<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Linux Archives - Triii Technologies LLC</title>
	<atom:link href="https://triii.org/category/linux/feed/" rel="self" type="application/rss+xml" />
	<link>https://triii.org/category/linux/</link>
	<description>Triii Technologies LLC - Technology solutions</description>
	<lastBuildDate>Fri, 18 Sep 2026 06:21:59 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.1.1</generator>

<image>
	<url>https://triii.org/wp-content/uploads/2022/07/cropped-sizedalpha-32x32.png</url>
	<title>Linux Archives - Triii Technologies LLC</title>
	<link>https://triii.org/category/linux/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>XRDP Guide: Part 2 — Enabling System Audio on Ubuntu and Debian</title>
		<link>https://triii.org/xrdp-guide-part-2-enabling-system-audio-on-ubuntu-and-debian/</link>
		
		<dc:creator><![CDATA[triii]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 06:21:57 +0000</pubDate>
				<category><![CDATA[Knowledge Base]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://triii.org/?p=4118</guid>

					<description><![CDATA[<p>By Calabastro In the previous article of this series, we established a remote desktop session [&#8230;]</p>
<p>The post <a href="https://triii.org/xrdp-guide-part-2-enabling-system-audio-on-ubuntu-and-debian/" data-wpel-link="internal">XRDP Guide: Part 2 — Enabling System Audio on Ubuntu and Debian</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>By Calabastro</strong></p>



<p class="wp-block-paragraph">In the previous article of this series, we established a remote desktop session between your Windows workstation and an Ubuntu or Debian Linux server. We successfully routed the display, keyboard, and mouse over RDP.</p>



<p class="wp-block-paragraph">However, upon logging in for the first time, you likely noticed something missing: silence.</p>



<p class="wp-block-paragraph">Unlike a standard desktop installation where audio starts automatically when you log into the graphical interface, a <strong>headless</strong> Linux server does not have a default &#8220;Login Screen&#8221; to trigger sound services. Consequently, even if your server has sound hardware installed (or is an emulated sound card in a VM), XRDP will pass the video stream perfectly while dropping all audio packets because the background service isn&#8217;t running yet.</p>



<p class="wp-block-paragraph">This guide details how to configure <strong>PulseAudio</strong> specifically for headless Linux servers so you can route system sound from your remote session back to your Windows machine.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Prerequisites</h2>



<ol class="wp-block-list">
<li><strong>XRDP Installed:</strong> You should have completed <a href="https://triii.org/bridging-the-gap-managing-linux-servers-with-windows-remote-desktop-via-xrdp/" data-type="post" data-id="4114" data-wpel-link="internal">Part 1 of this guide</a> and be able to remote into the desktop.</li>



<li><strong>Hardware:</strong> Your server must have access to sound hardware. On a dedicated physical machine, this requires a sound card. On a Virtual Machine (VMware/VirtualBox/KVM), you must ensure the virtual machine is configured with an audio controller (usually &#8220;Intel HD Audio&#8221; or &#8220;AC97&#8221;).</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 1: Install PulseAudio and Debug Tools</h2>



<p class="wp-block-paragraph">Ubuntu and Debian use <strong>PulseAudio</strong> as their default sound server. We need to install the daemon itself, along with a utility called <code>pavucontrol</code> (PulseAudio Volume Control). While you won&#8217;t use it every day, it is essential for debugging why audio might be muted or routed incorrectly later.</p>



<pre class="wp-block-code"><code>sudo apt update
sudo apt install pulseaudio pavucontrol libpulse-dev -y</code></pre>



<ul class="wp-block-list">
<li><strong>libpulse-dev</strong>: This package is crucial if your XRDP installation wasn&#8217;t compiled with sound support built-in; it ensures the necessary libraries are present for binding to the audio system.</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 2: Enable Sound in XRDP Configuration</h2>



<p class="wp-block-paragraph">XRDP, by default, may attempt to ignore sound requests to save resources on the server. We need to explicitly tell it to bridge audio to PulseAudio.</p>



<p class="wp-block-paragraph">Open the sesman configuration file: </p>



<ol class="wp-block-list"></ol>



<pre class="wp-block-code"><code><code>sudo nano /etc/xrdp/sesman.ini</code></code></pre>



<p class="wp-block-paragraph">Locate the section labeled <code>[Xorg]</code>. </p>



<p class="wp-block-paragraph">You will see a list of parameters such as <code>param=Xvnc</code> or <code>arg=-config xrdp/xorg.conf</code>.</p>



<p class="wp-block-paragraph">Find the line that looks like this: </p>



<pre class="wp-block-code"><code><code>Sound=none</code></code></pre>



<p class="wp-block-paragraph">Change it to pulse.</p>



<pre class="wp-block-code"><code>Sound=pulse</code></pre>



<p class="wp-block-paragraph">Save and exit the file (<code>Ctrl+O</code>, Enter, <code>Ctrl+X</code>).</p>



<ol class="wp-block-list"></ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 3: Start PulseAudio on Headless Servers (Crucial)</h2>



<p class="wp-block-paragraph">This is the specific step required for <strong>headless</strong> servers. On a PC with a monitor attached, the audio starts when you click &#8220;Login&#8221; at the greeter screen. On a headless server, there is no login screen, so we must create a trigger that starts the PulseAudio daemon automatically as soon as a user connects via XRDP.</p>



<p class="wp-block-paragraph">We will do this by adding a startup script to the profile directory.</p>



<p class="wp-block-paragraph">Create a new file for system-wide profile execution:</p>



<ol class="wp-block-list"></ol>



<pre class="wp-block-code"><code><code>sudo nano /etc/profile.d/start_pulse.sh</code></code></pre>



<p class="wp-block-paragraph">Paste the following content into the file. This script checks if PulseAudio is running; if not, it starts it in system mode to bypass user session permission issues</p>



<ol class="wp-block-list"></ol>



<pre class="wp-block-code"><code>#!/bin/bash
# Check if PulseAudio is already running
if ! ps -A | grep -v grep | grep pulseaudio > /dev/null
then
    echo "Starting PulseAudio for headless XRDP..."
    # Start as a daemon with high priority to prevent audio glitches
    /usr/bin/pulseaudio --system -D --daemonize=true 
fi</code></pre>



