SysAdmin Weekly
Andy Syrewicze and Eric Siron
0
SysAdmin Weekly is a podcast for busy system administrators, hosted by longtime sysadmins and Microsoft MVPs Andy Syrewicze and Eric Siron. The show covers IT-related topics, technical know-how, and real-world insights to help sysadmins navigate their daily challenges. Each episode dives into relevant issues and solutions, offering expert advice and engaging discussions tailored to professionals in the trenches.
Jaksot
-
059 - How Should SysAdmins Handle Remote Access in 2026? 11.09.2026 1t 14minWhich protocol you use to reach the box is the least interesting decision you will make about remote access.Andy Syrewicze and Eric Siron go after the piece they cut from the tools episode. Eric lands the sharpest version half an hour in: what you are actually doing is moving from one-sided authentication to mutual authentication. Around that sit overlay networks against the VPN concentrator, the RMM console as the most attractive target in an MSP estate, the outbound tunnel nobody watches for, and whether just-in-time access holds up at 3am with something down and nobody awake to approve it.Chapters:00:00:00 - Cold Open: Remote Access Gets Its Own Episode00:01:20 - Welcome and Show Plugs00:04:16 - News React: Anthropic Safety Researcher Resigns00:12:54 - News React: Broadcom Pulls Public VDDK Access00:16:21 - Nerd Hour: Eric's Hugo Migration00:17:24 - Three Gates Against a Runaway API Bill00:20:38 - Main Topic: The Tooling Is the Small Part00:23:08 - SSH on 22, and the Port Change Experiment00:24:21 - Name a Reason to Expose a Management Port00:27:10 - Overlay Networks, Tailscale, and WireGuard00:29:31 - Eric: This Is About Mutual Authentication00:32:20 - RMM Tools and the Central Console Problem00:33:41 - Do You Need Remote Management All the Time?00:34:36 - Just Enough Administration Meets Just in Time00:36:00 - Eric: I Attack the Endpoint, Not the Protocol00:40:16 - Risk Assessment Is a SysAdmin Skill00:42:47 - The Firewall Is Also the VPN, and Fortinet00:45:17 - Outbound Access, Attacker's Side00:47:32 - Is Anyone Watching Outbound Traffic?00:50:52 - The 3am Phone Call00:52:46 - Eric: MFA Everything, No Remember Me00:55:44 - PAM, PIM, and Where to Read Up00:56:14 - Nothing Revokes Itself Unless You Build It00:58:13 - Key Takeaways: Never Rely on One Control00:59:40 - Access Should Be Ephemeral01:01:46 - Risk Profiles: Tomcat vs Medical Records01:03:52 - The Tools: Tailscale, SSH, Remmina01:07:56 - Eric's Kit: PuTTY, WinSCP, rsync01:11:17 - Do This Monday01:13:52 - Wrap Up and OutroResources / Show Notes:- NBC News, Anthropic researcher Jacob Coxon resigns: https://www.nbcnews.com/tech/tech-news/anthropic-safety-researcher-resigned-warning-rapid-ai-development-gamb-rcna596767- RentAHuman, where AI agents hire people for real world tasks: https://rentahuman.ai- Brandon Lee (vExpert), Broadcom pulled public VDDK access: https://www.virtualizationhowto.com/2026/09/leaving-vmware-just-got-harder-after-broadcom-pulled-vddk-downloads/- CISA, hardening Fortinet devices after credential exposure: https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure- Microsoft Learn, Entra PIM, eligible versus active access: https://learn.microsoft.com/en-us/entra/id-governance/privileged-identity-management/pim-configure- Tailscale, free Personal plan covers 6 users: https://tailscale.com/pricing- WireGuard, what Tailscale manages under the hood: https://www.wireguard.com- Cisco Duo, free tier for teams of 10 or fewer: https://duo.com- Remmina, open source RDP, VNC and SSH client: https://remmina.org- PuTTY: https://www.chiark.greenend.org.uk/~sgtatham/putty/- WinSCP: https://winscp.net- SysAdmin Weekly: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions -
058 - What Tools Do SysAdmins Actually Use Every Day? 04.09.2026 1t 5minThe tools that stay in the kit for a decade are the ones that still work when the network, the domain, or the boot volume is the thing that broke.Andy Syrewicze and Eric Siron open their real toolboxes and argue about what earns permanent residency. nmap and Wireshark for what is actually on the wire, Sysinternals for what a box is really doing, GParted and SystemRescue for the volume that will not mount, and the chkdsk, DISM, then SFC sequence Eric can run in his sleep. Andy's list skews hard toward triage because MSP work meant walking into a stranger's burning network every week. Remote access is missing on purpose; RDP, SSH, and overlay networks are getting their own episode.Chapters:00:00:00 - Cold Open: The Tools That Save Your Bacon00:01:13 - Welcome and Show Plugs00:03:11 - News React: Anthropic's Enterprise Frontier Safeguards00:07:01 - News React: The US Goes Openly Offensive in Cyber00:12:57 - Nerd Hour: CC Top and a Pomodoro Timer That Remembers00:15:53 - What Earns a Permanent Spot in the Toolbox00:17:32 - Why MSP Years Produce a Triage Kit00:20:13 - nmap, and the Licensed Cisco Utility Story00:22:31 - Sysinternals and Process Monitor00:23:16 - Wireshark Past the Basics00:24:09 - netstat and nslookup Are Not Wizardry00:25:12 - dig, and Why ping Is Not a DNS Tool00:27:22 - Test-NetConnection Instead of ping00:27:59 - Why Anyone Blocks ICMP in the First Place00:30:11 - MXToolbox, PingPlotter, and the Neighbor's Air Conditioner00:33:18 - GParted, SystemRescue, and the Live CD Shelf00:35:58 - chkdsk, DISM, then SFC, in That Order00:38:06 - DBAN and Decommissioning Disks00:40:51 - The Multi-Pass Wipe Myth00:43:25 - Greenshot and Capture Last Region00:46:07 - Spectacle, Client Hypervisors, Docker and Podman00:47:33 - Get-Help and man: Nobody Remembers Syntax00:48:28 - OpenSSL, Qualys SSL Labs, and testssl.sh00:50:13 - WSL as the Whole Toolbox00:51:37 - The Everyday List: Vim, Bitwarden, Git, Package Managers00:54:20 - Remote Access Gets Its Own Episode00:55:30 - The Platform Tax After Leaving Windows00:58:18 - Edge on WSL on Windows, for Certificate Chains01:01:02 - Do This Monday01:03:31 - Eric's Advice: Go Look for the Tool01:04:37 - Wrap Up and OutroResources / Show Notes:- Anthropic, Developing Enterprise Frontier Safeguards: https://www.anthropic.com/news/enterprise-frontier-safeguards- Nmap: https://nmap.org/- Wireshark: https://www.wireshark.org/- Microsoft Sysinternals, and Sysinternals Live: https://learn.microsoft.com/en-us/sysinternals/- MXToolbox, external DNS and blacklist checks: https://mxtoolbox.com/- PingPlotter, latency and packet loss per hop: https://www.pingplotter.com/- GParted, and the live image: https://gparted.org/- SystemRescue: https://www.system-rescue.org/- DBAN, still there, spinning disk era, not for SSDs: https://sourceforge.net/projects/dban/- Greenshot, Windows only: https://getgreenshot.org/- Qualys SSL Labs, tick the box to stay off the public board: https://www.ssllabs.com/ssltest/- testssl.sh, for internal sites: https://testssl.sh/- DevToys, clipboard certificate parser: https://devtoys.app/- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions, what is in your toolbox: https://github.com/ProjectRunspace/sysadmin-weekly/discussions -
