Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # raatti.net: A DevOps Architect writing about IT, travel, and the outdoors he rarely sees ## Sitemaps [XML Sitemap](https://www.raatti.net/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [314 Votes Against – and Chat Control Still Moved Forward](https://www.raatti.net/2026/07/10/314-votes-against-and-chat-control-still-moved-forward/): Two weeks ago I wrote that Chat Control wasn't buried, only deferred, and that the Council and the EPP were preparing to revive the lapsed "voluntary" scanning regime through an emergency procedure in Parliament's last sitting before summer. I hate being right this fast. On 9 July it happened, almost to the letter. And if your feed says the EU just approved scanning your private messages: that is not what happened. What happened is stranger, and in some ways worse. - [Scanning Everyone Protects No One: Chat Control Returns for Its Final Trilogue](https://www.raatti.net/2026/06/27/scanning-everyone-protects-no-one-chat-control/): On 29 June the EU holds what may be the final trilogue on Chat Control. The engineer-to-engineer case against scanning 450 million people, why it will not survive the Court, and the letter I sent seven MEPs so you can send your own. - [Code Is the End: Vision-First Development with AI Agents](https://www.raatti.net/2026/06/12/code-is-the-end/): "I just want to get to the code." With AI agents, that is exactly backwards. Build the vision first, make the model prove it understands the requirements, then loop code agents and test agents against that vision. Code comes last — and that is architect work. - [Self-Hosted AI: A Local Coding Agent on a GTX 1080 Ti](https://www.raatti.net/2026/06/07/local-coding-agent-gtx-1080-ti/): I already keep GitHub's AI off my commits. Running the AI itself on my own hardware was just the next logical step. Same principle, one layer down. No tokens leaving the building, no per-request meter ticking in the background, no quietly feeding someone else's training run. My GPU, my weights, my rules. - [AI Capacity Is Getting Full](https://www.raatti.net/2026/05/05/ai-capacity-is-getting-full/): Something shifted in the AI developer space over the past few weeks. Subscription limits tightened, usage-based billing appeared where flat rates used to be, and companies that were handing out unlimited inference started quietly pulling back. Streaming developers have been sounding the alarm — AI prices have been heavily subsidized, and that era is ending. But the reason isn’t what most people think. It’s not greed. It’s physics. - [Headscale vs Tailscale vs NetBird vs Cloudflare Mesh for Private Networking](https://www.raatti.net/2026/04/17/tailscale-vs-netbird-vs-cloudflare/): A hands-on comparison of four mesh VPN solutions — Tailscale, Headscale, NetBird, and Cloudflare Mesh — covering architecture, installation, performance benchmarks, security sovereignty, and cost. Includes real iperf3 data across Hetzner, AWS, and GCP routes, plus a practical hybrid deployment strategy using Headscale for server-to-server backbone and Cloudflare Mesh as a resilient backup path. - [Self-hosted Git with Forgejo on RHEL](https://www.raatti.net/2026/04/11/self-hosted-git-with-forgejo-on-rhel/): A practical install guide for Forgejo on RHEL - self-hosted Git forge with MariaDB, Apache reverse proxy, Cloudflare TLS, and direct SSH on port 2222. Keep your code on your own hardware. - [Simplicity is a Feature: Migrating to Cloudflare Tunnel on Red Hat Linux](https://www.raatti.net/2026/03/22/simplicity-is-a-feature-migrating-to-cloudflare-tunnel-on-red-hat-linux/): Unnecessary is the enemy of perfect. This is a principle I keep coming back to when managing server infrastructure. It is not enough to have something that works — if it works through unnecessary complexity, it is already a liability waiting to become a problem. - [From Bandwidth Mystery to Hardened Origin: A Day of Server Security](https://www.raatti.net/2026/03/20/from-bandwidth-mystery-to-hardened-origin-a-day-of-server-security/): What started as a bandwidth mystery turned into a full server security audit: wp-cron self-hammering, attack traffic analysis, compiling mod_evasive from Fedora src.rpm on RHEL 10, and locking WordPress behind Cloudflare-only origin access via firewalld ipset. Plus the firewalld chain order trap that took the site down mid-session. ## Pages - [CV](https://www.raatti.net/cv/): Seasoned DevOps Architect with over 20 years of experience across Linux, Cloud platforms, and modern IT software delivery. Deep expertise in Azure and AWS, Infrastructure as Code, virtualization, containers, and Kubernetes/OpenShift. Passion for security and automation, building resilient and scalable, standards‑compliant solutions. - [Home](https://www.raatti.net/): By Jani Karlsson - [Blog](https://www.raatti.net/blog/) - [About](https://www.raatti.net/about/): A seasoned DevOps Architect with over 20 years of experience in Linux and IT. Dedicated advocate for security and automation, with specialized knowledge in Linux, Cloud (Azure/AWS), Infrastructure as Code (IaC), Information Security (InfoSec), Cloudflare, virtualization, containers, Kubernetes/OpenShift as well as OS and network-level security. - [Privacy Policy](https://www.raatti.net/privacy-policy/): This is a personal blog and portfolio site run by Jani Karlsson, accessible at https://www.raatti.net.