<p class="wp-block-paragraph">Make the script executable: </p>



<ol class="wp-block-list"></ol>



<pre class="wp-block-code"><code><code>sudo chmod +x /etc/profile.d/start_pulse.sh</code></code></pre>



<p class="wp-block-paragraph"><strong>Permission Setup:</strong> Because we are running PulseAudio in &#8220;system mode&#8221; (allowing it to talk to hardware directly), we must grant your users permission to control the audio device. Create the system group: </p>



<ol class="wp-block-list"></ol>



<pre class="wp-block-code"><code><code>sudo addgroup --system pulse-access</code></code></pre>



<p class="wp-block-paragraph">Add your primary user (and root, if necessary) to this group: <code># Replace 'username' with your actual login name </code></p>



<ol class="wp-block-list"></ol>



<pre class="wp-block-code"><code><code>sudo usermod -aG pulse-access username</code></code></pre>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 4: Restart XRDP Services</h2>



<p class="wp-block-paragraph">Now that the software is installed and the scripts are in place, restart the XRDP services to apply the configuration changes.</p>



<pre class="wp-block-code"><code>sudo systemctl restart xrdp
sudo systemctl restart xrdp-sesman</code></pre>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 5: Configure Windows Remote Desktop Client</h2>



<p class="wp-block-paragraph">The server-side configuration allows audio to be captured, but your Windows computer needs to know where to send it. You may need to re-connect the session for these changes to take effect fully, or simply log out and log back in on the Linux side.</p>



<ol class="wp-block-list">
<li>Open <strong>Remote Desktop Connection</strong> (<code>mstsc.exe</code>) on your Windows machine.</li>



<li>Click <strong>&#8220;Show Options&#8221;</strong> (or &#8220;Options&#8221; in newer versions).</li>



<li>Navigate to the <strong>Local Resources</strong> tab.</li>



<li>Under the <strong>Remote audio</strong> section, click <strong>&#8220;Settings&#8230;&#8221;</strong>.</li>



<li>Select <strong>&#8220;Play on this computer&#8221;</strong>.</li>



<li>From the dropdown menu, ensure your local speakers or headphones are selected.</li>



<li>Click <strong>OK</strong>, then <strong>Connect</strong>.</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Troubleshooting Audio Issues</h2>



<p class="wp-block-paragraph">If you connect and still hear silence, follow these checks:</p>



<p class="wp-block-paragraph"><strong>1. Check the Virtual Output</strong><br>Once logged into your Linux desktop, open a terminal (Ctrl+Alt+T) and type:</p>



<pre class="wp-block-code"><code>pavucontrol</code></pre>



<ul class="wp-block-list">
<li>Go to the <strong>Output Devices</strong> tab.</li>



<li>If you see a &#8220;Fallback Device&#8221; but all sliders are grayed out or at 0%, right-click and enable it.</li>



<li>Ensure it hasn&#8217;t been set to &#8220;Dummy Output.&#8221;</li>
</ul>



<p class="wp-block-paragraph"><strong>2. The First Connection Glitch</strong><br>Sometimes, the very first connection after configuring <code>start_pulse.sh</code> may result in static or silence because the PulseAudio daemon takes a few seconds to initialize but XRDP has already grabbed the stream. Log out of the Linux session and log back in; the second attempt usually works perfectly.</p>



<p class="wp-block-paragraph"><strong>3. Microphone Input (Optional)</strong><br>If you need to use your Windows microphone on the Linux server:</p>



<ul class="wp-block-list">
<li>Go back to <strong>Local Resources</strong> > <strong>Remote Audio</strong>.</li>



<li>Click Settings, then check <strong>&#8220;Record from this computer&#8221;</strong>.</li>



<li>Note that your Linux audio levels in <code>pavucontrol</code> under the <strong>Input Devices</strong> tab must be unmuted.</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Conclusion</h2>



<p class="wp-block-paragraph">With these steps completed, your headless Linux server is now a fully functional remote workstation. You have video over RDP, and you have system audio routed back to your local machine. This creates a truly seamless experience for running multimedia applications, listening to music, or attending conference calls directly through your Linux management server.</p>
<p>The post <a href="https://triii.org/xrdp-guide-part-2-enabling-system-audio-on-ubuntu-and-debian/" data-wpel-link="internal">XRDP Guide: Part 2 — Enabling System Audio on Ubuntu and Debian</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Bridging the Gap: Managing Linux Servers with Windows Remote Desktop via XRDP</title>
		<link>https://triii.org/bridging-the-gap-managing-linux-servers-with-windows-remote-desktop-via-xrdp/</link>
		
		<dc:creator><![CDATA[triii]]></dc:creator>
		<pubDate>Fri, 18 Sep 2026 03:04:42 +0000</pubDate>
				<category><![CDATA[Business Solutions]]></category>
		<category><![CDATA[Knowledge Base]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://triii.org/?p=4114</guid>

					<description><![CDATA[<p>By Calabastro If you have spent years in system administration or IT support, you know [&#8230;]</p>
<p>The post <a href="https://triii.org/bridging-the-gap-managing-linux-servers-with-windows-remote-desktop-via-xrdp/" data-wpel-link="internal">Bridging the Gap: Managing Linux Servers with Windows Remote Desktop via XRDP</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>By Calabastro</strong></p>



<p class="wp-block-paragraph">If you have spent years in system administration or IT support, you know the comfort of the Windows Remote Desktop Protocol (RDP). It offers a seamless bridge between your workstation and a server—complete with clipboard sharing, drive mapping, and that familiar window management feel.</p>



<p class="wp-block-paragraph">However, managing Linux servers often forces you to switch contexts: opening SSH terminals, relying heavily on command-line tools like <code>htop</code> or <code>top</code>, and occasionally wrestling with VNC (Virtual Network Computing). While VNC is a powerful tool, it often feels clunky compared to the polished experience of RDP.</p>



<p class="wp-block-paragraph">What if you could manage your Ubuntu or Debian Linux servers with the exact same familiarity as your Windows Server instances?</p>



<p class="wp-block-paragraph">In this guide, we will set up <strong>XRDP</strong> (eXtended Remote Desktop Protocol) paired with the <strong>GNOME Desktop Environment</strong>. This allows you to use the native Microsoft &#8220;Remote Desktop&#8221; client on your PC to control a headless Linux machine just like it were another piece of Windows hardware.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Why XRDP over VNC?</h2>



