Shared posts

26 Nov 15:07

Larry Ellison Met With Trump To Discuss Which CNN Reporters They Plan To Fire

by Karl Bode

Trump’s right wing billionaire friend Larry Ellison (and his nepobaby son, David) recently acquired CBS and likely co-ownership of TikTok. Like Elon Musk’s acquisition of Twitter, the goal isn’t really subtle: rich, thin-skinned right wingers want to own the entirety of U.S. new and old media, then convert it into a giant propaganda and lazy infotainment bullhorn that blows smoke up their asses.

The Ellisons have since set their sights on Warner Brothers, CNN, and HBO. It won’t be cheap; it’s estimated that Larry and company will have to pay upwards of $60 billion for the acquisition. The Trump administration has openly signaled that they’d very much like the Ellisons to succeed here, in part to force a dying cable news channel (CNN) to be even friendlier to Trump than it already is.

While Ellison has some competing suitors with names like Comcast NBC Universal and Netflix, the winning bidder will need approval from the Trump DOJ and FCC. Knowing that they likely have a distinct tactical advantage via corruption, Ellison and Trump appear to be already measuring the drapes, discussing programming changes (and CNN hirings and firings) that will please the president:

“Ellison often speaks to connections at the White House and in at least one phone call engaged in a dialogue about possibly axing some of the CNN hosts whom Donald Trump is said to loathe, including Erin Burnett and Brianna Keilar, the people said.”

You might recall that during the first Trump administration, Trump tried very hard to offload Time Warner (and CNN) to Rupert Murdoch, who worked behind the scenes to scuttle the AT&T Time Warner deal. Trump has repeatedly filed unsuccessful lawsuits against CNN trying to silence critical voices at the network. With those gambits having failed, buying and destroying CNN from the inside is the next step.

The great irony is these networks that offend Trump weren’t exactly what you’d call bastions of hard-nosed journalism to begin with. Under the ownership of Trump fan David Zaslav, CNN is already know for flinging softball questions at Trump authoritarians, failing to challenge obvious lies on air, and generally airing a sort of safe, infotainment-centered pseudo-journalism.

But even that’s too much critical thinking for America’s thinnest skinned billionaires.

Ellison is already hard at work turning whatever was left of CNN into a right wing propaganda mill. If he acquires ownership of TikTok and CNN as well; the potential exists to create a propaganda empire that’s arguably larger and much worse than Fox News.

But given the recent failures of efforts to dominate U.S. media through consolidation (again, see AT&T) it’s also equally likely that this weird assortment of trolls and nepobabies simply creates a mountain of unsustainable debt and hubris crushed by the weight of its own incompetent ambition.

26 Nov 07:51

Internacional. ONU aprueba resolución para prohibir la tortura / EE. UU., Israel y Argentina la rechazan

by Verdaderofalso

La resolución se aprobó con 169 votos a favor. EE. UU., «Israel» y Argentina votan en contra, mientras Cuba denuncia torturas en Guantánamo. Estados Unidos se opuso el jueves a un proyecto de resolución de Naciones Unidas destinado a prohibir la tortura, dentro del marco del octogésimo periodo de sesiones de la Asamblea General.

etiquetas: trump, milei, netanyahu, israel, argentina, eeuu, tortura, onu

» noticia original (www.resumenlatinoamericano.org)

26 Nov 07:51

Tesla vuelve a ocupar el último lugar en fiabilidad según el informe TÜV 2025

by Grahml

Una vez más, el organismo alemán TÜV ha publicado su esperado informe anual de fiabilidad, y los datos no son nada buenos para Tesla. Los americanos vuelven a aparecer en los últimos puestos de la clasificación, con el Model Y como el coche con mayor tasa de errores en Alemania entre los vehículos de 2 a 3 años de antigüedad. El informe, elaborado tras analizar más de 9,5 millones de inspecciones técnicas periódicas (ITV) realizadas entre julio de 2024 y junio de 2025, deja cifras que deberían hacer reflexionar a más de un fabricante.

etiquetas: tesla, tüv, fiabilidad, alemania

» noticia original (forococheselectricos.com)

26 Nov 07:50

Estos trabajadores saben cómo funciona la IA y piden a sus amigos y familiares que no la usen: "Es un 'no' rotundo"

by oghaio

“Una vez que has visto cómo se arman estos sistemas —los sesgos, los plazos apresurados, los compromisos constantes— dejas de ver la IA como futurista y empiezas a verla como frágil”, dice Adio Dinika, quien estudia el trabajo detrás de la IA en el Distributed AI Research Institute, fundado por la reputada investigadora Timnit Gebru.

etiquetas: trabajadores, ia, no, rotundo, uso

» noticia original (www.eldiario.es)

26 Nov 07:50

Bolsonaro cumplirá su condena a 27 años de cárcel en una sala de doce metros cuadrados

by CalifaRojo

El expresidente brasileño Jair Bolsonaro comenzó a cumplir la condena a 27 años de prisión que le fue impuesta por intento de golpe de Estado en una pequeña sala de doce metros cuadrados de la sede de la Policía Federal en Brasilia.

etiquetas: bolsonaro, condena, 27 años, brasil, brasilia

» noticia original (efe.com)

26 Nov 07:50

La asociación Defiéndete en Derecho pide la dimisión de la Sala de lo Penal del Tribunal Supremo

by Beltenebros

La asociación Defiéndete en Derecho presentó hace meses un escrito ante el Consejo General del Poder Judicial, suscrito por 10.500 personas de todos los sectores de la sociedad civil española, solicitando el no procesamiento del Fiscal General del Estado, sin haber recibido respuesta alguna a dicho escrito...Llamamos a toda la ciudadanía que esté de acuerdo con nuestra proposición para que firme el apoyo público a este escrito, a fin de remitírselo al Defensor del Pueblo y al Consejo del Poder Judicial, por considerar que es presumible la...

etiquetas: fiscal general del estado, tribunal supremo, sala segunda, dimisión

» noticia original (www.defiendetenderecho.org)