057 - Is Your Air Gap Actually an Air Gap? Port 22 Says No 28.08.2026 1t 6minSomewhere inside that isolated network, port 22 is open, and it has been open since the outage six months ago that nobody wrote up.Andy Syrewicze and Eric Siron take apart a term the industry uses constantly and almost never earns. They walk the management plane hole by hole: SSH and RDP so somebody can patch the thing, SMB for the files that have to move, DNS and NTP because nothing works without them, and the iDRAC, iLO, and IPMI boards that get parked on the management VLAN and then never patched at all. The argument they land on is not that a real air gap is impossible, it is that calling something an air gap ends the conversation, and a promise nobody re-verifies is worse than a risk everybody can see.Chapters:00:00:00 - Cold Open: Your Air Gap Probably Is Not an Air Gap00:01:12 - Welcome and Show Plugs00:04:19 - News React: An AirTag, a Rare Book, and an Amazon Scanning Facility00:10:10 - News React: Bill Gates Changes His Mind on AI and Jobs00:13:03 - What the Entry Level Job Market Looks Like Right Now00:15:05 - When Nobody Is Left Who Knows How to Program It00:19:25 - Nerd Hour: Claude Code, Agents, and Building CC Top00:23:54 - Nerd Hour: Moving Project Runspace to Hugo, JavaScript Free00:28:22 - What an Air Gap Actually Means00:31:22 - Logical, Network, Virtual: How the Word Got Laundered00:32:36 - Every Hole You Poke Just to Manage the Thing00:34:18 - The One Nobody Segments: iDRAC, iLO, and IPMI00:36:26 - A Brief and Deserved Detour About Printers00:37:23 - NTP, DNS, License Activation, and Telemetry00:40:34 - Why Leaving Hyper-V Out of the Domain Is Not Security00:43:16 - VLANs, Switch Fabric, and Breakout Attacks00:44:40 - Assume Breach: Zero Trust, JIT, and JEA00:50:36 - Sneaker Net and Poisoned USB Drives00:52:20 - Stuxnet and the Gap That Was Real00:54:59 - How Would You Even Safely Clean a USB Drive?00:56:58 - Say What You Have, Then Defend It00:57:29 - The Real Danger Is the False Sense of Security01:00:23 - The Windows Firewall Lesson01:03:11 - What a Genuine Air Gap Actually Costs01:04:59 - Wrap Up and OutroResources / Show Notes:- Symantec Security Response, W32.Stuxnet Dossier, the canonical technical analysis: https://docs.broadcom.com/doc/security-response-w32-stuxnet-dossier-11-en- Ralph Langner, To Kill a Centrifuge, on why post-Stuxnet air gap strategies miss the point: https://www.cs.yale.edu/homes/jf/Langner.pdf- The 2008 USB breach of US military networks, Agent.btz and Operation Buckshot Yankee: https://en.wikipedia.org/wiki/2008_malware_infection_of_the_United_States_Department_of_Defense- Microsoft Security Advisory 967940, the update that killed USB AutoRun: https://learn.microsoft.com/en-us/security-updates/securityadvisories/2009/967940- NIST SP 800-82 Rev. 3, Guide to Operational Technology Security, for naming what you actually have: https://csrc.nist.gov/pubs/sp/800/82/r3/final- 404 Media, tracking a shipment of rare books to an Amazon AI training facility: https://www.404media.co/we-tracked-a-shipment-of-rare-books-it-ended-at-an-amazon-ai-training-facility/- Semafor, Bill Gates has changed his mind about AI and jobs: https://www.semafor.com/article/08/25/2026/this-is-crazy-this-is-insane-bill-gates-has-changed-his-mind-about-ai-and-jobsGates Notes, the essay itself: The turbulent AI era is here: https://www.gatesnotes.com/a-turbulent-ai-era-and-critical-choices-to-make- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions, tell us about your air gap and why you have one: https://github.com/ProjectRunspace/sysadmin-weekly/discussions -
056 - How People Actually Get Into SysAdmin Work 22.08.2026 1t 29minTwo careers, two completely different entry points, and the exact same first catastrophe: data gone, no idea if it was coming back.Andy Syrewicze and Eric Siron trade full origin stories, from the 486 and the VIC-20 through the first paid tech jobs neither of them was qualified for. They get specific about the failures that rewired how they work, the mentor advice that still holds up decades later, the advice that aged badly, and the question underneath all of it: the on-ramp that produced both of them was cheap hardware, full access, and time to break things, and most of that is gone. Whether that actually matters for anyone starting in 2026 is the argument they finish on.Chapters:00:00:00 - Cold Open: How We Actually Got Into IT00:01:01 - Welcome, Show Plugs, and Why There Was a Gap00:05:03 - News React: Meta Goes Open Source Again With Muse Glimmer00:07:55 - News React: Lithium Battery Farms, Data Centers, and Zoning Boards00:16:39 - Nerd Hour: A Black Hat Demo on Local LLMs and M365 Spear Phishing00:19:34 - Nerd Hour: Fish Tape, a Whole House Vacuum, and a 160 Degree Attic00:24:51 - The Stuff We Broke Before Anyone Paid Us00:26:31 - Andy: The 486, the Matrix Boot Screen, and Getting Told to Change It Back00:30:41 - Eric: The VIC-20, a Xerox 286, and Overclocking With a Box Fan00:37:53 - Andy's First IT Job: A K-12 Summer Gig and 30 Cables a Foot Short00:44:05 - Eric's First IT Job: Freight Dock to Phone Support00:49:14 - Would Either of These Paths Still Get You Hired Today?00:56:02 - Andy Nukes the Application Share and Prays at a Tape Drive01:00:11 - Eric's Version: Dad, I Deleted All Your Files01:02:46 - Why Almost Every SysAdmin's First Disaster Involves Data01:04:21 - Advice That Held Up: The Key to IT Is Laziness01:10:06 - Being Decent Beats Being Smart, and Learning to Say I Don't Know01:15:01 - Advice That Aged Badly: Always, Never, and Best Practice01:17:31 - Nobody Ever Got Fired for Buying IBM01:23:02 - Does This On-Ramp Still Exist in 2026?01:26:07 - You Do Not Need Commercial Gear to Learn This01:27:56 - Wrap Up and OutroResources / Show Notes:- VentureBeat - Meta returns to open source with Muse Glimmer: https://venturebeat.com/technology/meta-returns-to-open-source-with-muse-glimmer-an-apache-2-0-licensed-30b-parameter-ai-model-optimized-for-agents-available-now- MultiState - Federal AI data center policy meets resistance from state lawmakers: https://www.multistate.us/insider/2026/4/14/federal-ai-data-center-policy-meets-resistance-from-state-lawmakers- Black Hat official YouTube, where the USA 2026 Briefings recordings post: https://www.youtube.com/@BlackHatOfficialYT- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions, tell us your first broke something moment: https://github.com/ProjectRunspace/sysadmin-weekly/discussions -
055 - How Do You Run IT With No Budget? 14.08.2026 1t 5min"No budget" is almost never no budget. It is no budget yet, and the thing that closes the gap is your ability to put a real dollar figure on the risk you are carrying.Andy Syrewicze and Eric Siron have both run IT for organizations where getting the credit card out meant you had done something wrong. They walk through what that actually looks like: a PC DOS 4 machine still passing parts in a quality lab, an end of life Cisco ASA swapped for an open source firewall on scavenged workstations, NetGear ReadyNAS units kept on a shelf for SAN emergencies, and the iSCSI arguments that never die. Then the harder part: where the first dollar goes when budget finally shows up, and how to translate aging gear into risk language that a business owner will actually fund.Chapters:00:00:00 - Cold Open: Keeping the Lights On With No Budget00:01:00 - Welcome and Show Plugs00:03:32 - News React: 25 Companies Sign On for Open Weight Models00:07:51 - News React: OpenAI, Profitability, and the Missing CFO00:12:56 - Nerd Hour: A Baldur's Gate Randomizer on GitHub Pages00:16:02 - Nerd Hour: Unicode, MiniForge, and Why the Human Said No00:20:51 - Community Comments: Cable Pulls and Fat WIM Files00:24:34 - The Reality of the Zero Budget Shop00:29:56 - End of Life Cisco ASA to an Open Source Firewall00:34:04 - You Do Not Have to Buy Cisco00:40:00 - Where Open Source Wins: Monitoring, Logging, Nmap00:43:35 - Budget Storage: NAS Stopgaps and the iSCSI Argument00:51:31 - Spending the First Dollar on Maximum Risk Reduction00:52:44 - Backups: The One Place Not to Go Free00:57:02 - No Budget Usually Means No Budget Yet01:01:40 - Document the Risk, Get the Decision in Writing01:03:40 - Wrap Up and OutroResources / Show Notes:- Microsoft - Open Weights and American AI Leadership, the letter itself: https://www.microsoft.com/en-us/corporate-responsibility/topics/open-weight/- TechCrunch - Industry urges against broad open-weight restrictions: https://techcrunch.com/2026/07/24/as-us-weighs-response-to-chinese-ai-industry-urges-against-broad-open-weight-restrictions/- Fortune - OpenAI CFO reportedly at odds with Altman over spending: https://fortune.com/2026/04/28/openai-cfo-sam-altman-missed-revenue-target/- Andy's Infinity Engine party randomizer, the Nerd Hour web app: https://asyrewicze.github.io/infinity-engine-randomizers/- PomoCLI, Andy's terminal Pomodoro timer: https://github.com/asyrewicze/pomocli- Miniforge, the package manager Andy declined to add as a dependency: https://github.com/conda-forge/miniforge- OPNsense, open source firewall: https://opnsense.org/- pfSense, open source firewall: https://www.pfsense.org/- Nagios, open source monitoring: https://www.nagios.org/- Nmap, free network scanner: https://nmap.org/- Restic, fast secure backup program: https://restic.net/- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- GitHub Discussions, share your no budget stories: https://github.com/ProjectRunspace/sysadmin-weekly/discussionsSources and clarifications (News React):- The open weights letter had 25 signatories on July 24, 2026. OpenAI and Google were absent that day and signed by July 26; the list has since passed 270. Anthropic has not signed.