Sign in

Jake Howard 🍊

@theorangeone.net
336 followers 248 following 203 posts

Part Developer, Part SysAdmin, Part InfoSec. Avid self-hoster. - All things Systems @torchbox.com. - Core & Security Teams @wagtail.org. - @djangoproject.com Security Team and Foundation Member.

PostsRepliesMedia
Jake Howard 🍊 @theorangeone.net · 28/09/2026
I'd be pretty scared if I were a Rails dev right now. If you are, maybe come give #Django a try - the grass is lovely and green over here. And it's not going anywhere! jardo.dev/what-about-r...
jardo.dev
What About Rails? | Jared Norman
DHH's opening keynote had shockingly little to say about Rails.
000
Jake Howard 🍊 @theorangeone.net · 23/09/2026
It's a good day for me* - it's network upgrade day! 🙌 WiFi 7 and 6GHz, here I come! *By "me", I actually mean the company office I live hours away from and so will rarely experience myself. But hopefully it means fewer stability complaints!
A pile of Unifi networking equipment.
030
Jake Howard 🍊 @theorangeone.net · 22/09/2026
After a near-complete rewrite, I'm releasing django-sri 1.0.0! 🥳 It's almost entirely breaking changes, but nothing too complex. In return, you get a simplified API, cleaner codebase, and some performance improvements await. Give it a go! pypi.org/project/djan...
pypi.org
django-sri
Subresource Integrity for Django
000
Jake Howard 🍊 @theorangeone.net · 21/09/2026
I had an interesting idea, and now it's submitted for @djangocon.eu. 7 weeks before the deadline... This is far too much thinking ahead for my liking!
A screenshot of the proposal system showing a submitted proposal. The name is redacted.
010
Jake Howard 🍊 @theorangeone.net · 18/09/2026
I put a Home Assistant dashboard on my fridge, using an old Windows tablet. theorangeone.net/posts/fridge...
theorangeone.net
Building a Dashboard for my Fridge
Surprisingly, given the kind of person I am, there's very few conventional "smart home" devices in my house. There are temperature sensors in almost every room, and plenty of integrations with Home As...
000
Jake Howard 🍊 @theorangeone.net · 28/08/2026
Almost 6 months since the last release, django-tasks-db 0.13.0 is out! 🥳 10(!) new contributors helped make it happen ❤️ Dropped required django-tasks dependency, Improved support for MySQL and MariaDB, Improved lock handling and much much more! Give it a go! github.com/RealOrangeOn...
github.com
Release 0.13.0 · RealOrangeOne/django-tasks-db
Breaking changes Remove django-tasks dependency by @jrd in #46 Drop support for unsupported versions of Django What's Changed Update package installation instructions by @decadecity in #11 Hide ...
010
Jake Howard 🍊 @theorangeone.net · 25/08/2026
Today, it was not DNS. It was SNI.
100
Jake Howard 🍊 @theorangeone.net · 20/08/2026
The cupboard with my router in finally has power without running an extension lead under the door! All it took was 15 minutes and £1.99! And the really janky wiring left over from the previous owner.
010
Jake Howard 🍊 @theorangeone.net · 08/08/2026
No prizes for guessing when I fixed a race condition which resulted in nginx hammering its error log...
020
Jake Howard 🍊 @theorangeone.net · 07/08/2026
I've had my pebble almost a week and a half. I _guess_ I should charge it...
A screenshot from the pebble battery interface, showing 19% remaining, drained over 9.2 days.
000
Jake Howard 🍊 @theorangeone.net · 31/07/2026
I replaced linkchecker with @adamj.eu's django-crawl on my website. Shaved 2 minutes off my CI time, with a fancy UI, fewer bodges, and a sprinkling of #rust for good measure 🙌 github.com/adamchainz/d...
github.com
GitHub - adamchainz/django-crawl: An in-process site crawler using Django’s test client.
An in-process site crawler using Django’s test client. - adamchainz/django-crawl
011
Jake Howard 🍊 @theorangeone.net · 27/07/2026
My Pebble is finally here 🙌 Unfortunately, it arrived at 10am, so I need to do a whole day's work before I can play with it 🥲 If this is how my Monday starts, then this is going to be a good week! 🥳
A Pebble Time 2 in box
010
Jake Howard 🍊 @theorangeone.net · 24/07/2026
I've been building my latest side-project on Codeberg, but the git operations are distractingly slow - sometimes double that of GitHub. Still beats actually using GitHub! Building on my own Forgejo instance, and pushing to Codeberg when it's ready to publish might be a great DX improvement.