<p class="wp-block-paragraph">Before we dive into the terminal, let&#8217;s discuss why this setup is often preferred for server management:</p>



<ol class="wp-block-list">
<li><strong>Performance:</strong> RDP generally requires less bandwidth than VNC, making it much smoother over slow or high-latency internet connections.</li>



<li><strong>Client Familiarity:</strong> Every Windows machine has an RDP client installed by default. You don&#8217;t need to download third-party viewers like TightVNC or TigerVNC.</li>



<li><strong>Feature Set:</strong> Native clipboard integration and drive redirection (accessing your local C: drive from the remote server) are much easier to configure.</li>
</ol>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Prerequisites</h2>



<p class="wp-block-paragraph">To follow this guide, you will need:</p>



<ul class="wp-block-list">
<li><strong>A Linux Server:</strong> Ubuntu Server (20.04, 22.04, or 24.04 LTS) or Debian 11/12.</li>



<li><strong>Root/Sudo Access:</strong> You must have administrative privileges.</li>



<li><strong>GNOME Desktop Environment:</strong> This guide assumes you are installing the desktop <em>on</em> the server (headless setup).</li>



<li><strong>A Windows Workstation:</strong> The machine from which you will remote in.</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 1: Update and Install GNOME</h2>



<p class="wp-block-paragraph">If your Linux installation is currently a bare-bones server with no graphics, we need to install the desktop environment first. While KDE or XFCE are lighter, GNOME provides the most polished &#8220;modern OS&#8221; feel similar to Windows 10/11.</p>



<p class="wp-block-paragraph">Connect via SSH and run the following updates:</p>



<pre class="wp-block-code"><code>sudo apt update
sudo apt upgrade -y</code></pre>



<p class="wp-block-paragraph">Now, install the Ubuntu Desktop package (which works for Debian as well):</p>



<pre class="wp-block-code"><code>sudo apt install ubuntu-desktop gnome-panel gnome-settings-daemon metacity nautilus gnome-terminal -y</code></pre>



<p class="wp-block-paragraph"><em>Note: During installation on Debian, you may be prompted to choose a display manager. Select <strong>gdm3</strong>.</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 2: Installing XRDP</h2>



<p class="wp-block-paragraph">Now we install the server-side software that will translate the GNOME interface into RDP packets.</p>



<pre class="wp-block-code"><code>sudo apt install xrdp -y</code></pre>



<p class="wp-block-paragraph">Once installed, the XRDP service usually starts automatically. However, to be safe and ensure it runs at boot:</p>



<pre class="wp-block-code"><code>sudo systemctl enable xrdp
sudo systemctl start xrdp</code></pre>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 3: Configuring GNOME for XRDP (Crucial Step)</h2>



<p class="wp-block-paragraph">This is the most common point of failure. By default, GNOME often tries to launch a &#8220;Wayland&#8221; session when a user logs in locally or remotely. <strong>XRDP does not support Wayland.</strong> It requires Xorg. If you try to connect right now, you will likely get a black screen or an immediate disconnect.</p>



<p class="wp-block-paragraph">We must force GNOME to use the X11 (Xorg) session specifically for XRDP. We do this by creating a specific session file in the user&#8217;s home directory.</p>



<p class="wp-block-paragraph">Open the <code>.xsession</code> file in your text editor (replace <code>username</code> with your actual username):</p>



<pre class="wp-block-code"><code>sudo nano /home/username/.xsession</code></pre>



<p class="wp-block-paragraph"><em>Note: The <code>.</code> at the beginning hides the file; this is correct behavior.</em></p>



<p class="wp-block-paragraph">Paste the following configuration into the file:</p>



<pre class="wp-block-code"><code>export XDG_CURRENT_DESKTOP=GNOME
export XDG_SESSION_TYPE=x11
exec gnome-session</code></pre>



<p class="wp-block-paragraph">Save and exit (Ctrl+O, Enter, then Ctrl+X in nano). Now ensure the file has executable permissions so the system can run it upon connection:</p>



<pre class="wp-block-code"><code>sudo chmod +x /home/username/.xsession</code></pre>



<p class="wp-block-paragraph"><em>(If you have multiple users who need access, you must repeat this step for each user&#8217;s home directory, or simply copy the configuration to <code>/etc/skel/.xsession</code> to apply it automatically to new users.)</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 4: Firewall Configuration</h2>



<p class="wp-block-paragraph">XRDP listens on port <strong>3389</strong>. If you are running a firewall (UFW is standard on Ubuntu/Debian), you must open this port or the connection will time out.</p>



<p class="wp-block-paragraph">Check your firewall status:</p>



<pre class="wp-block-code"><code>sudo ufw status</code></pre>



<p class="wp-block-paragraph">Enable port 3389:</p>



<pre class="wp-block-code"><code>sudo ufw allow 3389/tcp</code></pre>



<p class="wp-block-paragraph"><em>Security Tip:</em> For a production environment, it is highly recommended to tunnel RDP over SSH rather than opening port 3389 to the entire public internet. However, for local network management, opening the port is standard practice.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Step 5: Connecting from Windows</h2>



<p class="wp-block-paragraph">You are now ready to bridge the gap.</p>



<ol class="wp-block-list">
<li>On your Windows machine, open the Start Menu and type <strong>&#8220;Remote Desktop Connection&#8221;</strong>, then launch it.</li>



<li>In the <strong>Computer</strong> field, enter the IP address of your Linux server (e.g., <code>192.168.1.50</code>).</li>



<li>Click <strong>Connect</strong>.</li>
</ol>



<p class="wp-block-paragraph">You will be presented with an XRDP login screen. It will look slightly different than a standard Windows RDP screen—usually gray or dark grey.</p>



<ul class="wp-block-list">
<li><strong>Session:</strong> Ensure &#8220;Xorg&#8221; is selected in the dropdown (if it doesn&#8217;t default correctly).</li>