- Eric flagged the Sam Altman "no path to profitability" clip as possibly a deep fake, and we could not verify that specific video. The underlying reporting on OpenAI's CFO and spending tension is real; see the Fortune link above. -
054 - Windows Admin Center in 2026: Good Tool, Broken On-Ramp? 24.07.2026 1t 16minWindows Admin Center is a genuinely useful tool wrapped in an on-ramp so rough it took Andy four hours, a from-scratch certificate authority, and a pile of misleading error messages just to reach the login screen.Andy rebuilt his lab on an all-Core Windows Server 2025 fleet, set out to manage it from a browser the way Microsoft keeps telling us to, and hit a certificate wall that most SysAdmins would never fight through. He and Eric Siron walk the full gauntlet: the 60-day self-signed cert trap, an ERROR_DS_RANGE_CONSTRAINT that pointed the wrong way, a web server template that blocks computer requests, a silent blank SAN that kills the HTTPS binding, and the bigger question of whether a web tool is even the right way to manage Windows. Along the way: a News React on open-source AI, China, and a possible federal clampdown, plus the domain-join debate that never dies.Chapters:00:00:00 - Cold Open: Four Hours to Install a Free Tool00:01:15 - Welcome and Show Plugs00:03:52 - News React: Apple, the EU, and the Walled Garden00:08:55 - News React: Open-Source AI, China, and a Possible Federal Clampdown00:16:00 - Nerd Hour: Ripping Out KVM, Putting Hyper-V Back00:18:55 - Setting the Scene: An All-Core Lab and the Certificate Wall00:30:08 - The Four-Hour Gauntlet: A Sequence of Failures00:44:00 - What WAC Gets Right, and Where It Falls Down00:59:24 - Azure Arc and the Real Agenda01:07:45 - Does WAC Move the Needle? The VerdictResources / Show Notes:- Microsoft - Windows Admin Center overview: https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/overview- Hornetsecurity (Eric Siron) - Public Key Infrastructure explained, including why to stop using self-signed certificates: https://www.hornetsecurity.com/en/blog/public-key-infrastructure/Sources and clarifications (News React / AI segment):We referenced several press claims from memory during the AI segment. The claims hold up, but a few were under-attributed on air, so here is the precise record.- Moonshot AI - Kimi K3, the open-weight model released the week before we recorded that benchmarks near frontier US models. The whole news cycle is downstream of it: https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems- Dean Ball, OpenAI's Head of Strategic Futures and a former senior AI adviser in the Trump administration, is the source of the "AI communism" line, in a post on X. On air Andy first said "CEO of Claude" and "CEO of Anthropic," then corrected to "someone from OpenAI." The correct attribution is Ball at OpenAI, NOT Anthropic. Naming note: Claude is the model, Anthropic is the company: https://x.com/deanwball/status/2078133895766114412- Dean Ball - follow-up clarifying he was predicting that outcome, not advocating for it: https://x.com/deanwball/status/2078619513575137330- Axios (July 20, 2026) - the federal-action angle. Frame it as reportedly under consideration; no formal policy has been proposed. Mechanisms discussed include Commerce Entity List additions, security advisories, and federal procurement rules: https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi- David Sacks, former White House AI adviser, publicly argued that closed labs want the government to eliminate their open-source competition, in a post on X: https://x.com/DavidSacks/status/2078826291638522127- Dario Amodei has called open-source AI a dangerous path; the source quotes are collected in this r/Anthropic thread: https://www.reddit.com/r/Anthropic/comments/1ui759l/amodei_says_open_source_is_dangerous/ -
053 - How to Survive as a Solo SysAdmin: Where to Start When You're the Only One 17.07.2026 1t 13minWhen you are the only person standing between a working business and total collapse, the job stops being about doing everything and starts being about deciding what not to do this week.Andy and Eric Siron tackle a listener-requested topic: you just became the solo SysAdmin, whether by hire, downsizing, or promotion, and now you own the firewall, the servers, the backups, and the printer nobody wants to replace. This one is heavy on the career and survival skills that keep a team of one sane: triage before projects, documentation as an insurance policy, buying time back through automation and managed services, and speaking business value instead of acronyms to leadership. Plus a News React on Windows Server hot patching and 1Password for Claude, and a Nerd Hour on Debian 13.6 Secure Boot certs and SAML auth for Nagios.Chapters:00:00:00 - You're the Only SysAdmin. Now What?00:01:02 - Welcome and Show Plugs00:05:13 - News React: Windows Server Hot Patching via Azure Arc00:11:00 - News React: 1Password for Claude and AI Guardrails00:13:50 - Nerd Hour: Debian 13.6 and Secure Boot Certificate Updates00:16:33 - Nerd Hour: SAML Auth for Nagios via ADFS00:23:20 - Main Topic: The Case of the Solo SysAdmin00:28:23 - Triage Before Projects00:30:57 - Note-Taking Systems: ARC, Bullet Journal, Rocketbook00:46:40 - Documentation Is Survival and the Hit-By-A-Bus List00:50:25 - Greenshot and Fast Screenshot Documentation00:54:14 - Buying Time Back: Automation00:58:16 - Buying Time Back: Managed Services01:03:44 - Communicating Business Value to Leadership01:09:09 - Managing and Documenting Risk01:10:17 - Wrap-UpResources / Show Notes:- MacRumors - 1Password for Claude lets AI log in without seeing your passwords: https://www.macrumors.com/2026/07/16/1password-claude-integration/- Microsoft Learn - Enable Hotpatch for Azure Arc-enabled servers (now free for Windows Server 2025): https://learn.microsoft.com/en-us/windows-server/get-started/enable-hotpatch-azure-arc-enabled-servers- Debian - 13.6 release notes and Secure Boot CA guidance: https://www.debian.org/News/2026/20260711- Greenshot, free open-source screenshot tool: https://getgreenshot.org/- Rocketbook, reusable notebook: https://getrocketbook.com/- Bullet Journal method: https://bulletjournal.com/- SysAdmin Weekly, all show links: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- SysAdmin Weekly GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions- Andy on Tech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org -