000
Jake Howard 🍊 @theorangeone.net · 19/07/2026
My feed is full of people giving me FOMO at #emfcamp or #europython. Then there's me - today I'm tidying the garage...
010
Jake Howard 🍊 @theorangeone.net · 17/07/2026
Happy Friday to me - my Pebble order is finally ready to ship! 🥳
000
Jake Howard 🍊 @theorangeone.net · 10/07/2026
Cloudflare silently added opt-in support for respecting the Vary header! Welcome to 1997 internet, Cloudflare! developers.cloudflare.com/changelog/po... Hoping this simplifies a lot of caching rules (and some funky worker deployments too)!
developers.cloudflare.com
Cache multiple versions of a URL with Vary
Cache Rules now support the origin Vary response header, so the same URL can hold multiple cached versions selected by the request headers your origin varies on.
011
Jake Howard 🍊 @theorangeone.net · 03/07/2026
I needed a way to see exactly what our web servers were doing, with zero latency. Log ingestion wasn't good enough. And then it hit me: process names! theorangeone.net/posts/proces...
theorangeone.net
Process names: The forgotten Observability channel
When it comes to observability, especially in an incident, more data is usually better. Without data, it's almost impossible to know what's going on. With insufficient data, you only get half the pict...
000
Jake Howard 🍊 @theorangeone.net · 02/07/2026
Modern Standby (s2idle) claims another victim. Bought a Thinkpad E14 G7, but was surprised with the battery life. Turns out it drains around 40% when asleep for 12 hours. Firmware only supports s2idle (no S3), which isn't suitable for me. Refund it is 😔 www.youtube.com/watch?v=OHKK...
youtube.com
Microsoft is Forcing me to Buy MacBooks - Windows Modern Standby
YouTube video by Linus Tech Tips
100
Jake Howard 🍊 @theorangeone.net · 18/06/2026
There is no bigger compliment 🥰
A comment reading "Worked very well. Thank you so much. AI could not fix this."
020
Jake Howard 🍊 @theorangeone.net · 07/06/2026
Finally got around to setting up @techaro.lol Anubis on my Forgejo instance - Hilariously simple! The rate of issued challenges is slightly crazy, but I'm just glad my projects now stay out of the slop factory datasets 🙌 git.theorangeone.net/systems/infr...
git.theorangeone.net
Protect forgejo with anubis · c82140c347
infrastructure - Servers, containers and stuff
020
Jake Howard 🍊 @theorangeone.net · 05/06/2026
I finally figured out how to properly firewall a machine running Docker, to limit exposed ports theorangeone.net/posts/docker...
theorangeone.net
Firewalling Docker with nftables
Docker has a reputation when it comes to firewalling - it's pretty difficult to restrict ports. It's best practice to have a firewall on your servers, to restrict incoming traffic by port or IP addres...
110
Jake Howard 🍊 @theorangeone.net · 20/05/2026
If you make a device where an internal wire is attached solely by its solder joints, you are a bad person and deserve a bad day! 🙈 In related news, I fixed the temperature sensor on my son's baby monitor 🙌
010
Jake Howard 🍊 @theorangeone.net · 18/05/2026
Typo of the day: "bureaucrazy"
010
Jake Howard 🍊 @theorangeone.net · 18/05/2026
In today's instalment of "#django is confusing": transaction.on_commit. Consider this code - when does the on_commit fire (and "on commit" print)? A, B, C?
A code snippet with the following code:

from django.db import transaction
from functools import partial

with transaction.atomic():
    print("before")
    with transaction.atomic():
        print("Before inner")
        transaction.on_commit(partial(print, "on commit"))
        print("After inner")
    # A
    print("after")
    # B
# C
110
Jake Howard 🍊 @theorangeone.net · 11/05/2026
It's midday on a Monday, and I've already triaged 13 #security reports for #django. 10 raised in the space of 20 minutes by a single reporter. Not a single one was legitimate. I don't think this "AI Security" thing is really making life better.
