Keys to the Engine Bay

Posted by Omega8.cc - 11 Sep 2026 at 22:47 UTC
Handing an outside developer your one and only SSH login because the job was one theme on one site is the oldest mistake in hosting, and the collaborator button on the big platforms only hides the question of what that seat can actually do. On a BOA server a Client, the control panel's word for the person a site belongs to, gets its own limited login built automatically, one which sees that Client's sites and their files and nothing else; and now your host can turn on a second login of the platform kind for that Client, which reaches the whole codebase of every platform whose sites are all the Client's, with Composer and the Drush shipped inside the platform, and refuses any platform where somebody else's site is parked as well. The grant is decided by root from one line, re-derived every three minutes and readable in one file and one log; Drupal 8 and newer platforms are unlocked for the developer an hour at a time, on request, and locked back by themselves.

DrupalCamp Poland 2026: AI Hallucinations, Drupal System Failures and Agentic Maintenance

Posted by The Drop Times - 11 Sep 2026 at 10:49 UTC
Some of the hardest technology failures arrive without a broken component or a clear error. Two DrupalCamp Poland speakers examine what teams can learn from convincing AI mistakes, system-level performance failures, and automation that still depends on human judgement.

Rebuilding a data-driven Drupal site: Separating data objects from pages

Posted by Berliners blog - 11 Sep 2026 at 09:07 UTC
Rebuilding a data-driven Drupal site: Separating data objects from pages

In the previous post in this series, I described how we rebuilt our page templates with Layout Builder. I ended that post by mentioning that templates are less suitable when the page hierarchy must be derived from the data itself.

To explain that part of the rebuild, it helps to look at a more basic change. In the Drupal 7 site, an imported data object and the page that presented it were the same node, whereas the rebuilt site stores them as separate entities.

berliner Fri, 09/11/2026 - 11:07

Tags

Vibe-coding my dream CMS (an internal monologue)

Posted by Sitback Solutions - 11 Sep 2026 at 04:59 UTC
Whiteboard mind map with "My dream CMS" circled in the centre, surrounded by nine invented CMS feature names, and a hand-drawn water droplet with question marks in the cornerIs Drupal outdated? Ask around and you might get a confident yes. Sitback developer Max spent a free weekend designing his ideal CMS from scratch, to work out what he’d build instead. Step one: build your own CMS, how hard can it be? Right. That’s it. I’ve had enough of legacy CMSes. Bloated, over-engineered, designed ...

Talking Drupal #569 - Site Templates

Posted by Talking Drupal - 10 Sep 2026 at 18:00 UTC

On today's show we are talking about Site Templates, What they do, and How you can use them with guests Tim Lehnen & Adam Globus-Hoenich. We'll also cover Haven as our module of the week.

For show notes visit: https://www.talkingDrupal.com/569

Topics
  • MOTW: Haven
  • What Site Templates Are
  • Canvas Components Included
  • Promoting Templates Beyond Drupal
  • Templates vs Distributions
  • Who Benefits from Templates
  • Template Types and Adoption
  • Where to Find Templates
  • Featured vs Installer List
  • Free vs Paid Templates
  • Recipes vs Templates
  • Distributions and Themes
  • Empowering Site Builders
  • Exporting a Template
  • Designing for Users
  • Releases Without Upgrades
  • Best Practices and AI
  • How to Contribute
Resources

Webinar: Drupal Canvas and Agentic Content Management: What Enterprise Teams Need to Know Drupal Site Templates Tim's book - Fog & Fireflies

Guests

Tim Lehnen - @TimLehnen hestenet

Adam Globus-Hoenich - @PhenaProxima phenaproxima

Read more

Centarro Bootstrap: A Centralized Design System for Drupal Commerce

Posted by Centarro - 10 Sep 2026 at 15:08 UTC

Register for our next webinar to see a live demonstration of Centarro Bootstrap.

Every new theme for a Drupal Commerce project starts with the same sequence: define your colors, configure button styles, set typography, style your forms, change icons, and then wire all of it into whatever page-building paradigm Drupal currently offers.