26 Nov 07:50

Aprobada la PNL que reclama el fin de la alimentación forzada para producir foie gras

by SVSRTZ

La Comisión de Agricultura del Congreso de los Diputados ha dado un paso firme en favor de los animales aprobando la Proposición no de Ley, con una enmienda del PSOE y Sumar, que reconoce la necesidad urgente de revisar el sistema de producción de foie gras mediante alimentación forzada. Han votado a favor el PSOE, ERC, Junts per Catalunya, Bildu, GM Podemos e Izquierda Unida dentro del Grupo Sumar, promotora de la PNL, y el PNV se ha abstenido. El Partido Popular y Vox han votado en contra.

etiquetas: pnl. maltrato animal, foie gras, alimentacion forzada

» noticia original (igualdadanimal.org)

26 Nov 07:49

Los técnicos de Hacienda van a la huelga y alertan de la falta de medios contra el fraude: "Con un 40% más de plantilla se ingresarían 5.000 millones más al año"

by Lon
Gestha, el sindicato mayoritario entre este colectivo profesional, convoca el primer paro en 17 años para pedir no solo más recursos contra el fraude, sino mejores condiciones laborales....
26 Nov 07:49

Las cinco edades del cerebro humano: los años que reconfiguran quiénes somos

by Lon
El cerebro humano atraviesa cinco edades clave marcadas por cambios silenciosos que determinan cómo pensamos, sentimos y envejecemos.
25 Nov 22:29

La administración Trump sigue cancelando informes económicos clave y todo el mundo empieza a sospechar [EN]

by Dragstat

El informe del PIB se suma a una lista de informes económicos que no se han publicado, incluidos los informes de empleo y el de inflación de octubre. A pesar de la insistencia continua del presidente en lo contrario, los bolsillos de la gente están sintiendo los efectos de la mala situación, y muchos han especulado con que las cancelaciones de datos son un intento de esconder información sobre el verdadero estado de la economía: “probablemente los cancelaron porque son muy buenos”. "¿Tan mal está la economía para tener que ocultar datos?".

etiquetas: ee.uu., económia, informes económicos, cancelación, sospechas

» noticia original (www.indy100.com)

25 Nov 22:28

Desvelan la contraseña de la DGT en Informativos Telecinco y es tan fácil que cualquiera podría adivinarla

by Meinhard

Durante el telediario, varios usuarios han podido capturar el dominio privado de la DGT, junto a las credenciales de inicio de sesión, con una de las contraseñas más fáciles.Concretamente, en una toma del vídeo reportaje en las dependencias de la DGT, se puede observar claramente al parar el frame que aparece una pegatina en la parte inferior del monitor con el nombre de usuario y contraseña.

etiquetas: dgt, contraseña, telecinco

» noticia original (computerhoy.20minutos.es)

25 Nov 22:28

Protección de Datos impone una multa récord de 10M a Aena por sus sistemas de reconocimiento facial

by Lon
La Agencia Española de Protección de Datos iguala su sanción más elevada con el operador español por desplegar sistemas de reconocimiento facial sin contar con una evaluación de impacto que cumpliera las exigencias legales
25 Nov 21:03

Se va a haber una erupción volcánica para la cual el mundo no está ni mijita preparado [ITA]

by Leclercia_adecarboxylata

En 1815, el volcán indonesio Tambora produjo la erupción más potente jamás registrada en la historia, esparciendo una enorme columna de diminutas partículas en la atmósfera y enfriando el planeta. Lo que siguió fue llamado “el año sin verano”. La pregunta no es si esto va a volver a ocurrir sino cuándo. El problema de estas megaerupciones no es la erupción en sí sino el polvo y las partículas que emitirá a la atmósfera. Y no hay por el momento manera precisa de saber cuándo ocurrirá.

etiquetas: erupción, volcán

» noticia original (www.passioneastronomia.it)

25 Nov 21:03

Una congresista republicana reconoce que Trump quiere Venezuela por el petróleo y que están a punto de entrar

by bonobo

Sin cortapisas ni argumentarios, la congresista de origen hispano María Elvira Salazar explicaba a Fox Business que el principal interés de la administración norteamericana en al ofensiva contra Venezuela es conseguir la explotación de petróleo y gas natural porque Venezuela será "un festín para las petroleras estadounidenses". Sin pestañear añade: "Hay una enorme oportunidad de negocio para las energéticas norteamericanas. Hablamos de más de un billón de dólares de potencial económico

etiquetas: maría elvira salazar, venezuela, petróleo

» noticia original (cadenaser.com)

25 Nov 21:03

Brutal caso de bullying en Portugal: compañeros amputan dedos a niño de 9 años

by Dragstat

Según la madre, su hijo era víctima constante de bullying por su origen brasileño, color de piel, sobrepeso y por ser nuevo en el colegio. Asegura que ya había sido golpeado, estrangulado, tironeado y humillado en otras ocasiones. Pese a las denuncias previas, la escuela nunca tomó medidas, del mismo modo, minimizó la gravedad, calificándolo como una travesura. Una docente llamo a la madre para informarle que el menor “estaba jugando” y se había lastimado con una puerta, restando importancia al hecho: “le podría haber pasado a cualquier niño”.

etiquetas: portugal, bullying, colegio, niño, dedos, amputación

» noticia original (www.elpais.hn)

25 Nov 21:03

Tres jueces del Supremo que condenaron al fiscal general impartieron tras el juicio un curso pagado por una acusación

by Lon
Los magistrados Andrés Martínez Arrieta, Juan Ramón Berdugo y Antonio del Moral protagonizaron la semana pasada varias ponencias en una formación organizada por el Colegio de Abogados de Madrid, que reclamó cuatro años de cárcel para García Ortiz
25 Nov 20:57

The Government Is Hiding Something Much Worse Than Epstein — Former CIA Spy Explains

by Tom Bilyeu

True Classic: Upgrade your wardrobe at https://trueclassic.com/impact
Shopify: Sign up for your one-dollar-per-month trial period at https://shopify.com/impact
CashApp: Download Cash App Today: https://capl.onelink.me/vFut/v6nymgjl #CashAppPod

On today’s episode of Impact Theory, Tom Bilyeu sits down with former CIA operative Andrew Bustamante for a deep and eye-opening conversation that’s going to challenge how you see government transparency, conspiracy theories, and global power plays. Together, they dig into the silence and confusion surrounding high-profile cases like the assassination attempt on Trump, Charlie Kirk’s killing, and the ever-shadowy Epstein files—exploring why the FBI keeps the public in the dark and whether it’s just incompetence or calculated strategy.

