<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Damien Dye&#39;s Blog</title>
    <link>https://blogs.damiendye.uk/en/</link>
    <description>Recent content on Damien Dye&#39;s Blog</description>
    <generator>Hugo</generator>
    <language>en-GB</language>
    <lastBuildDate>Sun, 04 Oct 2026 10:30:00 +0100</lastBuildDate>
    <atom:link href="https://blogs.damiendye.uk/en/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Moving an OEM Licence Into a Proxmox VM, and What Moves With It</title>
      <link>https://blogs.damiendye.uk/en/proxmox/moving-an-oem-licence-into-a-proxmox-vm/</link>
      <pubDate>Sun, 04 Oct 2026 10:30:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/moving-an-oem-licence-into-a-proxmox-vm/</guid>
      <description>How the OEM licence in a PC&amp;#39;s firmware, the ACPI MSDM table, gets into a Proxmox VM: reading it, validating it before QEMU fixes up a broken one, storing it root-only in pmxcfs, and Microsoft&amp;#39;s own terms on moving it, including one VM on the licensed machine and why volume licences never use it.</description>
    </item>
    <item>
      <title>Branding a Proxmox VM, and Keeping It Branded Through the Next Upgrade</title>
      <link>https://blogs.damiendye.uk/en/proxmox/branding-a-proxmox-vm/</link>
      <pubDate>Sun, 04 Oct 2026 10:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/branding-a-proxmox-vm/</guid>
      <description>Five places a stock Proxmox VM shows somebody else&amp;#39;s name, and how to replace each so apt cannot undo it: SMBIOS strings filled from the VM&amp;#39;s own config, the SeaBIOS splash, a rebuilt OVMF logo or an option ROM that leaves the firmware alone, and the web UI logo, all read from source.</description>
    </item>
    <item>
      <title>NetBox: What It Holds, And How To Make It Hold Yours</title>
      <link>https://blogs.damiendye.uk/en/netbox/what-is-netbox/</link>
      <pubDate>Wed, 30 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/netbox/what-is-netbox/</guid>
      <description>A walk through NetBox 4.7.2 with a real rack in it: the elevation, the cable trace, the IPAM tree, and a cabinet reporting 90.7% power at 28.6% space. Then setup, the order you fill it in, per-customer access, config contexts, plugins, custom objects, validation rules, driving it from Ansible, and the fork that produced Nautobot.</description>
    </item>
    <item>
      <title>DNSSEC: Protecting Your Traffic From Forgery</title>
      <link>https://blogs.damiendye.uk/en/dns/dnssec-the-root-is-signed-you-are-not/</link>
      <pubDate>Sun, 27 Sep 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dnssec-the-root-is-signed-you-are-not/</guid>
      <description>Counted from the live root zone: 1,351 of 1,438 TLDs are signed, every single gTLD among them. Then it stops. 39 of 2,390 live gov.uk domains, 1 of 9 certificate authorities, and windowsupdate.com has no DS at all. What DNSSEC stops, what is really blocking it, and whether the problem is that we still do not understand DNS.</description>
    </item>
    <item>
      <title>Resolved: The Resolver You Are Already Running</title>
      <link>https://blogs.damiendye.uk/en/dns/resolved-the-resolver-you-are-already-running/</link>
      <pubDate>Sun, 27 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/resolved-the-resolver-you-are-already-running/</guid>
      <description>systemd-resolved is on most Linux desktops, caching every lookup and validating none of them. What the stub on 127.0.0.53 does, measured cache figures, turning DNSSEC on, why DNS over TLS works but DNS over HTTPS does not exist, what Fedora, Ubuntu, Debian and RHEL each ship, and why you almost certainly do not need a custom build.</description>
    </item>
    <item>
      <title>DNS Over HTTPS Walks Straight Past Your Controls</title>
      <link>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</link>
      <pubDate>Thu, 24 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/dns-over-https-walks-past-your-controls/</guid>
      <description>DoH sends your DNS lookup to a resolver of the client&amp;#39;s choosing on port 443, which your own resolver never sees, so it cannot block a bad name or log it. Sold as privacy, but DoT gave you that in 2016. What DoH really adds is bypassing the network admin. The mechanism, the malware, who pushed it, the courts now suing the resolvers, and the fix.</description>
    </item>
    <item>
      <title>The News Site Sent Me The Article, Then Deleted It</title>
      <link>https://blogs.damiendye.uk/en/random/the-news-site-sent-me-the-article-then-deleted-it/</link>
