55 épisodes
- Windows Admin Center is a genuinely useful tool wrapped in an on-ramp so rough it took Andy four hours, a from-scratch certificate authority, and a pile of misleading error messages just to reach the login screen.
Andy rebuilt his lab on an all-Core Windows Server 2025 fleet, set out to manage it from a browser the way Microsoft keeps telling us to, and hit a certificate wall that most SysAdmins would never fight through. He and Eric Siron walk the full gauntlet: the 60-day self-signed cert trap, an ERROR_DS_RANGE_CONSTRAINT that pointed the wrong way, a web server template that blocks computer requests, a silent blank SAN that kills the HTTPS binding, and the bigger question of whether a web tool is even the right way to manage Windows. Along the way: a News React on open-source AI, China, and a possible federal clampdown, plus the domain-join debate that never dies.
Chapters:
00:00:00 - Cold Open: Four Hours to Install a Free Tool
00:01:15 - Welcome and Show Plugs
00:03:52 - News React: Apple, the EU, and the Walled Garden
00:08:55 - News React: Open-Source AI, China, and a Possible Federal Clampdown
00:16:00 - Nerd Hour: Ripping Out KVM, Putting Hyper-V Back
00:18:55 - Setting the Scene: An All-Core Lab and the Certificate Wall
00:30:08 - The Four-Hour Gauntlet: A Sequence of Failures
00:44:00 - What WAC Gets Right, and Where It Falls Down
00:59:24 - Azure Arc and the Real Agenda
01:07:45 - Does WAC Move the Needle? The Verdict
Resources / Show Notes:
- Microsoft - Windows Admin Center overview: https://learn.microsoft.com/en-us/windows-server/manage/windows-admin-center/overview
- Hornetsecurity (Eric Siron) - Public Key Infrastructure explained, including why to stop using self-signed certificates: https://www.hornetsecurity.com/en/blog/public-key-infrastructure/
Sources and clarifications (News React / AI segment):
We referenced several press claims from memory during the AI segment. The claims hold up, but a few were under-attributed on air, so here is the precise record.
- Moonshot AI - Kimi K3, the open-weight model released the week before we recorded that benchmarks near frontier US models. The whole news cycle is downstream of it: https://venturebeat.com/technology/chinas-moonshot-ai-releases-kimi-k3-the-largest-open-source-model-ever-rivaling-top-u-s-systems
- Dean Ball, OpenAI's Head of Strategic Futures and a former senior AI adviser in the Trump administration, is the source of the "AI communism" line, in a post on X. On air Andy first said "CEO of Claude" and "CEO of Anthropic," then corrected to "someone from OpenAI." The correct attribution is Ball at OpenAI, NOT Anthropic. Naming note: Claude is the model, Anthropic is the company: https://x.com/deanwball/status/2078133895766114412
- Dean Ball - follow-up clarifying he was predicting that outcome, not advocating for it: https://x.com/deanwball/status/2078619513575137330
- Axios (July 20, 2026) - the federal-action angle. Frame it as reportedly under consideration; no formal policy has been proposed. Mechanisms discussed include Commerce Entity List additions, security advisories, and federal procurement rules: https://www.axios.com/2026/07/20/ai-us-china-open-source-kimi
- David Sacks, former White House AI adviser, publicly argued that closed labs want the government to eliminate their open-source competition, in a post on X: https://x.com/DavidSacks/status/2078826291638522127
- Dario Amodei has called open-source AI a dangerous path; the source quotes are collected in this r/Anthropic thread: https://www.reddit.com/r/Anthropic/comments/1ui759l/amodei_says_open_source_is_dangerous/ 053 - How to Survive as a Solo SysAdmin: Where to Start When You're the Only One
17/07/2026 | 1 h 13 minWhen you are the only person standing between a working business and total collapse, the job stops being about doing everything and starts being about deciding what not to do this week.
Andy and Eric Siron tackle a listener-requested topic: you just became the solo SysAdmin, whether by hire, downsizing, or promotion, and now you own the firewall, the servers, the backups, and the printer nobody wants to replace. This one is heavy on the career and survival skills that keep a team of one sane: triage before projects, documentation as an insurance policy, buying time back through automation and managed services, and speaking business value instead of acronyms to leadership. Plus a News React on Windows Server hot patching and 1Password for Claude, and a Nerd Hour on Debian 13.6 Secure Boot certs and SAML auth for Nagios.