052 - Why is Homelab Hardware So Expensive in 2026 (and When Will It Get Cheaper)? 10.07.2026 1t 12minSomewhere between a $305 Raspberry Pi board and a used NVMe listing on eBay, the homelab hobby quietly stopped making financial sense.Andy and co-host Eric Siron dig into why memory, NAND, and storage prices went vertical in 2026, who is actually eating the supply, and what practitioners should do about it. They cover the AI buildout swallowing the manufacturing capacity, why prices probably never return to pre-shortage levels, and the return of a skill the industry let atrophy: right-sizing hardware to the workload instead of throwing spec at it.## Chapters:00:00:00 - The Hardware Market Is Fire and Brimstone00:01:18 - Welcome and Intros00:04:33 - News React: The First Fully AI-Run Ransomware (JadePuffer)00:08:16 - News React: AI Job-Blame and the Unix Lawsuit That Won't Die00:13:32 - Nerd Hour: Thunderbird Finally Speaks Exchange Online00:18:47 - Nerd Hour: Hugo, AI, and the 80% Problem00:23:13 - Show Plugs00:24:09 - Why Homelab Hardware Broke Me: The eBay Moment00:41:44 - Why This Is Happening: AI Is Eating the Supply Chain00:46:43 - Local Models and the Willingness-to-Pay Problem00:52:41 - The New Normal: Prices Aren't Coming Back00:59:05 - Right-Size the Hardware to the Problem01:06:02 - Could China Break the Bottleneck?01:09:29 - One More Casualty, and Wrap-Up## Resources / Show Notes- BleepingComputer, JadePuffer AI-run ransomware: https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/- Thunderbird Blog, native Microsoft Exchange (EWS) support in 145: https://blog.thunderbird.net/2025/11/thunderbird-adds-native-microsoft-exchange-email-support/- Raspberry Pi Foundation, memory-driven price rises: https://www.raspberrypi.com/news/more-memory-driven-price-rises/- GamersNexus, SSDs WTF (NAND makers sold out for 2026): https://gamersnexus.net/features/ssds-wtf- Gartner, surging memory costs (125% DRAM / 234% NAND surge): https://www.gartner.com/en/newsroom/press-releases/2026-02-26-gartner-says-surging-memory-costs-will-reduce-global-pc-and-smartphone-shipments-in-2026- TechPowerUp, Samsung and SK Hynix $870B capacity plan and fab timelines: https://www.techpowerup.com/350478/samsung-and-sk-hynix-to-expand-semiconductor-capacity-with-usd-870-billion-plan- BBC, Samsung's memory-driven profit surge: https://www.bbc.com/news/articles/c1kyy8yrpxdo- IDC, why the memory market stays tight and makers aren't rushing capacity: https://www.idc.com/resource-center/blog/why-the-memory-market-is-still-tight-what-comes-next/- Tom's Hardware, SK Group chairman says the shortage runs until 2030: https://www.tomshardware.com/pc-components/dram/sk-group-chairman-says-memory-chip-shortage-will-last-until-2030- SemiAnalysis, China's CXMT challenging DRAM incumbents: https://newsletter.semianalysis.com/p/chinas-cxmt-is-set-to-challenge-dram- Tom's Hardware, China's YMTC and homegrown NAND tooling: https://www.tomshardware.com/pc-components/ssds/chinas-ymtc-moves-to-break-free-of-u-s-sanctions-by-building-production-line-with-homegrown-tools-aims-to-capture-15-percent-of-nand-market-by-late-2026- TrendForce, China's GPU makers scaling as enterprise accelerators: https://www.trendforce.com/news/2025/10/07/news-chinas-gpu-trio-rise-as-nvidia-retreats-decoding-moore-threads-metax-and-cambricon/- CSIS, China and global cyber supply chain risk: https://www.csis.org/blogs/strategic-technologies-blog/chinas-weaponization-global-cyber-supply-chains- AndyOnTech, Andy's hub for all his output: https://www.andyontech.com- Project Runspace, the organization behind the show: https://www.projectrunspace.org- SysAdmin Weekly GitHub Discussions, share your hardware battle stories: https://github.com/ProjectRunspace/sysadmin-weekly/discussions -
051 - What's Actually in Our Homelabs (and Why) 03.07.2026 1t 27minThe hardest part of running a home lab in 2026 is not building it up; it is being honest about what earns its place.Andy is joined by returning guest and member of the SysAdmin Weekly community, Clay Tamam, a working SysAdmin over in the Netherlands, for a real tour of what is actually sitting in their labs: the hardware, the hypervisors, the services they use every day, and the reasoning behind each choice. Andy explains why he tore a four-node Kubernetes cluster down to five VMs on a single Debian box, Clay walks through building a rack from scratch on a practical budget, and both of them dig into what current memory and hardware prices are doing to the hobby. It closes with the Graveyard: the gear and services that got powered off, and why pruning is an important part of the discipline.## Chapters00:00:00 - Welcome and a Returning Guest: Clay from the Netherlands00:07:20 - News React: A US Firm's Bid for the Dutch DigiD Infrastructure00:15:21 - News React: An AI-Assisted Hack Hits US Festival Ticketing00:18:11 - Nerd Hour: Scoping AI Agents and Building a Lab From Scratch00:24:29 - Main Topic: What Is Actually in Our Home Labs00:25:15 - The Hardware: Andy's Pared-Down Single-Box Lab00:31:25 - The Hardware: Clay's From-Scratch Rack Build00:45:52 - The Foundation: KVM vs. Proxmox00:56:33 - The Services That Earn Their Keep01:02:37 - Self-Hosting, the Plex Price Hike, and Leaving Discord01:13:57 - Learning Goals and the Graveyard01:24:19 - Local Inference and the Urge to Panic-Buy01:25:49 - Wrap-Up## Resources / Show Notes- Wired - Researcher used Claude to break Front Gate Tickets: https://www.wired.com/story/claude-helped-a-hacker-find-a-way-to-issue-tickets-to-almost-every-us-music-festival/- NL Times - Netherlands blocks the US takeover of DigiD operator Solvinity: https://nltimes.nl/2026/05/26/netherlands-blocks-us-takeover-digid-operator-solvinity-security-concerns- Security Now with Steve Gibson: https://www.grc.com/securitynow.htm- Proxmox Virtual Environment and Backup Server: https://www.proxmox.com- Forgejo, the self-hosted Git forge (Gitea fork): https://forgejo.org- Tailscale, the overlay mesh VPN: https://tailscale.com- Foundry Virtual Tabletop: https://foundryvtt.com- Plex - New Lifetime Plex Pass pricing: https://www.plex.tv/blog/new-lifetime-plex-pass-pricing/- Jellyfin, the free software media system: https://jellyfin.org- Vaultwarden, a self-hosted Bitwarden-compatible server: https://github.com/dani-garcia/vaultwarden- Framework Desktop: https://frame.work/desktop- Connect with Clay on LinkedIn: https://www.linkedin.com/in/clay-tamam-00b6441b3/- AndyOnTech: https://www.andyontech.com -
050 - How Do You Run a Blameless Incident Postmortem? 26.06.2026 1t 1minA postmortem that ends with a name instead of a root cause wasted everyone's time in the room.Andy and Eric Siron pull from a combined several-decades of incident reviews to break down what a postmortem actually is, what kind of outage earns one, and who really needs to be at the table. The throughline: keep it blameless without making it unaccountable, separate root cause from contributing factors, and remember that the follow-through is the entire point. Whether your postmortem is sixty people in a war room or just you writing a summary for one nervous boss, the discipline scales.## CHAPTERS00:00:00 - Why Postmortems Matter00:01:31 - Welcome and Show Plugs00:04:29 - News React: AI Job Hype Walkbacks, Teams Pain, Oracle Layoffs, AMD Trust00:17:42 - News React: Ubiquiti UniFi OS Max-Severity RCE CVEs00:19:41 - Nerd Hour: Claude Code, Hugo, and Pandoc00:23:36 - The Incident Postmortem Process00:26:40 - What Actually Earns a Postmortem00:29:22 - Who Needs To Be In the Room00:38:49 - Blameless, Not Unaccountable00:46:50 - What Information To Gather00:50:33 - Running the Review00:55:15 - Follow Through Is the Whole Point## RESOURCES / SHOW NOTES- SysAdmin Weekly home and show links: https://www.sysadminweekly.com- SysAdmin Weekly companion newsletter: https://newsletter.sysadminweekly.com- AndyOnTech: https://www.andyontech.com- Project Runspace: https://www.projectrunspace.org- BleepingComputer - Ubiquiti patches three max-severity UniFi OS RCE flaws (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910): https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/- Postmortem markdown template (free, CC BY 4.0, version-tracked in the show repo): https://github.com/ProjectRunspace/sysadmin-weekly/blob/main/resources/postmortem_markdown_process_template.md- Pandoc, universal document converter (Markdown to docx): https://pandoc.org- Hugo, the Markdown-driven static site generator: https://gohugo.io -