      <pubDate>Tue, 22 Sep 2026 22:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/the-news-site-sent-me-the-article-then-deleted-it/</guid>
      <description>UK news sites send the whole article, then their vendors&amp;#39; code deletes it if you block ads. How it works on Newsquest, National World and Reach titles, why I call it malware, the Chrome extension I built in a day to stop it, the fixes that made it worse, and how the consent-or-pay walls get refused.</description>
    </item>
    <item>
      <title>The Grid We Did Fix</title>
      <link>https://blogs.damiendye.uk/en/energy/the-grid-we-did-fix/</link>
      <pubDate>Sun, 20 Sep 2026 19:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/energy/the-grid-we-did-fix/</guid>
      <description>Great Britain&amp;#39;s grid clean-up in numbers: carbon intensity from 251 to 124 g/kWh, a full year at zero coal, wind now the largest single source, two decades of falling demand that absorbed 1.8 million EVs, the DVLA fleet split by body type, and why the price never followed the carbon down.</description>
    </item>
    <item>
      <title>Rejected Energy: What the Livermore Chart Actually Shows</title>
      <link>https://blogs.damiendye.uk/en/energy/rejected-energy-what-the-livermore-chart-shows/</link>
      <pubDate>Sun, 20 Sep 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/energy/rejected-energy-what-the-livermore-chart-shows/</guid>
      <description>Lawrence Livermore publishes a diagram of where American energy goes, and two thirds of it goes nowhere useful. What rejected energy is, why the 62% everyone quotes is really 65.8%, why wind and solar shrink that block rather than add to it, and the three fixes for transport: electrify the cars, redraw the zoning, build the metros.</description>
    </item>
    <item>
      <title>Webex Is Looking For Your Certificates On A Cisco Build Server</title>
      <link>https://blogs.damiendye.uk/en/certificates/webex-certificates-on-a-build-server/</link>
      <pubDate>Tue, 15 Sep 2026 09:30:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/certificates/webex-certificates-on-a-build-server/</guid>
      <description>Webex on Linux says &amp;#34;Offline - No internet connection&amp;#34; on a machine whose network is fine: the OpenSSL Cisco ship looks for its trust store inside their own build container. What breaks, the fixes that fail, the one that works, what the build process got wrong, and how a security appliance vendor ships a client that cannot check a certificate.</description>
    </item>
    <item>
      <title>A VPN Out of Parts: PPP, Tap Devices and Netcat</title>
      <link>https://blogs.damiendye.uk/en/networking/a-vpn-out-of-parts-and-what-egress-really-is/</link>
      <pubDate>Mon, 14 Sep 2026 15:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/a-vpn-out-of-parts-and-what-egress-really-is/</guid>
      <description>A VPN is a virtual link plus a carrier, and Linux ships a program for each: pppd or a tap device, and netcat. Building it both ways — over TCP, UDP, TLS and DTLS, with zstd compression — shows what a VPN is made of, and what egress really is: once an attacker has root and outbound is open, the tunnel is already installed.</description>
    </item>
    <item>
      <title>Your Firewall Takes Instructions From Strangers. Turn Off the Protocol Helpers.</title>
      <link>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</link>
      <pubDate>Mon, 14 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/protocol-helpers-turn-them-off/</guid>
      <description>A NAT helper reads the inside of your packets and opens inbound ports on what it finds there. Anyone can write that text — a web page has been enough since 2010. How helpers work, how crafted packets turn them into a port-opening service for strangers, what IPsec pass-through does, why they fail Cyber Essentials, and how to switch the lot off.</description>
    </item>
    <item>
      <title>IPsec Was a Good Idea. It Is Time to Turn It Off.</title>
      <link>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</link>
      <pubDate>Sun, 13 Sep 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/ipsec-was-a-good-idea-turn-it-off/</guid>
      <description>IPsec bound security to the IP address, then the industry took the address away. NAT, double NAT under CGNAT, NAT64 that will not carry it at all, no ports so no load balancing, the MTU tax, L2TP, PPTP and Windows interop — with diagrams, Cisco and Juniper documentation, a full diagnostic method, and the case for retiring it.</description>
    </item>
    <item>
