Hi,
Welcome to the September Self-Hosted Stack update. Thanks for subscribing.
This newsletter covers recent developments across my self-hosted AI and VPN open source projects. As before, I’ll keep it focused on the changes most useful to people running or evaluating the projects.
A New Self-Hosted AI Book
I recently published The Self-Hosted AI Builder’s Guide, a practical guide to deploying, securing, and operating private AI services with Docker and open source components.
The book brings the individual projects together into a complete system. It covers local LLMs and private chat, document intelligence and RAG, Whisper and Kokoro voice pipelines, authenticated MCP tools, and an optional containerized AI agent. It also includes CPU and NVIDIA CUDA deployments, security boundaries, troubleshooting, backups, restores, and upgrades.
The book is now available in Kindle, audiobook, paperback, and hardcover formats.
AI Project Updates
The Self-Hosted AI Stack now uses AnythingLLM 1.16.1 and includes a dedicated AnythingLLM healthcheck for more reliable startup.
Whisper gained a per-request beam-size option, with a configurable limit to control resource use. WhisperLive received an important fix for WebSocket API-key authentication. Several Python-based AI images also now use stronger dependency-age safeguards during builds.
In case you missed the June update, fresh persistent installations of Whisper, WhisperLive, Kokoro, Embeddings, and Docling now generate API keys. Fresh AnythingLLM installations also start password-protected. Existing installations retain their previous configuration.
VPN Project Updates
The IPsec VPN Docker images and setup and upgrade scripts now use Libreswan 5.4, superseding the Libreswan security update mentioned in June.
Legacy DH2/MODP1024 support has been removed, and Android users should now use IKEv2. Additional fixes improve IPv6 and nftables compatibility, Enterprise Linux 10 support, ESP module detection, and Docker IKEv2 split tunneling.
Headscale was updated to 0.29.3, with a fix for binary labeling on SELinux systems. The OpenVPN installer also added Amazon Linux 2023 support, while the IPsec installer retired Amazon Linux 2 support.
Updated Deployment Guides
I’ve attached the latest versions of the deployment guides:
VPN Deployment Guide
IPsec/IKEv2, WireGuard, OpenVPN, and Headscale on bare metal and Docker.
AI Stack Deployment Guide
Ollama, LiteLLM, Whisper, Kokoro, and more.
Both guides have been refreshed since the June issue to incorporate recent project, compatibility, and security-related changes. If you still have an earlier copy, you can replace it with the attached version.
The guides are provided as a subscriber benefit for your personal use. Please don’t redistribute or republish them.
Thanks again for following the projects. Your feedback helps shape future improvements to the book, deployment guides, and open source projects.
- Lin
Browse all projects: github.com/hwdsl2
Join the community: reddit.com/r/selfhostedstack