030
Jake Howard 🍊 @theorangeone.net · 11/05/2026
After over a year in the works, I finally deployed my new website last night Same content, new platform. And no more CMS. theorangeone.net/posts/not-so...
theorangeone.net
My not-so-static new static website
It's been 3.5 years since I last did this, so it's clearly about that time - time I rewrote my website. If you're reading this post, it's on a brand new custom built platform to serve my website. Unde...
000
Jake Howard 🍊 @theorangeone.net · 27/04/2026
Earlier today my server ran out of disk space. It's amazing how much fails when there's nowhere to write to - Proxmox won't even let you delete VMs. Turns out I had some hefty ZFS snapshots. A few deletes later, and it was 80GB lighter. Retention tweaked to stop this happening again.
000
Jake Howard 🍊 @theorangeone.net · 25/04/2026
Woke up to a parking ticket after I forgot to pay for parking for one day of a 5-day event. That's what I get for being in a rush. Happy Saturday to me!
000
Jake Howard 🍊 @theorangeone.net · 19/04/2026
Now leaving Athens tired but fulfilled. A great time at @djangocon.eu, catching up with friends old and new, and ticking some sights off the bucket list 🙌 20% of talks mentioned Tasks, which still feels crazy - I can't believe the community response ❤️ Until next time...
030
Jake Howard 🍊 @theorangeone.net · 17/04/2026
The problem with being on the Security team at a conference is you're terrified to check your email in case there are some shoulder surfers around who catch a glimpse of an unreleased vulnerability 🙈 #djangoconeurope
020
Jake Howard 🍊 @theorangeone.net · 15/04/2026
I was on an episode of @djangochat.bsky.social - it was great! 🤩 Security, Tasks, Wagtail and more! theorangeone.net/talks/django... On YouTube, and wherever you get your podcasts.
theorangeone.net
Django Tasks - Django Chat #200
I was invited to an episode of Django Chat, to chat about Django Tasks, the Security Team and much more. <aside> I'm well aware that a podcast isn't really a "talk", but it's appropriate enough. </asi...
030
Jake Howard 🍊 @theorangeone.net · 14/04/2026
Athens here I come 🛫 #djangoconeurope
000
Jake Howard 🍊 @theorangeone.net · 05/04/2026
Cleared out my car today ready for selling. This is what I found: - Multiple wooden sporks - A Lidl receipt from 2022 (just after I bought it) - 2 unopened bags of M4 bolts - A roll of wrapping paper - A roll of dog poo bags - 3 broken coathangers I need to deep clean my car more often... 🙈
000
Jake Howard 🍊 @theorangeone.net · 02/04/2026
First run through of my @djangocon.eu talk is looking pretty good, and hitting the timings almost perfectly. A few tweaks, and it'll be ready - 13 whole days early!
A timer showing 19:33
020
Jake Howard 🍊 @theorangeone.net · 26/03/2026
> If you have not received contact within the next 24 working hours What does that even mean!? 1 working day? ~3 working days? 3 days?
000
Jake Howard 🍊 @theorangeone.net · 25/03/2026
The exact definition of my job is, complicated. In the best possible way. For example, last week I ran A/V for an internal event, streamed live on Zoom. theorangeone.net/posts/tbx-sp...
theorangeone.net
Torchbox Spring Event 2026 A/V
A few times a year, everyone at Torchbox (my employer) gets together in person to hear updates about the company and its strategy from various members of the team (or "co-owners"). Those in the UK are...
000
Jake Howard 🍊 @theorangeone.net · 18/03/2026
The @wagtail.org security team no longer accepts GPG-encrypted reports. GPG adds a lot of burden to manage, and it's just not worth it for us. wagtail.org/blog/wagtail...
wagtail.org
Wagtail Security team no longer accepts GPG-encrypted emails | Wagtail CMS
You can still report Wagtail security issues via email — just not with GPG.