      <title>Zero Trust VDI Without the Cloud Bill — Proxmox, Intel Arc Pro and Cloudflare Access</title>
      <link>https://blogs.damiendye.uk/en/networking/zero-trust-vdi-cloudflare-access/</link>
      <pubDate>Wed, 02 Sep 2026 14:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/zero-trust-vdi-cloudflare-access/</guid>
      <description>Part one: the architecture and the cost argument for replacing Azure Virtual Desktop with Proxmox, Intel Arc Pro SR-IOV and Cloudflare Access. On-prem OAuth for identity, browser-rendered RDP, a firewalled LXC tunnel on its own VLAN, KSM for memory density, and profiles on Ceph. The next post builds it.</description>
    </item>
    <item>
      <title>Ping: The Diagnostic Tool That Opens a Whole Lot More</title>
      <link>https://blogs.damiendye.uk/en/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</link>
      <pubDate>Tue, 01 Sep 2026 08:05:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/ping-the-diagnostic-tool-that-opens-a-whole-lot-more/</guid>
      <description>Why ping — ICMP echo, not the rest of the protocol — is a liability: a channel every host must answer, so a network that &amp;#39;only allows ping&amp;#39; has a full VPN out. The threat, who can open one, three tunnels (Hans, icmptunnel, a Python one with AES-128), and the rule that shuts it: nftables, pf, Cisco, Junos, MikroTik and Windows.</description>
    </item>
    <item>
      <title>Is Your MSP Lying To You To Sell You Premium Products?</title>
      <link>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part1/</link>
      <pubDate>Fri, 28 Aug 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part1/</guid>
      <description>Part 1 of 3. Some MSPs lie; most never have to, because the vendors whose products they recommend pay them and nobody must tell you. The tells that you are being sold to rather than engineered for: the free fix refused, requirements never written down, one option on the shortlist, no open source line, and the addresses you rent forever.</description>
    </item>
    <item>
      <title>What Your MSP Built You, And Who Else Can Reach It</title>
      <link>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part2/</link>
      <pubDate>Fri, 28 Aug 2026 17:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part2/</guid>
      <description>Part 2 of 3. Cloud for a business all in one building. The firewall brand with the most exploited vulnerabilities on CISA&amp;#39;s list. Backups nobody has restored, reports that never reach you, an agent on every machine answering to a console you have never seen. What the ICO found at Advanced and Capita, and the keys that open all of it.</description>
    </item>
    <item>
      <title>When It Breaks, Who Actually Carries It?</title>
      <link>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part3/</link>
      <pubDate>Fri, 28 Aug 2026 16:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/is-your-msp-lying-to-you-part3/</guid>
      <description>Part 3 of 3. What the SLA actually promises, what the liability cap is worth, and what the excuses sound like when it fails: the meeting about an invented crisis, the day it becomes your fault, the account that goes quiet, the advice that costs them money, what leaving really involves, and why nobody regulates the selling.</description>
    </item>
    <item>
      <title>The Firewall Is Eleven Hops Away</title>
      <link>https://blogs.damiendye.uk/en/networking/how-far-away-is-the-firewall/</link>
      <pubDate>Fri, 28 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/how-far-away-is-the-firewall/</guid>
      <description>A connection that times out tells you nothing about where it died. TTL does. Here is how to count the hops to whatever is eating your port, on Linux, macOS, the BSDs, Solaris and Redox, with a script that needs no root on Linux.</description>
    </item>
    <item>
      <title>We Never Ran Out of Addresses. We Ran Out of Effort.</title>
      <link>https://blogs.damiendye.uk/en/networking/we-never-ran-out-of-addresses/</link>
      <pubDate>Thu, 27 Aug 2026 18:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/networking/we-never-ran-out-of-addresses/</guid>
      <description>The UK has spent twenty years bolting workarounds onto IPv4 rather than turning on IPv6. I counted every UK network in the routing table to see who has actually done it, and the answer says this was never about money.</description>
    </item>
    <item>
      <title>Who Actually Writes &amp; Uses Ceph</title>
      <link>https://blogs.damiendye.uk/en/ceph/who-actually-writes-and-uses-ceph/</link>