Andrew Bustamante brings his unique insider’s perspective, breaking down how America’s branches of government operate, what really happens when the public gets answers (and when they don’t), and why conspiracies spread so fast in the age of social media. The episode doesn’t stop there: Tom and Andrew debate popular narratives, including Candace Owens’ claims about coordinated killings, and examine how to separate fact from fiction in the current torrent of information. Plus, the two tackle bigger issues like America’s distrust for its institutions, China’s global rise and potential conflict over Taiwan, and the uncomfortable realities behind economic meltdowns and national security.

If you’re interested in seeing past the headlines and understanding the mechanics—both visible and hidden—of government, power, and misinformation, this is an episode you won’t want to miss. Let’s jump in!

00:00 What Is Going On With The FBI?
11:45 How To Properly Debunk Conspiracy Theories
19:39 Global Influence: Every Country Shapes Reality
25:42 The Cause For The Rise Of Political Violence
30:42 History Behind Israel & Mossad's Military Strategy
38:50 History Of Jewish Community Advantages
44:26 How Fear Drives Society's Negative Energy
56:32 Explaining "Government Transparency"
01:00:20 Delegating Accountability Amid Political Redactions
01:07:03 The Truth Behind Our Assault On Venezuela
01:19:11 China's Technological Rise vs. U.S.
01:25:23 Taiwan, China, and India's Role
01:35:51 US Economic Downturn
01:37:50 Invest to Combat Inflation


Want to learn more from Andrew?
Find your Spy Superpower: https://yt.everydayspy.com/3WMHWwf
Read Andrew’s CIA book ‘Shadow Cell’: https://geni.us/ShadowCellBook
Follow Andy on YouTube: https://youtube.com/@Andrew-Bustamante
Explore Spy School: https://everydayspy.com/
Support Andy's sponsor Axolt Brain: https://axoltbrain.com/andy
Listen to the podcast: https://youtube.com/@EverydaySpyPodcast



Cash App is a financial services platform, not a bank. Banking services provided by Cash App’s bank partner(s). Prepaid debit cards issued by Sutton Bank, Member FDIC. See terms and conditions at cash.app/legal/us/en-us/card-agreement. Promotions provided by Cash App, a Block, Inc. brand. Visit cash.app/legal/podcast for full disclosures.
25 Nov 20:52

Así se domina el mundo

by El Canal del Coronel

Desvelando las claves del poder mundial
25 Nov 20:50

Vagrant Box Catalog And Vagrant Box Repository Tutorial

by Marco Antonio Carcano

As we saw in the Vagrant - installing and operating post, Vagrant provides a convenient way for automating the setup, configuration and management of virtual machines, enabling reproducible and consistent development environments.

In that post, we also had an overview of how to create a Vagrantbox from scratch for the Parallels provider. We then digged further the process of creating Vagrant boxes from scratch in the Create Oracle Linux 10 aarch64 Vagrantbox for UTM post, where we generated a full featured Vagrant box for ARM64 using the UTM provider.

The missing part to complete your Vagrant skill sets is the creation of Vagrant Boxes Repositories, grouping them into a Vagratn Box Catalog and publish them on an HTTP server, so to make them available to other users.

Vagrant Box Catalog And Vagrant Box Repository Tutorial explains how to pack mutliple Vagrant boxes into a box repositotory and publish it on an HTTP server.

As explained in the Create Oracle Linux 10 aarch64 Vagrantbox for UTM post, a Vagrant Box is just a bzipped2 tarball archive used to ship a single VM with a certain operating system which

  • has a specific major version
  • runs on a particular hardware architecture
  • supports a certain Vagrant provider

This means that not only to run the same operating system of the same major version with a different hardware it is necessary to create another Vagrant box, but also that is necessary to create additional Vagrant boxes whenever you need to support different Vagrant providers.

In addition to that, multiple version of the same Vagrant box may be produced, shipping  different patchlevels of the same contents.

As you can infer, this leads to the spreading of the number of boxes after some time.

The solution to this problem is storing the boxes in repositories, which can be easily located and accessed by the user when performing vagrant box install and vagrant box update operations.

A Vagrant box repository provides the entry point to locate every version of the same Vagrant box.

In other words, a Vagrant box repository contains a set of logically related Vagrant boxes, through which:

  • provides all the available version of a specific operating system major version
  • for every supported hardware architecture
  • for all the available Vagrant providers

If you need to provide Vagrant boxes for different operating systems, including different major versions, you must create a new Vagrant box repository specifically for it.

A Box Repository is nothing but a directory tree containing its own metadata.json file describing each single box in the repository.

More specifically, for for each single box, it contains:

  • the Vagrant box version
  • information about the location from where to retrieve the Vagrant box file,
  • the supported hardware architecture
  • the Vagrant provider supported
  • the Vagrant box's SHA256 checksum

Vagrant Boxes Catalog

The best practice is to group Vagrant Box Repositories into a Vagrant Box Catalog: this provides a convenient entry point to locate every Vagrant box repository, which can even be easily shared for example publishing it using an HTTP server.

For this purpose, let's create the catalog directory tree where to store the Vagrant Box repositories alltogether:

mkdir -m 755 ~/vagrant-catalog ~/vagrant-catalog/catalog
cd ~/vagrant-catalog/catalog

Vagrant Box Repository

To enable different packagers to provide Vagrant box repositories avoiding naming collisions, the best practice is to use the packager/boxrepository structure.

