Big Tech Exit, Gitea Patch, and Floppy Imaging

Homelab Highlights for 2026-09-21: self-hosting and homelab notes worth knowing.

[Audio embed placeholder]

News Roundup

If you’re running Gitea, make sure it’s patched! Easily exploitable RCE in <1.27.0

A security report describes an easily exploitable remote code execution issue in Gitea versions before 1.27.0, chained from a file-read flaw. The discussion asks whether Forgejo is affected, and one commenter points to a Forgejo security fix released on August 7th.

Why it matters: Commenters report real-world impact: one found config files with base64-encoded miner settings after a compromise, and another saw attack attempts in their access log after automatic updates had already patched their instance. The report notes exposure matters too, whether port-forwarded or reachable from a shared network like Tailscale. If you run Gitea or Forgejo, check your version and patch.

Source: yusmpgroup.com

Updating an Aqara FP300 over Matter/Thread with no Aqara hub, full walkthrough (matterjs-server + Docker)

A Home Assistant user details how to update Aqara FP300 presence sensors over Matter/Thread without buying an Aqara hub, by serving firmware locally through a self-hosted Matter server with an OTA provider directory. Aqara never pushed version 1.1.3.8 through the normal Matter update path.

Why it matters: The walkthrough covers backing up the Matter fabric first, verifying the community-archived firmware’s size and checksum before flashing, and keeping the sensor about one meter from the border router during the roughly twelve-minute transfer. The author also notes reported occupancy regressions on the equivalent Zigbee release and suggests updating one sensor as a control. The firmware comes from a community archive, not Aqara, so verify hashes before you try it.

Source: r/homeassistant

Youtarr update (v1.84.0): watched status from Plex/Jellyfin/Emby, automatic cleanup, and whole-channel downloads

Youtarr, a free, open-source, self-hosted YouTube DVR that downloads channel videos for viewing in Plex, Jellyfin, Emby, or the browser, has reached version 1.84.0 with a substantial feature set.

Why it matters: New in this release: watched status flows one-way in from Plex, Jellyfin, or Emby; automatic cleanup rules can delete watched videos while protecting recent downloads or whole channels, with a preview before enabling; and whole-channel downloads are now supported. The author also added more playlist controls, clearer progress reporting, manual yt-dlp updates, and standard Docker Compose installation. One user says the cleanup feature alone sold them after accumulating three terabytes of half-watched streams.

Source: r/selfhosted

Tool & Software Highlight: Goodbye US Big Tech: I replaced 17 dependencies (Google Cloud, GitHub, Cloudflare…) in one week

The founder of Fluado says the company started on Google Cloud for convenience, but a year later found itself relying on Cloudflare, GitHub, Supabase Cloud, Firebase, Slack, and Google Workspace. At the end of August, the team set out to move away from US providers, and reports the bulk of the work took about a week. Services going out include Google Cloud and Cloud Run, GitHub, Supabase Cloud, Firebase, Cloudflare, and Slack; replacements include Hetzner, Forgejo, self-hosted Supabase, Scaleway, and Mattermost.

Why it matters: The post covers seventeen changes and names what remains unfinished, including Google Workspace, coding agents, and a Let’s Encrypt replacement, where the author says no true drop-in European option was found. It is a practical example of mapping dependencies and deciding which changes are worth maintaining, with commenters adding suggestions like ZeroSSL, BunnyCDN, and k3s, and some pushing back that it reads as a startup’s cloud migration rather than pure self-hosting.

Source: yves.vg

Sources

Transcript

Host A: Welcome to Homelab Highlights, the show that surfaces practical homelab wins and useful self-hosted tools.

Host A: A small software company says it moved the bulk of its infrastructure away from US Big Tech in about a week. The founder says Fluado started on Google Cloud because it was familiar and there was already plenty to do while building a company. A year later, that convenience had turned into a wider dependency list: Cloudflare, Google Cloud, Supabase, GitHub, Slack, and Google Workspace were all in the picture.

Host B: The article says the goal had been to operate outside US Big Tech from the start, but it was easy to postpone that decision. At the end of August, the team decided to make the move. Its list of services going out includes Google Cloud and Cloud Run, GitHub, Supabase Cloud, Firebase, Cloudflare, and Slack. The replacements named in the post include Hetzner, Forgejo, self-hosted Supabase, Scaleway, and Mattermost. The author says the bulk of the work took a week; the article goes through seventeen changes in total.

Host A: One useful detail is is that it is not framed as a magic one-click escape. Some services are replaced with European providers, and some are operated by the team itself. That changes who runs the infrastructure and what the team has to maintain. The post does not give a verified savings percentage or tie the decision to a particular outage, neither belongs in the script. The useful question for a homelabber is smaller: which dependencies are defaults you chose deliberately, and which ones stuck because changing them felt like one more job?

