have different personal opinions. You believe in your heart that DHH is evil, that you have the moral high ground, and that nothing will change your mind.
However, not everyone believes that. It is not fair to claim a monopoly and ostracize team members who might disagree with you. There are people who are afraid to speak up simply because they will be personally attacked.
CEO David Faugno responded on a different note, telling employees the company doesn't endorse DHH's views, while also noting that Omarchy is the second most used Linux distribution among 1Password's own users.
Why the backlash?DHH is known to be someone who firmly falls on the "right" side of the political spectrum, someone who doesn't shy away from putting his opinions in public view.
He regularly posts blogs that show where he stands on certain societal issues, and some of his recent writeups are what's fueling this particular backlash.
His recent July post, titled "Wolves, sheep, and gypsies," compares Denmark's wolf population with the Romani people camping in Copenhagen parks, where he argues: "When gypsies take over public spaces, you deport them."
Then there's "As I remember London" from September 2025, where he laments about London losing its native Brit majority and a nod of approval for a Tommy Robinson march.
Of course, these aren't the only factors behind his disapproval, but you get the gist of it, right?
Users could jump ship
If you search for the terms "1Password" and "Omarchy" right now, you are bound to run into the many comments made by disgruntled 1Password users on Reddit and Hacker News.
They are calling the choice tone-deaf, given how many smaller open source projects could've benefited from the money. Some are already jumping to alternatives like Bitwarden, while others suggest self-hosting Vaultwarden or going with KeePass and its forks instead.
I see the issue compounding too. Back in February, 1Password raised subscription prices, taking effect at renewals from March 27. Individual plans went up 33 percent from $35.88 to $47.88 a year, and family plans went up 20 percent from $59.88 to $71.88.
Its community forum already has a long thread full of longtime users saying they were leaving over it. If 1Password continues playing with its users' trust like this, who knows what kind of exodus it will see next?
1Password Just Pledged $300,000 to DHH's Omarchy, and its Own Employees Aren't Happy
Internal Slack messages show the CEO and cofounder gave staff two very different explanations for the decision.Sourav Rudra (It's FOSS)
like this
Sickday and bretton.dev like this.
Uuuuhhhh... those prices... kinda have a, um, theme.
I see the issue compounding too. Back in February, 1Password raised subscription prices, taking effect at renewals from March 27. Individual plans went up 33 percent from $35.88 to $47.88 a year, and family plans went up 20 percent from $59.88 to $71.88
like this
TVA likes this.
like this
TVA likes this.
I'm glad to be aware of FOSS alternatives nowadays for pretty much any service I use/require.
I would never pay these prices for a password manager (not even the initial price), specially considering my sensitive data would be sent to a 3rd party company through a closed source project which no one can verify.
Even using Bitwarden free (which admittedly I use for convenience) is not exactly comfortable to me, even being mostly open source. I'm constantly considering moving back to KeePass as I used to do some years ago.
Any subscription whose monthly price ends in .99 will have an annual price that ends in .88.
- Netflix @ 8.99 a month? That’s 107.88! Nazis!
- Crunchyroll @ 9.99 / 13.99 / 17.99 a month! Nazis!
- Xbox Gamepass @ 9.99 a month? That’s 119.88! Nazis!
Did no one in these comments pass grade school math?!
I'm guessing it's more of a critical thinking issue.
"Huh, that's a weird number. I wonder why that is..." is harder than "That number is associated with Nazis!"
That being said... Maybe 1Password should offer an annual subscription discount. Both because buying in bulk often comes with a discount, but also to avoid the number that's associated with Nazis.
Netflix do not sell a product that costs $107.88. There is no option to spend that amount on their website. No sniggering 4Chan gremlin set the price of Netflix to a number that is used as a call sign of Nazis.
These cunts have a whole menu of products that all have fixed prices that they specifically decided should end in 88. They could have rounded up or down to the nearest dollar, or use the same .99 price as everyone else, but they didn't and, the more I read of these people, the less I'm thinking it's accidental. And you're defending them.
You want to criticise other people for their maths skills, maybe brush up on your reasoning skills first.
Sounds bad...until you realize that this is how math works. Any subscription whose monthly price ends in .99 will have an annual price that ends in .88.
- Netflix @ 8.99 a month? That's 107.88! Nazis!
- Crunchyroll @ 9.99 / 13.99 / 17.99 a month! Nazis!
- Xbox Gamepass @ 9.99 a month? That's 119.88! Nazis!
Only people who are bad at math and committed to finding Nazis, real or imaginary, hiding in every nook and cranny even think about this.
If that that's not enough consider that prices ending .99 have been a sales tactic since forever. It's sometimes called "Charm Pricing" or "The 99 Effect".
The 99 Effect: Psychological Pricing Strategy to Boost Sales
Part 1 - Unlocking the Power of Perceived Savings: The Psychological Impact of the 99 Effect on Consumer BehaviorMy PM Interview (My PM Interview® - Preparation for Success)
I just looked at their website, there isn't a .88 price anywhere. If you select annual payment, it shows the price as "$3.99 per month, billed annually", which turns out to be the 47.88 from the article if you multiply it with 12.
ETA: I don't want to defend 1password, but we should criticize them for things they actually do. Like funding facists.
like this
giantpaper likes this.
This is the first time I see a conspiracy theory gain traction like that on Lemmy.
Please, do not fall for that bullshit.
I refuse!
I use KeepassXC instead.
You have two phones!!
Guys, this one has the money. Let's get davel!! 😀
I had to redo was my passkeys
phew Glad I don't use passkeys.
like this
Little1Lost likes this.
They don't. DHH is a rich guy with rich friends. This is just friend's donating to a friend's project to show support.