In our scenario, we use:

  • grimoire as the packager
  • ol10 as the box repositoy, which provides only Oracle Linux 10 boxes

So, let's create the grimoire directory tree as follows:

mkdir -m 755 grimoire

Then, beneath it, let's create the ol10 box repository directory:

mkdir -m 755 grimoire/ol10

we can now copy the Vagrant box we created in the Create Oracle Linux 10 aarch64 Vagrantbox for UTM post to grimoire/ol10 box repository:

cp ~/ol10-1.0.0-arm64-utm.box grimoire/ol10

Since the Vagrant box files are often quite heavy, and since the Vagrant Box Catalog containing the Vagrant Box Repository is typically HTTP published, to improve reliability, each single Vagrant Box entry in the metadata.json must also provide the SHA-256 checksum.

We can calculate it by running:

shasum -a 256 grimoire/ol10/ol10-1.0.0-arm64-utm.box

in my case, the output is:

fed838374269630ce9cca199b4ab8daac22df59f8263d167fbca41eaee746db7  grimoire/ol10/ol10-1.0.0-arm64-utm.box
If shasum is not available on your system, you can generate the sha256 sum by running openssl sha256 grimoire/ol10/ol10-1.0.0-arm64-utm.box.

We have now all the necessary information to create the initial repository box's metadata file - Just create the grimoire/ol10/metadata.json file with the following contents:

{
  "name": "grimoire/ol10",
  "description": "This box contains Oracle Linux 10.",
  "versions": [
    {
      "version": "1.0.0",
      "providers": [
        {
          "name": "utm",
          "url": "grimoire/ol10/ol10-1.0.0-arm64-utm.box",
          "checksum": "fed838374269630ce9cca199b4ab8daac22df59f8263d167fbca41eaee746db7",
          "checksum_type": "sha256",
          "architecture": "arm64",
          "default_architecture": false
        }
      ]
    }
  ]
}
In this example, since the url field does not specify any protocol, Vagrant retrieves the file from the local filesystem, using the Vagrant Box Repository path as the base path.

If you already installed this box while running the examples in the Create Oracle Linux 10 aarch64 Vagrantbox for UTM post, remove it by running:

vagrant box remove --provider utm grimoire/ol10

We can now install the box by running:

vagrant box add --provider utm grimoire/ol10/metadata.json

the output should look like as follows:

==> box: Loading metadata for box 'grimoire/ol10/metadata.json'
    box: URL: file:///Users/mcarcano/boxes/grimoire/ol10/metadata.json
==> box: Adding box 'grimoire/ol10' (v1.0.0) for provider: utm (arm64)
    box: Downloading: grimoire/ol10/ol10-1.0.0-arm64-utm.box
    box: Calculating and comparing box checksum...
==> box: Successfully added box 'grimoire/ol10' (v1.0.0) for 'utm (arm64)'!

While creatingVagrant boxes and publishing them in aVagrant box repository is an excellent lab exercise, enterprise environments require secure, automated artifact management. If you want to systematically fill your DevOps and DevSecOps knowledge gaps by reading a crash-course like book full of hands-on enterprise exercises, jump directly to the Apress Blueprint Box below to discover how to boost and evolve your career using a self-paced learning path.

HTTP Publishing The Vagrant Box Catalog

The straightforward limitation of implementing Vagrant Box repositories and a Vagrant Box Catalog on your local filesystem is that they remain accessible only to you. It's far more effective to publish them over HTTP, allowing other users to benefit from them. This approach promotes corporate-wide standard images, prevents teams from reinventing the wheel multiple times, and fosters collaboration and efficiency across your organization.

There are several options for achieving this, ranging from simple setups to more advanced tools:

  • Simple publishing: Host the Vagrant Box Catalog directory tree using a standard web server, such as Apache HTTPd. This is a straightforward way to make your boxes available via HTTP without much overhead.
  • Application-specific repository managers: Leverage tools like Pulp3 (with the pulp-vagrant plugin) for robust artifact management, or source code management platforms like Gitea, which natively support publishing Vagrant Box artifacts.
  • Official or cloud-based solutions: For a more polished experience, consider Atlas (now integrated into HCP Packer) or, if you prefer a cloud-hosted option, Vagrant Cloud. These provide built-in features for versioning, sharing, and discovery, making them ideal for larger or distributed teams.
Here we implement a solutions which is just a lab to learn the mechanisms used under the hood by a Vagrant Box Catalog: for production use, consider one of the aforementioned solutions.

To see how a Vagrant Box Catalog in action, we can spin up a disposable Apache HTTPd container - using a container allows us to experiment and make sense of the process, thus avoiding to mess up our system with an unnecessary Apache HTTPd instance.

To operate more comfortably, let's change to our users' home directory:

cd ~

Let's start from creating the ~/vagrant-catalog/conf directory where to store the Apache HTTPd's configuration file:

mkdir -m 755 ~/vagrant-catalog/conf

Then, we must create a minimalist Apache httpd.conf file - we must include only the very minimum features to support our use case.

