Launches and notable updates. Short posts — no fluff.
webtarpit 0.7.0 invents a different
static document for each path (About, Contact, login, admin, products, …)
even when the model is slow, and plants decoy
mailto: addresses for scanners to harvest.
webtarpit 0.6.2 treats a hung or slow
OpenAI-compatible backend as a generation failure: the listener returns
static fallback HTML instead of dropping the TCP connection.
respond_timeout (default 8s) is how long a client waits
for the model; the LLM may still finish in the background and replace
the cached page.
webtarpit 0.6.1 sends a proxy key
as Authorization: Bearer plus x-api-key /
api-key. Set it in YAML (api_key /
api_key_file), CLI, or env
(WEBTARPIT_API_KEY, LITELLM_API_KEY,
OPENAI_API_KEY). Installer onboarding asks for the key;
systemd units load optional webtarpit.env.
webtarpit 0.6.0 ships
curl | bash install.sh:
install path, systemd or cron, run user (default webtarpit), optional
config onboarding, auto-update opt-in. webtarpit sample-config
writes the example YAML. Manual docs now show source .venv/bin/activate.
webtarpit 0.5.0 rate-limits first-hit
generation, randomizes response delay, keeps the link graph shallow,
varies fallback chrome, turns auto-update off unless you opt in,
adds webtarpit report, and accepts a custom prompt per Host.
webtarpit 0.4.0 serves multiple domains from one listener (Host header + per-vhost config) and keeps a persistent invented site per device using passive HTTP fingerprints, optional HttpOnly cookies, and ETags — no JavaScript in generated pages.
webtarpit 0.3.0 reads a YAML or JSON
config file (--config / WEBTARPIT_CONFIG).
Flags still win; the file overrides environment variables.
webtarpit 0.2.0 checks this site for a
newer tarball, verifies SHA-256, installs it, and restarts. Channel:
version.json. Disable with
--no-auto-update.
webtarpit is a scanner honeypot: it listens on HTTP, asks an OpenAI-compatible model to invent a static HTML page for each requested path, and stores the result. Shared site or one site per client IP. MIT, no JavaScript in generated pages.
HESK API 1.8.0 shows this install versus the
latest Tactical Data Concepts package on the staff dashboard and a new
Updates page. Header and footer print the installed version. If the
host is behind, Upgrade instructions links to the
upgrade guide. Admins can set
check / notify / auto-install, ticket owner + category, and
allow_auto_install there (or via
PATCH /v1/updates/settings). Download and checksum on the
product page.
HESK API 1.7.0 can check Tactical Data Concepts for a newer package. Safer default is check-only; you can open a HESK ticket to a staff user or category with the zip URL, SHA-256, and install steps, or opt in to auto-install (HTTPS, host allow-list, checksum required, local config and storage left alone). Upgrade instructions and checksum are on the product site.
HESK API 1.6.0 keeps ticket, reply, and note
bodies readable in the HESK staff UI. Optional format
(auto, plain, html, markdown)
converts newlines and markdown, and no longer treats log timestamps
such as <2026-08-19T21:58:12.969Z> as HTML tags.
Download and checksum on the product page.
HESK API 1.5.0 adds time worked on tickets: increment duration on each staff reply, or set / add time on the ticket. Same staff privileges and time-tracking setting as HESK. Download and checksum on the product page.
HESK API is a REST layer and staff token portal you install beside an existing HESK 3.7 help desk. Tickets, replies, note attachments, and a live OpenAPI spec — without changing HESK PHP.
A hosted dashboard for OriginReach: install a small agent, assign origin / edge / DNS checks, see 30-day up/down history, and get throttled email alerts. Free for one agent and five services. The CLI is fully free (check, watch, reports) and is the agent that reports here.
tacticaldataconcepts.com now has a full top menu (Products, Services, Tools, Guides, News, About) and a dedicated tools directory so “Tools” no longer dumps you only into the JSON app.
LineItemLab extracts line items from receipts and invoices to CSV. Free tier: one document at a time. Paid Starter from $10/month for 100 documents, batch upload, and reporting exports. Paid checkout still rolling out.
OriginReach helps diagnose whether a self-hosted service is down on the origin or only on the public edge/tunnel. Free one-shot checks; Pro adds watch and file reports.
Longer guides on config drift, dotenv tooling, Cloudflare Tunnel 502s, and multi-host Ollama setups are up at guides.tacticaldataconcepts.com.