      <pubDate>Thu, 27 Aug 2026 13:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/ceph/who-actually-writes-and-uses-ceph/</guid>
      <description>I counted every commit to Ceph&amp;#39;s main branch for the last ten years, traced every maintainer to the company that employs them, and gathered the public deployments. 69,613 commits, 1,718 people, 478 organisations, and a project that has outlived most of the companies that built it.</description>
    </item>
    <item>
      <title>VMware to Proxmox with Ansible — Build the Shells Before You Move a Byte</title>
      <link>https://blogs.damiendye.uk/en/ansible/vmware-to-proxmox-ansible/</link>
      <pubDate>Wed, 26 Aug 2026 10:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/ansible/vmware-to-proxmox-ansible/</guid>
      <description>Reading a vSphere estate with the dynamic inventory, mirroring its VLANs into Proxmox SDN, and rebuilding every VM as a diskless shell before a single disk moves. Why every VMware info module hides the one field the migration needs, why vlan_id is three different types, and why one NFS export mounted twice turns the cutover into a local read.</description>
    </item>
    <item>
      <title>Who Actually Controls DNS</title>
      <link>https://blogs.damiendye.uk/en/dns/who-actually-controls-dns/</link>
      <pubDate>Tue, 25 Aug 2026 14:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/who-actually-controls-dns/</guid>
      <description>The root of the internet is a 1.5 MB text file. Who edits it, who signs it, and what ICANN has done with the power to decide what goes in it.</description>
    </item>
    <item>
      <title>What Happened at Nominet</title>
      <link>https://blogs.damiendye.uk/en/dns/what-happened-at-nominet/</link>
      <pubDate>Tue, 25 Aug 2026 13:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/what-happened-at-nominet/</guid>
      <description>The .uk registry is owned by its members. In March 2021 they voted half the board out. This is what the estate looked like from inside, and how a registry with no regulator ended up being disciplined by the only people who could.</description>
    </item>
    <item>
      <title>How Technology Became Something You Rent</title>
      <link>https://blogs.damiendye.uk/en/random/technology-you-rent/</link>
      <pubDate>Tue, 25 Aug 2026 12:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/technology-you-rent/</guid>
      <description>Part 1 of 8. Twenty years back you bought software and the copy was yours. Now you rent it, and the supplier sets the terms. This post walks through how that happened, one step at a time, and why every step made it harder to pack up and go elsewhere. Plain language, short lines.</description>
    </item>
    <item>
      <title>What Renting Your Technology Costs</title>
      <link>https://blogs.damiendye.uk/en/random/what-renting-costs/</link>
      <pubDate>Tue, 25 Aug 2026 11:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/what-renting-costs/</guid>
      <description>Part 2 of 8. Once moving supplier is hard, the costs change shape. The price follows how hard it is to leave. Profit gets declared somewhere other than where it was earned. The law that applies follows who owns the company, not where the building stands. And a service can stop for reasons that have nowt to do with you. Plain language, with sources.</description>
    </item>
    <item>
      <title>Who Pays for the Software You Use</title>
      <link>https://blogs.damiendye.uk/en/random/who-pays-for-the-software/</link>
      <pubDate>Tue, 25 Aug 2026 10:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/who-pays-for-the-software/</guid>
      <description>Part 3 of 8. The first two posts looked at what dependency costs you; this one at who else foots the bill. Open source was fought for about 15 years, then taken up, and much of it is now kept going by people paid nowt for it. And how the firms that build software get bought, borrowed against and stripped of what other folk built.</description>
    </item>
    <item>
      <title>What the Record Shows</title>
      <link>https://blogs.damiendye.uk/en/random/what-the-record-shows/</link>
      <pubDate>Tue, 25 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/what-the-record-shows/</guid>
      <description>Part 4 of 8. Picking a supplier means guessing how they will behave later, and the fairest guess is what courts and regulators have decided. Findings against the largest tech firms, leaning on European decisions and the cases regulators lost, then the pattern: fines small next to the gain, remedies years late, harms known inside long before out.</description>