<li><strong>Username:</strong> Enter your Linux username.</li>



<li><strong>Password:</strong> Enter your Linux password.</li>
</ul>



<p class="wp-block-paragraph">Once authenticated, XRDP will load the GNOME desktop environment you installed earlier. You can now manage your server using a mouse and keyboard, open a terminal, or edit configuration files with text editors just like you would on Windows.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Troubleshooting Common Issues</h2>



<p class="wp-block-paragraph"><strong>&#8220;I get connected but it turns black immediately.&#8221;</strong><br>This is almost always the <code>.xsession</code> issue described in Step 3. Ensure <code>export XDG_SESSION_TYPE=x11</code> is present and that you have logged out of the GNOME desktop on the physical server (or via another SSH session) before trying the RDP connection again.</p>



<p class="wp-block-paragraph"><strong>&#8220;The mouse cursor moves weirdly / doesn&#8217;t match.&#8221;</strong><br>Adjust the display settings within your remote GNOME session. Right-click the desktop -&gt; <em>Display Settings</em>. Ensure the resolution is set to a value supported by your local machine.</p>



<p class="wp-block-paragraph"><strong>&#8220;I can&#8217;t type my password correctly (keyboard layout issues).&#8221;</strong><br>This happens if your Windows client uses a different keyboard layout than the Linux server. Usually, simply logging out and back in fixes this, but you may need to configure <code>/etc/default/keyboard</code> on the server to match your physical keyboard (e.g., <code>xkb-model="pc105"</code>).</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Final Thoughts</h2>



<p class="wp-block-paragraph">Managing a Linux server does not have to mean staring at a blinking cursor forever. By bridging the gap with XRDP and GNOME, you gain the performance of a Linux kernel combined with the accessibility and familiarity of Windows Remote Desktop. It allows for easier maintenance of desktop-centric tools, graphical file managers (Nautilus), and web development environments without leaving your workstation&#8217;s comfort zone.</p>



<p class="wp-block-paragraph">Welcome to the hybrid server environment!</p>
<p>The post <a href="https://triii.org/bridging-the-gap-managing-linux-servers-with-windows-remote-desktop-via-xrdp/" data-wpel-link="internal">Bridging the Gap: Managing Linux Servers with Windows Remote Desktop via XRDP</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>How to Install NVIDIA Drivers on Ubuntu 26.01</title>
		<link>https://triii.org/how-to-install-nvidia-drivers-on-ubuntu-26-01/</link>
		
		<dc:creator><![CDATA[triii]]></dc:creator>
		<pubDate>Thu, 10 Sep 2026 22:35:15 +0000</pubDate>
				<category><![CDATA[Knowledge Base]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://triii.org/?p=4013</guid>

					<description><![CDATA[<p>What you should know first 🔧 Installation Methods Here are the common ways to install, [&#8230;]</p>
<p>The post <a href="https://triii.org/how-to-install-nvidia-drivers-on-ubuntu-26-01/" data-wpel-link="internal">How to Install NVIDIA Drivers on Ubuntu 26.01</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h3 class="wp-block-heading">What you should know first</h3>



<ul class="wp-block-list">
<li>There are <strong>two main kinds of NVIDIA driver packages</strong>:
<ol class="wp-block-list">
<li><strong>Unified Driver Architecture (UDA)</strong> — more “general purpose”, used for desktops/gaming.</li>



<li><strong>Enterprise Ready Drivers (ERD) / “-server” suffix</strong> — optimized for servers / compute workloads. </li>
</ol>
</li>



<li>If Secure Boot is enabled, you’ll need signed kernel modules or enroll a Machine Owner Key (MOK). </li>



<li>Always check which kernel you’re running and make sure kernel headers for that version are installed. Without matching headers, driver modules may fail to compile.</li>
</ul>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f527.png" alt="🔧" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Installation Methods</h3>



<p class="wp-block-paragraph">Here are the common ways to install, with pros &amp; cons.</p>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th>Method</th><th>Pros</th><th>Caveats</th></tr></thead><tbody><tr><td>Using <code>ubuntu-drivers</code> tool (<strong>recommended</strong> <strong>Route</strong>)</td><td>Easy, handles dependencies; works well with Secure Boot; automatically picks a compatible driver. (<a href="https://documentation.ubuntu.com/server/how-to/graphics/install-nvidia-drivers/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">Ubuntu Documentation</a>)</td><td>Less control over specific version if you need something non-standard.</td></tr><tr><td>Manual install via APT packages (<code>nvidia-driver-...</code>, kernel modules, etc.)</td><td>More control; can pick server vs non-server branch; good for fine-tuning. </td><td>More steps; risk of mismatch; need kernel headers; Secure Boot handling can be trickier.</td></tr><tr><td><strong>run script from NVIDIA website</strong></td><td>Sometimes only way to get latest drivers or support for very new/edge hardware.</td><td>More risk: clashes with packages; you must manage updates yourself; more manual work; not always recommended.</td></tr></tbody></table></figure>



<h3 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Step-by-Step (Ubuntu’s Recommended Route)</h3>



<p class="wp-block-paragraph">Here’s a streamlined version using Ubuntu’s <code>ubuntu-drivers</code> tool and APT.</p>



<p class="wp-block-paragraph"><strong>Update system</strong> </p>



<pre class="wp-block-code"><code><code>sudo apt update</code></code></pre>



<p class="wp-block-paragraph"><strong>Check current driver version (if any)</strong> (if you haven&#8217;t installed a driver, you can skip this!)</p>



<pre class="wp-block-code"><code><code>cat /proc/driver/nvidia/version</code></code></pre>



<p class="wp-block-paragraph"><strong>List drivers available for your hardware</strong> (Optional)</p>



<p class="wp-block-paragraph"><span style="font-size: revert;">For generic desktop/gaming: </span></p>



<pre class="wp-block-code"><code><code style="font-size: revert; background-color: rgb(255, 255, 255);">sudo ubuntu-drivers list</code></code></pre>



<p class="wp-block-paragraph"><code style="font-size: revert; background-color: rgb(255, 255, 255);"><span style="font-size: revert; font-family: Poppins, sans-serif;">For server / GPGPU / compute workloads: </span></code> </p>



<pre class="wp-block-code"><code><code style="font-size: revert; background-color: rgb(255, 255, 255);"><code style="font-size: revert; background-color: rgb(255, 255, 255);">sudo ubuntu-drivers list --gpgpu</code></code></code></pre>