Chapters:
00:00:00 - You're the Only SysAdmin. Now What?
00:01:02 - Welcome and Show Plugs
00:05:13 - News React: Windows Server Hot Patching via Azure Arc
00:11:00 - News React: 1Password for Claude and AI Guardrails
00:13:50 - Nerd Hour: Debian 13.6 and Secure Boot Certificate Updates
00:16:33 - Nerd Hour: SAML Auth for Nagios via ADFS
00:23:20 - Main Topic: The Case of the Solo SysAdmin
00:28:23 - Triage Before Projects
00:30:57 - Note-Taking Systems: ARC, Bullet Journal, Rocketbook
00:46:40 - Documentation Is Survival and the Hit-By-A-Bus List
00:50:25 - Greenshot and Fast Screenshot Documentation
00:54:14 - Buying Time Back: Automation
00:58:16 - Buying Time Back: Managed Services
01:03:44 - Communicating Business Value to Leadership
01:09:09 - Managing and Documenting Risk
01:10:17 - Wrap-Up
Resources / Show Notes:
- MacRumors - 1Password for Claude lets AI log in without seeing your passwords: https://www.macrumors.com/2026/07/16/1password-claude-integration/
- Microsoft Learn - Enable Hotpatch for Azure Arc-enabled servers (now free for Windows Server 2025): https://learn.microsoft.com/en-us/windows-server/get-started/enable-hotpatch-azure-arc-enabled-servers
- Debian - 13.6 release notes and Secure Boot CA guidance: https://www.debian.org/News/2026/20260711
- Greenshot, free open-source screenshot tool: https://getgreenshot.org/
- Rocketbook, reusable notebook: https://getrocketbook.com/
- Bullet Journal method: https://bulletjournal.com/
- SysAdmin Weekly, all show links: https://www.sysadminweekly.com
- SysAdmin Weekly Newsletter: https://newsletter.sysadminweekly.com
- SysAdmin Weekly GitHub Discussions: https://github.com/ProjectRunspace/sysadmin-weekly/discussions
- Andy on Tech: https://www.andyontech.com
- Project Runspace: https://www.projectrunspace.org052 - Why is Homelab Hardware So Expensive in 2026 (and When Will It Get Cheaper)?
10/07/2026 | 1 h 12 minSomewhere between a $305 Raspberry Pi board and a used NVMe listing on eBay, the homelab hobby quietly stopped making financial sense.
Andy and co-host Eric Siron dig into why memory, NAND, and storage prices went vertical in 2026, who is actually eating the supply, and what practitioners should do about it. They cover the AI buildout swallowing the manufacturing capacity, why prices probably never return to pre-shortage levels, and the return of a skill the industry let atrophy: right-sizing hardware to the workload instead of throwing spec at it.
## Chapters:
00:00:00 - The Hardware Market Is Fire and Brimstone
00:01:18 - Welcome and Intros
00:04:33 - News React: The First Fully AI-Run Ransomware (JadePuffer)
00:08:16 - News React: AI Job-Blame and the Unix Lawsuit That Won't Die
00:13:32 - Nerd Hour: Thunderbird Finally Speaks Exchange Online
00:18:47 - Nerd Hour: Hugo, AI, and the 80% Problem
00:23:13 - Show Plugs
00:24:09 - Why Homelab Hardware Broke Me: The eBay Moment
00:41:44 - Why This Is Happening: AI Is Eating the Supply Chain
00:46:43 - Local Models and the Willingness-to-Pay Problem
00:52:41 - The New Normal: Prices Aren't Coming Back
00:59:05 - Right-Size the Hardware to the Problem
01:06:02 - Could China Break the Bottleneck?
