LINUX Unplugged - 687: Linux by Proxy
Episode Date: October 5, 2026Millions of people may already be using Linux by proxy, so we went digging through their strange little cloud desktops to see if we can turn them into servers.Sponsored By:Jupiter Party Annual Members...hip: Put your support on automatic with our annual plan, and get one month of membership for free!Managed Nebula: Meet Managed Nebula from Defined Networking. A decentralized VPN built on the open-source Nebula platform that we love.Support LINUX UnpluggedLinks:Web Boost — Send us a boost via sats or USD💥 Gets Sats Quick and Easy with Strike📻 LINUX Unplugged on Fountain.FMConnecTen Internet: promo Jupiter35YouTube: Clanker Therapy 2: What We Have Been BuildingAudio: Clanker Therapy 2: What We Have Been BuildingBootleg: Clanker Therapy 2: What We Have Been Building | Members StreamJupiter Uplink — Tell us what you’re building.SpaceXAI’s Grok Bot Agent Tops 400,000 Users After First Month - BloombergMeta’s Muse reportedly passes 3 million weekly users and 5m downloadsOpenAI launches dots, always-on AI agents with their own cloud computersWhat Is the Meta Muse Secure VM? Sentinel, Egress, RisksHow We Built Safety Into Muse | Meta AI ResearchPick: hw-monitor — Linux desktop application designed to monitor various aspects of your computer's hardware.Pick: tincan-cli — Serverless peer-to-peer voice and text chat for your terminal.
Transcript
Discussion (0)
So friends and welcome back to your weekly Linux talk show.
My name is Chris.
My name is Wes.
And my name is Brent.
Hello, gentlemen, coming up on the show today.
We're digging into those weird little desktop VMs that are hiding behind all of these new strange consumer bot platforms.
And we'll see what we can do with them that they probably don't want us to do with them.
Then we'll round out the show with some great boost, some great picks, some great feedback, and a lot more.
So before we get to any of that, let's say time approves to our virtual.
lug. Hello, Mumble Room.
Hello. Hi. Hello. Hello.
Strong.
Yeah, it's very good. We're going to need a bigger room.
Hello. Oh, and the quiet listening is getting a little bigger too. Hello. And of course,
shout out to everybody watching live. Making it a Tuesday on a Sunday. Makes it special.
Also, good morning to our friends over at Defined Networking. Go to Define.net slash unplugged
and meet Manage Nebula from Define Networking. A Decentralized VPN? A BPN? No. We should call it
a DPN, a decentralized VPN built on the open source Nebula platform that we love and use ourselves.
And Nebula was originally created to securely connect Slack's global infrastructure.
So it's been designed from day one for serious scale, serious performance, and serious security.
And you get strong encryption.
You get a decentralized architecture with no central traffic bottleneck or big tech login plane.
And you get the option to self-host your own lighthouse so that way you were in full control of discovery, names and all of that.
So if you're just connecting your home lab or a global enterprise, you've got to check it out.
Nebula gives you privacy, resilience, and speed.
Resources are just like unbelievable with Nebula.
It's sips it.
If you're on a limited connection, you're going to really love that.
You've got CPU constraints, you're really going to love it.
Who doesn't want something that uses less resources anyways?
See what I'm saying.
Try it for free 100 hosts.
No credit card required.
Go to Defined.net slash unplugged.
It's defined.net slash unplugged.
Big thank you to Define for sponsoring them.
program thank you for everybody who sponsors or who supports the show by supporting our sponsor.
You're kind of, you know, second-order sponsor in there.
I feel like we should also thank them for continuing to make our networks work so well.
Yeah, there's that too.
Well, we have some news for you all.
We have some news.
A brand new clanker therapy to what we have been building is out on YouTube and for audio.
And, of course, there's a bootleg version for our members to get the complete stream.
That'll all be linked in our show notes.
Been getting pretty good feedback so far.
Yeah, right.
We put it in the extra show, and then, right, yeah, your membership, you can go to a page.
We'll have more.
Yes.
And stay tuned.
Hopefully something we'd be doing more often.
Yes.
More clanker therapies.
What we've been doing is using meetup.com slash Jupiter Broadcasting to announce them.
And then just streaming them at jbblive.
You don't need a meetup account to actually watch the stream.
But we've been kind of organizing.
Just a single place for details for now.
And if you watch this week's clanker therapy, you will get a bit of the story behind something we're announcing today.
A brand new resource for our community that we're very excited about.
And I want you to go to uplink.jupiterbroadcasting.com, where we now have a two-minute voice note that you can leave us, all using built-in in-browser technology, and it will send us a note.
It lets you record very briefly so you can just allow your audio device, make a two-minute record.
recording when you are done, you can play it back and double check or delete it if you don't
like it. And then you give us a name and tell us what you've been working on, what your project is
you want to talk about. And if you wanted to go to the clanker therapy stream, you choose
what are you building. If you want to go to Linux Unplugged, you choose Linux Unplugged.
And optional contacted note, and you can send your update. And we will get a voice note from you.
And we'll incorporate some of them into future episodes. We won't play all of them for airtime.
but we'll play some future voice notes.
So it's uplink.
Dot jupiterbroadcasting.com.
We want to know about your home lab, your projects, things like that.
And if you're a member and you sign them with memberful,
you get an extra minute.
You get an extra minute.
So if you're a member, you get a three-minute voice note.
And that is something which if you're curious about the tech or how we built it
or the story behind that, that's all in that clinkered therapy too.
uplink.jupiterbroadcasting.com.
Tell us what you've been building,
a Linux project, a homelab project,
a new desktop setup.
We want to hear it.
We built it.
And it's just for you.
And as producer Jeff says,
voicemails aren't cool again.
Yeah.
And you don't even have to use the phone.
You can use, like, if you got a headset
and you want to sound good.
You don't have to go jump through a bunch of hoops.
Just use that.
Or use your phone with the browser.
Or maybe you want to go through hoops
and you could, maybe there's a way
you could leave a voice.
It probably works from the phone, Wes.
You could probably do it from the phone.
Oh, it definitely does.
Yeah, yeah.
All right.
So we thought, you know, we like to do something from time to time here on the show.
So something a little different, something a little crazy.
And we like to do a little live thing from time to time to see how it goes.
And you know, if you've been listening for a bit, we've been kind of toying behind the scenes with different ways to render our website.
We played around with Zola.
And that was interesting.
But Wes and I have been wondering, could you build and deploy?
the entire website using Nix.
Could Nix be the deployment method?
And we wanted to see if it could do it and do it right.
And we thought the best person to verify this would be our chief QA.
Well, who else?
Manager and producer, Brentley.
And so, Brantley, we want you to go to nix.
Dot jupiterbroadcasting.com.
Mm-hmm.
Mm-hmm.
Mm-hmm.
And tell us how the website, if it looks weird to you at all, if anything seems out of
place.
Okay.
Should I check my profile photo first?
Is that,
how this is going to go?
Okay.
I see it looks kind of,
you know,
at first glance,
like our website.
That's good.
A couple of things you might notice,
Neal,
if you go to Community and Matrix.
If you go to the Matrix website,
oh, I think a lot of people
are visiting it right now, Wes.
Yeah.
Is it running off Wes's website
or laptop, probably?
It is not.
No, it's not.
No, it's not.
Oh, there's a whole, yeah, there's a whole kind of index of all the chats that we use.
Yeah, it's a nice update, right?
That's awesome.
That's very nice.
It's a nice improvement.
Hey, we're making it easier for everyone else.
That's the goal.
Nothing stands out, though, right?
Not yet, although I see a couple buttons that I want to check out here.
So Boost, does Boost still, oh.
Even better now.
Boost is even better now the boost button.
Hey.
Yeah. Oh, that's sweet. That's what we should have put in the first place. So the boost leads to now boosting instead of just talking about boosting. That's way better.
Okay, so when does this deploy or has it already been deployed? Is that the...
Well, that is on the public internet right now. Of course, it's at a subdomain.
What if I told you that your original line of questioning was more on the money than you might know?
It is not running on Wes's laptop.
But it's not running on a VPS.
It's running off your alarm clock.
It's running off of Wes's muse.
Come on.
The VM, Wes has gotten the VM in his muse to install Nix and host our website.
Wow. That's amazing.
Yes. So this is what I want to talk about today is I don't recommend
these bots and we'll get into the privacy stuff.
But I realize something this week
that I think has gone over everybody's head.
And that is
if these platforms start to
break through,
there are going to be millions
and millions of Linux desktops deployed.
And it does look like Muse is doing pretty
well. It may already
be in the millions of users.
