<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Phil Vishnevsky — Writing</title><description>Guides on homelab networking, self-hosting, and building things that don&apos;t break in production.</description><link>https://pvi.sh/</link><language>en-us</language><item><title>Principles</title><link>https://pvi.sh/blog/principles/</link><guid isPermaLink="true">https://pvi.sh/blog/principles/</guid><description>Twelve of them, including why you should spend real money on anything that separates you from the ground.</description><pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate><category>life</category><category>principles</category><category>coding</category></item><item><title>Reverse Proxy for a Homelab: Caddy and Automatic HTTPS</title><link>https://pvi.sh/blog/reverse-proxy-homelab/</link><guid isPermaLink="true">https://pvi.sh/blog/reverse-proxy-homelab/</guid><description>Putting Caddy in front of a rack of services: real certificates on internal domains, and no port numbers in any URL.</description><pubDate>Wed, 25 Feb 2026 00:00:00 GMT</pubDate><category>self-hosting</category><category>homelab</category><category>caddy</category><category>networking</category><category>security</category></item><item><title>SSO for Self-Hosted Apps: One Login for the Whole Rack</title><link>https://pvi.sh/blog/sso-for-self-hosted-apps/</link><guid isPermaLink="true">https://pvi.sh/blog/sso-for-self-hosted-apps/</guid><description>Pocket ID, Tinyauth, and a reverse proxy, wired so every service behind them takes the same login.</description><pubDate>Mon, 23 Feb 2026 00:00:00 GMT</pubDate><category>self-hosting</category><category>homelab</category><category>security</category><category>sso</category><category>oidc</category></item><item><title>Self‑Hosting With Tailscale: Secure Access Without Open Ports</title><link>https://pvi.sh/blog/self-hosting-with-tailscale/</link><guid isPermaLink="true">https://pvi.sh/blog/self-hosting-with-tailscale/</guid><description>Running services at home and reaching them from anywhere, without forwarding a single port.</description><pubDate>Thu, 19 Feb 2026 00:00:00 GMT</pubDate><category>self-hosting</category><category>tailscale</category><category>homelab</category><category>security</category><category>docker</category></item><item><title>Tailscale Explained: A Mesh VPN With No Open Ports</title><link>https://pvi.sh/blog/tailscale-explained/</link><guid isPermaLink="true">https://pvi.sh/blog/tailscale-explained/</guid><description>How Tailscale gets two machines talking directly through a router that should not allow it, and what it falls back to when NAT wins.</description><pubDate>Tue, 17 Feb 2026 00:00:00 GMT</pubDate><category>tailscale</category><category>vpn</category><category>networking</category><category>homelab</category><category>wireguard</category></item><item><title>What Is a VPN? What It Hides, and From Whom</title><link>https://pvi.sh/blog/what-is-a-vpn/</link><guid isPermaLink="true">https://pvi.sh/blog/what-is-a-vpn/</guid><description>A VPN moves the point where your traffic joins the internet. That is the whole trick, and it explains most of what the ads get wrong.</description><pubDate>Sun, 15 Feb 2026 00:00:00 GMT</pubDate><category>vpn</category><category>networking</category><category>security</category><category>privacy</category></item><item><title>How This Blog Renders MDX</title><link>https://pvi.sh/blog/how-this-mdx-blog-works/</link><guid isPermaLink="true">https://pvi.sh/blog/how-this-mdx-blog-works/</guid><description>The Astro and MDX pipeline behind this site: what runs at build time, what ships to the browser, and why that is almost nothing.</description><pubDate>Fri, 21 Feb 2025 00:00:00 GMT</pubDate><category>mdx</category><category>astro</category><category>performance</category><category>web-dev</category></item></channel></rss>