01:09:29 - One More Casualty, and Wrap-Up
## Resources / Show Notes
- BleepingComputer, JadePuffer AI-run ransomware: https://www.bleepingcomputer.com/news/security/jadepuffer-ransomware-used-ai-agent-to-automate-entire-attack/
- Thunderbird Blog, native Microsoft Exchange (EWS) support in 145: https://blog.thunderbird.net/2025/11/thunderbird-adds-native-microsoft-exchange-email-support/
- Raspberry Pi Foundation, memory-driven price rises: https://www.raspberrypi.com/news/more-memory-driven-price-rises/
- GamersNexus, SSDs WTF (NAND makers sold out for 2026): https://gamersnexus.net/features/ssds-wtf
- Gartner, surging memory costs (125% DRAM / 234% NAND surge): https://www.gartner.com/en/newsroom/press-releases/2026-02-26-gartner-says-surging-memory-costs-will-reduce-global-pc-and-smartphone-shipments-in-2026
- TechPowerUp, Samsung and SK Hynix $870B capacity plan and fab timelines: https://www.techpowerup.com/350478/samsung-and-sk-hynix-to-expand-semiconductor-capacity-with-usd-870-billion-plan
- BBC, Samsung's memory-driven profit surge: https://www.bbc.com/news/articles/c1kyy8yrpxdo
- IDC, why the memory market stays tight and makers aren't rushing capacity: https://www.idc.com/resource-center/blog/why-the-memory-market-is-still-tight-what-comes-next/
- Tom's Hardware, SK Group chairman says the shortage runs until 2030: https://www.tomshardware.com/pc-components/dram/sk-group-chairman-says-memory-chip-shortage-will-last-until-2030
- SemiAnalysis, China's CXMT challenging DRAM incumbents: https://newsletter.semianalysis.com/p/chinas-cxmt-is-set-to-challenge-dram
- Tom's Hardware, China's YMTC and homegrown NAND tooling: https://www.tomshardware.com/pc-components/ssds/chinas-ymtc-moves-to-break-free-of-u-s-sanctions-by-building-production-line-with-homegrown-tools-aims-to-capture-15-percent-of-nand-market-by-late-2026
- TrendForce, China's GPU makers scaling as enterprise accelerators: https://www.trendforce.com/news/2025/10/07/news-chinas-gpu-trio-rise-as-nvidia-retreats-decoding-moore-threads-metax-and-cambricon/
- CSIS, China and global cyber supply chain risk: https://www.csis.org/blogs/strategic-technologies-blog/chinas-weaponization-global-cyber-supply-chains
- AndyOnTech, Andy's hub for all his output: https://www.andyontech.com
- Project Runspace, the organization behind the show: https://www.projectrunspace.org
- SysAdmin Weekly GitHub Discussions, share your hardware battle stories: https://github.com/ProjectRunspace/sysadmin-weekly/discussions- The hardest part of running a home lab in 2026 is not building it up; it is being honest about what earns its place.
Andy is joined by returning guest and member of the SysAdmin Weekly community, Clay Tamam, a working SysAdmin over in the Netherlands, for a real tour of what is actually sitting in their labs: the hardware, the hypervisors, the services they use every day, and the reasoning behind each choice. Andy explains why he tore a four-node Kubernetes cluster down to five VMs on a single Debian box, Clay walks through building a rack from scratch on a practical budget, and both of them dig into what current memory and hardware prices are doing to the hobby. It closes with the Graveyard: the gear and services that got powered off, and why pruning is an important part of the discipline.
## Chapters
00:00:00 - Welcome and a Returning Guest: Clay from the Netherlands
00:07:20 - News React: A US Firm's Bid for the Dutch DigiD Infrastructure
00:15:21 - News React: An AI-Assisted Hack Hits US Festival Ticketing
00:18:11 - Nerd Hour: Scoping AI Agents and Building a Lab From Scratch
00:24:29 - Main Topic: What Is Actually in Our Home Labs
00:25:15 - The Hardware: Andy's Pared-Down Single-Box Lab
00:31:25 - The Hardware: Clay's From-Scratch Rack Build
00:45:52 - The Foundation: KVM vs. Proxmox
00:56:33 - The Services That Earn Their Keep
01:02:37 - Self-Hosting, the Plex Price Hike, and Leaving Discord
01:13:57 - Learning Goals and the Graveyard
01:24:19 - Local Inference and the Urge to Panic-Buy
01:25:49 - Wrap-Up
## Resources / Show Notes
- Wired - Researcher used Claude to break Front Gate Tickets: https://www.wired.com/story/claude-helped-a-hacker-find-a-way-to-issue-tickets-to-almost-every-us-music-festival/
- NL Times - Netherlands blocks the US takeover of DigiD operator Solvinity: https://nltimes.nl/2026/05/26/netherlands-blocks-us-takeover-digid-operator-solvinity-security-concerns
- Security Now with Steve Gibson: https://www.grc.com/securitynow.htm
- Proxmox Virtual Environment and Backup Server: https://www.proxmox.com
- Forgejo, the self-hosted Git forge (Gitea fork): https://forgejo.org
- Tailscale, the overlay mesh VPN: https://tailscale.com
- Foundry Virtual Tabletop: https://foundryvtt.com
- Plex - New Lifetime Plex Pass pricing: https://www.plex.tv/blog/new-lifetime-plex-pass-pricing/
- Jellyfin, the free software media system: https://jellyfin.org
- Vaultwarden, a self-hosted Bitwarden-compatible server: https://github.com/dani-garcia/vaultwarden
- Framework Desktop: https://frame.work/desktop
- Connect with Clay on LinkedIn: https://www.linkedin.com/in/clay-tamam-00b6441b3/
- AndyOnTech: https://www.andyontech.com - A postmortem that ends with a name instead of a root cause wasted everyone's time in the room.