And that also means that the CEO of 1Password really has no problems with DHH as a person, those who talk about Omarchy being revolutionary/special or anything like that at best have rose-tinted glasses.
like this
Little1Lost likes this.
like this
Little1Lost likes this.
88 can absolutely be a fascist dog whistle. (It may or may not be here, hard to tell.)
Here's the explanation of they dog whistle: the phrase "Heil Hitler" becomes just the pair of letters "HH", which then becomes "88" since H is the 8th letter of the alphabet.
88 by itself is kind of rare, you'll usually see it paired with 14, most often as 1488. The number 14 is a reference to the 14 words which is a fascist saying that I can never remember but can always recognize. To paraphrase, it's something about securing the future for white children. It's pretty easy to find if you just search "14 words"
I have been using keepassXC on Linux and keepass2android offline on Android for the last years too!
I started with syncthing as a method of syncing the KeePass file, but now that I have all my files in nextcloud, I'm just using that.
Works flawlessly! Especially for me, as I am the only user.
like this
giantpaper likes this.
This is unfortunately a side effect of "Year of the Linux Desktop". With adoption comes "market share" so...
It's on the radar now, of everyone who ruined everything else for us. They're gonna try to infect Linux with their cancerous greed and surveillance capitalism as well.
I've come to the point I just hate business. Ugh. Can't we just be fine and left alone?
CERN Transitioning Industrial Computers To Debian After Being A Longtime RHEL Institution
CERN Transitioning Industrial Computers To Debian After Being A Longtime RHEL Institution
CERN, the European Organization for Nuclear Research, besides being well known for its Large Hadron Collider (LHC) is known among longtime Linux users as a RHEL/CentOS shopwww.phoronix.com
like this
originalucifer likes this.
The key reason for doing this, as stated in the article:
ultimately they say "the straw that broke the camel's back" to abandon Red Hat Enterprise Linux for their industrial accelerator-control computers was the "-march=x86-64-v2" compiler flag default as "forced obsolescence" for old hardware.
From what I understand, the v2 option requires relatively newer CPU instruction sets, making it incompatible with some older CPUs, even 64 bit ones. I don't know what is gained by using the v2 flag, but I would imagine that it may be something performance-related, by more fully utilizing those newer instruction sets.
like this
Infrapink and bretton.dev like this.
I would imagine that it may be something performance-related, by more fully utilizing those newer instruction sets.
Or they're deprecating shit just because, the mantainer must be just a late zoomer that drank the cool aid saying that removing old hw support is the way to go.
-march=native*
Here is the explanation from redhat
developers.redhat.com/blog/202…
It's worth noting that the archlinux devs found very little benefit for switching to v2 in their benchmarks (not that a benchmark ever covers every usecase) lists.archlinux.org/pipermail/… v3 has significantly more notable benefits but you loose even more hardware support.
Building Red Hat Enterprise Linux 9 for the x86-64-v2 microarchitecture level | Red Hat Developer
Find out why Red Hat recommends building Red Hat Enterprise Linux 9 for x86-64-v2 and what you can expect from this new, optional microarchitecture levelFlorian Weimer (Red Hat Developer)
CachyOS uses -march=x86-64-v3 or newer. I have a windows 8 era secondhand PC that I'm performance testing, and it shows marginal but statistically-significant gains over vanilla Archlinux.
V2? That's from the transition from Windows Vista to Win7 iirc.
and “kill-cycle” work in Israel
this is the first i've heard about this -- can you share more about it pls?
I mean you only need duckduckgo it, but here's an example link covering it, here's the original paper bragging about how RedHat lets the US DoW do much more murder.
The U.S. Air Force and its mission partners are fielding new mission capabilities ... to compress the kill chain. ... Red Hat® Device Edge embeds captured, analyzed, and federated data sets in a manner that
positions the warfighter to use artificial intelligence and machine learning (AI/ML) to increase the accuracy of airborne targeting and mission-guidance systems.
The disturbing white paper Red Hat is trying to erase from the internet – OSnews
The disturbing white paper Red Hat is trying to erase from the internetOSnews
Omarchy Quattro crosses 200,000 ISO downloads
Omarchy Quattro crosses 200,000 ISO downloads
Two hundred thousand Quattro ISOs in under 19 days, downloads from 215 countries and territories, and a date for the first million.DHH (Omarchy News)
This is just hyprland + quickshell.
Why are people saying this guy built all this?
I too have hyprland installed and looking nice... so that means I made hyprland. It's mine. I created it.
like this
Mordikan likes this.
but I get constant video recommendations on YouTube from Tech Bros telling me to install this thing, and then 90% of Lemmy hate it,
It's run by a fascist. That's why the techbros like it and Lemmy hates it.
It’s preconfigured arch that’s ai-forward.
At a time when a massive fraction of the open source world is thrashing around trying to figure out how to align themselves to ai that stands out.
E: people on lemmy hate it because the creator has incoherent European migration politics that come to the opposite conclusion of their own incoherent migration politics.
Tech Bros want you to install it because DHH is a fellow tech bro and a millionaire
90% of Lemmy hates it because of DHH's post about how he used to idolize London as a kid but now stays the fuck away because not enough white people.
What makes it special is that it comes preinstalled with hyprland so you don't have to pacman it. What makes hyprland special is that it's a tiling wm for wayland made by someone who, judging by their behaviour on discord and github, is 13 years old. You can just install it on Arch. You also get it as an option in the installer for CachyOS, meaning you can get it preinstalled on Arch without using Omarchy.
Also you can just use Sway, which is also a tiling wm for Wayland. Less eye candy, but probably more stable and less likely to have significant security issues.
Loading more entries...
This website uses cookies. If you continue browsing this website, you agree to the usage of cookies.

hendrik
in reply to sic_semper_tyrannis • • •