Every one of these commercial bot platforms,
be it Muse, the Grockbot
thing, or the OpenAI
dots, or some of the other ones, they all
are coming with a full Linux VM.
And some of them are actually really, really nice systems.
Like the OpenAI dot box is a pretty reasonable spec box with like, I think 12 gigs of RAM,
was it, or something like that?
And a modern Debian base and AMD Optron, something like that.
I think, what, what, eight cores too maybe?
Yeah.
Yeah.
And Muse is a little bit less, but it's still a full desktop VM.
Yeah, you get eight gigs of RAM, 2X, Xeon Platinum.
in there?
100 gigs, I think.
It is just an implementation detail.
However, the actions
these agents are taking on behalf
of their users are taking place
in the Linux VM.
So when they go out and browse the web,
when they go look something up,
when they ping an API,
they're doing it, for the most part,
from a Linux VM,
from a Linux client.
It's another Linux machine.
And that's got to be good
for Linux.
And look at these numbers.
Muse alone has reported
half a million daily users,
within weeks, and the current numbers as of yesterday
are 3 million people prompted at least once a week,
1 million people are prompting Muse every day,
and more than 4 million people use it in some form each week.
Every one of those 4 million users has a Linux desktop.
Grockbot has hit 418,000 weekly users as September 14th,
so that's a little old, and no word on OpenAI dots yet
because they're very new, but chat GPT has 1.2 billion active weekly users.
Wow. This gets me thinking that our traditional ways of measuring Linux usage is very outdated now.
I don't think we're even, I don't even think this is sunk in.
So, like, take Muse, for example.
Muse is an Ubuntu 2405 box.
It's got their own custom kernel 7.
Yeah, the 6-8 if you just run with the Stock Distro, but clearly they're doing some special things.
Yeah, 100 gigs of persistent storage.
We'll get into some of the technical limitations here.
And that's just Muse.
And Muse is essentially free right now.
It's essentially absolutely free.
And if you use an invite link, you get a billion free tokens additional.
Rockbot is using Firecracker MicroVM.
And it's a little more expensive, but it's again a full Linux desktop.
And then the OpenAI dots win all the way.
It's depending on the image you get, it could be Ubuntu 24-04, some report.
the one I tested was Debbie and Trixie.
Linux 61844, but get this, Brent.
The dot Linux VM includes an XFCE desktop,
a terminal emulator, a file manager, a browser,
blender, Gimp, Inkscape, Kadyin Live,
like more and more.
And the agent can use all of it,
and you can take over.
You can, in the web browser,
you can take over the desktop session.
It seems like those installs are pretty targeted, though,
to visual arts, I would say?
Yeah.
Which is not the first place I expected that to go.
A lot of those tools can be stacked to, like, grab clips for people and, you know, make little videos.
Editor change images.
Mm-hmm.
Mm-hmm.
The numbers could be pretty nuts in that it's like it reminds me of Android, where we got millions of Linux users, but they don't even know it.
But there is the incentive for certain hardware device manufacturers now to target Linux.
Because of that fact, you know, like it feels like it's a version of that.
Only, it's not just the kernel now.
It's a full Linux desktop.
If you want folks as, you know, helper agents to be able to use your thing,
well, then it better support Linux.
Let's talk a little bit about the design, too,
because they're trying to do these in a secure way.
And Metis pitch is for Muse is that every user gets their own Linux computer in the cloud.
Nat Friedman said out on X, I think he said, quote,
a free Linux computer in the cloud with every Muse.
And the way they're doing it is a container that sits on top of a VM.
And the container runs under SystemDNSpawn as PID 1.
And then they just wipe that container, right?
Yep.
That's their like deploy mechanism.
Yeah.
So you do get, like there is a VM from cloud hypervisor that sort of runs everything.
But then internally, like, yeah, all the, the only thing that really persists is your home slash home slash hatch.
And then they use the container to sort of deploy everything around.
around that, a lot of the environment. It kind of sets everything up and it makes it so that, like, because they'll restart the service frequently, every couple of hours, overnight. They're doing updates during the day. And they've tried to make it work so that they can just sort of cleanly roll things out and maybe you notice a little blip in like the bot isn't showing up as green for a second or something. But otherwise it just, you know, gets it right back into action. And as long as you're not relying anything that just got rolled by the container update, you'll be okay. But it does mean you lose everything outside your home directory. Yes. But you can design a
around that, obviously as Wes has, which we'll talk about more later. There's also a really
kind of super strict network design around Muse. Really, Muse has, the Muse VM has no direct
access to the internet inbound or outbound. So anything you do is, is definitely being intercepted
by meta. DNS is intercepted. Yeah. TLS is intercepted. These are not private. There's no
UDP at all including loopback.
Wow.
So there's a lot of VPNs that won't work too because of the way they've structured their
network.
There's a lot of apps that rely on UDP that won't work, a lot of network communications
tools that rely on UDP that won't work.
Yeah, egress is basically all done through an authenticated HGDP proxy.
Port 22 is blocked.
You can get SSH to work, but you have to jump through a couple of hoops.
And you can get TAL scale to work, which is surprising.
And that's because TAL scale supports DERP, which is how it's able to communicate in
this funky network setup. But what that allows is that they've got this separate sentinel that
they call, and it's able to then do fine-grained control. So you can allow access to a particular
domain or whatever once, or you can allow it all the time, and a prompt just sort of loads that,
and that's all done by sort of not restricting what the request sort of you can make in theory
inside the VM, but just only allowing ones to succeed that actually go through their gateway.
And on the topic of networking, Grockbot just really quickly, I'd say you could
characterize it is probably the most open.
There are ways to connect it to external services and it can communicate.
And then what they do with Grockbot is they sell the lockdown as kind of like an
enterprise upsell.
So if you want the business version of Grockbot, they start locking that down.
And then on open A.I. dots, the picture is much more murky.
And the irony and the pitch with open AI dots is that if you get a dot, you get GPT6 Astra
behind it.
supposedly the best of all of these agentic platforms that they're just begging you to use.
Mews'es is actually quite good, but, you know, it's not the frontier model or whatever the crap.
But this thing is so constrained at the agentic layer that it really doesn't know what's going on.
It appears from what I can tell that a lot of the security practices and the networking best practices and all of that are like, almost like at the agent's MD level for this thing and not at like the OS and architecture level.
where with Muse, they're at the OS and architecture level,
and the Muse agent can just figure it out.
But with dots, because it's being constrained more at the agent layer,
it won't push, it kind of refers you to open AI support instead.
It won't do, I have to really push it to really make modifications.
Like, just as a brief aside, you could ask Muse, where was my persistent storage and where is it not?
And Muse can answer that.
The dot cannot.
You have to just have it deploy file.
and monitor them for 24 hours
and then tell you what files persisted.
Yeah, it really feels like the Musebot
is just sort of sitting in this, you know,
containerized Linux environment,
and within that is happy to try to poke around for you.
It's surprisingly unrestricted.
Mm-hmm. Yeah.
Whereas you've got to wonder,
as on the dot side, like, is it a more limited harness experience
where it's mostly just sort of adjudicated APIs
and not like a full fat shell?
Something like that.
It feels like that to me.
It definitely, I was able to get Nix installed in my dot,
in my dot VM,
and get it persistently reloaded
after VM wipes. So I did get there after a while. But architecturally, Wes, is there anything
else you think it's worth noting how these things, these things are set up from like a Linux VM or
system standpoint? Well, yeah, like we've tried to dig into some of the details. There's mixed a lot of
assumptions or guesses because not all of the details are public. It does seem like meta has been
particularly fairly open about a lot of the design. And in their case, they're using a lot of
eBPF.
Like they have, one thing that you might run into when you try to get something like
Nick's working is they use extended attributes to sort of track files that you've modified.
So they have two particular ones and they mark stuff that gets downloaded from the network
and they also mark any user modified or created files.
And you can list that, you can see it.
They don't hide it from you, but you can't remove it, at least from, you know, within the virtual machine.
So they're clearly, and I think then they have like EBPF filtering for that kind
of thing and are doing a whole bunch of extra sort of, I assume, observability and telemetry
on that because it does seem like they've really put work into the harness engineering
side of this. Whether or not you like the product or want to use it or trust them, it is
kind of impressive. It is well integrated. They have crons that seem to work quite well.
It has no problem doing subagents or polling. And all within a VM is happy to poke around.