After twelve years, our front-end team accumulated a long list of friction points and recurring tasks. Centarro Bootstrap is the result of addressing all of them in a single, reusable foundation. What used to take weeks of custom theming can now be accomplished in hours.

The problem Centarro Bootstrap solves

Beyond making it faster and simpler to complete repetitive theming tasks that every custom Drupal website must perform, Centarro Bootstrap also helps with dynamic page layouts.

Drupal has gone through several iterations of page builders, both as contrib modules and part of Drupal core. Canvas is the current tool, which brings a Figma-like experience. Users can place components directly on a page, compose layouts visually, and see immediate results. Content teams can create single-use content straight from the interface.

Read more

Putting paths first: Views support for path alias entities

Posted by Joachim's blog - 10 Sep 2026 at 12:56 UTC
Putting paths first: Views support for path alias entities

On a recent project, I was struck by how the content editors used spreadsheets to manage their content. This wasn't just as a planning tool in the early stages; they had spreadsheets which essentially mirrored the content in Drupal, and this is where they kept track of who was responsible for sign-off on a piece of content, what stage it was at, and so on.

Leaving aside for a future post or many the matter that if editors are needing to use spreadsheets to manage their content, it doesn't speak well of the 'M' part of the CMS and that there are surely things we need to improve in Drupal, one thing I noticed was how content was listed.

The main identifier of content, the first column in the spreadsheet, wasn't the title, or the node ID, but the path. To these editors, the path was the starting point, it represented that piece of content.

This is completely add odds with how Drupal treats paths. Paths in Drupal are like an afterthought: tacked onto entities as second-class citizens. They're not even shown in the content admin pages, you're left to discover them for yourself by hovering over the content link.

But what if we could change that, and put path aliases first? What if we could make Drupal list content in the same way that these users have in their spreadsheets? It would be a first step in providing the sort of content overview and administration tools that Drupal is currently lacking for these users. Other things are needed too, such as a sign-off user content, and more complex statuses. But paths are the starting point.

Read more

The 60-second procurement test

Posted by Dries Buytaert - 9 Sep 2026 at 18:45 UTC

Open Source projects have spent decades asking companies to contribute. Projects should also give buyers the information they need to reward the companies that do.

Any Open Source project with a commercial or institutional funding ecosystem should publish an official contribution record: who contributes, how much and over what period, what kind of work they do, which parts of the project they work on, and, where disclosed, who paid for the work.

The test for a good record is simple. A buyer should be able to answer three questions in about a minute: does this vendor contribute at all, how much do they contribute compared to other vendors, and do they work on the parts of the project I care about?

Contribution does not prove that a vendor can deliver. It is one procurement factor alongside delivery capability, expertise, and price. It matters because some buyers want the money they already spend on Open Source services to help maintain the software they depend on.

Vendors that pay people to do that work carry costs that others avoid, and some of those costs may appear in their rates. A price comparison that ignores those costs can put contributing vendors at a disadvantage. I've argued that procurement should score contribution alongside price. APELL, the European Open Source Software Business Association, has also asked the EU to consider a provider's record of Open Source contribution.

Vendor claims are hard to verify and compare

Say you need a vendor for your Drupal site, your Kubernetes cluster, or whatever Open Source software you use, and two firms bid. Both say they're deeply involved in the project, and both might be telling the truth by their own definition of "involved".

Read more

Doors That Do Not Exist

Posted by Omega8.cc - 9 Sep 2026 at 14:57 UTC
Read one night of a Drupal or Backdrop site's log and most of it had no business with that site: WordPress login probes on a site which never ran WordPress, fishing for secret files, a thousand pages nobody ever made, from about as many addresses, one request apiece. On an ordinary server each of them wakes PHP for a not-found page, until no worker is free and your real visitors see an error instead of the site. On a BOA server those shapes are refused inside the web server before PHP or the database are consulted, the connection closed for what is only ever abuse, a cheap static not-found where a real page could once in a while match; the rest is judged afterwards by what an address did, a fleet by the share of failures it collects, the search engines whitelisted before anyone is banned; and during a swarm nobody can classify, each site keeps a limit on uncached renders so the cache answers everybody else. A block lasts about a quarter of an hour and lifts on its own.