<p class="wp-block-paragraph">You’ll see something like <code>nvidia-driver-535</code>, <code>nvidia-driver-535-server</code>, etc.</p>



<p class="wp-block-paragraph">I<strong>nstall the driver</strong></p>



<pre class="wp-block-code"><code>sudo ubuntu-drivers install</code></pre>



<p class="wp-block-paragraph"><strong>Reboot</strong>.</p>



<pre class="wp-block-code"><code>sudo reboot</code></pre>



<p class="wp-block-paragraph">After the system has rebooted, the drivers should now be installed and running. Try the <strong>nvidia-smi</strong> command.</p>



<p class="wp-block-paragraph"><strong>Additional steps for power users.</strong> (Optional)</p>



<ol class="wp-block-list">
<li><strong>Install additional utils</strong> (optional/if needed)<br>Especially for server drivers, you might want things like <code>nvidia-utils-&lt;version&gt;</code>, or for special hardware <code>nvidia-fabricmanager</code> or <code>libnvidia-nscq</code>. (<a href="https://documentation.ubuntu.com/server/how-to/graphics/install-nvidia-drivers/" data-wpel-link="external" target="_blank" rel="nofollow external noopener noreferrer">Ubuntu Documentation</a>)</li>



<li><strong>Verify installation</strong><br>Use commands like: <code>nvidia-smi</code> to check GPU is recognized, see driver version, etc. </li>
</ol>



<h3 class="wp-block-heading">Removing / Switching Drivers</h3>



<p class="wp-block-paragraph">If things go wrong, or you want to switch versions:</p>



<ol class="wp-block-list">
<li><strong>Purge existing NVIDIA drivers</strong> ( <code>sudo apt --purge remove '*nvidia*' sudo apt autoremove</code> )</li>



<li>Then install the new one via above methods. </li>
</ol>
<p>The post <a href="https://triii.org/how-to-install-nvidia-drivers-on-ubuntu-26-01/" data-wpel-link="internal">How to Install NVIDIA Drivers on Ubuntu 26.01</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Ultimate Guide to User and Group Management in Ubuntu/Debian Linux</title>
		<link>https://triii.org/the-ultimate-guide-to-user-and-group-management-in-ubuntu-debian-linux/</link>
		
		<dc:creator><![CDATA[triii]]></dc:creator>
		<pubDate>Thu, 27 Aug 2026 05:14:18 +0000</pubDate>
				<category><![CDATA[Knowledge Base]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://triii.org/?p=3991</guid>

					<description><![CDATA[<p>By Calabastro In the Linux ecosystem, permissions are everything. Unlike some other operating systems where [&#8230;]</p>
<p>The post <a href="https://triii.org/the-ultimate-guide-to-user-and-group-management-in-ubuntu-debian-linux/" data-wpel-link="internal">The Ultimate Guide to User and Group Management in Ubuntu/Debian Linux</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph"><strong>By Calabastro</strong></p>



<p class="wp-block-paragraph">In the Linux ecosystem, permissions are everything. Unlike some other operating systems where &#8220;admin&#8221; is a status you earn after a long tenure, in Linux, it&#8217;s strictly about group membership and ownership. Whether you are setting up a web server, a personal workstation, or a container environment, knowing how to manipulate users and groups is not just useful—it&#8217;s essential.</p>



<p class="wp-block-paragraph">In this guide, we will cover everything from the basics of <code>adduser</code> and <code>useradd</code> to the nitty-gritty of group manipulation using command-line tools native to <strong>Ubuntu</strong> and <strong>Debian</strong>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Prerequisites</h2>



<p class="wp-block-paragraph">To follow along with these examples, you need a terminal (bash) and root privileges.</p>



<ul class="wp-block-list">
<li><strong>Root Access:</strong> Commands requiring system changes usually need <code>sudo</code>.</li>



<li><strong>The OS:</strong> Debian or Ubuntu derivatives (Linux Mint, Pop!_OS, etc.).</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Part 1: The User Concept in Linux</h2>



<p class="wp-block-paragraph">A user account represents an individual or a service that needs to access the system. Every file and process on Linux belongs to a specific User ID (UID) and Group ID (GID).</p>



<h3 class="wp-block-heading">Creating Users</h3>



<p class="wp-block-paragraph">On Debian/Ubuntu systems, you have two main tools for this: <code>useradd</code> and <code>adduser</code>. While they do similar things, they behave very differently.</p>



<h4 class="wp-block-heading">1. The Interactive Way: <code>adduser</code></h4>



<p class="wp-block-paragraph">This is the recommended way for human users on Debian/Ubuntu. It is a user-friendly Perl script that prompts for information, creates the home directory automatically, and copies skeleton files (like <code>.bashrc</code>).</p>



<p class="wp-block-paragraph"><strong>Command:</strong></p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo adduser newuser</code></pre>



<p class="wp-block-paragraph"><strong>Example Output:</strong></p>



<pre class="wp-block-code"><code>Adding user `newuser' ...

Adding new group `newuser' (1001) ...

Adding new user `newuser' (1001) with group `newuser' ...

Creating home directory `/home/newuser' ...

Copying files from `/etc/skel' ...

Enter new UNIX password:

Retype new UNIX password:

passwd: password updated successfully

Changing the user information for newuser

Enter the new value, or press ENTER for the default

Full Name &#91;]: New User

Room Number &#91;]:

Work Phone &#91;]:

Home Phone &#91;]:

Other &#91;]:

Is the information correct? &#91;Y/n] Y</code></pre>



<h4 class="wp-block-heading">2. The Non-Interactive/Scriptable Way: <code>useradd</code></h4>



<p class="wp-block-paragraph">This is the low-level binary command. It does <strong>not</strong> prompt for anything and does <strong>not</strong> create home directories by default. This makes it excellent for automation scripts but dangerous if you forget a flag.</p>



<p class="wp-block-paragraph"><strong>Command:</strong></p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo useradd -m -s /bin/bash -c "John Doe" john</code></pre>



<p class="wp-block-paragraph"><strong>Flag Breakdown:</strong></p>



<ul class="wp-block-list">
<li><code>-m</code>: Create the home directory (<code>/home/john</code>).</li>