I want to talk about that just for a moment. I'll start with the
privacy aspect because I do feel like this is the elephant in the room. All of these are a privacy
nightmare. Like in the case of connecting your Gmail accounts, they all, when you start them,
want to immediately connect to your Google calendar, your Gmail inbox. And in the case of Muse,
and I'm certain this is how the other ones are doing it, those emails are getting pulled into a
queue box that lives outside your muse, that lives outside the VM, that lives outside your agent,
that is a service that meta runs and a service that Open AI runs. And it
creates like a queue, and then the agents basically over like an MCP can connect to that queue
and check for email for you. So that's doing the polling. And while it's in that queue,
there's absolutely nothing that says they couldn't be reading all of those emails, right? And this
is the problem throughout. They can do DNS interception. They can tell what files you've modified.
It's clearly not a private platform, where when you do this stuff with something like Hermes
or OpenClaw, that data exists on your system to the extent of what it sends to the LLM or not.
Yeah, it does seem like they're trying to give you control.
Like it is pretty transparent about the network stuff, right?
Yeah.
They are very transparent about everything, actually.
You can ask it, and it will tell you.
And I think they're going to offer something like confidential VMs or, you know,
where they do more encryption or whatever.
But, yeah, fundamentally, you can't, you just can't really trust that beyond what you're willing to.
And then the other thing that struck me compared to now, you know,
so what's happened is, what I realized is January and February,
we started getting our own agentic harnesses.
And people that can self-host had access to this pretty early in the year.
Now what we're seeing is the mass consumer versions of these, where they have commoditize the technology, they have bought the compute infrastructure, like meta overbought infrastructure.
So that's why they can give Muse away for free for a while.
And then their intention to monetize is that you're going to love using this thing so much that you'll do transactions that they can take a piece of the action on.
Right.
So they have like all this compute.
They have all this strategy.
They can now bring it and blasted everybody's Facebook feed and everybody's Instagram feed.
And they can take something that was only available to us geeks back in February and just 10,000.
months later, now it's available to anybody that has an Instagram account. That's where we're at now,
or anybody that has a chat GPT account, or anybody that has an X account, and they're willing to pay
the fee, or Muse is free. So this is where we're at, and it's all running on Linux. The whole stack is
running on Linux, right? So that's, that element I like. And when you start using them initially,
if you're familiar with the self-hosted versions, they feel very primitive and very basic. But as you
continue to use, or in our case, poke and test at them, you will find that they actually have incorporated
ideas that we spent a lot of time building the last 10 months, they've just baked it right into
their product. And the normies just get it by clicking a button. Clearly been paying attention.
Yeah. Like if you've ever had a problem getting your agent to follow up on a task,
they've all solved that, buddy. If it says, I'll report back when it's done. It reports back when
it's done. Yeah, very good. Very good at that. Lots of little things. It's like, clearly they've
polished that. And it's going to be compelling to some people. And they're all going to, I mean,
there's millions of people already. In that sense, it's almost like I, you know, again,
I agree with all of the qualifiers. Yeah. It is.
somewhat heartening to see
a product rollout in this category that
isn't trash. Because we've seen a lot of
really bad rollouts for quote-unquote
AI. And we've
talked a bit about some of the backlash from that.
So I'm not saying this is a perfect product or that
y'all should use it. It doesn't really respect a lot of
the stuff we like on the show. But... It's pretty much better than
pretty much every other AI product
big tech companies have rolled out. Yeah.
And it comes with a Linux VM. I mean,
again... That you can install
almost whatever you want. Well, we can even run
a website on it, which we'll get to in a moment. But you're
thought so far, Brentley.
Yeah.
This feels like we've gotten to the point where we're seeing like mass shifting compute
to the cloud or whatever you want to call it.
And away from personal devices.
So, you know, those of us who are listening to the show are fine because we have way
too many computers probably around us and we're doing all sorts of things with them.
But this feels like a major shift.
Like if they're deploying millions of these on a daily basis, it's just a matter
of time that most people are
using these if this catches on
in the way that we're seeing
at least early. And what cooks
my noodle is the way
people are going to be interacting with the Linux desktop
in a way that outnumbers all
of us is they're going to open up
an app on their phone and they're going to ask it to do
a thing. And then the thing
that needs done
will happen on the Linux box.
It'll launch a Chrome browser and
go look at stuff and take
screenshots.
It kind of reminds me of the popularity of Linux through Android,
but now it's just another version of that, which is both very cool, technically, and unfortunate.
Which, I mean, kind of want to Linus's goals, right?
But out of all of those, the Androids, the TiVos, this one maybe has the most upside for desktop Linux users,
because these are Linux desktops using Linux desktop applications with Linux desktop web agents,
right like before it was all lower level kernel stuff networking drivers embedded devices maybe they didn't even want like the user land right but this like if you open up an open a i dot and you go and look at the they all they will all show you their computer screens grokbot muse that all let you just basically vnc into the computer and the dot one is just sitting there with an xfc desktop with a freaking doc and chromium just sitting there ready to go that's its default state and you can click on the terminal and you can you name to
and you can type or it's wild.
Or you tell the thing to do it and you can watch it.
You can sit there and watch it use the computer.
Wow.
Wow.
It doesn't seem like the most efficient way.
Like, you know, it reminds me like KDE Plasma was thinking about ways to make it more friendly for AI workflows.
Well, here you go.
Like, yeah, don't force it to take the slope.
I'm surprised they're not using desktops that are more like AI friendly.
Why didn't they choose Hyper5?
Well, I mean, I imagine because they want something that's low resources, doesn't need a compositor, you know, that has a GPU.
Didn't we see...
Reliable remote setup.
Yeah, because you're using this like through VNC.
But didn't we see like Hyperland getting...
Was it Hyperland getting like APIs or MCPs to use the desktop itself?
Wouldn't that be far more efficient?
Sure would be.
Also, you could do this with pipe wire and RDP and that would also be more efficient.
But, I mean, it'd be interesting to...
know exactly what they are doing.
Somebody will probably figure it out, but it's amazing they've gotten this far in some ways.
It's just mind-blowing that Linux desktop is just a feature that comes with these things.
Just a whole freaking VM with RAM and disks, you know, various amounts.
We're just a commodity now.
Oh, here it is.
Yeah, AMD Epic CPUs and the OpenAI dot, some people are reporting 32 gigs of RAM in their, in this day and age,
We could raise RAM prices.
Yeah.
32 gigs.
You can have to spend a little bit just to get that for it yourself.
So it just begs the question, is there something more you could do with this?
Like if Muse and dots are going to be thrown in your face for free,
is there something more you could do with that Linux box?
That was the question we asked ourselves.
And I think you already know the answer.
I think it's time we tell you how we did it.
I've been kind of busy this week, not really connected as I usually am to our,
conversations here internally at J.B.
And I noticed this part of the segment of the show just says, Wes.
So, Wes, what the heck is going?
What have you got yourself into?
Wes, what have you done?
Yeah, well, I mean, it started just with, you know, the obsession with Nix, if I'm honest, right?
Because I got on this thing where, you know, we were making some updates, working with the website a little bit.
And I just wanted to be able to do it all with Nix and not have to deal with the container I set up, which is totally fine.
and definitely works, but I already have Nix all set up.
Plus, then I realized, like, we're more than a few versions behind on Hugo at this point.
There's some other stuff under the hood, like the horribleness of dart sass and upgrades to lib sass and deprecations in things there.
And I wanted to be able to test things out, right?
And here at the same time, I'd been playing with Mews just to see what was this all about, how does it compare with the various setups?
Honestly, when somebody's going to throw that much free compute at you.
Yeah.
And so it just sort of clicked, and I thought, well, why not just test it this way?
I don't have to spin up a VPS.
I've already got a VPS.
The Muse.
Well, and also, you know, these are shipping Ubuntu or Debian, right?
There's maybe some logic to having the Nix package manager inside these because it just opens you up to so much.
AppTaz a lot, which is great, but there's going to be stuff that App doesn't have.
And then your bot's probably going to come up with whatever ad hoc way.
it happens to land on to go download a binary
or install home or whatever it does.
Like, for example, in my muse and in my dot,
I have open code set up.
And I want open code version two because it has an API backend.
And version one is available in Debian,
but version two is not.
It's available in MPM, but I don't want to deal with that.
I want to use Nix packages to manage that and install that for me.
So in my Mews and in my dot,
I have Nix packages installed.
and then they installed open code with the API backend
and the goal plug-in,
and I authorized it to my open-code account,
and I can, through Muse and through Dot,
submit jobs to open code
and have it like build on Space Bunny or something,
and then they can monitor it through the API.
And when it's time for an update,
they use NICS packages to update it.
Which is kind of what you exactly wanted, right?
Yeah, I just basically have a little background build machine
that's always just working on something.
I mean, if you're going to give me free compute,
I'm just going to have it sit there turning on something.
And, you know, space bunny's free right now too.
So I'm going to eat it up.
You know, build that Nick's stuff.