049 - How Do Attackers Use Local LLMs to Phish At Scale? 19.06.2026 1t 2minAsk Claude or ChatGPT to write a phishing email and it politely refuses; pull the right open-weight model onto your own laptop and that refusal layer simply does not exist in many cases.Andy brings his InfoSecurity Europe session to the show, and Eric Siron joins to walk through how threat actors run local LLMs on their own hardware to generate targeted spear phishing at scale, in any language, with no internet connection and no guardrails. The guys break down what the attack workflow actually looks like, why these capabilities never disappear once a model is downloaded, and where the real defensive line sits. Spoiler: "spot the typo" awareness training is dead, and verification culture plus strong email authentication is what carries the load now.## Chapters:00:00:00 - Cold Open: Local LLMs and Phishing at Scale00:01:37 - Welcome Back and InfoSecurity Europe00:03:55 - News React: Washington Pumps the Brakes on Fable00:06:46 - News React: NY Ghost Gun Printing Law and Google AI Liability00:12:07 - Nerd Hour: Camera Gear and Mac Studio Dreams00:13:27 - Nerd Hour: Building the InfoSec Demo00:15:55 - Show Plugs and Community Links00:17:00 - Main Topic: What Local LLMs Actually Are00:21:23 - The Guardrail Gap: Cloud Refuses, Local Complies00:26:55 - The Demo: 15 Tailored Spear Phishing Lures in 90 Seconds00:30:04 - Why These Capabilities Never Go Away00:32:59 - AI on the Defensive Side00:39:01 - Voice Cloning, Deepfakes, and SPF for Phones00:46:20 - The Low-Tech Deepfake Defense00:47:26 - Why Spot-the-Typo Training Is Dead00:50:09 - Verification Culture and Email Authentication00:54:32 - Common Questions: Legality, Detection, and Adoption01:00:18 - Wrap Up: Stay Safe Out There## Resources / Show Notes:- Ollama, the easiest way to run open models locally: https://ollama.com- Hugging Face, open repository of machine learning models: https://huggingface.co- OpenCode, terminal coding agent that runs against local models: https://opencode.ai- Evilginx, reverse-proxy phishing framework referenced in the demo: https://github.com/kgretzky/evilginx2- SysAdmin Weekly Episode 024 - On-Prem AI with Ollama (Spotify): https://open.spotify.com/episode/1Huz7fy7axxOqjXei1HLI0- SysAdmin Weekly - all show links in one place: https://www.sysadminweekly.com- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com- SysAdmin Weekly GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions- Project Runspace: https://www.projectrunspace.org- AndyOnTech: https://www.andyontech.com -
048 - The AI Doom Narrative vs the Data: Layoffs, Energy, and Jobs in 2026 14.06.2026 1t 24minThe AI doom headlines do not line up with what the actual data says, and that gap is doing real damage. Andy and Eric Siron take a practitioner read on the fear stories: the layoff narrative, the data center energy and water panic, and the executive predictions that office workers are gone in 18 months. They put the WEF Future of Jobs numbers, the hyperscaler nuclear and cooling commitments, and the post-COVID overhiring correction next to the headlines, and walk through what AI looks like at a SysAdmin's keyboard versus what the press would have you believe.Also in this one: Elon Musk's OpenAI lawsuit, Linus Torvalds on AI-generated bug reports clogging the kernel security list, Edge storing passwords in clear text, Eric on the Samsung browser on Windows, and Andy's Forgejo and Restic lab cleanup. Plus listener comments on broken IT job postings and the SCVMM question for Hyper-V shops.---## Chapters00:00 - Introduction to SysAdmin Weekly04:39 - AI Doom and Gloom Narrative07:36 - News React: Elon Musk vs OpenAI10:18 - News React: Linus Torvalds on AI Bug Reports13:36 - Nerd Hour: Exploring New Browsers16:30 - Microsoft Edge Password Concerns19:28 - AI's Impact on Jobs22:20 - The Reality of AI in the Workplace25:39 - AI's Role in Documentation28:28 - Critique of AI Predictions31:41 - Conclusion and Future Outlook34:12 - The Responsibility of Executives in AI Predictions38:16 - The Impact of AI on Job Markets41:42 - Understanding Layoffs in the Tech Industry49:56 - The Future of Jobs in the Age of AI56:00 - Energy and Water Concerns in Data Centers01:00:48 - The Shift in Carbon Neutral Promises01:03:37 - Concerns Over Water and Energy Resources01:05:32 - The Debate on Nuclear Power Safety01:08:40 - Real-World Applications of AI in Sysadmin01:11:12 - The Importance of Honest Communication in Tech01:13:44 - Job Market Realities for IT Professionals---## Resources / Show Notes- The Register - Linus Torvalds on AI-powered bug hunters: https://www.theregister.com/security/2026/05/18/linus-torvalds-says-ai-powered-bug-hunters-have-made-linux-security-mailing-list-almost-entirely-unmanageable/5241633- TechCrunch - A comprehensive archive of 2023 tech layoffs: https://techcrunch.com/2024/05/01/a-comprehensive-archive-of-2023-tech-layoffs/- Crunchbase News - Tech Layoffs Tracker: https://news.crunchbase.com/startups/tech-layoffs/- WEF - Future of Jobs Report 2025, 78 Million New Job Opportunities by 2030: https://www.weforum.org/press/2025/01/future-of-jobs-report-2025-78-million-new-job-opportunities-by-2030-but-urgent-upskilling-needed-to-prepare-workforces/- NPR - Three Mile Island will reopen to power Microsoft data centers: https://www.npr.org/2024/09/20/nx-s1-5120581/three-mile-island-nuclear-power-plant-microsoft-ai- Data Center Dynamics - Google signs nuclear SMR deal with Kairos: https://www.datacenterdynamics.com/en/news/google-signs-nuclear-smr-deal-with-kairos-for-data-center-power/- X-energy - Amazon invests in X-energy to support advanced SMRs: https://x-energy.com/news/amazon-invests-in-x-energy-to-support-advanced-small-modular-nuclear-reactors-and-expand-carbon-free-power/- Microsoft Cloud Blog - Sustainable by design, next-generation datacenters consume zero water for cooling: https://www.microsoft.com/en-us/microsoft-cloud/blog/2024/12/09/sustainable-by-design-next-generation-datacenters-consume-zero-water-for-cooling/- Consumer Reports - AI Data Centers, Big Tech's Impact on Electric Bills, Water, and More: https://www.consumerreports.org/data-centers/ai-data-centers-impact-on-electric-bills-water-and-more-a1040338678/- Forgejo, the self-hosted lightweight software forge: https://forgejo.org/- Restic, fast, secure, efficient backup program: https://restic.net/- SysAdmin Weekly - past episodes referenced are at https://www.sysadminweekly.com -