Host B: There is a real trade-off in that list. Hetzner and Scaleway are providers; Forgejo, self-hosted Supabase, and Mattermost mean taking on some operational work as well. The article presents the move as a deliberate change in dependencies, not as proof that every company should copy the exact stack. That distinction keeps the story practical: map where the important data and services live, then decide which change is worth maintaining.

Host A: First, Gitea users should check the version they are running. The selected security report describes a file-read flaw in the markup path that can become much more serious when chained with other weaknesses. Gitea’s own 1.27.1 security release names CVE-2026-59774 for unauthenticated file reading and CVE-2026-60004 for remote code execution through Git-hook installation. The practical advice is simple: read the project advisory and upgrade to a fixed release; do not rely on the placeholder CVE number that appeared in the earlier draft.

Host B: The Aqara FP300 post is a hands-on workaround, not a vendor release announcement. The author had sensors on firmware 1.1.0.1 and wanted 1.1.3.8 without buying another hub. Their walkthrough serves the firmware locally through a configurable, self-hosted Matter server and explains how they verified the downloaded image before trying it. That last part matters: this involves a community firmware archive and the author explicitly warns to check the image and checksum before flashing. Treat it as one person’s detailed procedure, not a universally supported update path.

Host A: And Youtarr’s author posted version 1.84.0 with a substantial set of features: watched status can flow in from Plex, Jellyfin, or Emby; cleanup rules can remove watched videos while protecting recent downloads or whole channels; and there is now a way to download every video from a channel. The post also describes more playlist controls and clearer progress reporting. It is a useful example of a small self-hosted project growing in response to requests from its users, without invented testimonials or usage numbers.

Host B: The Gitea discussion also asks whether Forgejo was affected; one commenter points to a Forgejo security fix from August. Another describes finding miner-related configuration after a compromise. That is an individual report, not evidence about how common exploitation is, but it explains why the patch advice is worth taking seriously.

Host B: The Aqara walkthrough is quite specific about prerequisites: a configurable Matter server, a working Thread border router, and a sensor already commissioned over Matter and Thread. The author says to check the image size and checksum before flashing. They report two transfers taking about thirteen and a half minutes and eleven and a half minutes. Those are their results, not a timing guarantee.

Host A: On Youtarr, the author says watched status is one-way into the app; playback inside Youtarr does not mark a video watched. Cleanup can be previewed before it is enabled, and a channel can be protected from cleanup. Those details matter because automatic deletion is useful only when the rules are visible and controllable.

Host A: This one starts with a practical bench question: can one Deviceside PSU5 tabletop supply run two TEAC FD-55GFR floppy drives on a Greaseweazle imaging setup? The story gives the drive-side numbers from the TEAC specification: together, the pair draw about 1.1 amps continuously on 12 volts, with a short startup transient below 2 amps, and about 0.8 amps on 5 volts.

Host B: The important missing number is the PSU5’s current rating. The product page says it provides 5 and 12 volts on a connector for a bare 5.25-inch drive, but it does not publish per-rail current capacity. The poster says they had asked the seller and had not heard back when they wrote the post. There is no basis to say it is safe for two drives, recommend a capacitor, or claim someone tested this exact setup.

Host A: That makes the useful takeaway a cautious one: before putting vintage hardware on a shared supply, compare the drive’s continuous and spin-up demand with the adapter’s documented rating. If that rating is missing, ask the maker or choose a supply with published headroom. It is a niche little tool story, but it is also a good reminder that “the connector fits” is not the same thing as “the power budget works.”

The product listing describes the PSU5 as a brick-style supply for powering a bare drive on a lab bench, not for installing a drive inside a computer. The current listing does not give the per-rail capacity needed to settle this two-drive question. Until that rating is known, the safe answer is that the setup remains unverified.

Host A: For the community highlight, a platform engineer shared a public homelab repository and a deliberately detailed README. The author says it documents a small setup that includes services such as Jellyfin and Home Assistant, and covers networking with Cloudflare, Caddy, and Tailscale.

Host B: The same post says the README walks through backups using Restic and R2, secrets management with SOPS, and other tools the author uses to make the lab secure and portable. Their explanation is refreshingly modest: they apply practices from their platform-engineering job because it keeps the hobby easier and more fun, and they hope the write-up helps other people or gives them a chance to learn from feedback.

Host A: That is a nice model for documentation: record the decisions and recovery details that future-you will forget, then keep sensitive values out of the public repo. This segment sticks to what the post actually says; it does not provide evidence for star counts, Terraform use, a particular recovery time, or a specific backup rotation. If you want an example to borrow from, the linked README is the artifact to inspect.

The author links the repository itself, so listeners can inspect the README rather than relying on a paraphrase. The story is not a claim that one documentation style fits every lab; it is an example of making infrastructure choices easier to find again when something needs to be changed or rebuilt.

Host A: That’s Homelab Highlights for Monday. Until next time, happy hosting!