Fixing logrotate's Glob Confusion

A follow-up to the wildcard bug post from last year. Picking the Thread Back Up The rename workaround, *.example.com to _.example.com, fully resolved the operational problem. Retention became predictable again, and there was no pressing reason to go further. But a workaround isn’t a fix, and the actual bug was still sitting in logrotate’s own source, waiting to bite the next person who names a file after a wildcard domain. This week I finally sat down and found it properly, instead of just renaming files around it. ...

August 20, 2026 · Alexander Bakin

The Wildcard That Broke Nginx Log Rotation

One of those infrastructure problems that looks simple, until you realize the filename itself is part of the problem. The Setup We had Nginx configured to handle wildcard subdomains: server_name *.example.com;, with access logs named after the server block. That’s a convenient pattern for multi-tenant setups where subdomains get created dynamically and you don’t want to hand-maintain a vhost file per tenant. Nginx doesn’t care that the resulting log filename contains a literal * - it just opens the file and writes to it. ...

July 5, 2025 · Alexander Bakin

Deploying Vaultwarden with Ansible: My Homelab's First Real Service

I started self-hosting for a boring reason: I didn’t like that a single cloud account breach could hand someone every password I own. A self-hosted password manager has its own risks, but at least the blast radius is mine to control. Vaultwarden (a lightweight Bitwarden-compatible server) was the obvious first service, and I used it as an excuse to do my homelab properly instead of SSH-ing in and running commands by hand. ...

July 18, 2021 · Alexander Bakin