<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Cumps · Geek.</title><link>/</link><description>Recent content on Cumps · Geek.</description><generator>Hugo</generator><language>en-us</language><copyright>Copyright &amp;copy; 2026</copyright><lastBuildDate>Tue, 08 Sep 2026 10:00:00 +0200</lastBuildDate><atom:link href="/index.xml" rel="self" type="application/rss+xml"/><item><title>SPF, DKIM, DMARC: Getting Mail Delivered</title><link>/articles/2026-09-08-getting-mail-delivered/</link><pubDate>Tue, 08 Sep 2026 10:00:00 +0200</pubDate><guid>/articles/2026-09-08-getting-mail-delivered/</guid><description>&lt;p&gt;&lt;a href="/articles/2026-09-01-deploying-stalwart/"&gt;Last week&lt;/a&gt; ended with Stalwart running on two nodes. At that point I had a mail server in the same sense that a teenager with a learner&amp;rsquo;s permit has a car: technically true, not yet trusted by anyone. The big providers treat unknown mail servers as guilty until proven innocent, and the proof is a stack of DNS records and protocols that grew up as patches on a protocol from 1982.&lt;/p&gt;</description></item><item><title>One Binary for All of Email</title><link>/articles/2026-09-01-deploying-stalwart/</link><pubDate>Tue, 01 Sep 2026 10:00:00 +0200</pubDate><guid>/articles/2026-09-01-deploying-stalwart/</guid><description>&lt;p&gt;Email is the service this whole project exists for, and the one my family will not forgive me for breaking. It&amp;rsquo;s also the service with the scariest reputation in self-hosting. Part of that reputation comes from the traditional stack: Postfix for SMTP, Dovecot for IMAP, rspamd for spam, something else for CalDAV, each with its own config language, its own failure modes, and its own opinions about the others.&lt;/p&gt;</description></item><item><title>LUKS on Every Data Volume</title><link>/articles/2026-08-25-luks-everywhere/</link><pubDate>Tue, 25 Aug 2026 10:00:00 +0200</pubDate><guid>/articles/2026-08-25-luks-everywhere/</guid><description>&lt;p&gt;The threat model for a rented server is simple to state: my data sits on disks I will never see, in a data center I will never visit, handled by people I will never meet. Disks get decommissioned, snapshots get copied, hardware gets recycled. I can&amp;rsquo;t control any of that. What I can control is whether the bytes on those disks mean anything without a passphrase. &lt;a href="/articles/2026-08-18-secrets-in-git/"&gt;Last week&lt;/a&gt; covered the secrets that never leave the git repository; this week is about the disks those secrets unlock.&lt;/p&gt;</description></item><item><title>Secrets That Live in Git</title><link>/articles/2026-08-18-secrets-in-git/</link><pubDate>Tue, 18 Aug 2026 10:00:00 +0200</pubDate><guid>/articles/2026-08-18-secrets-in-git/</guid><description>&lt;p&gt;This is the first of the foundation retrospectives I promised in &lt;a href="/articles/2026-08-11-catching-up/"&gt;the catch-up post&lt;/a&gt;. We&amp;rsquo;re going back to December, before a single server existed, when the first real decision of the project wasn&amp;rsquo;t about compute or DNS. It was: where do the secrets live?&lt;/p&gt;</description></item><item><title>Catching Up: Six Months of Building, Zero Posts</title><link>/articles/2026-08-11-catching-up/</link><pubDate>Tue, 11 Aug 2026 10:00:00 +0200</pubDate><guid>/articles/2026-08-11-catching-up/</guid><description>&lt;p&gt;The &lt;a href="/articles/2026-02-23-architecture-overview/"&gt;last post&lt;/a&gt; on this blog is dated February 23rd. It ended with a to-do list: monitoring, backups, Git hosting, password management, migrating out of Google. Then nothing for almost six months.&lt;/p&gt;</description></item><item><title>Building a Self-Hosted Platform: Architecture Overview</title><link>/articles/2026-02-23-architecture-overview/</link><pubDate>Mon, 23 Feb 2026 11:00:00 +0100</pubDate><guid>/articles/2026-02-23-architecture-overview/</guid><description>&lt;p&gt;In the &lt;a href="/articles/2026-02-22-why-self-host/"&gt;previous post&lt;/a&gt; I explained why I&amp;rsquo;m moving my family off Google Workspace and onto self-hosted infrastructure. This post is about how it&amp;rsquo;s built.&lt;/p&gt;</description></item><item><title>Why I'm Self-Hosting Everything</title><link>/articles/2026-02-22-why-self-host/</link><pubDate>Sun, 22 Feb 2026 10:00:00 +0100</pubDate><guid>/articles/2026-02-22-why-self-host/</guid><description>&lt;p&gt;A few months ago my nine-year-old asked me why YouTube always seems to know what she wants to watch. I gave her a half-answer about algorithms and changed the subject. That evening, after the kids were in bed, I sat staring at my Google Workspace admin console and felt uneasy for the first time in years. Not because Google had done something wrong exactly, but because I finally sat with the question: why is every email my family sends, every calendar invite, every contact stored on servers I have zero control over, in a jurisdiction that doesn&amp;rsquo;t answer to us?&lt;/p&gt;</description></item><item><title>Search Result</title><link>/search/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>/search/</guid><description/></item></channel></rss>