David Pinkerton's avatar
David Pinkerton
dave@dpinkerton.com
npub1jz0r...aju6
Systems thinking applied to servers, sats, and sets. CTO building self-hosted infrastructure and Bitcoin systems.
David Pinkerton's avatar
David Pinkerton 2 months ago
I'm astonished by how good Claude is at troubleshooting things. Here's a small example from this morning: I find it entertaining to watch how it gathers info then sets about fixing the problem. In this case, it was an intermittent connectivity issue with a lightning channel. I'd initially connected to ln.mineracks.com over clearnet, as it was operating as a hybrid node. Later, it switched to Tor only, which broke things. I prefer clearnet, but I still wanted to maintain the connection, so now my node is configured to use Tor when needed to reach peers while advertising only its clearnet address.
David Pinkerton's avatar
David Pinkerton 3 months ago
I offended an open source maintainer with an @-mention on my PR. I got a stern response but his points were valid. I got thinking on how AI tools are creating a new "Eternal September" for open source with more contributions, but more noise for volunteer maintainers who are already stretched thin. What if AI could help their side too? Triage, first-pass review, quality gates, etc to protect volunteer time instead of just consuming it. A few already discussing this and putting it into practice. My reflections:
David Pinkerton's avatar
David Pinkerton 3 months ago
SeedSigner doesn't support message signing for multisig keys — it throws "Not implemented" for any m/48' derivation path. I raised this as an issue two years ago, no fix came, so I patched it myself. The change is small (21 lines) and the actual signing function already worked — it was just the path parser blocking multisig paths unnecessarily. I use message signing for key ownership and control verification in multisig SMSF custody setups via Gatekeeper (https://gatekeeper.dpinkerton.com). Coldcard handles this fine, but SeedSigner users were stuck. Blog post: PR: Patched image (Pi Zero): #seedsigner #bitcoin #multisig #opensource
David Pinkerton's avatar
David Pinkerton 3 months ago
Wrote up how my homelab proxying strategy evolved over four phases — from port forwarding with DDNS to a VPS running nothing but HAProxy for L4 passthrough. The key insight: keep the VPS dumb. SNI inspection, encrypted passthrough, nothing else. TLS termination belongs on hardware you control. Comparison table of L7-on-VPS vs L4-passthrough vs direct port forwarding, plus thoughts on Traefik for automatic Docker service discovery. #selfhosting #homelab #haproxy #caddy #traefik #reverseproxy
David Pinkerton's avatar
David Pinkerton 3 months ago
Most bot/notification setups use Telegram or Signal. Both require trusting someone else with your metadata. I set up SimpleX CLI in Docker with my own relay. E2E encrypted, no phone numbers, no accounts, infrastructure I control. Wrote up the setup including the gotchas (expect scripts for headless user creation, socat to work around localhost binding). Blog: Repo:
David Pinkerton's avatar
David Pinkerton 3 months ago
Spent an afternoon debugging why Caddy's forward_auth wasn't passing group headers from oauth2-proxy when calling it over HTTPS across networks. The fix was one line: header_up Host oauth2-proxy.example.com Without it, Caddy sends the original request's Host header, oauth2-proxy's cookie validation gets confused, and X-Auth-Request-Groups silently disappears. Wrote it up:
David Pinkerton's avatar
David Pinkerton 3 months ago
Wanted to spin up a new VPS tonight. Prompted for password + SMS 2FA. Phone was already off. Didn't bother. Started thinking about how much simpler passkeys are and how infrastructure providers should've adopted them years ago. So I built a demo and pitched the VPS provider on adding them. WebAuthn is cleaner than passwords done properly. No secrets cross the network. Your DB only stores public keys. The main barrier is just inertia, I think. Wrote up the implementation details:
David Pinkerton's avatar
David Pinkerton 3 months ago
If I follow you, you now have a home relay. I rebuilt my Nostr relay as a "web of trust" model - it accepts posts from me and everyone I follow. Your content, replies to you, all stored. Add it as a backup: wss://nostr.dpinkerton.com Full writeup on what I did and why: #nostr #relay
David Pinkerton's avatar
David Pinkerton 3 months ago
Trying negative inbound fees for passive rebalancing Depleted channels: -1 sat, -300ppm inbound discount, 500ppm outbound Heavy channels: 0.25 sat, 25ppm outbound The idea: create arbitrage so routers move liquidity where I need it. Every route through me is a rebalance. Seems better than manual rebalancing since you're earning fees instead of paying them, and it only happens when there's actual demand. Using charge-lnd to auto-adjust as balances shift. LND 0.18+ required. We'll see how it goes. #lightning #bitcoin #lnd
David Pinkerton's avatar
David Pinkerton 4 months ago
WORD5 #452 6/6 ⬛⬛⬛⬛⬛ ⬛⬛🟧⬛⬛ ⬛🟪⬛⬛🟧 ⬛🟪⬛⬛⬛ ⬛🟪⬛⬛🟪 🟪🟪🟪🟪🟪
David Pinkerton's avatar
David Pinkerton 4 months ago
WORD5 #447 5/6 ⬛⬛⬛⬛⬛ 🟧⬛🟧⬛🟧 🟪🟧🟧🟧⬛ 🟪🟪🟪⬛🟪 🟪🟪🟪🟪🟪