Create the ~/vagrant-catalog/conf/httpd.conf with the following contents:

ServerRoot "/usr/local/apache2"
Listen 80

# Minimal modules for static content and .htaccess support
LoadModule mpm_event_module modules/mod_mpm_event.so
LoadModule authz_core_module modules/mod_authz_core.so
LoadModule access_compat_module modules/mod_access_compat.so
LoadModule mime_module modules/mod_mime.so
LoadModule log_config_module modules/mod_log_config.so
LoadModule env_module modules/mod_env.so
LoadModule headers_module modules/mod_headers.so
LoadModule setenvif_module modules/mod_setenvif.so
LoadModule unixd_module modules/mod_unixd.so
LoadModule dir_module modules/mod_dir.so
LoadModule autoindex_module modules/mod_autoindex.so

# User/Group for Alpine
<IfModule unixd_module>
    User www-data
    Group www-data
</IfModule>

ServerAdmin www-admins@carcano.corp

# Deny access to root
<Directory />
    AllowOverride none
    Require all denied
</Directory>

DocumentRoot "/usr/local/apache2/htdocs"

# Enable .htaccess and disable auto-indexing for static content
<Directory "/usr/local/apache2/htdocs">
    Options -Indexes
    AllowOverride All
    Require all granted
</Directory>

# Basic logging (to stdout/stderr for Docker)
ErrorLog /proc/self/fd/2
LogLevel warn
<IfModule log_config_module>
    LogFormat "%h %l %u %t \"%r\" %>s %b \"%{Referer}i\" \"%{User-Agent}i\"" combined
    CustomLog /proc/self/fd/1 common
</IfModule>

# Basic MIME types
<IfModule mime_module>
    TypesConfig conf/mime.types
</IfModule>

If you are already used to work with Apache HTTPd, you can blame this is not the real bare minimal configuration for running Apache HTTPd: we indeed need to enable a few additional modules to support a few options we are about to configure using an .htaccess file.

We can then spin up the Apache HTTPd container by running:

docker run -d --rm --name vagrant-catalog -p 8080:80 \
-v ~/vagrant-catalog/conf/httpd.conf:/usr/local/apache2/conf/httpd.conf \
-v ~/vagrant-catalog/catalog:/usr/local/apache2/htdocs httpd:alpine

The above statement spins-up an Apache HTTPd instance, mapping the ~/vagrant-catalog/catalog directory to the httpd root directory and mounting the ~/vagrant-catalog/conf/httpd.conf file we just created to the path where the Apache HTTPd in the container looks for its configuration. The Apache instance endpoint is also bound to the 8080 port on localhost.

Lastly, it is necessary to add the .htaccess file to the ~/vagrant-catalog/catalog directory - just create the ~/vagrant-catalog/catalog/.htaccess file  with the following contents:

Header unset Pragma
FileETag None
Header unset ETag
DirectoryIndex metadata.json
IndexIgnore *
Header set Cache-Control "max-age=0, no-cache, no-store, must-revalidate, private"
Header set Pragma "no-cache"
Header set Expires "Wed, 14 Jun 1978 10:00:00 GMT"

The most important among the above settings is configuring the metadata.json file as Directory index: the rest, which is optional, is mostly related to handling negative cache and hiding the actual contents.

You can of course add any other option as needed, such as authorization directives - just remember to add the necessary modules to the ~/vagrant-catalog/conf/httpd.conf file and recreate the container.

We can check the outcome of this setup by running:

curl http://localhost:8080/grimoire/ol10/

the output must look like as follows:

{
  "name": "grimoire/ol10",
  "description": "This box contains Oracle Linux 10.",
  "versions": [
    {
      "version": "1.0.0",
      "providers": [
        {
          "name": "utm",
          "url": "grimoire/ol10/ol10-1.0.0-arm64-utm.box",
          "checksum": "fed838374269630ce9cca199b4ab8daac22df59f8263d167fbca41eaee746db7",
          "checksum_type": "sha256",
          "architecture": "arm64",
          "default_architecture": false
        }
      ]
    }
  ]
}

As expected, even if we didn't specify it in the URL, we got the contents of the metadata.json file.

Now, consider the above output by a remote client perspective: it is clear this setup still cannot still work - the url field still provided the file system related path to the Vagrant box file

To make it work while HTTP published, we must change it to the HTTP url pointing to it.

So, in our scenario, the ~/vagrant-catalog/catalog/grimoire/ol10/metadata.json file must be changed to look like as follows:

{
  "name": "grimoire/ol10",
  "description": "This box contains Oracle Linux 10.",
  "versions": [
    {
      "version": "1.0.0",
      "providers": [
        {
          "name": "utm",
          "url": "http://localhost:8080/grimoire/ol10/ol10-1.0.0-arm64-utm.box",
          "checksum": "fed838374269630ce9cca199b4ab8daac22df59f8263d167fbca41eaee746db7",
          "checksum_type": "sha256",
          "architecture": "arm64",
          "default_architecture": false
        }
      ]
    }
  ]
}

Be wary that, since the metadata file is fetched by Vagrant while running vagrant box statement, the hostname's part of the URL must be reachable by the client, or it will not be able to download it.

This means that, if the HTTPd server with the Vagrant Box Catalog is behind a reverse proxy, you must set as the host part of the url parameter the hostname set on the reverse proxy for the virtual host used to publish the Vagrant Box Catalog.

Let's go on with the HTTP published Vagrant Box Catalog, having a go with it.

First, let's remove the Vagrant Box we previously installed:

vagrant box remove --provider utm grimoire/ol10

We can now install the box using our brand new HTTP published Vagrant Box Catalog, ... just run:

vagrant box add --provider utm http://localhost:8080/grimoire/ol10

the output must look like as follows:

==> box: Loading metadata for box 'http://localhost:8080/grimoire/ol10'
==> box: Adding box 'grimoire/ol10' (v1.0.0) for provider: utm (arm64)
    box: Downloading: http://localhost:8080/grimoire/ol10/ol10-1.0.0-arm64-utm.box
    box: Calculating and comparing box checksum...
==> box: Successfully added box 'grimoire/ol10' (v1.0.0) for 'utm (arm64)'!

If you fancy, you can avoid specifying the Vagrant Box Catalog's host each time you run vagrant box command by exporting it in the VAGRANT_SERVER_URL environment variable. For example:

export VAGRANT_SERVER_URL="http://localhost:8080"

you should be now able to run the vagrant box add statement without explicitly specifying the host part.