There are some hoops you've got to jump through with Nix
because of those extended attributes in particular.
Because Nix wants to be really pure.
And so it's going to want to try to strip extended attributes
to keep things fully under its control and deterministic
when it's adding stuff to the store.
But you're not allowed to remove those extended attributes.
So ultimately we've explored like a few different things.
That's funny because I was sorry to interrupt, but I was going to say the trickiest thing is that they wipe themselves.
Well, that too. That's also the...
And so you have to build it in a way that recovers from a complete system wipe.
But you have to get it working first in all.
Yeah, yeah, yeah.
So these are the caveats.
And then you've got the networking caveats.
It does look like we've explored like we had the bot right like an LD preload shim for a while.
I explored a custom Nix build, but it does look like there are sufficient config options that you can get it to totally ignore.
those ATLs, there's an ignore ACL option essentially,
and then not have to worry about it.
But then you run into that second problem,
which is like if you have a regular slash Nix or something,
that's just going to get wiped.
Or if you put it on a TempoFest,
there's only like two gigs available there by default.
And it'll get wiped.
And yeah, and it's the only real static place is under slash home slash hatch.
And then what you are going to want to end up doing
is writing some wrappers.
You know how we love rappers.
Because you want something item potent so that it basically can,
every time it runs, it can say like, am I set up?
Okay, great.
Use the tool normally.
If not, go re-bootstrap the environment, which is pretty fast, actually, but it still needs to be done.
Another trick you could add to that is the scheduler is persistent and the home directory is persistent.
So you could, if you knew the wipe schedule or every so often, you could have Cron essentially reset up your environment when it gets wiped out or something.
Do a little check and then reset it up.
Yes.
And that has been a huge help in making this website not fall apart constantly.
These are some of the limitations.
Wes had to work around.
Yeah, exactly.
So, like, right now,
you know,
the Quest Press,
I am using a VPS,
but that's just for a public IP,
essentially.
And then,
and then,
because there is,
you need some kind of proxying going on,
and you have to get through
the sort of,
approved egress
going out of this whole setup
from the Sentinel.
Yeah.
I'm using,
essentially,
a nice SSH forwarding setup.
Ah, classic.
A goody.
But even that,
there have been times
where the, like,
the egress has been a little bit flaky,
so you're definitely going to
want to build in some ability to handle drops.
At one point it was like, today it's been, you know, pretty good.
But, you know, there were times where like 50% loss on some of the connections.
So it needs to be resilient, reset itself up, that kind of thing.
So you got a SSH tunnel going back to a VPS where a VPS is running with a public IP
and a little engine X proxy that's just taking the Port 80 traffic and the 443 traffic
and sending it back over the SSH tunnel.
Right.
Which is then sending it to the museum.
And then on the Muse thing, I essentially gave it access to the version of the site that's now building with Nix.
And so then it could use its Nix wrapper script to bootstrap the Nix environment, which pulls in the updated version of Hugo, builds the whole site.
And then it wrote its own little quick static server just to add on, it's using Python just to be easy, but it also added on threading and GZIP for some of the assets,
few optimizations just to make it not super painfully slow.
And then it starts that up as part of this setup as well.
And then that's ultimately what terminates the whole thing.
Python serves the static sites that Hugo built.
But of course, we want that item potent too.
So there's a start site script that kills anything that's existing.
It makes sure everything is correct, make sure the server is running,
does some loop checks to actually make sure that it is fully serving to the outside world as well.
Wow.
Yeah.
We can basically, we're good to go.
And that's where there's also the site-wide.
Watchdog Cron every five minutes that goes and checks to make sure everything's happening.
There's also some other stuff.
Similar, like Nix to just make sure everything's still set up and ready to go.
And then the other part I ended up setting up, which was just kind of helpful, was I set up a mailbox on that VPS so that I was using an open code locally and Mews could start working together.
Interesting.
So you're having like handoffs essentially between Mews and an open code job to set stuff up?
Yeah.
I love that.
And so Open Code could just go leave messages.
And then the Crohn's are so reliable that, like, it just had it set every two minutes.
It goes and checks for new mailbox messages.
And it'll automatically pick it up and it'll ping me if it has a question about it or whatever.
Or it can ping the bot back if it would like to.
That's great.
I should think about that.
Yeah, the big thing for me was figuring out.
The breakthrough was just figuring out getting the environment restored.
I have not done, I have not hosted any persistent services in it.
I got to imagine we're going to watch them try to respond to people doing this.
Probably.
Because an SSH tunnel is sort of a pretty well-known foo.
You know what I mean?
Like, people are going to do that.
Yeah, so it wasn't crazy.
There were some hoops to jump through.
The performance is okay.
Muse did not try to get in the way.
Nothing about the system seemed to be like, what are you doing?
Yeah.
Yeah, performance is fine.
Not the fastest box, not the slowest.
I mean, the Muse VM is better than the VPS that I'm renting to me, the proxy.
Wow.
Yeah, well, that's the thing.
were just trying to
host some private stuff for yourself,
you could add this to your tailnet,
and you could put jellyfin
on this thing or something.
Like, you could have it be a little server
on your tailnet.
Yep.
And there's a set up a cron that just make sure
it's running and starts it if not.
You got to be a special, kind of special.
Read the terms of service first, right?
However, don't put your weirdest media on that.
All like the ACL stuff and the lockdown stuff
you can do with tailnet devices,
you can do with the muse, too.
Yes, yeah, you don't have to,
expose it to everything on your tailnet.
Right, right.
But it's just a wild, if like,
because then all of a sudden,
all this stuff you've done
for the networking layer
kind of just completely goes away.
You still have to recreate the persistent environment
and all of that,
but like all of those networking workarounds
with the VPS and an SSH tunnel
and checking to see if it's gone down,
probably don't have to worry about that if you just...
You definitely don't, no.
You mostly just need one thing
guarantee that like whatever service you want
is running and starts it if not.
I got to imagine these things
are going to end up loaded with crypto miners
and,
and bot networks, right?
Right?
Like, don't you think?
Like, this is just going to get abused?
100%.
As soon as there's free compute,
that's always what happens.
I mean, like, yeah, it's too irresistible.
I mean, that came to my mind like about five minutes ago.
So anybody who's actually wanting to mine Bitcoin would have thought of it already.
I'm curious what you both ran into that was like your most, I don't know,
annoying or largest paper cut in this process?
Because it sounds like you have to go through a couple of hoops just to get a compute environment
that you actually want.
But was there anything
that, like,
you didn't expect
was going to be an issue?
Hmm.
I mean, you got to wrap,
you know,
your head around the fact
that you got to sign into meta
or you got to sign into Open AI,
right?
That's probably the hardest part
of the process
if you don't already have an account.
Like, to me,
the worst implementation of these
is in a web browser chat interface.
That's actually the absolute
worst implementation.
Then next on that list
is, like, telegram and WhatsApp
and those types of chat apps.
And then, like, for me,
the best is the
2E implementation. A couple of the desktop
electron apps are okay, but nothing has really
beat the 2E apps for me
for flexibility and building my own environment
to manage these things with skills and
MCPs and workflows that I establish.
And so what would be
really awesome is if I could pull it into
open code. But that's never going to happen,
I imagine. So if
that's the, you got to live in their
sandbox, you got to live with their networking
limitations, their VM limitations,
and their interface limitations.
but if you're just looking for free compute
and you kind of
on some of the other products
you might get a little more choice
but you don't get full model choice either right?
Like with Muse you just get
Spark AI or whatever it's
I suppose they're going to iterate it pretty quickly
but it's not and you don't
you can actually go at first it doesn't show you
very obviously that super details
about what it's doing but if you go poke
you can actually see a lot of the commands that's running
and tool calls it's making so
it actually expose quite a bit to you
the other thing that you just sort of touched on
there made me just again with the Android analogy
is it really feels like you're just going to have
all of these people using this
and they're not really thinking about it.
So not only they're not thinking about the fact that it's a Linux desktop,
but they're not asking what model it is.
People that are signing up for Muse,
they're not asking, is it using GPT6?
Is it using Claude?
Is it using something meta-built?
Like, it's not even part of the discussion.
Just like when you buy an Android device,
they're not asking what Linux kernel it's using.
They might not know that's the whole thing that's on there.
Yeah. But for us, it's like...
They hardly know the version of Android of that.
If you were to look at all of these,
that's like one of the key things to evaluate
is what model is powering them.
And to that end,
their open source model behind this has been pretty damn good.
Pretty damn good.
Surprised me, actually, how good it was.
And the implementation in Muse, the service has been pretty good.
It's not perfect.
It's not the best I've ever used,
but it's quite reliable.