047 - Is DNS Over HTTPS Actually Private? What ECH Fixes That DoH Doesn't 01.06.2026 56minTurning on DNS over HTTPS does not make your browsing private. The hostname you are trying to reach still leaks in the TLS handshake through the Server Name Indication field, and that is the part most coverage of DoH quietly skips.Andy and Eric pick up where the DNS deep dive in episode 045 left off, this time focused on the privacy half of the problem. The episode walks through why DoH on its own only solves part of the equation, what Encrypted Client Hello (ECH) is doing to close the SNI gap, and which browsers actually support it today. Andy also unpacks Cloudflare's quiet deprecation of cloudflared's proxy-dns feature, what that means for every Pi-hole plus cloudflared setup still in the wild, and the Quad9 plus UDM Pro stack he landed on instead.Also in this one: California's age verification law and the operating system level approach the state landed on, Microsoft Edge keeping decrypted passwords in memory at all times (and Microsoft initially calling it "working as intended"), the Humble Bundle SysAdmin and Linux book bundle that is live right now, and Andy retiring his last Windows machine in favor of Debian.## Resources- SysAdmin Weekly Episode 045 - Why Is It Always DNS? (the prior DNS deep dive referenced throughout this episode): https://open.spotify.com/episode/2oAh0KzE7J2o7NQFJK8Mza?si=D0OO9XwkRb2GQ-hxM9duUA- Cloudflare announcement on the deprecation of cloudflared's proxy-dns feature (November 2025): https://developers.cloudflare.com/changelog/post/2025-11-11-cloudflared-proxy-dns/- Pi-hole, network-wide ad blocking and DNS sinkhole: https://pi-hole.net- cloudflared, the Cloudflare Tunnel client referenced in the proxy-dns discussion: https://github.com/cloudflare/cloudflared- Quad9, the Swiss-based privacy-focused DNS resolver Andy migrated to: https://www.quad9.net- Ubiquiti UDM Pro, which Andy moved his DNS forwarding onto: https://techspecs.ui.com/unifi/cloud-gateways/udm-pro- Microsoft Edge password manager vulnerability, security researcher disclosure from May 4 showing credentials decrypted and held in memory: https://www.bleepingcomputer.com/news/microsoft/microsoft-edge-to-stop-loading-cleartext-passwords-in-memory-on-startup/- Humble Bundle's SysAdmin and Linux book bundle from Packt (live for ~20 days from the recording date): https://www.humblebundle.com/books/ultimate-linux-sysadmin-bundle-books- Andy's prior AndyOnTech post on the state of web browsers, referenced for the Safari and Brave standardization context: https://www.andyontech.com/posts/there_are_no_good_web_browsers_left_and_thats_a_problem/- Encrypted Client Hello, Cloudflare's reference write-up on how ECH works alongside DoH: https://blog.cloudflare.com/announcing-encrypted-client-hello- Apple iCloud Private Relay, referenced as Apple's likely answer to the SNI privacy problem in lieu of shipping ECH in Safari: https://support.apple.com/en-us/102602- California's age verification law and the operating system level approach: https://www.theregister.com/software/2026/03/06/us-state-laws-push-age-checks-into-the-operating-system/4750249- SysAdmin Weekly main site, all episode links and platforms: https://www.sysadminweekly.com- SysAdmin Weekly newsletter, the companion weekly newsletter: https://newsletter.sysadminweekly.com- Contact the show: [email protected]## Chapters02:29 - Exploring Secure DNS Lookups04:17 - Tech News Reactions08:25 - Microsoft Edge Security Concerns14:58 - Humble Bundle Book Recommendations20:05 - Nerd Hour: Home Lab Updates26:23 - Understanding DNS Over HTTPS and Its Importance30:11 - The Role of Encrypted Client Hello (ECH)36:13 - Rebuilding the DNS Stack: A Personal Journey42:06 - Cloudflare's Changes and Privacy Concerns47:11 - The Future of Privacy and Quantum Cryptography -
046 - Can Claude Code Help SysAdmins? Scripting, Log Analysis, and the Claude.md workflow 15.05.2026 58minThe skepticism is earned. Most AI demos are built for developers. Most AI hype is vendor noise. And most SysAdmins have better things to do than adopt another tool that solves a problem they may or may not have.That said: this is Andy putting the grumpy SysAdmin argument aside for an hour to make the honest case for Claude Code in SysAdmin workflows. With caveats. With the parts that still fall short. With a clear line between where it helps and where you should keep your hands on the wheel.The episode also covers a rough few weeks for the Linux kernel: three local privilege escalation vulnerabilities publicly disclosed in quick succession. All local, not remote. Still worth knowing about before your next patch cycle.In this episode:- A rundown of the three recent Linux kernel LPE vulnerabilities (Fragnesia, DirtyFrag, and CopyFail) and what they mean for SysAdmins running Linux in their environments- Nerd Hour: Restic offsite backups via Hetzner storage, Beszel and Uptime Kuma monitoring running on K3S- What Claude Code actually is, and why the CLI-based workflow changes the value proposition compared to chatbot-style AI use- The CLAUDE.md file: the single biggest thing most SysAdmins are missing when they try AI tools. What it is, how to build one, and how it turns Claude into something that actually knows your environment- Practical use cases: script generation with real AD and environment context, incident triage as a thinking partner, log analysis, documentation from terminal history, run book drafting, and YAML/Kubernetes help- Where to stay skeptical: sensitive data, the "do whatever you want" permission mode, and always reviewing AI-generated scripts before running them anywhere near productionThe tool amplifies competence. It doesn't substitute it. That framing is the whole episode.---## Resources and Show Notes### Linux Vulnerabilities:- Fragnesia (CVE-2026-46300): https://www.helpnetsecurity.com/2026/05/14/fragnesia-cve-2026-46300-linux-lpe-vulnerability/- DirtyFrag (CVE-2026-43284 + CVE-2026-43500): https://www.helpnetsecurity.com/2026/05/08/dirty-frag-linux-vulnerability-cve-2026-43284-cve-2026-43500/- CopyFail (CVE-2026-31431): https://www.helpnetsecurity.com/2026/04/30/copyfail-linux-lpe-vulnerability-cve-2026-31431/### Claude Code:- Claude Code Security Documentation: https://code.claude.com/docs/en/security- Claude Code Permissions Documentation: https://code.claude.com/docs/en/permissions### Tools Mentioned:- Restic Backup: https://restic.net- Beszel Monitoring: https://beszel.dev- Uptime Kuma: https://github.com/louislam/uptime-kuma- Hetzner Object Storage: https://docs.hetzner.com/storage/object-storage/- Hetzner Object Storage + Restic Setup Guide: https://docs.hetzner.com/storage/object-storage/howto-backups/restic/### Community:- Friends and Family IT Support Stories on GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions- Andy's Music TUI Terminal Apple Music Controller: https://github.com/asyrewicze/music_tui### Previous Related Episodes:- SysAdmin Weekly 008 - Getting Started with GitHub Copilot: https://open.spotify.com/episode/2eTtoAgeKEikKeLzYExfOY?si=ySl9Ho7mQ861mHAKiTAQ5w- SysAdmin Weekly 016 - AI Agents for IT Admins episodes featuring Mike Nelson: https://open.spotify.com/episode/7u5T3Tp04EEP0hZRst3KPZ?si=zTpzVTXZR42vle4Gk0-tow## Chapters04:32 - Community Comments and News React07:16 - Linux Vulnerabilities Overview10:08 - Nerd Hour: Personal Projects and Backups13:21 - Exploring Claude Code for Sysadmins16:09 - The Grumpy Sysadmin and AI Adoption19:24 - Understanding Claude Code's Functionality22:35 - Use Cases for Claude Code30:01 - The Importance of Documentation in Sysadmin Work32:52 - Leveraging Claude.md for Enhanced Context37:27 - Practical Applications of Cloud Code in Sysadmin Tasks42:11 - Challenges and Limitations of Cloud Code53:54 - Future of Cloud Code and Its Value in Sysadmin Work -