For example (remember to remove the box we already installed first): 

vagrant box add --provider utm grimoire/ol10

the output is:

==> box: Loading metadata for box 'grimoire/ol10'
    box: URL: http://localhost:8080/grimoire/ol10
==> box: Adding box 'grimoire/ol10' (v1.0.0) for provider: utm (arm64)
    box: Downloading: http://localhost:8080/grimoire/ol10/ol10-1.0.0-arm64-utm.box
    box: Calculating and comparing box checksum...
==> box: Successfully added box 'grimoire/ol10' (v1.0.0) for 'utm (arm64)'!

Building Vagrant Catalogs is Just One Brick in the DevSecOps Wall

Mastered Vagrant boxescreation, structuring them into a Vagrant box repository and HTTP publishing them using an Apache HTTPd serve?

Excellent. Now, it's time to scale your skillset.

True DevOps proficiency requires a cohesive understanding of the entire Linux ecosystem.

To help you systematically bridge the gap between simple automation and advanced security infrastructure, I wrote "DevSecOps and DevOps for Linux: The Foundations", published by Apress.

The book is specifically designed to provide a comprehensive, lab-driven blueprint tailored for both students and professionals to systematically fill their knowledge gaps through intensive, hands-on enterprise exercises — built entirely on open-source, cloud-agnostic architectures to ensure zero vendor lock-in.

Key insights covered in this volume:

  • The Holistic Skills Set Brick: Bridge technical engineering with team management frameworks. Master Scrum, Kanban, and Lean methodologies to design system architectures aligned with real corporate workflows.
  • The Shell Scripting & Unix Tools Brick: Build rigorous operational foundations. Master advanced Bash shell scripting architecture while learning how to combine core Unix tools into robust, repeatable, and enterprise-ready host automations.
  • The Version Control Engineering Brick: Move past basic commits. Dive deep into Git version control, mastering feature-branch workflows, repository lifecycle management, and complex conflict resolution.
  • The Data & Core Automation Brick: Build bulletproof data processing setups. Learn advanced RegEx, how to operate using evergreen tools such as Grep, Sed, and AWK, and how to master structured data parsing (XML, JSON, YAML) using Python and tools like xmlstarlet, jq, and yq.
  • The Modern Python & Automation Brick: Develop a modern Python project using pyproject.toml with pytest-based unit tests, governing the project with GNU Make for testing, building, and digitally signing RPM packages. The project is presented in an evolving fashion, showing how features are added step by step, highlighting how a properly structured Python project can be improved and evolved with minimal or no rework at all.
  • The Linux OS Hardening & PKI Brick: Learn the real mechanics of security. Implement X.509/PKI architectures, TLS configurations, and GPG encryption and signing, while mastering low-level kernel defenses like SELinux and Linux Capabilities.
  • The Compliance Check and Shift-Left Security Brick: Learn how to leverage the pre-commit framework to automate compliance checks with Pylint and Flake8, and perform security scans with Bandit and Safety, extending the security audit to the full software supply chain.
  • The Application Integration Brick: Master the foundational protocols used to securely interconnect enterprise microservices, including HTTP, REST, OpenAPI, SOAP, and LDAP/LDAPS.
  • The Infrastructure Delivery Brick: Put theory into practice with vertical, real-world labs. Move from basic scripts to engineering Ansible architectures, rootless Podman setups, image creation via Buildah, and complete Pulp3 deployments using Docker Compose.
  • The Enterprise GitOps Pipeline Brick: Tie everything together by automating your software supply chain. Build complete continuous deployment workflows using Gitea CI pipelines hosted natively on Kubernetes (RKE2).

Footnotes

Here it ends this post on how to create Vagrant Box repositories and a Vagrant Box Catalog. As you see, it is not as hard: it's al about using standard tool you are probably already working with in your daily work.

Being able to create Vagrant Box Repositories and Vagrant Box Catalogs is a very important skill for DevSecOps professionals, as it enables setting up and maintaining a shared point for distributing Vagrant Boxes within your environment. In a DevSecOps workflow, where speed, security, and collaboration are key, these tools help ensure consistency across teams by providing a centralized, version-controlled hub for pre-configured virtual environments. This reduces setup time, minimizes configuration drift, and enhances security by allowing you to vet and distribute boxes that meet your organization's standards—preventing vulnerabilities from creeping into development or testing pipelines. Mastering this not only streamlines infrastructure provisioning but also empowers you to scale environments efficiently, integrate with CI/CD pipelines, and foster better collaboration in distributed teams.

I hope this post sparked some inspiration and equipped you with practical skills for your DevSecOps toolkit. If it did, why not fuel the fire? Drop a tip in the small cup below - blogs like this thrive on community support, and every contribution keeps the knowledge flowing!

I hate blogs with pop-ups, ads and all the (even worse) other stuff that distracts from the topics you're reading and violates your privacy. I want to offer my readers the best experience possible for free, ... but please be wary that for me it's not really free: on top of the raw costs of running the blog, I usually spend on average 50-60 hours writing each post. I offer all this for free because I think it's nice to help people, but if you think something in this blog has helped you professionally and you want to give concrete support, your contribution is very much appreciated: you can just use the above button.
25 Nov 20:48