    </item>
    <item>
      <title>How Far One Country&#39;s Law Reaches</title>
      <link>https://blogs.damiendye.uk/en/random/how-far-the-law-reaches/</link>
      <pubDate>Tue, 25 Aug 2026 08:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/how-far-the-law-reaches/</guid>
      <description>Part 5 of 8. Part 2 covered the law that reaches your data; this one the law that reaches your company. Non-American firms paying huge penalties under US law for conduct barely connected to America, what the French National Assembly made of it as a commercial weapon, and the assumptions a product carries from its home market.</description>
    </item>
    <item>
      <title>Backdoors, and Who Gets Accused of Them</title>
      <link>https://blogs.damiendye.uk/en/random/backdoors-and-who-is-accused/</link>
      <pubDate>Tue, 25 Aug 2026 07:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/backdoors-and-who-is-accused/</guid>
      <description>Part 6 of 8. Barring a supplier on security grounds needs a standard applied evenly. A Swiss inquiry confirmed two intelligence services owned an encryption firm and sold weakened machines to 120&#43; governments; a crypto standard was pulled over a suspected weakness; kit gets intercepted in transit. Then the 2024 event that settled it.</description>
    </item>
    <item>
      <title>The Same Pattern in Other Industries</title>
      <link>https://blogs.damiendye.uk/en/random/the-same-pattern-elsewhere/</link>
      <pubDate>Tue, 25 Aug 2026 06:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/the-same-pattern-elsewhere/</guid>
      <description>Part 7 of 8. This is not really about technology. Four firms control most of the world&amp;#39;s seed supply and licence terms can stop a farmer replanting; ten retailers move most of Britain&amp;#39;s food. Both got a legal answer, a Groceries Code Adjudicator here and an unfair-trading directive across the EU. Software has nowt like it, and this asks why.</description>
    </item>
    <item>
      <title>Where Your Choices Are Coming Back</title>
      <link>https://blogs.damiendye.uk/en/random/choice-coming-back/</link>
      <pubDate>Tue, 25 Aug 2026 05:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/random/choice-coming-back/</guid>
      <description>Part 8 of 8. Since 2025 the European answer has turned from plans into things you can actually install. Office suites, payment systems and new rules are all real now. This post covers what has landed, what is honestly still years off, and 3 questions to work out where you stand. Plain language.</description>
    </item>
    <item>
      <title>Samba4 and Securing AD Records Using DNSSEC</title>
      <link>https://blogs.damiendye.uk/en/dns/samba4-securing-ad-records-with-dnssec/</link>
      <pubDate>Mon, 24 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/dns/samba4-securing-ad-records-with-dnssec/</guid>
      <description>Every domain-joined machine finds its DC by asking DNS for an SRV record, so the _msdcs locators are the most security-critical records you have. Signing them from a Samba4 DC: BIND with dlz_bind9, inline signing, a hidden primary, dynamic updates kept out of the locator zone, then forcing Windows and Linux clients to validate the signatures.</description>
    </item>
    <item>
      <title>Tri-Mode Adapters Buy Flexibility With Your NVMe Queues</title>
      <link>https://blogs.damiendye.uk/en/hardware/tri-mode-adapters-nvme-as-sas/</link>
      <pubDate>Thu, 13 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/hardware/tri-mode-adapters-nvme-as-sas/</guid>
      <description>A tri-mode adapter lets any bay take SAS, SATA or NVMe, which is why U.3 backplanes exist. What it hides: your NVMe drives arrive in Linux as SCSI disks on mpt3sas, queue depth 128, sharing one tag pool and one x8 uplink. Two Gen4 drives saturate the card, one Gen5 is already past it. Whether the trade still makes sense in 2026.</description>
    </item>
    <item>
      <title>Creating Proxmox VMs with Ansible — The Host You Are Building Does Not Exist Yet</title>
      <link>https://blogs.damiendye.uk/en/ansible/proxmox-create-vms-community-proxmox/</link>
      <pubDate>Wed, 12 Aug 2026 11:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/ansible/proxmox-create-vms-community-proxmox/</guid>
      <description>The community.proxmox collection is an API client, not a configuration agent, and that changes the shape of every playbook. Where the tasks actually run, why proxmox_kvm declines to converge rather than update, why proxmox_disk and proxmox_nic own disk and NIC changes, and the undocumented return value you will end up needing.</description>