Drupal GovCon 2026: From Site Building to AI Orchestration

Posted by The Drop Times - 9 Sep 2026 at 14:39 UTC
AI is changing how people build, search, and interact with websites, but not every organisation is moving at the same speed. Chad Capellman argues that Drupal's flexibility may matter more as different generations of the web continue to coexist.

Building an open source knowledge base for the AI era

Posted by drunomics - 9 Sep 2026 at 12:55 UTC
Building an open source knowledge base for the AI era A human and agent working into a common knowledge base wolfgang.ziegler Wed, 9 Sep 2026 - 14:55 AI agents are only as good as the knowledge they are given. So we are building OpenKnowledgebase: an open source wiki and AI knowledge base where people and agents work together, with trust built in.

How to mark foreign words for accessibility in Drupal with the CKEditor Language plugin

Posted by Metadrop - 9 Sep 2026 at 11:20 UTC

The European Accessibility Act came into force in June 2025, raising WCAG AA compliance from a best practice to a legal requirement for most web projects in the EU. Among the criteria that standard covers, WCAG 3.1.2 is one of the most consistently missed in editorial workflows: it requires that any change of language within a page be identified in the markup. Content that mixes languages is nearly universal, since any site writing in Spanish will borrow English terms, and any site writing in English does the same in the other direction. That language-mixing fails this criterion silently, and most sites have no mechanism in place to fix it. Drupal 10 and later ship with a native solution in Core that requires no extra modules, and the gap between sites that comply and sites that fail is almost always just a matter of awareness.

The accessibility gap: foreign words

Accessibility now carries weight on two fronts at once. It improves SEO, and it is a legal requirement. Since the European Accessibility Act came into force in June 2025, meeting WCAG level AA stopped being a good practice and became a legal must for any web project.

One of the most frequent mistakes when authoring content sits right at this intersection: using a word or expression from another language without identifying or marking it semantically. The most common case is writing in your main language and reaching for loanwords. A text in Spanish borrows…

Druxt (for Drupal) 1.3.x; the resource list is yours

Posted by Stuart Clark (Deciphered) - 9 Sep 2026 at 09:30 UTC

Druxt's Drupal module carries a list of twelve JSON:API resources it answers for. It's been the same twelve since 2021, hardcoded in a PHP array, and changing it has meant carrying a patch.

1.3.0, tagged today, makes that list yours. The twelve stay exactly as they are, so nothing a site exposes changes when it updates. What is new is being able to choose, and the first thing I would choose is the one my frontend has always had to guess at: the toolbar an administrator configured for a text format.

A CORS default ships in the same release. If you keep a proxy rule in front of your frontend so that authenticated calls succeed, this is the release where you delete it.

Continue reading →

Drupal AI Context — beta 5 released

Posted by Salsa Digital - 9 Sep 2026 at 06:45 UTC
Beta 5 release of Drupal AI Context Beta 5 of Drupal AI Context , also known as Context Control Center (CCC), is now available. This is expected to be the final beta release, and an RC 1 release should be available soon. CCC helps Drupal sites provide governed, reusable context for AI workflows and agents, from brand voice and editorial standards to organisational knowledge and governance rules. This gives AI systems access to more structured and relevant information while allowing teams to manage that information centrally. Following the beta 4 release , beta 5 has been shaped by extensive community testing and an expanded scope. The community testing revealed refinements for a more intuitive user experience, and several features earmarked for 1.1 have been brought forward into 1.0.

ExperienceKit: AI Content Governance - A Practical Framework for Digital Teams

Posted by Cheppers - 9 Sep 2026 at 00:00 UTC
Somewhere in your organization, someone put AI-generated content on your website this week. Nothing marks those pages as AI-generated, and no record exists of which tool produced them, from what prompt, or who checked the result before it went live. Closing that gap is what AI content governance is about.