Cómo calmarte sin desconectarte de lo que sientes

by Beatriz García Ricondo
¿Te pasa que una frase, un gesto, un mail o un WhatsApp te encienden por dentro y, cuando te das cuenta, ya has contestado en caliente? ¿Luego llegan las disculpas, la culpa o el “¿por qué reaccioné así?” … y notas que te alejaste de tu centro? ¿O te quedas rumiando por dentro, con el malestar de lo que querías decir y no te diste permiso —por evitar un problema o por no saber cómo hacerlo—? A todos nos ocurre. La buena noticia es que puedes aprender a calmarte sin desconectarte de lo que sientes. No se trata de apagar la emoción, sino de regularla para responder alineada contigo. ## Un día cualquiera **Por la mañana**. Me despierto con una punzada en el pecho: “Se me olvidó enviar la propuesta revisada al cliente.” Abro el correo con prisa, ya con el latido acelerado. La mente empieza a correr por delante de la realidad: “Pensarán que no soy profesional.” Antes de escribir, dejo el móvil en la mesa. Tres respiraciones largas. Siento los pies. Nombrar lo que aparece: “Esto es ansiedad en la boca del estómago.” Con ese mínimo espacio, en vez de mandar un mensaje atropellado, envío uno claro: “Buenos días. Acabo de revisar la propuesta; te lo envío a las 10:30 con los ajustes acordados.” Y, entonces sí, cumplo. **A mediodía**. Reunión. Un colaborador levanta una ceja ante lo que propongo. Mi cuerpo lo registra como una bofetada sorda. La vieja historia se activa: “Me están cuestionando.” En vez de soltar una defensa automática, apoyo las manos en la mesa y vuelvo a la respiración. “Esto es enfado; lo noto caliente en el pecho.” Cuando baja medio grado, pregunto: “¿Qué parte te genera duda? Así afinamos.” El gesto se deshace: no era ataque, era confusión. Ganamos todos. **Por la noche**. Llego a casa agotada. Una pregunta inocente —“¿Has comprado pan?”— me enciende la mecha. Respondo en seco. Silencio. Esa escena que conozco: la culpa llamando a la puerta. Respiro en la cocina, con la espalda contra la pared. “Esto es agotamiento; necesito cuidado.” Vuelvo y digo: “Perdona, he contestado mal. Estoy muy cansada. ¿Te parece que cenemos algo?” No siempre me sale así. Pero cuando me sale, me siento en casa por dentro. ## Claves para calmarte y responder sin negar lo que sientes No es magia; es pausa. Entre lo que pasa y lo que hago hay unos segundos en los que puedo elegir. En esa rendija habita tu libertad. No para ser perfecta, sino para volver a ti. * **Respira**: La respiración es el timón más sencillo. Inhala en 3, exhala en 6 (seis veces). La exhalación larga baja revoluciones. En ese medio minuto, tu cuerpo deja de empujar y tu mente gana claridad. * **Acoge**: En lugar de pelearte con la emoción, dale un asiento: “Esto es enfado, ansiedad, tristeza y está en…”. Escanea tu cuerpo, dale su lugar, siente su temperatura, tamaño, textura. Nombrar no lo agranda. Al contrario, lo acoge con amabilidad y lo ordena. Te recuerda que tú no eres la emoción. Eres quien la observa. * **Comprende**: Toda emoción trae un mensaje: protegerte, pedir claridad, marcar un límite, sentirte vista. Pregunta: “¿Qué necesitas de mí ahora?” A veces es tiempo; a veces, información; a veces, decir “no”. * **Integra**: Elige un gesto mínimo coherente con lo que has comprendido: formular una pregunta, escribir más tarde, dar un paseo breve, mantener una conversación. La integración convierte lo sentido en acción alineada con tus necesidades. ## Qué empieza a cambiar cuando practicas esto * Pasas de reaccionar a responder: ya no te dejas arrastrar por la ola. Tú decides cómo anclarte para no perder pie. * La culpa se transforma en reparación: reconoces, corriges y sigues adelante con amabilidad, sin machacarte. * Dejas de tragarte lo que te duele: pides claridad sin atacar y marcas límites sin romper el vínculo. * Te sientes en casa por dentro más a menudo. Incluso en días torcidos, vuelves antes a tu centro. ## Cómo llevarlo al día a día (en 2 minutos reales) Cuando notes que la emoción aprieta, no aceleres: * **Exhala más largo que lo que inhalas**. Por ejemplo, inhala en tres y exhala en seis. Hazlo tres veces. Es tu freno suave. * **Nombra lo que hay y dónde lo sientes**. Quizá sea como un nudo en el estómago, calor en el pecho, un peso sobre los hombros. Nombrar ordena. * Pregúntate: **¿Qué necesito ahora mismo?** Claridad, una pausa, apoyo, poner un límite, etc. * Haz un pequeño gesto que sientas coherente con lo que necesitas: una **frase-puente** que te ayude a sostenerte sin reaccionar como: “Me noto activada, te respondo en un rato”. Una pregunta concreta: “¿Qué parte exactamente quieres que revise?” o un acuerdo de tiempo como, por ejemplo: “Lo veo a las 17:00 y te digo”. Hazlo en micro-momentos: antes de contestar un WhatsApp, al entrar a una reunión, al llegar a casa cansada. Es ahí donde se entrena de verdad. No se trata de dejar de sentir, sino de sentir con conciencia para elegir mejor. No siempre saldrá como deseas. Aun así, cada pausa, cada emoción nombrada y cada gesto van cultivando dentro de ti un lugar más amable en el que sostenerte sin reaccionar. Si te resuena y quieres profundizar con práctica guiada (cuerpo, emoción, pensamiento y acción), lo trabajamos en mi **Especialización en Inteligencia Emocional y Atención Plena “El Despertar de la Consciencia”**. Tienes edición presencial en Madrid y también online en tiempo real. Aquí puedes ver fechas y contenidos: Inteligencia Emocional y Atención Plena @professional(2082817) ## ¿Qué micro-momento de hoy vas a transformar con esta secuencia? Escríbelo, aplícalo y observa qué cambia en tu cuerpo, en tu gesto y en tu manera de estar contigo.
25 Nov 19:52

John Mearsheimer: Bleak Future of Europe - Defeated & Broken

by Glenn Diesen

John J. Mearsheimer is the R. Wendell Harrison Distinguished Service Professor of Political Science at the University of Chicago, where he has taught since 1982. Prof. Mearsheimer discusses why Europe will face a bleak future.