    </item>
    <item>
      <title>Proxmox VE Is Not a Hypervisor — KVM Is, and You Are Already Running It</title>
      <link>https://blogs.damiendye.uk/en/proxmox/kvm-the-hypervisor-inside-proxmox-ve/</link>
      <pubDate>Wed, 12 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/kvm-the-hypervisor-inside-proxmox-ve/</guid>
      <description>&amp;#34;Is Proxmox enterprise grade?&amp;#34; is a question about the hypervisor, and Proxmox VE does not contain one. The hypervisor is KVM, the same kernel module under EC2, Google Cloud, Nutanix AHV and OpenShift Virtualisation. What Proxmox actually maintains, why the type 1 argument aims at the wrong line, and what the shared foundation does not buy you.</description>
    </item>
    <item>
      <title>Making HDD-Backed Proxmox Ceph Clusters Fast — NVMe Metadata, One Optane Per Spindle, and What It Costs You</title>
      <link>https://blogs.damiendye.uk/en/proxmox/hdd-backed-ceph-bcache-optane/</link>
      <pubDate>Fri, 07 Aug 2026 20:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/hdd-backed-ceph-bcache-optane/</guid>
      <description>Flash pricing has made all-NVMe hard to justify, and enterprise HDDs are worth another look. Acceptable latency out of them on hyper-converged Proxmox Ceph: move RocksDB off the spindle, pair each disk with its own Optane through bcache (Optane, because NAND endurance is wrong for the job), and be honest about the failure modes it buys.</description>
    </item>
    <item>
      <title>Licence-Free Windows VDI on Proxmox with an Intel Arc Pro B50 — and the Firmware Limit That Stopped It</title>
      <link>https://blogs.damiendye.uk/en/proxmox/licence-free-vdi-intel-arc-pro-sriov/</link>
      <pubDate>Fri, 07 Aug 2026 17:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/licence-free-vdi-intel-arc-pro-sriov/</guid>
      <description>Intel&amp;#39;s Arc Pro cards do SR-IOV natively, with no vGPU licence to buy — which makes a licence-free Windows VDI on Proxmox genuinely possible. The whole build on a B50, the Windows-first bootstrap problem, why the firmware caps it at two virtual functions, and how many each card in the B-series gives you.</description>
    </item>
    <item>
      <title>A Switchless Proxmox Mesh with SDN OpenFabric — Ceph and Client Networks Without a 100G Switch</title>
      <link>https://blogs.damiendye.uk/en/proxmox/proxmox-routed-mesh-sdn-openfabric/</link>
      <pubDate>Fri, 07 Aug 2026 16:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/proxmox-routed-mesh-sdn-openfabric/</guid>
      <description>Three Proxmox nodes wired directly to each other in a triangle, with OpenFabric routing over the mesh and Ceph plus VXLAN client networks riding on top. Built entirely in the web interface, and honest about where the design stops scaling.</description>
    </item>
    <item>
      <title>Two Boot Lines — Which Kernel Flags Belong on a Proxmox Host, and Which Belong in the Guest</title>
      <link>https://blogs.damiendye.uk/en/proxmox/kernel-boot-flags-host-guest/</link>
      <pubDate>Fri, 07 Aug 2026 15:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/kernel-boot-flags-host-guest/</guid>
      <description>Most Proxmox tuning lines you find online are one blob of kernel flags. Half of them belong on the hypervisor, half belong inside the guest, two of the popular ones do nothing at all, and a few change meaning depending on which side of the boundary they land.</description>
    </item>
    <item>
      <title>A Virtual NVMe Device in Proxmox — and the Three Things You Give Up</title>
      <link>https://blogs.damiendye.uk/en/proxmox/virtual-nvme-proxmox/</link>
      <pubDate>Fri, 07 Aug 2026 14:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/virtual-nvme-proxmox/</guid>
      <description>QEMU can emulate a real NVMe controller, so the guest uses its own in-box NVMe driver with no VirtIO media required. It is also unmigratable by design, invisible to Proxmox backups, and no faster than VirtIO SCSI. Here is how to add one and when it is worth it.</description>
    </item>
    <item>
      <title>A VM&#39;s Clock Cannot Be Trusted — and the ptp_kvm Fix for QEMU/KVM</title>
      <link>https://blogs.damiendye.uk/en/proxmox/vm-time-ptp-kvm/</link>
      <pubDate>Fri, 07 Aug 2026 13:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/vm-time-ptp-kvm/</guid>