011
Jake Howard 🍊 @theorangeone.net · 17/03/2026
After I saw someone complain they recently fixed their backup prunes, I went to check mine - and they were broken too 🙈 And had been for around a year. A quick fix and some manual prunes later, and my backups are 130GB lighter 🙌
000
Jake Howard 🍊 @theorangeone.net · 16/03/2026
I'm not really a of AI at the best of times, but the recent unnecessarily hostile drama against the author of Booklore honestly makes me kinda embarrassed to call myself a "self-hoster" 🙈 I'll be keeping an eye on the fork and hope it gains some traction. www.reddit.com/r/selfhosted...
reddit.com
From the selfhosted community on Reddit: PSA: Think hard before you deploy BookLore
Explore this post and more from the selfhosted community
101
Jake Howard 🍊 @theorangeone.net · 08/03/2026
I spent half an hour this afternoon wondering why the switch I'd just installed didn't work. Turns out I'd wired it wrong on the first attempt, tripped the RCD, and I hadn't noticed everything downstairs was off when I checked different configurations. That's enough DIY for me for today.
000
Jake Howard 🍊 @theorangeone.net · 07/03/2026
I ditched Gandi domains. More security, more features, and saving nearly £100/yr 🥳 Now powered by Hover and deSEC. theorangeone.net/posts/moving...
theorangeone.net
Moving on from Gandi: Registrar and DNS migration
DNS is the cornerstone of any infrastructure. Us humans are terrible at remembering strings of numbers (162.55.181.67), but we're good at remembering words (theorangeone.net). When people own a domain...
010
Jake Howard 🍊 @theorangeone.net · 06/03/2026
It's been a long time since I've sat down to write, and stay in the flow. 2 hours and over 3000 words later, I feel more accomplished than I have in a while 🥳 It should probably have a review pass though. Coming soon!
3,454 words 20,049 characters 17:24 read
010
Jake Howard 🍊 @theorangeone.net · 03/03/2026
To use Zed you need to be 18+, force a binding arbitration and waive your right to class action lawsuits. That's, a strange move. zed.dev/blog/terms-u...
zed.dev
We Overhauled Our Terms of Service and Privacy Policy - Zed Blog
From the Zed Blog: Effective March 2, 2026, we're updating our Terms of Service, Privacy Policy, and related documentation. Our privacy commitments have not changed.
124
Jake Howard 🍊 @theorangeone.net · 02/03/2026
Finally got around to pre-ordering a #Pebble Time 2. I don't think I've been this excited for a new tech launch in a while! 🥰
130
Jake Howard 🍊 @theorangeone.net · 27/02/2026
Why does every project now need to be "for agents"? Opening a port? Better make it for agents! github.com/vercel-labs/... If your agent can use the tools you already have which are designed for good "human" UX, it's probably not an agent worth using.
github.com
GitHub - vercel-labs/portless: Replace port numbers with stable, named .localhost URLs. For humans and agents.
Replace port numbers with stable, named .localhost URLs. For humans and agents. - vercel-labs/portless
020
Jake Howard 🍊 @theorangeone.net · 26/02/2026
My talk for @djangocon.eu was accepted 🥳 🥰 Time to start writing it...
A screenshot of a conference talk "Scaling the database - using multiple databases with Django", with status "Confirmed".
120
Jake Howard 🍊 @theorangeone.net · 21/02/2026
If you use an LLM to generate your security report, but ignore the part where it says "triage this report according to your security process" and just post it as a public GitHub issue, you deserve bad things!
041
Jake Howard 🍊 @theorangeone.net · 08/02/2026
As part of the recent django-tasks refactor, I had to extract some directories, with history, into their own repositories. The process was quite interesting, and easier than I expected. theorangeone.net/posts/git-di...
theorangeone.net
Extracting directories into their own repositories
Software projects in git repositories (or Version Control Systems - yes there are others) tend to be made up of much more than just 1 file, or even 1 directory. To make functions and functionality eas...
020
Jake Howard 🍊 @theorangeone.net · 06/02/2026
This is getting out of hand, now there are 3 of them! With 0.12.0 of django-tasks, the DB and RQ backends are now in their own packages and repositories - making the separation between the interface and flagship backends clearer. github.com/RealOrangeOn...
github.com
Release 0.12.0 · RealOrangeOne/django-tasks
Breaking changes DB and RQ backends have been extracted into their own packages From this version onwards, django-tasks will aim to mirror the upstream django.tasks package as much as possible. The...
110
Jake Howard 🍊 @theorangeone.net · 06/02/2026
So, Heroku is basically dead now? Again... www.heroku.com/blog/an-upda...
heroku.com
An Update on Heroku
Today, Heroku is transitioning to a sustaining engineering model focused on stability, security, reliability, and support. Heroku remains an actively supported, production-ready platform, with an emph...
010