Archive: 2026

GossipNetworking2 min read

SecretNest has moved to Cloudflare

After almost twenty years on WordPress, SecretNest has a new home. The whole site, including every post since 2004, the comments, the photos, the music and the downloads, now runs entirely on Cloudflare. The old server is no longer part of the picture.

Nothing was wrong with WordPress. But for a blog that gets a new post every few months, running a VM with PHP, MariaDB, nginx, a tunnel, a dozen plugins and their updates felt like a lot of machinery to keep alive. I wanted something that costs nothing to idle, has nothing to patch, and is fast everywhere.

The stack

  • Cloudflare Workers renders every page on the server. The app is written in TypeScript with Hono and its JSX renderer. The whole Worker is about 60 KB gzipped and fits comfortably in the free plan.
  • D1 (Cloudflare's SQLite) stores posts, pages, categories, tags, comments and settings. Search uses SQLite FTS5 with a trigram tokenizer, so Chinese and Japanese text can be searched too.
  • R2 holds about 16 GB of media. Images, music and downloads are served straight from R2 on their own subdomains, so they never touch the Worker.
  • Rendered pages are cached at the edge and invalidated whenever something changes. Most visits never reach the database.

I first looked at Payload CMS on D1 and R2, but its bundle is far too large for a free-plan Worker. A small purpose-built app turned out to be the simpler answer. Writing it went much faster than I expected with an AI pair programmer.

Keeping the old links alive

Old links had to keep working. Every permalink keeps its exact path. Old wp.secretnest.info and www addresses redirect permanently to the same path here, and old image URLs redirect to the new media host. Even WordPress's attachment pages and ?p=123-style links land on the right post.

Before the switch I checked every published URL, plus everything Google had indexed, against the new site. All 1,806 of them returned either the page or a correct redirect. Google Search Console's change-of-address tool took care of the rest.

Comments

Comments are still open, and you don't need an account. Spam protection is layered: a honeypot field, a signed timestamp that rejects instant submissions, Cloudflare Turnstile, per-IP rate limits and a few content rules. Everything that passes waits for my approval, and I get a push notification when something new arrives. All 177 existing comments came along, replies included.

Writing

The admin side is small: a rich-text editor (TipTap) that round-trips the old WordPress HTML without losing anything, a media library that resizes images in the browser before uploading, and pages for comment moderation, redirects and settings. That's everything I actually used in WordPress, and nothing I didn't.

What's next

Mostly writing again, I hope. If you find a broken link, an image that doesn't load or anything else that looks off after the move, please leave a comment below. Moderation means it will reach me.

NAS1 min read

AzureStorageBackup — I got tired of waiting for someone else's backup tool to be fixed

I run a QNAP NAS, and for a long time its HBS3 handled my backups to Azure. Or tried to. Every so often something strange would surface in the Azure job, and every fix meant days of back-and-forth with support before anything moved. Eventually the arithmetic flipped: with AI helping me write it, building my own tool became cheaper than waiting for theirs to work.

So I did — and I added the things HBS3 never gave me. The one I wanted most is encrypted file names: archives are written with 7-Zip AES-256 including the header, so the storage container holds opaque pack blobs, not a readable map of my directory tree.

What it does today:

  • Incremental backups — unchanged files are never reopened; a file whose timestamp moved but whose content didn't is re-hashed, not re-uploaded.
  • Small files packed, large files split into volumes, with per-extension rules for what not to compress.
  • Versions, retention, and Hot/Cool/Archive tiers.
  • Pause, Suspend, Resume. Every confirmed upload is journalled to disk, so an interrupted run — including a container upgrade — picks up where it stopped instead of resending terabytes.
  • Network hiccups back off and retry rather than failing the run.
  • Scheduled jobs, integrity checks, repair from your local copy, and restore.
  • One multi-arch Docker image (amd64 + arm64), web UI on a single port. Built for a NAS: 7-Zip runs at lowest CPU priority by default.

It only targets Azure Blob Storage, because that is all I need. If your destination is S3, Backblaze or a box in your basement, the engine is the part worth having — fork it and swap the back end. MIT licensed.

Try it: https://github.com/SecretNest/AzureStorageBackup

Issues and pull requests welcome.

SqlServer1 min read

SqlServer official docker image REVERTED to old version

I have some servers with sqlserver installed with official docker image (https://hub.docker.com/r/microsoft/mssql-server) and the "latest" tag. After a image upgrading fired by watchtower, all these containers fails on start. Only error displayed "PAL initialization failed. error 101".

Fortunately, the databases on these servers are all attached. After I cleaned the mounted folder and restart, when trying to attach the databases back, I got this: The database 'xxxx' cannot be opened because it is version 998. This server supports version 958 and earlier.

So the solution is simple: turns the tag from "latest" to "2025-latest", then re-composes docker with f-word to Microsoft.

May this article save your day.