Andy and Eric Siron pull from a combined several-decades of incident reviews to break down what a postmortem actually is, what kind of outage earns one, and who really needs to be at the table. The throughline: keep it blameless without making it unaccountable, separate root cause from contributing factors, and remember that the follow-through is the entire point. Whether your postmortem is sixty people in a war room or just you writing a summary for one nervous boss, the discipline scales.
## CHAPTERS
00:00:00 - Why Postmortems Matter
00:01:31 - Welcome and Show Plugs
00:04:29 - News React: AI Job Hype Walkbacks, Teams Pain, Oracle Layoffs, AMD Trust
00:17:42 - News React: Ubiquiti UniFi OS Max-Severity RCE CVEs
00:19:41 - Nerd Hour: Claude Code, Hugo, and Pandoc
00:23:36 - The Incident Postmortem Process
00:26:40 - What Actually Earns a Postmortem
00:29:22 - Who Needs To Be In the Room
00:38:49 - Blameless, Not Unaccountable
00:46:50 - What Information To Gather
00:50:33 - Running the Review
00:55:15 - Follow Through Is the Whole Point
## RESOURCES / SHOW NOTES
- SysAdmin Weekly home and show links: https://www.sysadminweekly.com
- SysAdmin Weekly companion newsletter: https://newsletter.sysadminweekly.com
- AndyOnTech: https://www.andyontech.com
- Project Runspace: https://www.projectrunspace.org
- BleepingComputer - Ubiquiti patches three max-severity UniFi OS RCE flaws (CVE-2026-34908, CVE-2026-34909, CVE-2026-34910): https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-severity-unifi-os-vulnerabilities/
- Postmortem markdown template (free, CC BY 4.0, version-tracked in the show repo): https://github.com/ProjectRunspace/sysadmin-weekly/blob/main/resources/postmortem_markdown_process_template.md
- Pandoc, universal document converter (Markdown to docx): https://pandoc.org
- Hugo, the Markdown-driven static site generator: https://gohugo.io
Plus de podcasts Technologies
Podcasts tendance de Technologies
À propos de SysAdmin Weekly
Welcome to the SysAdmin Weekly Podcast, your go-to source for IT-related content tailored to busy system administrators in the trenches. Hosted by longtime sysadmins and Microsoft MVPs Andy Syrewicze and Eric Siron, this show dives deep into the challenges and solutions that matter most to sysadmins on any given day. From technical know-how to real-world insights, SysAdmin Weekly is dedicated to those tireless professionals who keep our digital world running. Tune in for relevant topics, expert advice, and engaging discussions to make your busy schedule a little bit easier.
Site web du podcastÉcoutez SysAdmin Weekly, De quoi jme mail ou d'autres podcasts du monde entier - avec l'app de radio.fr

Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités
Obtenez l’app radio.fr gratuite
- Ajout de radios et podcasts en favoris
- Diffusion via Wi-Fi ou Bluetooth
- Carplay & Android Auto compatibles
- Et encore plus de fonctionnalités


SysAdmin Weekly
Scannez le code,
Téléchargez l’app,
Écoutez.
Téléchargez l’app,
Écoutez.




