<li><code>-s /bin/bash</code>: Set the default shell to Bash (default might be <code>/bin/sh</code>).</li>



<li><code>-c "John Doe"</code>: Add a comment/full name.</li>
</ul>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Part 2: Creating Users <em>with</em> Groups</h2>



<p class="wp-block-paragraph">Sometimes you want to assign a user to a specific group immediately upon creation, or set their primary group identity.</p>



<h3 class="wp-block-heading">Setting the Primary Group (-g)</h3>



<p class="wp-block-paragraph">Every user must belong to one primary group. By default, <code>useradd</code> creates a private group with the same name as the user. You can change this at creation time.</p>



<p class="wp-block-paragraph"><strong>Scenario:</strong> Create a user named <code>webadmin</code> whose primary group is <code>www-data</code>.</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo useradd -m -g www-data -s /bin/bash webadmin</code></pre>



<h3 class="wp-block-heading">Setting Supplementary Groups (-G)</h3>



<p class="wp-block-paragraph">You can assign the user to secondary groups (e.g., <code>sudo</code>, <code>docker</code>) at the moment of creation. Note the capital <code>-G</code>.</p>



<p class="wp-block-paragraph"><strong>Scenario:</strong> Create a user <code>devops</code> who is in both the <code>sudo</code> and <code>docker</code> groups immediately.</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo useradd -m -s /bin/bash -G sudo,docker devops</code></pre>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Part 3: Managing Users</h2>



<p class="wp-block-paragraph">Once a user exists, you need to manage them.</p>



<h3 class="wp-block-heading">Changing Passwords</h3>



<p class="wp-block-paragraph">Regardless of how the user was created, use <code>passwd</code> to set or change passwords.</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo passwd newuser</code></pre>



<p class="wp-block-paragraph">Force the user to change their password on next login (good for temporary accounts)</p>



<pre class="wp-block-code"><code>sudo passwd -e newuser</code></pre>



<h3 class="wp-block-heading">Modifying User Properties (<code>usermod</code>)</h3>



<p class="wp-block-paragraph">Use <code>usermod</code> to update existing users without deleting and recreating them.</p>



<p class="wp-block-paragraph"><strong>Example 1: Locking an account</strong> (Disables the password, user cannot log in, but files remain).</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo usermod -L newuser</code></pre>



<p class="wp-block-paragraph"><strong>Example 2: Unlocking an account</strong></p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo passwd -u newuser</code></pre>



<p class="wp-block-paragraph"><strong>Example 3: Changing the home directory path</strong> (User moves to <code>/opt/new_home</code>)</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo usermod -d /opt/new_home -m newuser</code></pre>



<p class="wp-block-paragraph"><em>(Note: <code>-m</code> is used here to move the contents of the old home dir to the new one).</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Part 4: Creating and Managing Groups</h2>



<p class="wp-block-paragraph">Groups are logical collections of users used for access control.</p>



<h3 class="wp-block-heading">Creating a Group (<code>groupadd</code>)</h3>



<p class="wp-block-paragraph"><strong>Command:</strong></p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo groupadd developers</code></pre>



<p class="wp-block-paragraph">If you want to assign a specific Group ID (GID) rather than letting the system pick one automatically:</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo groupadd -g 1050 developers</code></pre>



<h3 class="wp-block-heading">Deleting a Group (<code>groupdel</code>)</h3>



<p class="wp-block-paragraph"><em>Warning: If users belong to this group, their GID will become orphaned.</em></p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo groupdel developers</code></pre>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Part 5: Managing Group Memberships</h2>



<p class="wp-block-paragraph">This is where the real power of Linux permissions lies. You rarely change the <em>definition</em> of a group; you change the <em>membership</em> of users within it.</p>



<h3 class="wp-block-heading">Adding a User to a Supplementary Group</h3>



<p class="wp-block-paragraph">The golden rule here is using <code>usermod</code> with <code>-aG</code>. <strong>You must include the &#8216;a&#8217; (append)</strong>. Without it, the user will be removed from all other groups and added only to this one!</p>



<p class="wp-block-paragraph"><strong>Scenario:</strong> Add <code>newuser</code> to the <code>sudo</code> group (so they can become root) and the <code>www-data</code> group.</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo usermod -aG sudo,www-data newuser</code></pre>



<h3 class="wp-block-heading">Removing a User from a Group</h3>



<p class="wp-block-paragraph">It is easiest to use <code>gpasswd</code>.</p>



<p class="wp-block-paragraph"><strong>Scenario:</strong> Remove <code>newuser</code> from the <code>docker</code> group.</p>



<pre class="wp-block-code"><code>sudo gpasswd -d newuser docker</code></pre>



<p class="wp-block-paragraph"><em>Note: You cannot easily remove a user from their <strong>Primary</strong> group without using <code>usermod -u</code> to change their primary UID/GID entirely, which is complex.</em></p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Part 6: Verifying Your Work</h2>



<p class="wp-block-paragraph">How do you know if your changes stuck?</p>



<h3 class="wp-block-heading">Check User Identity</h3>



<p class="wp-block-paragraph"><strong>bash</strong></p>



<pre class="wp-block-code"><code>id newuser</code></pre>



<p class="wp-block-paragraph"><strong>Output:</strong></p>



<pre class="wp-block-code"><code>uid=1001(newuser) gid=1001(newuser) groups=1001(newuser),27(sudo),33(www-data)</code></pre>



<h3 class="wp-block-heading">Check Group Members</h3>



<p class="wp-block-paragraph">Use <code>getent</code> (gets entries from databases) or <code>cat /etc/group</code>.</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>getent group sudo</code></pre>



<p class="wp-block-paragraph"><strong>Output:</strong></p>



<pre class="wp-block-code"><code>sudo:x:27:root,newuser</code></pre>



<p class="wp-block-paragraph">(This tells us users <code>root</code> and <code>newuser</code> are members of the <code>sudo</code> group).</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading">Summary Cheatsheet for Calabastro Fans</h2>