      <description>A virtual machine&amp;#39;s clock is built on an assumption virtualisation breaks: that the CPU keeps counting. Why guest time drifts on every hypervisor, what the skew actually breaks — Kerberos, TLS, Ceph, Windows — and how ptp_kvm fixes it properly on QEMU/KVM.</description>
    </item>
    <item>
      <title>4Kn, 512e and 512n — Why Native 4K Wins, and What the Emulation Costs</title>
      <link>https://blogs.damiendye.uk/en/proxmox/block-sizes-4kn-512e/</link>
      <pubDate>Fri, 07 Aug 2026 12:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/block-sizes-4kn-512e/</guid>
      <description>512e drives present 512-byte sectors they do not have, and the firmware makes up the difference on every unaligned write. What that costs on the medium, in the host and in write amplification — why direct synchronous writes are the worst case — and how to convert a fleet to 4Kn.</description>
    </item>
    <item>
      <title>PCIe Resizable BAR and Modern GPUs — Intel Arc, NVIDIA and AMD</title>
      <link>https://blogs.damiendye.uk/en/proxmox/pcie-resizable-bar/</link>
      <pubDate>Fri, 07 Aug 2026 11:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/pcie-resizable-bar/</guid>
      <description>Resizable BAR lets the CPU map a GPU&amp;#39;s whole framebuffer instead of peering at it through a 256MB window. Intel calls it required for Arc, NVIDIA enables it per game, AMD sells it as Smart Access Memory — and for AI work it changes the transfer, not the maths.</description>
    </item>
    <item>
      <title>PCIe Passthrough Performance on Proxmox VE — The IOMMU Tax and How to Minimise It</title>
      <link>https://blogs.damiendye.uk/en/proxmox/pcie-passthrough-performance-the-iommu-tax/</link>
      <pubDate>Fri, 07 Aug 2026 10:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/pcie-passthrough-performance-the-iommu-tax/</guid>
      <description>Why PCIe devices lose throughput when passed through to a VM via VFIO, and the practical tuning steps that claw most of it back.</description>
    </item>
    <item>
      <title>NUMA Alignment on Proxmox VE — Why It Matters and How to Get It Right</title>
      <link>https://blogs.damiendye.uk/en/proxmox/numa-alignment-proxmox/</link>
      <pubDate>Fri, 07 Aug 2026 09:40:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/numa-alignment-proxmox/</guid>
      <description>On multi-socket systems, a VM with its vCPUs on one NUMA node and its passed-through device on another loses 20–30% throughput before you&amp;#39;ve even looked at anything else.</description>
    </item>
    <item>
      <title>PCIe ASPM and Why You Should Disable It for Passthrough</title>
      <link>https://blogs.damiendye.uk/en/proxmox/pcie-aspm-passthrough/</link>
      <pubDate>Fri, 07 Aug 2026 09:20:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/pcie-aspm-passthrough/</guid>
      <description>Active State Power Management saves a few watts on idle PCIe links. Under VFIO passthrough, it adds latency jitter that&amp;#39;s hard to diagnose and easy to fix.</description>
    </item>
    <item>
      <title>PCIe MaxPayloadSize — A Free Performance Win for Passthrough</title>
      <link>https://blogs.damiendye.uk/en/proxmox/pcie-maxpayloadsize/</link>
      <pubDate>Fri, 07 Aug 2026 09:00:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/pcie-maxpayloadsize/</guid>
      <description>QEMU&amp;#39;s virtual root complex defaults to 128-byte TLP payloads. Most devices support 256 or 512. One kernel parameter fixes it.</description>
    </item>
    <item>
      <title>Always Use Q35, Not i440fx — Why It Matters on Proxmox VE</title>
      <link>https://blogs.damiendye.uk/en/proxmox/q35-not-i440fx/</link>
      <pubDate>Fri, 07 Aug 2026 08:45:00 +0100</pubDate>
      <guid>https://blogs.damiendye.uk/en/proxmox/q35-not-i440fx/</guid>
      <description>The two QEMU virtual chipsets are not interchangeable. Q35 provides a proper PCIe topology that passthrough, modern Windows, and the wider KVM ecosystem all depend on.</description>
    </item>
    <item>
      <title>About</title>
      <link>https://blogs.damiendye.uk/en/about/</link>
      <pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate>
      <guid>https://blogs.damiendye.uk/en/about/</guid>
      <description>I&amp;#39;m Damien Dye — presales engineer at croit, a Ceph Foundation founding member and a Proxmox Gold Partner. Twenty-odd years across Microsoft, Linux, virtualisation, networking, storage and security, self-taught on Linux since age eight, and an open-source advocate throughout. Who I am, how I got here, and what this site is for.</description>
    </item>
  </channel>
</rss>