045 - Why is It ALWAYS DNS?!? 08.05.2026 1t 16minIt's always DNS. Every SysAdmin has said it, usually at the worst possible moment. This episode is the explanation for why that joke is only half a joke.Andy and Eric walk through how DNS actually works from first request to final answer: recursive resolvers, root servers, authoritative name servers, TTLs, and caching. From there they get into Windows Server and Active Directory DNS integration, covering SRV records, dynamic registration, and scavenging. The back half covers DNS security: DNSSEC, DNS over HTTPS, Encrypted Client Hello, DNS-based content filtering, and how attackers use DNS for C2 traffic and exfiltration. Throughout, the guys pull from real war stories, including a ticketing system that silently failed every few weeks because one of four DNS servers had a stale record, and a BIND config that refused to load because of a trailing space.---## Show Notes and Resources### News React- Cloudflare DNS filtering tiers: https://blog.cloudflare.com/introducing-1-1-1-1-for-families/- AI token costs exceeding replacement labor costs: https://fortune.com/2026/04/28/nvidia-executive-cost-of-ai-is-greater-than-cost-of-employees/- Claude deleting company data and backups: https://www.tomshardware.com/tech-industry/artificial-intelligence/claude-powered-ai-coding-agent-deletes-entire-company-database-in-9-seconds-backups-zapped-after-cursor-tool-powered-by-anthropics-claude-goes-rogue- Backyard RAM manufacturing: https://www.theregister.com/2026/04/23/youtuber_builds_working_dram/### Nerd Hour- Andy's PomoCLI app: https://github.com/asyrewicze/pomocli### Main Segment Resources- Cloudflare: What is DNS?: https://www.cloudflare.com/learning/dns/what-is-dns/- MXToolbox: https://mxtoolbox.com- DNS over TLS vs. DNS over HTTPS - Cloudflare Learning: https://www.cloudflare.com/learning/dns/dns-over-tls/- Encrypted Client Hello - the last puzzle piece to privacy: https://blog.cloudflare.com/announcing-encrypted-client-hello/### Community- GitHub Discussions: Friends and family IT support stories: https://github.com/ProjectRunspace/sysadmin-weekly/discussions/15.## Chapters12:45 - Understanding DNS: The Final Boss25:49 - The DNS Resolution Process38:43 - Exploring DNS Services and Tools39:45 - Managing DNS: Windows vs. BIND43:36 - Active Directory and DNS Integration48:38 - Dynamic Registration and Scavenging in DNS52:42 - Understanding DNS Record Types54:44 - Common DNS Tools and Their Uses59:28 - DNS Security: Threats and Protections01:06:27 - DNS Filtering and Content Control01:12:36 - Should You Run Your Own DNS? -
044 - Hyper-V Failover Clustering in 2026 01.05.2026 1t 8minFailover clustering is the part of Hyper-V that trips up the most people, especially anyone arriving from the VMware side. In this episode Andy Syrewicze and Eric Siron pick up directly where episode 043 left off: you have standalone Hyper-V running, now what does it actually take to make it highly available in 2026?The guys start with the "why bother" question: Azure Local versus a traditional Hyper-V failover cluster comes down mostly to billing and governance overhead, not capability. From there the conversation moves into prerequisites: shared storage options (Storage Spaces Direct, iSCSI, SMB shares, Fiber Channel), Active Directory integration, and the heartbeat NIC myth Eric has been fighting against since he started seeing outdated Microsoft docs still getting passed around. The bulk of the episode is quorum: what split-brain means, why a two-node cluster needs a third vote, and the practical tradeoffs between a file share witness, a disk witness, and a cloud witness in Azure. Dynamic quorum gets its own explanation, including how graceful node shutdowns allow a cluster to shrink without taking everything offline. They close on the creation experience (PowerShell over Windows Admin Center, period), the gotcha that catches every VMware migrant (creating the cluster and adding VMs as clustered roles are two separate steps), live migration and shared nothing live migration.In the news and nerd hour segments this week: the FCC ban on foreign-made consumer routers (with Netgear already approved as an exception before anyone finished reading the press release), 3D printing of circuitry using microwave-based manipulation now down to the width of a human hair, Tim Cook stepping down from Apple, Andy using Claude Code to build a master index of every topic covered across all 43 episodes and every newsletter edition, and Eric deep in research on a home routing setup built around a mini PC with a separate router component so the internet does not require an IT degree to reset when he is traveling.---## Episode ResourcesSysAdmin Weekly Website: https://www.sysadminweekly.comSysAdmin Weekly Companion Newsletter: https://newsletter.sysadminweekly.comCommunity Discussion Board: https://github.com/ProjectRunspace/sysadmin-weeklyShare Your Family/Friends IT Support Stories (community post): https://github.com/ProjectRunspace/sysadmin-weekly/discussions/15AndyOnTech: https://www.andyontech.comProject Runspace: https://www.projectrunspace.org**Previous episodes referenced in this episode:**- Episode 043: Getting Started with Hyper-V in 2026: https://open.spotify.com/episode/4J77iiMVDWvvf8fshSurAL?si=D1hPaG7eSKiX6uU7UPBL3g- Episode 042: Should SysAdmins Job Hop or Stay Put?: https://open.spotify.com/episode/0o7EMW8JTGDm8rJv7Xu6Pg?si=uv1KIDZwS-y4l0g6yIV8jA- Episode 13: Should Hyper-V Be Domain Joined?: https://open.spotify.com/episode/0KWjIe5xgqZV9XYHuV2UF3?si=oK6XKjJiQ_mvpEEDqY_vyg- Episode 017: Hyper-V Management Story episode: https://open.spotify.com/episode/0rHwIc4U297R7I6KFayhlm?si=oTB7nX3bTgG7xekebnIU5g**Articles referenced in this episode:**- FCC ban on foreign-made consumer routers: https://www.wired.com/story/us-government-foreign-made-router-ban-explained/- What's New with Hyper-V in Windows Server 2025 (Microsoft Docs): https://learn.microsoft.com/en-us/windows-server/get-started/whats-new-windows-server-2025#hyper-v-ai-and-performance---## Chapters03:30 - Tech News Highlights14:38 - Nerd Hour: Personal Projects and Innovations21:02 - Listener Feedback and Career Insights25:54 - Hyper-V Failover Clustering in 202632:56 - Automated Setup and Shared Storage Solutions35:03 - Active Directory Integration and Clustering Best Practices36:55 - Understanding Quorum in Failover Clustering46:15 - Establishing a Failover Cluster: Tools and Processes57:18 - Live Migration and Storage Migration in Hyper-V01:01:14 - Day Two Operations and Cluster Management -
043 - Getting Started with Hyper-V in 2026 23.04.2026 1t 23minHyper-V has been around since 2008, runs Azure, runs Xbox, and still gets overlooked by shops fleeing VMware/Broadcom pricing. In this episode Andy Syrewicze and Eric Siron go back to basics: what Hyper-V actually is under the hood, why it is still worth your attention in 2026, and everything you need to know to stand it up and run your first virtual machine without losing your mind in the process.They walk through licensing (Standard versus Data Center, OSEs, core-based math, and the very short answer: call your licensing rep), then peel back the architecture to explain why Hyper-V is a genuine Type 1 hypervisor even though it boots into Windows. From there the conversation covers hardware requirements, the virtual switch types that trip up every VMware migrant, storage options, Gen 1 versus Gen 2 VMs (short answer: go Gen 2), Integration Services, and Dynamic Memory. Checkpoints and clustering get flagged as topics that deserve their own full episodes.In the news and nerd hour segments this week: CPU component prices climbing again with Intel and AMD reportedly raising costs by 15% or more, Microsoft announcing plans to rebuild Windows apps natively instead of relying on WebView, the MacBook Neo stirring up comparisons to the original Surface, Eric's week spent patching NetScaler appliances through a critical CVE while fighting Citrix's new licensing model, and Andy's experience standing up a Forgejo self-hosted git forge and putting Claude Code to work as a local repository agent.---## Episode ResourcesSysAdmin Weekly Website: https://www.sysadminweekly.comSysAdmin Weekly Companion Newsletter: https://newsletter.sysadminweekly.comCommunity Discussion Board: https://github.com/ProjectRunspace/sysadmin-weekly/discussionsShare Your Family/Friends IT Support Stories (community post): https://github.com/ProjectRunspace/sysadmin-weekly/discussions/15AndyOnTech: https://www.andyontech.comProject Runspace: https://www.projectrunspace.orgForgejo (self-hosted git forge): https://forgejo.orgClaude Code: https://claude.ai/code**Previous episodes referenced in this episode:**- VMware/Broadcom coverage: https://open.spotify.com/episode/764MqlqHjNimkiAdoWNoRb?si=pLZoVGM9RCivR6iBOW7b0A- Hyper-V management tools episode: https://open.spotify.com/episode/0rHwIc4U297R7I6KFayhlm?si=X_lxLkBDTuejzC_NCsoo2w---## Chapters02:50 - Getting Started with Hyper-V in 202615:25 - Nerd Hour: Personal Projects and AI Tools27:47 - Main Segment: Hyper-V Fundamentals29:06 - The Evolution of Hyper-V31:33 - Understanding Hyper-V Licensing37:53 - Navigating Hyper-V Licensing Complexities41:44 - Hyper-V Architecture Explained56:40 - Getting Started with Hyper-V01:03:45 - Understanding Hyper-V Networking Challenges01:08:45 - Exploring Hyper-V Storage Options01:13:29 - Choosing Between Generation 1 and Generation 2 VMs01:18:34 - Key Features of Hyper-V: Integration Services and Dynamic Memory01:20:50 - Managing Hyper-V with System Center Virtual Machine Manager -