<figure class="wp-block-table"><table class="has-fixed-layout"><thead><tr><th class="has-text-align-left" data-align="left">Action</th><th class="has-text-align-left" data-align="left">Command</th><th class="has-text-align-left" data-align="left">Notes</th></tr></thead><tbody><tr><td class="has-text-align-left" data-align="left"><strong>Create User</strong> (Interactive)</td><td class="has-text-align-left" data-align="left"><code>adduser username</code></td><td class="has-text-align-left" data-align="left">Debian/Ubuntu preference. Prompts for info.</td></tr><tr><td class="has-text-align-left" data-align="left"><strong>Create User</strong> (Silent)</td><td class="has-text-align-left" data-align="left"><code>useradd -m username</code></td><td class="has-text-align-left" data-align="left">Scripting friendly. Requires flags like <code>-s</code>.</td></tr><tr><td class="has-text-align-left" data-align="left"><strong>Change Password</strong></td><td class="has-text-align-left" data-align="left"><code>passwd username</code></td><td class="has-text-align-left" data-align="left">Requires sudo if changing others&#8217; passwords.</td></tr><tr><td class="has-text-align-left" data-align="left"><strong>Lock/Unlock Account</strong></td><td class="has-text-align-left" data-align="left"><code>passwd -l / -u</code></td><td class="has-text-align-left" data-align="left">Disables password login without deleting files.</td></tr><tr><td class="has-text-align-left" data-align="left"><strong>Add to Group</strong></td><td class="has-text-align-left" data-align="left"><code>usermod -aG group user</code></td><td class="has-text-align-left" data-align="left"><strong>ALWAYS use -a (append) or lose other groups.</strong></td></tr><tr><td class="has-text-align-left" data-align="left"><strong>Create Group</strong></td><td class="has-text-align-left" data-align="left"><code>groupadd groupname</code></td><td class="has-text-align-left" data-align="left">Simple creation. Use <code>-g</code> for custom ID.</td></tr><tr><td class="has-text-align-left" data-align="left"><strong>Remove from Group</strong></td><td class="has-text-align-left" data-align="left"><code>gpasswd -d user group</code></td><td class="has-text-align-left" data-align="left">Easy removal from supplementary groups.</td></tr></tbody></table></figure>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p class="wp-block-paragraph"><em>Stay tuned, Linux lovers! Calabastro out.</em></p>
<p>The post <a href="https://triii.org/the-ultimate-guide-to-user-and-group-management-in-ubuntu-debian-linux/" data-wpel-link="internal">The Ultimate Guide to User and Group Management in Ubuntu/Debian Linux</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Secure Self-Hosted Password Management: Install Vaultwarden on Ubuntu 24.04 &#038; Tunnel It with Tailscale</title>
		<link>https://triii.org/secure-self-hosted-password-management-install-vaultwarden-on-ubuntu-24-04-tunnel-it-with-tailscale/</link>
		
		<dc:creator><![CDATA[triii]]></dc:creator>
		<pubDate>Tue, 28 Apr 2026 06:40:23 +0000</pubDate>
				<category><![CDATA[Knowledge Base]]></category>
		<category><![CDATA[Linux]]></category>
		<guid isPermaLink="false">https://triii.org/?p=3654</guid>

					<description><![CDATA[<p>If you&#8217;re running a homelab, a private server, or a small team infrastructure, you&#8217;ve likely [&#8230;]</p>
<p>The post <a href="https://triii.org/secure-self-hosted-password-management-install-vaultwarden-on-ubuntu-24-04-tunnel-it-with-tailscale/" data-wpel-link="internal">Secure Self-Hosted Password Management: Install Vaultwarden on Ubuntu 24.04 &amp; Tunnel It with Tailscale</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">If you&#8217;re running a homelab, a private server, or a small team infrastructure, you&#8217;ve likely noticed a recurring security pattern: <strong>self-hosting services without exposing them to the public internet</strong>.</p>



<p class="wp-block-paragraph">This tutorial walks you through the modern, zero-trust way to deploy <strong>Vaultwarden</strong> (a lightweight Bitwarden-compatible password manager) on <strong>Ubuntu 24.04</strong>, and secure access using <strong>Tailscale VPN</strong>. No port forwarding, no reverse proxy headaches, and no SSL certificate management required for initial setup.</p>



<h2 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4cb.png" alt="📋" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Prerequisites</h2>



<ul class="wp-block-list">
<li>Ubuntu 24.04 LTS (Server or Desktop)</li>



<li>A user with <code>sudo</code> privileges</li>



<li>A free Tailscale account (<a href="https://tailscale.com" target="_blank" rel="noreferrer noopener nofollow external" data-wpel-link="external">tailscale.com</a>)</li>



<li>Basic terminal familiarity</li>
</ul>



<h2 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Step 1: Install &amp; Authenticate Tailscale on Ubuntu 24.04</h2>



<p class="wp-block-paragraph">Tailscale replaces traditional VPN complexity with WireGuard-based mesh networking. It automatically handles NAT traversal, DNS, and firewall rules.</p>



<h3 class="wp-block-heading">1. Install the Tailscale Client</h3>



<p class="wp-block-paragraph">Run the official automated installer:</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>curl -fsSL https://tailscale.com/install.sh | sh</code></pre>



<p class="wp-block-paragraph">This script detects your APT package manager and sets up the tailscaled systemd service automatically.</p>



<h3 class="wp-block-heading">2. Start &amp; Authenticate the Client</h3>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>sudo tailscale up</code></pre>



<p class="wp-block-paragraph">You&#8217;ll see output containing an authentication URL like <code>https://login.tailscale.com/a/...</code>. Open that link in any browser, sign in with your Tailscale account, and authorize the device.</p>



<h3 class="wp-block-heading">3. Verify Connectivity</h3>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>tailscale status</code></pre>



<p class="wp-block-paragraph">You should see your machine listed in the output. Head to your <a target="_blank" rel="noreferrer noopener nofollow external" href="https://login.tailscale.com/admin/machines" data-wpel-link="external">Tailscale Admin Console</a> to confirm the device appears in your tailnet. Take note of the <strong>4.x.x.x IPv4 address</strong> or the <strong>FQDN</strong> (e.g., <code>yourhostname.tail-12345.tailnet.goog</code>).</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Step 2: Install Docker Engine</h2>



<p class="wp-block-paragraph">Ubuntu 24.04 no longer ships Docker in its default repositories. We&#8217;ll install it via Docker&#8217;s official APT repository.</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>curl -fsSL https://get.docker.com -o get-docker.sh
sh get-docker.sh
rm get-docker.sh</code></pre>