Of the three, I've used.
been trying, I think it's been the fastest.
It is pretty fast.
And much more reliable than dots.
I don't know.
I don't, I think I could foresee long term setting something up like Mews to just do a few
reoccurring tasks that I want to burn tokens on that are maybe bandwidth heavy because
it's also in a cloud data center.
It is never going to replace my Hermes.
It is never going to replace my open code.
It just can't.
It can't.
It is not the same.
And then you ask the privacy.
And, you know, it's a difference between also building on somebody else's property and renting versus, you know, building your own place and having, owning the foundation, owning the home and everything you build with it and all the memories and all the documents.
So it's never going to replace that for me.
But if I had a job that was like scan YouTube and cut clips and save them to a drive for me, well, why not burn Muse compute for that?
I don't care if they know what YouTube videos I want to watch.
Yeah.
For the jobs that aren't going to say a whole lot about you, aren't linking personal information.
that is just sort of mechanical work.
They sure do want you to link it to your bank accounts and everything, though.
Just connect it right up.
Not doing that.
I'm not doing that.
I'm not even doing that to my own bots, all right?
So I'm not doing it to your bot.
Yeah, you do have to wonder a little bit about some of the practices.
It does seem like I tried out connecting mine to Cloudflare just to see what that was like
so it could sort of manage some things for it.
And you can revoke the connection really easily.
You just put in one sort of API key.
You can scope the API key like normal.
I think the connector there mostly is just to keep that key out of the muse environment totally so that it can be a proxy for it.
Yeah, they have a little vault for your API keys and stuff.
So the LLM can't see the keys and supposedly they can't see the keys.
So it's like a mix of good practices with mix of bad practices by getting you to dump all your data in there in the first place.
Yeah, yeah, exactly.
And that is, you know, the new privacy challenge that we are entering into is these things.
And they, like, they go further than you would expect.
I shared the RSS feed with Mews to have it find something in the RSS feed for Lupp.
Or no, I can't remember.
I never shared it, the Clanker Therapy feed or any of the URLs for that stuff.
And it, but we had talked about clanker therapy because we talked, I showed it on the stream.
And it later just said, hey, by the way, I verified.
Clanker Therapy published on YouTube.
It's on XRs.
Show, and I see the files are on R2.
Oh, yeah.
Didn't ask it to do that.
Didn't ask it to do that,
but it knows that that's how Twib and Lupp worked
because it knows about,
and it knew we were talking.
And so it just kind of tries to be helpful.
Yep.
And they've got some background crons,
which it seems like you can list,
so maybe you can disable too.
I haven't actually tried that
where it does go do dreaming
and then try to come up with, like,
helpful tips or are things that can do for you.
I guess at the end I'll wrap it with
to just answer your question with a button is
so there was those constraints
but what surprised to me was
is that these platforms let us do this
right because a lot of this has happened
like I'm having Muse and I'm having Dots
and GROC they're using
they're the ones that are using the machine so like if I ask
Dot to install Nix or I ask Mews to install Nix
it's just doing it. It's not telling me no
it's doing it and sent it up and it's helping me figure out
to make it persist and work with that constraint
I'm really appreciating what
they've released to the public says about
how these specific companies understand or use Linux
internally because how they've constructed
each of these, I don't know, ephemeral computes or I don't know
what we're calling these things.
You know, whether they've used modern Linux technologies
or they just, you know, through an XFC desktop at you says
a lot about what we don't get.
to see on the inside, which is, you know, some of their technology that they're running probably
on the everyday and how sophisticated they are. Yeah, that's a great point. I think you can definitely
see in particular. I've used to use here the most. You can really see the flavor of meta-engineering.
And as we know, regardless of if you like their products, they've done a lot of really good Linux
and SystemD and sort of Linux server work. And you see it in there. You definitely see it in there.
And they're using ButterFS because, of course, they're big supporters of Butterfess. And yeah,
And so it's that stuff, those open source projects they've contributed to are all at work in their VM.
So that's interesting.
I think maybe I found Muse the most technically interesting.
I think Dots has the most horsepower.
And Grock lets you do the most.
Did you buy that from a certified vendor?
Grock lets you do the most, but it's expensive.
You got to get it from a certified vendor.
And nothing beats Hermes even if you got to use like a remote API.
But I do love free compute, and I do think I'll leave it doing some jobs for me,
doing just little things that don't really matter.
You know, it could also be something, right,
where, like, Google rolled out the not great AI version of Google search, right?
But the Musebot searches very competently.
So if it's something you would have put into a public search engine
and you don't mind medicine that you wanted to search for,
could go, you know, pull up the economic news of the day, no problem.
That's true. That's true.
And I'll happily keep doing it for you every day and send you to a report.
They can even make quote-unquote podcasts.
Hey, I want to say thanks to connect an Internet.
Head on over to their website, check them out at connectedinternet.com and use the promo code, Jupiter 35.
They don't officially sponsor the show, but they hooked me up with some hardware a while ago.
And I just, every time I use it, I'm so grateful.
And I think I should mention it.
I check Jupy 35.
Jupiter 35 is our promo code.
And what I love about them is in the U.S. and in Canada, they ride on all of the networks,
auto switches between the network that has the strongest signal in your area.
You don't got a futz.
So great.
They have truly unlimited plans, which is really.
really, really rare in cellular, which includes you can buy a priority access plan, also very rare in cellular.
And then I think my new favorite thing that they have is they have that $39 a month backup plan that comes with an open WRT box that does automatic failover and health checks.
So you can just, you know, if you got, if you need a connectivity, you just add that.
You're good to go.
I like their seven antenna.
If you're going to just put something in, Jeff and Brent, they mounted the seven antenna,
beast on the top of my barn.
And every time I look up at there, it's just
glorious internet. And you think
of us, right? Flat rate. Now, did the installers come
for free with this package, or is that extra?
You got to email Brent on that one.
No contract. 14-day money back.
Go to connectininternet.com
and use the promo code Jupiter 35
to get $35 off your order. And we will
put a link in the show notes. That is
connectinininininet.com and the promo code
Jupiter 35.
Well, this week, we found a couple
musings in our inbox. A. Brightson, hey, gents, love your show. You're doing an unreal job
walking all the lines that need to be walked. I can't imagine how hard that can be these days.
You've struck a great balance with all the things, so here's a message to say,
keep it up. On another note, I was a self-hosted listener for almost since the beginning
and reluctantly moved over to Linux Unplugged, as I didn't think there'd be much content that would be up
my alley. But I drive so much that I thought I'd give it a try and my was I've wrong.
Since moving over to Linux unplugged, I've started hosting my company websites at home,
moved my Windows server over to Brockmox, and bought a GPU for some small machine learning
tasks. Nicely done. After several years of listening, I finally decided to just pull over,
become a member, and send out this a boost. I have some feedback for you that I hope
is taken as constructive
though.
The web boost
process could have been
a bit more obvious.
Yeah.
I first just googled Linux unplugged,
which came up with your website,
of course, but I couldn't find where to
send a boost. I finally
stumbled my way over to Jupiter.
Hold on. There is an irony.
I have set it on air
a few times. I do say boost.
at jupiterbroadcasting.com a few times.
And I just want to point out,
the reason why I say this stuff multiple times,
is because we get this kind of feedback all the time
where people still don't know the URL,
even though I say it two or three times an episode, every episode.
So if you ever wonder why I repeat myself, listeners,
this is Exhibit A.
Okay, in my defense, continue on.
Okay, they continue.
I finally stumbled my way over to jupiterbroadcasting.com
where there is a boost link at the top.
Amazing, though that page still doesn't have an obvious link to send a web boost.
So I finally found boost.
So I finally found boost.com and realized,
I've heard you say that,
URL about 100 times on the show.
I imagine if I set out to send a boost using my phone like some of the 2000s kids,
I would have just followed the link in the show notes.
But I'm a middle-aged, and sending a boost struck me as a big screen activity,
like booking flights or sending email.
I get that.
Anyway, in my self-serving interest, if you made this process a bit more streamlined,
more one-off boosts may come through,
and you'll continue making content that we all love so much.
I'm sending a concurrent boost now,
but just couldn't put it all into that 300 characters.
Oh, and by the way, Brent,
I'm a fellow Canadian currently typing this
from the shoulder of the road on Highway 3 in V.C.
You know where that is, Highway 3?
Yeah, yeah, yeah, major highway, actually.
Yeah.
I mean, it's not exactly where you are.
That was good feedback, and we have fixed it, right?
Is it on the public site?
Yep.
All right.
Yeah, if you go to jupiter Broadcasting.com slash boost now, it just goes to the right side.