042 - Should SysAdmins Job Hop or Stay Put? There's a Secret Option C.... 01.04.2026 1t 5minAndy and Eric Siron tackle one of the most debated questions in IT careers: do you find a company and stay for the long haul, or do you job hop every few years to chase better pay and new challenges? With over four decades of combined industry experience between them, they've lived both sides of the equation and they make the case that the real answer is neither.In News React, Eric calls out Nvidia CEO Jensen Huang's proposal that engineers should burn through AI tokens worth half their salary as a productivity metric, and Andy flags Intel's announced 10% consumer CPU price hike as the compute consolidation squeeze continues to tighten. Nerd Hour covers Andy's maddening K3S node kernel lockup mystery and Eric's journey from WordPress to Hugo for the Project Runspace site.For our main segment the guys walk through the case for staying long term at a job bringing deep institutional knowledge, ownership of your environment, the satisfaction of building something to your standards along with the real downsides: skill calcification, salary stagnation, and the risk of becoming so embedded you can't leave. Then they flip to the case for hopping. This method typically lands meaningful pay jumps, escaping bad culture, and breadth of experience alongside the pitfalls of being labeled a flight risk, never building depth, and fueling the contract economy. The guys then end the episode with Secret Option C....---## Episode Resources- Nvidia CEO Jensen Huang: Engineers Should Spend 50% of Salary on AI Tokens (CNBC) - https://www.cnbc.com/2026/03/20/nvidia-ai-agents-tokens-human-workers-engineer-jobs-unemployment-jensen-huang.html- Intel (AND AMD!!!) Preparing 15% Consumer CPU Price Increase (PCMag) - https://www.pcmag.com/news/intel-amd-reportedly-set-to-raise-cpu-prices-by-up-to-15-percent- SysAdmin Weekly Website - https://www.sysadminweekly.com- SysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com- AndyOnTech - https://www.andyontech.com- Project Runspace - https://www.projectrunspace.org- SysAdmin Weekly GitHub Community Discussions - https://github.com/ProjectRunspace/sysadmin-weekly/discussions- SysAdmin Weekly GitHub Discussion: Share Your Family & Friends IT Support Stories - https://github.com/ProjectRunspace/sysadmin-weekly/discussions/15## Episode Chapters00:00 - Introduction to Sysadmin Weekly03:02 - Navigating Career Choices in IT17:59 - The Case for Staying in One Organization34:13 - The Case for Job Hopping34:40 - The Job Hopping Dilemma42:42 - Navigating the Contract Economy47:47 - Finding Your Forever Home in IT58:22 - Advice for Sysadmins at Different Career Stages -
041 - Is Microsoft Giving Up on Security? - The SFI Leadership Shakeup Explained 25.03.2026 1tAndy and Paul Schnackenburg dig into a leadership change at Microsoft that has the security community raising eyebrows. Charlie Bell, the executive vice president of security who championed the Secure Future Initiative, is out and being replaced by a go-to-market sales executive from the Google Cloud. Satya Nadella's announcement focused on selling more security products, with no mention of continuing the SFI's mission. That omission says a lot.In News React, the crew covers the new Microsoft 365 E7 SKU (Copilot, Agent 365, and a $99/user/month price tag aimed squarely at mega-enterprises), and the Iran-linked Stryker wiper attack where hackers compromised an Intune admin account and remotely wiped devices across 79 countries (no malware required). Nerd Hour features Andy's Forgejo self-hosted Git setup and Paul's new electric vehicle.From there Andy and Paul trace the arc from Microsoft's repeated security breaches, to the scathing CSRB report that seemingly forced the creation of the SFI, to what now looks like the initiative quietly losing steam. Included is discussion on Microsoft's pattern of treating security as a profit center, the ethical tension of selling security add-ons for your own platform's vulnerabilities, and what SysAdmins should be watching for as this plays out. SysAdmin Weekly Website - https://www.sysadminweekly.comSysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.com SysAdmin Weekly GitHub Community Discussions - https://github.com/ProjectRunspace/sysadmin-weeklyAndyOnTech - https://www.andyontech.comProject Runspace - https://www.projectrunspace.orgKrebsOnSecurity: Iran-Backed Hackers Claim Wiper Attack on Stryker - https://krebsonsecurity.com/2026/03/iran-backed-hackers-claim-wiper-attack-on-medtech-firm-stryker/CSRB Report: Review of the Summer 2023 Microsoft Exchange Online Intrusion (PDF) - https://www.cisa.gov/sites/default/files/2025-03/CSRBReviewOfTheSummer2023MEOIntrusion508.pdfRisky Business Podcast (Recommended by Paul) - https://risky.biz -
040 - Big Tech Owns Your Compute... Should you be Worried? 21.03.2026 1t 29minAfter a brief hiatus, the crew is back! Andy is joined by both Paul Schnackenburg and Eric Siron to tackle a big question: what happens when access to compute becomes a subscription privilege instead of an owned capability?This week's topic goes deep! Big tech bankrolling elections, Bezos pushing rented cloud PCs over owned hardware, a global RAM shortage driven by AI demand. All the ingredients for a dangerous consolidation of compute seem to be in place. The crew explores the erosion of trust in cloud providers, geopolitical implications for non-US businesses, how consolidated AI models could subtly shape reality, the environmental cost of AI data centers, and the growing movement toward cloud repatriation and on-prem infrastructure. There's no silver bullet, but awareness and intentional choices about where we place our trust and spend our money are the first steps.## Episode Resources ##SysAdmin Weekly Website - https://www.sysadminweekly.comSysAdmin Weekly Companion Newsletter - https://newsletter.sysadminweekly.comSysAdmin Weekly GitHub Community Discussions - https://github.com/ProjectRunspace/sysadmin-weeklyVoidLink AI-Generated Malware Framework (The Hacker News) - https://thehackernews.com/2026/01/voidlink-linux-malware-framework-built.htmlGoogle Quietly Removes Net-Zero Carbon Goal Amid AI Data Center Buildout (Tom's Hardware) -https://www.tomshardware.com/tech-industry/google-quietly-removes-net-zero-carbon-goal-from-website-amid-rapid-power-hungry-ai-data-center-buildout-industry-first-sustainability-pledge-moved-to-background-amidst-ai-energy-crisisGoogle Plans to Power Data Center with Fossil Fuels and Carbon Capture - https://theconversation.com/google-plans-to-power-a-new-data-center-with-fossil-fuels-yet-release-almost-no-emissions-heres-how-its-carbon-capture-tech-works-270425Why a Carbon Capture Breakthrough Will/Won't Save Us (PBS Reactions) - https://www.pbs.org/video/why-a-carbon-capture-breakthrough-willwont-save-us-9cmmk0/
Suosittu maassa
Tämä podcast esiintyy myös näiden maiden podcast-listoilla.