<p class="wp-block-paragraph"><em>Log out and back in for group permissions to apply.</em> Verify with <code>docker --version</code> and <code>docker compose version</code>.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Step 3: Deploy Vaultwarden via Docker</h2>



<p class="wp-block-paragraph">Vaultwarden is a Rust-based, resource-efficient alternative to Bitwarden&#8217;s official server. We&#8217;ll run it with persistent storage.</p>



<h3 class="wp-block-heading">1. Pull the Image</h3>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>docker pull vaultwarden/server:latest</code></pre>



<h3 class="wp-block-heading">2. Run the Container</h3>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>docker run -d \

--name vaultwarden \

--restart unless-stopped \

-v /vw-data:/data \

-p 8082:80 \

-e SIGNUPS_ALLOWED=false \

-e ADMIN_PASSWORD="$(openssl rand -base64 32)" \

-e ENABLE_DB_WAL=true \

vaultwarden/server:latest</code></pre>



<p class="wp-block-paragraph"><strong>Why this configuration?</strong></p>



<ul class="wp-block-list">
<li><code>-v /vw-data:/data</code>: Persists your vault database, attachments, and config across container updates.</li>



<li><code>-p 8082:80</code>: Maps to a non-privileged port to avoid conflicts with nginx/apache (optional but recommended).</li>



<li><code>SIGNUPS_ALLOWED=false</code>: Disables public registration (recommended for private setups).</li>



<li><code>ADMIN_PASSWORD</code>: Generates a secure random admin password. Save this! You&#8217;ll need it to access <code>/admin</code>.</li>



<li>Tailscale&#8217;s encrypted tunnel means <strong>HTTP is perfectly secure here</strong>. The Chrome/Web Crypto HTTPS warning in the Vaultwarden docs applies to <em>public</em> internet exposure, which we&#8217;re bypassing entirely.</li>
</ul>



<p class="wp-block-paragraph">Verify it&#8217;s running:</p>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code>docker ps | grep vaultwarden

tailscale ip4</code></pre>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f539.png" alt="🔹" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Step 4: Access Vaultwarden Securely Over Tailscale</h2>



<p class="wp-block-paragraph">Because Tailscale creates a private encrypted network, you can access Vaultwarden as if you&#8217;re on the same local machine.</p>



<ol start="1" class="wp-block-list">
<li>On any device in your tailnet (Windows, macOS, Android, iOS, or another Ubuntu box), install the Tailscale client.</li>



<li>Open your browser and navigate to: http://&lt;ubuntu-tailscale-ip>:8082<em>(Replace <code>&lt;ubuntu-tailscale-ip></code> with the 4.x.x.x address from <code>tailscale ip4</code>)</em></li>



<li>Click <strong>Create Account</strong> and register as the first user.</li>



<li>Log in and set up your master password.</li>



<li>Install the <strong>Bitwarden browser extension</strong> or <strong>mobile app</strong>. In the extension settings, change the Server URI to your Tailscale address: http://&lt;ubuntu-tailscale-ip:8082</li>
</ol>



<p class="wp-block-paragraph"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f510.png" alt="🔐" class="wp-smiley" style="height: 1em; max-height: 1em;" /> You now have a fully functional, self-hosted password manager accessible only from your tailnet. No public IPs, no exposed ports, no reverse proxy required.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e0.png" alt="🛠" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Pro Tips for Production-Ready Setups</h2>



<h3 class="wp-block-heading">Backups</h3>



<p class="wp-block-paragraph">bash</p>



<pre class="wp-block-code"><code># Daily backup script (/vw-data contains everything)

sudo rsync -av /vw-data/ /mnt/backup/vaultwarden/

# Compress periodically

tar -czf /mnt/backup/vaultwarden-$(date +%F).tar.gz /vw-data/</code></pre>



<h3 class="wp-block-heading">Public Exposure (Optional)</h3>



<p class="wp-block-paragraph">If you ever want to access Vaultwarden over the public internet, you <strong>must</strong> enable HTTPS. Use <code>certbot</code> with a reverse proxy (Caddy or Nginx), or generate self-signed certs with <code>mkcert</code>. Never expose Vaultwarden over HTTP publicly.</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<h2 class="wp-block-heading"><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f3af.png" alt="🎯" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Conclusion</h2>



<p class="wp-block-paragraph">Combining <strong>Vaultwarden</strong> with <strong>Tailscale</strong> gives you enterprise-grade access control, military-grade encryption, and zero infrastructure overhead. By leveraging Tailscale&#8217;s WireGuard mesh network, you eliminate the most common self-hosting pitfalls: NAT complications, SSL certificate management, and port exposure risks.</p>



<p class="wp-block-paragraph">Your password manager is now:<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Self-hosted &amp; fully private<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Accessible from anywhere via your tailnet<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Secure by default (no public IPs or firewall rules needed)<br><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/2705.png" alt="✅" class="wp-smiley" style="height: 1em; max-height: 1em;" /> Ready for scaling with Docker Compose &amp; automated backups</p>



<p class="wp-block-paragraph">Drop a comment if you run into authentication hiccups, need help configuring Bitwarden clients, or want to extend this setup with TOTP generation or emergency access features. Stay secure, stay private. <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f6e1.png" alt="🛡" class="wp-smiley" style="height: 1em; max-height: 1em;" /><img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f4bb.png" alt="💻" class="wp-smiley" style="height: 1em; max-height: 1em;" /></p>



<p class="wp-block-paragraph"><em>Published for Ubuntu 24.04 LTS | Tailscale &amp; Vaultwarden versions current as of August 2026</em><br><em>Keywords: Ubuntu 24.04, Tailscale VPN, Vaultwarden, Docker, Self-Hosted Password Manager, Zero Trust Networking, Homelab Security</em></p>
<p>The post <a href="https://triii.org/secure-self-hosted-password-management-install-vaultwarden-on-ubuntu-24-04-tunnel-it-with-tailscale/" data-wpel-link="internal">Secure Self-Hosted Password Management: Install Vaultwarden on Ubuntu 24.04 &amp; Tunnel It with Tailscale</a> appeared first on <a href="https://triii.org" data-wpel-link="internal">Triii Technologies LLC</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