Or if you click the boost link at the top of the website, instead of telling you what a boost is, it just takes you to the boost website now, which we just had to work out.
But that was good feedback.
I'll take hybrid sarcasm.
Hybrid sarcasm writes in to me.
Thank you, Chris, for the rant about Google TV and Android set top boxes.
This is, I think, in the bootleg.
And my short version is the reason why Android TV is bad is your fault because you've bought them and we've enabled.
them. I just bought a new one and I cannot believe how bad it is. I'm ashamed that I've
paid them any money for anything that's gone towards Google TV at all. I can't believe it's such a
bad product. Hybrid rights, I'm not ashamed of being an Apple ecosystem guy. I like my iPhone and
my Apple Watch and because that I enjoy the Apple TV. When I decided that my commitment to jellyfin
was strong enough to warrant a proper TV client, I replaced my Apple TV with a Google TV box running
Android 14. Yes, I have been down this route myself. I mean, because early on too, like the
Jellyfin apps on Apple TV were not very good.
And the main jellyfin app was not nearly as good as the Android jellyfin app.
He said, you took greater offense to the Google-filled interface than I did.
I found the app-only mode to be sufficient for our needs,
and it meant I didn't have to bother with the launcher that may or may not launch upon reboot.
And I have to reboot this thing a lot, he says.
It randomly wakes up that Google TV would have an incredibly garbled audio,
like Michael Bay Transformers, chomping on another Michael Bay Transformer kind of audio.
and the infuriating thing is you wouldn't know until you'd already started playing your media, a movie, or whatever, a YouTube clip it might be.
The only known solution based on my non-agent searching was to restart the whole Google TV unit,
and a reboot takes long enough already before navigating the various clicks,
then selections just to have the system restart option.
Oh, I know.
My wife found it easier to turn the power strip off and back on again,
and this highlights my frustration with Android in general.
Blame it on varied hardware support, vague support boundaries, etc.
The bottom line is that you never really know what you're going to get when you pick up an Android-powered device.
No new Android image was coming to fix this audio bug, so I just had to deal with it.
I never had an Apple device with such an infuriating bug.
That's why I spent $150 on a new Apple TV, not $300, and $16 on Infuse.
My family's media viewing experience is top-notch again, thanks to Apple, jellyfin, and infuse.
Yeah.
I've been very disappointed with the Google TV HLS implementation recently.
it's been, I have an older one, but it's been mostly fine,
not as slow as some of the vendor implementations or anything.
So for that perspective, it's been fine.
Yeah.
YouTube works great, Jellyfin works great, which is most of the use cases.
But, boy, it hits some HLS stuff that it's just, the old Chromecast line, you know,
the Gen 2 stuff, had no problem with.
Oh, really?
Yeah.
Oh, that's a bummer.
It's like, how did you get worse?
Or like, why is HLS.js in my Firefox tab better than a device that's like whole job as to play streaming media?
It's just Google TV is insuffly bad, and it is the weakest link in the media TV setup.
And the Rokos are getting worse.
Yeah.
Infuse is good.
There's a cost to it.
Moonfin is getting better.
I still don't think it's quite as smooth on iOS as I would like, but Moonfin is another option to look at as well.
But, yeah, I don't know what to do because I've got two kid TVs, and I've got an Nvidia Shield on one and a Yamae Google TV on the other.
and they're both awful.
And they're really crappy when they wake up
about reconnecting to the Wi-Fi.
And I don't know what that's about.
So then that screws up tail-scale,
and that doesn't reconnect.
And jellyfin doesn't work
even when they get back on the Wi-Fi.
It's real bad, boys.
It sounds like we are primed for, like,
little tiny computers that are cheap
that we can just run our own software on
that accomplishes this.
Why do we have to rely on the big guys?
What we need is, like,
a headless jelly-fin Linux environment.
On an old phone that you might have around
that runs Linux?
just Linux boots to jellyfin, right?
It's like a whaling desktop that's just jellyfin.
And you just plug it in, you powered on, and it boots.
All it is is jellyfin, ready to go.
Pipwire for the audio, so the audio just freaking works.
What more do you need?
Can anybody build this?
Can we do this?
Is there a decent jellyfin app for Linux that we could boot to?
Anyways, let us know.
Boost.jubitabroadcasting.com.
And now it is time for the boost.
And Devator or Dev2R boost in as our baller booster.
Get ready for this, boys.
Buckle up.
Here we go.
266,806 Satoshi.
Wow.
So not to take away, but we do, I think, Dev here wanted to be transparent that this is a bit of an inflated number.
It's closer probably to like 140 because...
Split players?
Yeah.
The first three had four out of five nodes.
fail.
Dang it.
But they stuck with it to keep boosting until they all worked.
And that's why it looks so big.
So, like, I think the value is definitely there.
Tess, this is, he says, here is to the Texas Brisket Fund.
Which we appreciate.
Yes.
I'm looking forward to that.
I'm going to get Brent to eat so much meat.
Yeah, I'm on a diet right now.
Put some macaroni and cheese on there, too.
Yep.
Get ready.
You're going to have macaroni and cheese as well.
Well, hybrid sarcasm comes in with 250,000 sets.
Oh, all right.
I hoard that with your kind.
Also, fantastic.
Bala.
No message found, but that's okay.
We know you, hybrid.
And we appreciate it.
That's a lot of value.
It is.
Thank you, sir.
Appreciate it true.
We have here a derivation dingus with 76,500 sets.
Oh!
I loved the clanker therapy stream.
Personally, I enjoyed it even more this time around,
since it was less beginner focused.
I would love for them to be a more regular thing.
Yeah, we are working on that.
Unfortunately, I only caught some of the live stream this time,
but I still watch the entire recording
and haven't stopped tinkering with Hermes and open cord ever since.
Yes.
Another message here from Dingus.
Another fantastic episode, gents.
This episode was packed with stuff I want to try.
I'm definitely going to check out Nixar and NixFlexflex.
Chris's entire media stack always makes me jealous.
Alice, very well done.
And then there's one last message here for Wes.
Hey, Wes, thanks for the Fluxcast and OpenCode Flakes.
Both are working great for me.
You got users.
Oh, hey, that's great.
Wes, you got some Flakey users.
I've got it to be useful.
That's part of the goal of the, you know, the magic flakes.
I also am a West Flake user, at least on a couple of my systems.
Tomato comes in with a row of Mick Ducks 22,22sats.
Quaka, waka.
It's a treasure.
I'm being busy and still catching up on the show,
but I wanted to send some sets to help with Texas.
Coverage of these community events is a great thing,
and I'm looking forward to the episode.
Thank you, Tomata.
We really appreciate that.
We feel like it is, too.
Oh, I'm in.
We're happy to step up and make it, you know, happen if we can do without, you know,
bankrupting ourselves.
Shout out to Tech, Deb.
Abe comes in with 3,03 sets.
You make me want to be a better man.
As promised, we got the follow-up.
Came from self-hosted, is Lichen Lop, pulled over on the side of Highway 3NBC to become a member, which we sure appreciate.
Thank you. Thank you very much.
Do it safely.
Thank you for helping us. Help you. Help us all.
By the way, did PayPal ever unlock your funds? I sent some sets that way last year.
We didn't get some of the Fiat back, although they still have it.
They still have it. But it's only a couple hundred dollars. I think it's probably about $300, $400 worth.
So it is something I have to go through.
They're going to give you interest, right, when you get it unlocked?
Oh, they want me to fill out 17 documents to prove who I am.
Never again.
You know, I wanted to do it.
I thought it'd be easy.
Try to make it easy for fun.
It was bad.
That's a spicy meat of all.
It was bad.
It was bad.
Beardatech.
Beardatech comes in with 6,60043 Satoshes.
Thanks again for having me on the pre-show.
Great episode.
Keep up the great work as always.
P.S.
This is a zip code boost.
If you multiply it by 15.
That's a math boost.
Yes.
Zip code is a better deal.
All right, here's the, I kept them, here you go, I kept it for you, Wes.
Oh, thanks.
Well, it's been a while.
It's a little dusty there, Wes.
The old beard of tech, so 6, 6, 43 times 15.
Uh, yeah, can you do that in your head for me?
Wes, you're the guy that likes math.
I hate it.
When have you ever said that?
I believe the math says northward.
That's what I'm doing.
Yeah, okay, so 6643 by 15 would be 99,645.
You got any senses for where that?
is? Smells like Alaska.
Smells like Alaska.
You smell that? Kind of like seawater
and fish and a little bit too much bird poop.
You would be right. Oh really? That is Palmer, Alaska.
There you go.
Thank you, bearded tech.
Appreciate you.
We got Gene Bean boosting in with the Roa Ducks.