Vibing Drupal: Switching from "Brat mode" to "Drupal mode"

Posted by Jacob Rockowitz - 8 Sep 2026 at 21:37 UTC

As I've been experimenting with different AI models, I've observed varying behaviors. For example, I like the price point and the reasonable output from GPT-6 Luna. On Reddit, many people recommend running it at max, so I tried it. I assumed Luna Max would yield better results. Instead, it would take an unreasonable amount of time to respond, with not much better code. Because I am using AI as a coding assistant, speed matters. Luna Max may be better suited for autonomous coding agents.

I'm starting to feel like I have to track different models and modes, as if I were on a dating app looking for someone I'd be compatible with. Yes, I am humanizing AI, even though it is just an advanced pattern-recognition machine. Still, I recently discovered that AI can get stubborn and enter "Brat mode."

Brat mode

On one of the many AI-related podcasts I was listening to, someone shared a tip: if your AI gets stubborn and frustrating, clear the context and start a new session. Their theory was that the AI gets locked in a negative feedback loop and, instead of trying to please you, it leans into frustrating you. I am calling this "Brat mode."

I ran into "Brat mode" while trying to fix a simple report with duplicate records that needed a minor query tweak and some display adjustments. My prompt was matter-of-fact, but the AI would still make one change and then revert another. I caught myself asking the AI, "Why did you revert our recent changes? Please restore them," and the AI failed to explain or fix the problem. It felt like I was dealing with a stubborn child who was enjoying my frustration. Yep, I got frustrated. Fortunately, I knew better than to play this game, so I had the AI create a slightly better prompt, started a new session using the improved prompt, and the AI fixed the issue immediately.

Read more

simplytest.me should be good enough to sell Drupal with

Posted by Matt Glaman - 8 Sep 2026 at 13:00 UTC

simplytest.me had been sitting in the back of my mind for a long time. I knew it was unstable, and that release information kept falling out of date. It was a constant battle that always needed another round of maintenance, and it kept sliding.

Then Ryan Szrama wrote about someone cold calling the Centarro phone number looking for a way to sell online. Commerce Kickstart already did what the caller needed, so instead of selling him an engagement, Ryan pointed him to simplytest.me to try it.

Get your content cited by AI engines and get back that traffic you just lost. Read this AEO/GEO playbook to find out how.

Posted by Specbee - 8 Sep 2026 at 11:05 UTC
Get your content cited by AI engines and get back that traffic you just lost. Read this AEO/GEO playbook to find out how.

We chose to help build Drupal's future. Today, that choice became visible.

Posted by Dominique De Cooman - 8 Sep 2026 at 10:57 UTC
Read more

In April 2025, there was no Top Tier badge in the plan. There was a conviction that Drupal needed coordinated investment in AI. Today, Dropsolid's recognition makes that choice visible.

What Top Tier really means

Dropsolid is now listed as a Top Tier Drupal Certified Partner. I am genuinely proud of that. Not simply because we have reached the highest level in the Drupal Certified Partner Program, but because of what this recognition measures.

We chose to help build Drupal's future. Today, that choice became visible.

drupalTuesday, September 8, 2026 - 12:57

Uploads Ride in the Boot

Posted by Omega8.cc - 8 Sep 2026 at 10:54 UTC
The code of a Drupal or Backdrop site is the part everyone rebuilds, upgrades and throws away with a light heart; the uploads are the part nobody plans for, and they are the only part which cannot be downloaded again tomorrow. On a BOA server the files and private directories live outside the codebase, in the account's own store, with two symlinks in the site pointing there, so a platform rebuild, a core update or a move to a newer codebase never touches them, a clone gets a real copy of its own, a rename carries them along, a restore sets the old content aside instead of deleting it, and a delete moves the site's uploads into a dated archive, never removes them, and never blocks reusing the name. Every move is dry-run first, refused when the disk is short, and written down; the one thing the machine will not do on its own is delete your uploads, and the one thing it cannot stop is the store growing.

Pages

Subscribe with RSS Subscribe to Drupal.org aggregator - Planet Drupal