Follow Prof. Glenn Diesen:
Substack: https://glenndiesen.substack.com/
X/Twitter: https://x.com/Glenn_Diesen
Patreon: https://www.patreon.com/glenndiesen

Support the research by Prof. Glenn Diesen:
PayPal: https://www.paypal.com/paypalme/glenndiesen
Buy me a Coffee: buymeacoffee.com/gdieseng
Go Fund Me: https://gofund.me/09ea012f

Books by Prof. Glenn Diesen:
https://www.amazon.com/stores/author/B09FPQ4MDL
25 Nov 19:52

¿Estamos ya en la mіerda absoluta?

by Fino

Oye Fino, No da la sensación que el país está ya en la mierda hasta el punto de no retorno? Todos los días alguna noticia sobre algo que me hace ponerme de mala ostia. Estamos ante una olla express apunto de estallar? Por cierto, faltan 6 años para que descongelen a Jhon Sparta. La sociedad de Demolition Man cada día más cerca. Un saludo. @F

A la primera pregunta: no, aún queda margen para empeorar muuuuuuuucho más, toma asiento.

En cuanto a John Spartan: justo la tengo preparada para ver esta semana, ya toca volverla a ver.

Ver post completo: ¿Estamos ya en la mіerda absoluta?

25 Nov 19:51

Performance en el Congreso de España por los 50 años del fallecimiento de Franco.

by Fino
25 Nov 19:51

¿Cómo daría esta noticia EFE si el tal Martiño fuera ex-líder de VOX?

by Fino

¿Cómo daría esta noticia EFE si el tal Martiño fuera ex-líder de VOX?

La Habana (EFE).- Las autoridades cubanas han detenido en La Habana al ciudadano español Martiño Ramos Soto, condenado a 13 años y medio de cárcel en su país por vioIar a una menor de edad, según ha podido confirmar este lunes EFE. @efe

¿Cómo daría esta noticia EFE si el tal Martiño fuera ex-líder de VOX?

¿Cómo daría esta noticia EFE si el tal Martiño fuera ex-líder de VOX?

¿Cómo daría esta noticia EFE si el tal Martiño fuera ex-líder de VOX?

¿Cómo daría esta noticia EFE si el tal Martiño fuera ex-líder de VOX?

Ver post completo: ¿Cómo daría esta noticia EFE si el tal Martiño fuera ex-líder de VOX?

25 Nov 18:42

Ucrania habría aceptado el plan de paz de EE.UU. para poner fin a la guerra con Rusia

by Lord_Cromwell

Según reveló ABC News, Ucrania habría dado su visto bueno a los términos de un plan de paz impulsado por Estados Unidos para intentar poner fin a la guerra con Rusia, aunque se mantiene a la espera de pulir “detalles menores” antes de su presentación formal. Un funcionario estadounidense, citado bajo anonimato, aseguró que “los ucranianos han aceptado el acuerdo de paz” y que solo restan ajustes técnicos.

etiquetas: ucrania, rusia, guerra, eeuu

» noticia original (www.escenariomundial.com)

25 Nov 18:42

Jean Baptiste, el senegalés que pasó de fregar platos a ser dueño de un exitoso restaurante de Granada

by Delay

Un senegalés que llegó a Granada en 2008 y que empezó a trabajar en el restaurante con su antiguo dueño. «Pasé por todos los puestos, desde fregatín a jefe de sala. Y cuando mi jefe se iba a jubilar me propuso que me quedara yo con el restaurante», explica a IDEAL Jean Baptiste, que desde 2020 está al frente del mismo.

etiquetas: senegalés, restaurante, granada, el fargue

» noticia original (www.ideal.es)

25 Nov 17:27

CXMT anuncia su memoria DDR5 y LPDDR5X

by tul

El fabricante de memoria chino ChangXin Memory Technologies (CXMT) anunció sus primeros chips de memoria DDR5 y LPDDR5X de alto rendimiento. Este anuncio llega en un momento clave, que es en medio de una escasez mundial de memoria DRAM. Gracias a los bloqueos y prohibiciones de Estados Unidos, China se vio forzada a construir su propio hardware desde cero. Y quien nos hubiera dicho que gracias a ello podrá campear mejor este temporal que afecta a toda la industria gracias a chips de producción nacional.

etiquetas: ddr5, lpddr5x, cxmt, china, ram, memoria

» noticia original (elchapuzasinformatico.com)

25 Nov 17:27

Crece el pulso entre los aficionados y LaLiga por las cartas intimidatorias: preparación de una denuncia contra Javier Tebas

by nomeves

La escalada de tensión en torno al consumo de fútbol por vías no oficiales en España ha dado un giro más. A los bloqueos de webs y servicios sospechosos de emitir partidos sin licencia se suma ahora un frente jurídico: una denuncia en preparación contra LaLiga y su presidente, Javier Tebas, por el envío de cartas consideradas amenazantes a particulares. Cada vez más usuarios relatan haber recibido en los últimos meses una comunicación en la que se les acusa de haber visto partidos de forma ilícita y se les reclama el pago de 450,16 euros...

etiquetas: denuncia, iptv, cartas intimidatorias, laliga, javier tebas, fútbol

» noticia original (noticias.madrid)

25 Nov 17:27

El estudio que no gusta al Banco de España: no hay déficit de vivienda y construir más podría subir los precios

by YeahYa

La UPC alerta de más de 8 millones de viviendas sobrantes y avisa: el problema no es construir, sino garantizar vivienda asequible y social ...

etiquetas: vivienda, españa, crisis

» noticia original (www.catalunyapress.es)

25 Nov 17:26

La ONU condena la tortura en una votación aplastante, pero Israel se opone a la resolución(Eng)

by Henry

Israel y Estados Unidos han recibido fuertes críticas tras votar en contra de una resolución de las Naciones Unidas que reafirma la prohibición absoluta de la tortura. La votación, celebrada durante el 80.º periodo de sesiones de la Asamblea General la semana pasada, contó con el apoyo de 169 naciones. Solo tres Estados se opusieron: Estados Unidos, Israel y Argentina. La resolución reafirma la prohibición absoluta de la tortura según el derecho internacional y renueva el llamamiento a todos los Estados para que la prevengan, ayuden a las vic..

etiquetas: onu, tortura, israel, derechos humanos

» noticia original (www.middleeastmonitor.com)