You all have any thoughts about hindsight
as memory for Hermes and coding sessions both.
I'm trying out the coding agent plug-in that makes a big
for each repo I work in, plus using a custom skill to promote, select things like fleet-wide info
to a shared bank. I'm using the self-hosted version on my land.
Nice, Gene. Well, I'll tell you what, Gene. Tell you what, Gene. I use hindsight with my
Hermes agents, and it seems to be pretty useful. It does. And the nice thing I like is, depending
on the chat interface, I can see when they're calling hindsight, too, and I can see that they do use
it. I don't think it would be as useful in my open code sessions, because one of the reasons I
like to go to open code is kind of a clean, clear context focused. But, you know, I can see
their values. I like to do it as well, I suppose. I feel like a lot of things I would do with
hindsight in open code, I could just also probably define in a markdown document. Your thoughts?
On a memory system? Yeah, I suppose it depends on how much stuff you have. Do you customize it?
Is it worth having some sort of index look up if you're doing it per project? I think often
open code gets used for sort of per project stuff that you intentionally want to restrict.
But if you do have a fair amount of cross-cutting stuff
concerning maybe fleet deployment information,
I could definitely imagine it.
You just kind of have to decide,
are you using it for how many banks are you doing,
and then what are you letting,
what are you putting into context by default?
It's probably mostly what it comes down to.
But yeah, those, there is, it's great how easy various memory solutions.
Like, there's a ton of them.
They're all pretty easy to install in a lot of places.
They often have sort of MCPs or APIs or CILIs to get access to.
Now, that could be the way to go.
Right?
There's things like QMD, which is real easy.
Hindsight with the Hermes agents.
And then if you want your open code session,
maybe you turn on,
because you can turn MCPs on and off.
If you do slash MCPs in open code,
you could just turn it on when you need it,
turn it off and use hindsight via the MCP.
Nice.
That could work.
Also, Gene, just appreciate, love it when you send in
stuff you're working on.
Yes, thanks.
You're usually working on something cool.
Mm-hmm.
Appreciate you.
We have a new tool where you can tell us what you're working on.
Um, Magbot comes in with 2,500 sets.
Coming in hot with the booze.
I came here to chew fries and surprise the guys, and I'm all out of fries.
You got to say it like this.
All right.
I came here to chew fries and surprise the guys, and I'm all out of fries.
Well, I'll be dipped.
It's Duke Nukem, dude.
It's a Duke, well, I miss that.
It's a movie reference, too, but it's a Duke Nukem reference.
Yeah, I get you, mayhem.
I get you where you're coming from.
All right, let's go to the Fiat boost.
Skookum comes in with $30 of the Fiat's.
And he says, have a safe trip to Texas.
Thank you very much, Schucom.
Appreciate you.
Quick interruption.
Just to, you know, ball or booster hybrid over here, says,
I'm really enjoying the new version of Jalifin MPV shim.
That could be the Auto Start Linux app,
which I think might be a pretty good idea.
And, you know, there's probably also,
I know somebody's going to probably say you could do it with Cody.
you could probably run jellyfin inside Cody
Yeah, true
And I can probably point
It can talk to the library as well
And I can probably point Cody at my dispatcher
Live TV stuff too
Right?
Cody probably does that
I don't remember
Yeah, I haven't used it for a while
But it looks exactly the same almost
So
What I surely try is Cody
But I don't want to
Anonymous came in with two free member boosts
Your episode triggered some thoughts for me
I don't think that LMs
are like transitioning to digital photography
I think it's more like training your outsourced replacement.
I also wonder how much banning LMs is about othering people.
300 isn't enough.
Oh, 300 notes.
I'm a long-time listener since the land days, and your AI coverage is fantastic, balance, and practical.
On the flip side, personally, I have no interest in Hyperland OMARRR coverage.
Just a FYI signal.
Appreciate what you do.
Keep up the great show.
Well, haven't you heard the good word about Hyperland?
No, I get it.
It's pretty niche, right?
It's pretty niche.
Desktop stuff's already a little niche.
Although.
I would say pretty great and worth it, but yeah, I see what you're saying.
I'm also noticing this might be, well, not quite a zip code boost, but a postal code boost.
It's a free member boost.
What are you talking about?
Oh, yeah.
There's a K1B1A1 there, which I recognize as perhaps a Canadian postal code, but maybe, I don't know, the UK does the same.
I thought it was a ham sign.
That's why I thought it might be too.
I think you might just have to pull out the map, West.
I can help you if you need.
Yeah, I don't have the Canadian edition.
I left that with you.
It does say, it does say, KB, you could.
Gook says it is a Canadian.
All right, there we go.
You know what?
In Ottawa.
In Ottawa.
It's not.
Oh, yeah, Gloucester.
Hmm, delicious.
Thank you, Anonymous.
Good spot there, Brentley.
Yeah, good spot.
K-Mogged, came in.
My agents could barely escape out of a paper bag.
What kind of precautions are you guys putting in place?
Chris mentions he wants his agents to have access to.
everything. My coworker mentioned not giving them Git.
So can they just Git clone a random repo that contains an exploit?
Thoughts.
It's funny.
It's funny because I fought and fought and fought and fought to get these things.
They're so cautious now.
They clearly have the fear of God instilled them that they're going to delete something.
Of course, every now and then they do.
This is true.
They do every now and then.
Yeah, I've definitely had them delete some things.
What kind of precautions, Wes?
What kind of precautions?
Yeah, I mean, a lot of them come with a fair amount of approvals on by default.
So you might evaluate that.
It's useful to ask them to investigate their own config sometimes, see what options you have in terms of what all you can flip on.
And it kind of depends on what environment you layered on, right?
So, like, I think we both have Hermes agents that have their own virtual machines or equivalent.
And so within that, I tend to give them pretty broad permissions because I want them maintaining the box,
customizing their environment for what they need.
I do think you want some auditing ability, right?
Like, you might consider where, you know, do you have some sort of proxy?
Are you keeping track of like what tool calls they're making?
Do you have ways to check that?
Do you have ways to control it if you do want to control it?
But you could also then like maybe you run some of your development stuff within a container
and copy the repos in.
You can do that pretty easily.
So I think it depends on what you're worried about.
Are you concerned about malicious attacks?
Are you concerned about sort of accidental overrunning of unrued?
related data, those can be pretty different to defend.
Yeah, and I think the sort of characterization that they're sitting there,
idle, sort of looking for things to do and like downloading repos and doing stuff is,
I don't, you would have to develop a program that drives them to do that, right?
They're not just going to do that on their own, even if you put in their sole MD and their
agents MD and everything, and you said, I want you to run, and you prompted them.
You put it in their sole MD and you put in their agents MD, and you prompted them.
I want you to run all night and download, get stuff and build it.
They would stop.
They would stop 15, 20 minutes into it, and they would stop.
And they wouldn't proceed until you answered a question or approve something.
Where they can be as clumsy.
And so I think it does, if you are concerned, I would, the first thing to protect against is, like, have backups of the stuff on anything that they can touch.
And then maybe take snapshots.
You can do, like, I'd like to do snapshot commits and get where I take lots of frequent, you know, commits on a branch and then squash it later after the fact.
So I have a fine record of what they're doing.
And you can do the same for your file system.
You have that set up.
that way it's more of like a mutable log of their actions and you don't have anything that you that they accidentally RM because they had a too big of a glob or something like that.
Big plus one to that.
I think that's, I agree.
And then the last thing is Wes made a joke about how we love rappers.
So when my agents, say, for example, communicate with home assistant.
They don't just talk directly to the MCP or the API.
They do it through a wrapper.
And that wrapper only allows them to do certain things, which bit me actually.
because I wanted to remove a device from my Z-wave network,
but I have implicitly disabled deletions through the wrapper,
so they couldn't, when I was first setting this up,
I didn't want them to accidentally delete new devices.
Well, now I trust them enough that I'm willing to give them that access,
but I have to go back and add it to my wrapper.
But that's one way is, so they don't talk to the API directly,
which they absolutely could.
They investigate the API in a read-only way.
We identify the functions they need for their immediate task,
and then we build a wrapper that only allows those particular.
particular tasks. And then when they go to
communicate with Home Assistant, they execute that particular
wrapper. Yeah, that's where something like
MCPs, rappers, but ways
that you can offload the deterministic and perhaps
dangerous stuff you want more carefully audited
out of their direct hands and give them a
structured interface that guides them to the right path.
Yeah. Yeah. That's
why there's the hotness around MCPs too.
Senior Smile. Senior Smile
says, I figured some listeners may be interested,
similar to Clip R, one of my favorite
projects of all time
is as player. It allows
allows you to clip sections in YouTube,
Jellyfin, and many others.
And it exports to A-N-K-I.
Unki?
Anki?
I used this to...
Oh, like, I think that's a note or a flashcard set up, right?
I use this to learn several languages.
Nice, that's clever.
It looks like it's on mobile, too.
So you could clip this stuff.
That's maybe the nice thing that, you know...
I guess you could use Tuneart, absolutely, in the web browser.
But this is a mobile app.
That's...
I like where this is at.
I would not have thought of that.
Yeah.
That's great.
Neforo 92 member.
boosts in. A long time listener, now officially a member.
Yay! Thank you. Thank you much.
Thanks to you two years ago, I finally gave Nix OS a try.
And now I feel like a preacher telling everyone how awesome it is.
Funny how that happens. I'm even hosting a NIC session at work. Wow.
Do you have any tips on how to approach it for people who have little to know Linux experience?
Look at the Nixbook project? It depends on what their goal is. Are they trying to learn it in depth?
Are they trying to just have to use a computer that happens to be?
implemented with NixOS, those can be pretty different.
Are they already on Linux? Could they use Nix
on their existing Linux install and start
to get familiar with it that way? They don't have to go
full NixOS.
I think TechDev is doing this
during the show. He's trying to get
his hands on NixOS for the first time.
I don't know if you're there. TechDiv, how's it going?
Oh, I'm definitely here. It's not the first time.
But I am
trying to get this set up for a repeatable build.
There's a base project here that's for another
time to talk about. But admittedly, I'm a little outside of the context here.
Yeah, it's on a very cool device. Yeah. It's a unique Nix project, sort of like we've been doing
recently. That's such a great point, too, because there's so many ways to do that. I actually
think one of the most easiest ways to get started is on your existing desktop, even if it's
Mac OS or whatever, just get started.
I feel for what it's like to try to build stuff and install stuff with Nix.
We get really focused on the show with NixOS because once you learn,
the Nix stuff, you're like, oh, crap, I want to build my whole machine this way.
You don't really have to start that way.
I think my biggest recommendation would be, like, use your favorite bot to help you.
NixS is really super good at being understood by the Clankers and just have it explain what it's doing.
Like, explain what a Nix config is.
Explain what the parts are, how you install.
Like, it's excellent at that.
Explain what this Nix error message means because a lot of people struggle with that initially.
Or how do I do this thing?
We used to hear a lot about like,
ah, the Nix OS documentation isn't very good.
I'm having a hard time understanding it, et cetera, et cetera.
We haven't heard that, what, in a couple of years since, you know,
you could just use your favorite clanker to do it.
And I think that's a good thing.
Mm-hmm.
Mm-hmm.
I mean, it makes quick work of those air messages.
All right, rounding us out.
Adversary 17 comes in with a member booth.
Aversary's rights, a little behind because life has been busy.
I'm listening to this episode
and this Rust FS thing
and it sounds really cool.
This boost amount is how many
gigabytes my server has doing nothing.
So if you'd like to use some of it,
you know where to find me.
But this is a free member boost.
There was no amount.
Is this a trick question?
By the way, just a quick follow-up,
Rust FS is officially in production
here at J.B.
Mm-hmm.
Mm-hmm. All right.
Yep, we have put it in production
and we talked about it in our
clanker therapy stream.
if you are interested.
But yeah, I knew when we covered it,
I knew it'd be putting in production.
I just didn't know so soon.
All right, thank you, everybody.
Thank you to those of you who streamed Sats as you listened.
Seven of you did so,
and together you stacked a mighty 10,917 Satoshis.
And you bring it all together,
including our Fiat boosts taken at current market value for Sats.
This episode stacked a Texas-sized 677,277,232.
powering up the show to continue for yet another week and getting us ready for Texas.
Thank you, everyone. Checkpoint has been saved.
And of course, you can go to boost.jupiterbroadcasting.com to boost and get a message on the show and help us get to Texas.
And you can put your support on autopilot at jupiter.party or Linuxunplug.com slash membership.
A couple of picks. A couple of picks.
This one, this one is for those.
of you who like to watch what your system's doing.
It's called HW Monitor, and it's a desktop application designed to, guess what?
Monitor your hardware.
And look nice doing it.
Yeah, look real nice doing it.
And it's been a minute since we've mentioned something like this, so you know it's probably
worth it if we're bringing up a tool like this on the show.
And it is licensed under MIT, mostly written in TypeScript and your buddy Rust.
Newsentari.
I think it looks good.
I think it looks really good.
And if you've got temperature sensors on your graphics card, on your disk,
and on your GPUs, and your ICMs, and your PCMs,
it'll support those.
It supports your disk sensors.
It'll also monitor TCP and UDP socket connections.
It'll read your system info so it knows your distro, your kernel, your host name,
all of your hardware information.
And because SystemD does everything, it tells you about your SystemD services.
Boy, Brian, look at that.
Doesn't SystemD do a lot?
Including, showing you recent logs.
get the system CTL status output right there.
Yeah.
It does look good, doesn't it?
I mean, you know, it's good.
It's clean.
For if, like, for some reason,
you're just, like, not already in a terminal,
then you can launch this, you know,
until you get a terminal going.
You are in a terminal, though, right?
Oh, most of the time.
It must be.
Okay, good, because this next pick requires
you be in a terminal.
I was telling the boys before the show started,
like, I am in the terminal all day long.
That and a couple of the electron apps on Firefox.
That's it these days.
And so I need a way to communicate with the boys.
back in the day
if we were just boys around the neighborhood
we would have had tin cans with strength
never got to do that though we missed that phase of life
but we can live it again
we can relive the glory days we never had
with tin can cly
a serverless peer-to-peer voice and text chat
for the terminal
wow
yeah tin can does what discord does without needing anyone's server
the first person to open the app creates the room
sends the invite code it prints to their friends
and they connect with that code from anywhere
in the world. No VBN, no board boarding. No, it counts. I want to be clear, this is a terminal
app, and it has a really righteous toey. It's awesome. Made with Ratta Tuey. And it even has,
like, a little string between them and stuff like that. And the whole thing is just adorable.
It seems quite well done. I think there's like a ton server, right? There is like a proxy at some
point. So you will hit, like, a server that they're hosting to help discover the two, but then I think
the calls are direct peer to peer. Yeah, and then even on top of that, there's also like, you have a
coordinator role who kind of sets things up, but then separately the voice mesh is all where
any of the actual audio is sent, and that never goes through the control plane.
How good is that to-y, though? Right? It's worth the install just for the toi experience.
And if you're already in there, it's just one of your tabs now in your terminal,
and it is MIT license, and it is, you guessed it, 97.8% rust.
Not necessarily a requirement at all. It's just what people are releasing these things in.
And we just happen to have a soundboard.
I mean, you know, I think part of it is ratatooie has to become such a nice way to make tuis
that if you want to make a toui, that's a great way to do it.
Well, look at that thing.
It is beautiful.
Tin can dash CLI.
We'll have a link in the show notes.
We got some good links.
And those are all at Linuxunplug.com slash 687 or in your podcasting app.
We try to put them in there as well.
Yeah.
You got any hot tips before we get out of here?
Like speaking of like website, we got a website that links to an RSS feed.
Oh, yes, we do.
That seems like there might be something in there people want to know about.
Mm-hmm.
Well, like, if you have a question, because, like, maybe we're trying to repeat URLs that we're trying to tell you to go to, but we do a bad job of linking to them sometimes.
Well, that information could be found in the transcript.
That's true.
Yeah, there's a VT file.
You let download that.
You grab in there.
You get a bot to do it, whatever.
You can clank your way through it if you want.
Yes, you can.
Well, whatever.
Then there's also a sneaky amp before.
Right.
With our faces.
Sometimes you can.
And, like, sometimes the Tui apps.
Sometimes.
Sometimes you get to see them in there.
I can't say.
but you can find out.
Go to LinuxUmpug.com slash RSS
and get the RSS feed and put in any
app or clanker you want.
But the real pro moves to show up
and make it a Tuesday on a Sunday,
10 a.m. Pacific 1 p.m. Eastern
over at jbbylive.tv.
That's also labeled at jupiterbroadcasting.com
slash calendar in your time zone.
That's also where we'll put the clanker stream
when we're doing one.
And, of course, meetup.com slash juporbrodcast.
We love your feedback and your support,
boost.jupurbroadcasting.com.
And we have our mumble info.
our Matrix info, which has recently been updated,
all of it at Jupiter Broadcasting,
with links along the top of the website.
It's pretty great.
I love those links.
Thanks so much for joining us on this week's episode.
See you back here next week.
