Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Selfhosted
  3. Selfhosting Sunday - What's up?

Selfhosting Sunday - What's up?

Scheduled Pinned Locked Moved Selfhosted
selfhosted
149 Posts 78 Posters 834 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • C [email protected]

    A LOT of plugins in many projects are a huge concern. I say this as someone who ran security for an OS for a while. It's just people making bad decisions for everyone and then hand-waving the risks when questioned.

    jagged_circle@feddit.nlJ This user is from outside of this forum
    jagged_circle@feddit.nlJ This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #126

    I dont mean the plugins themselves but the fact that there's no way to safely download a plugin.

    Even if the plugin really is benign, jellyfin will happily download something inauthentic and malicious befuarse there's no cryptographic signature checks

    1 Reply Last reply
    0
    • atheartengineer@lemmy.worldA [email protected]

      Maybe, i haven't seen it yet though

      jagged_circle@feddit.nlJ This user is from outside of this forum
      jagged_circle@feddit.nlJ This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #127

      I do it for music

      atheartengineer@lemmy.worldA 1 Reply Last reply
      0
      • T [email protected]

        What's up, what's down and what are you not sure about?

        Let us know what you set up lately, what kind of problems you currently think about or are running into, what new device you added to your homelab or what interesting service or article you found.

        G This user is from outside of this forum
        G This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #128

        I've been fending off AI bots the last week or so; wrote about it here:

        https://gerowen.substack.com/p/the-ai-data-scraping-is-getting-out

        T 1 Reply Last reply
        0
        • N [email protected]

          I think so.

          It is LXD + KVM, so way more and finer tune control on lxc instances. It can run OCI images as well, so for docker instances with only a few configs and no persistent storage, it is actually quite handy. For docker instances that need pretty complicated compose files, I just run docker inside an lxc for now, until I figure that out.

          gnulinuxdude@lemmy.mlG This user is from outside of this forum
          gnulinuxdude@lemmy.mlG This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #129

          Does Incus allow you to use a VM with a GUI? One thing that's nice about Proxmox is I have one VM with a very basic lxqt setup for when I need that, and I can either use remote-viewer + the spice protocol to access it or access it through the Proxmox web ui. That's been very handy.

          N 1 Reply Last reply
          0
          • ? Guest

            If at all possible see if you can do wireguard yourself. Tailscale is basically inserting a third party company for no reason as its just wireguard with their servers involved. For example if you can run opnsense its easy to get running via the GUI. Very rewarding!

            paequ2@lemmy.todayP This user is from outside of this forum
            paequ2@lemmy.todayP This user is from outside of this forum
            [email protected]
            wrote on last edited by
            #130

            Any resources you'd recommend?

            1 Reply Last reply
            0
            • S [email protected]

              Power loss protection on SSDs is an interesting addition I hadn't come across before.

              We live in a very windy area and power blinks are common. A high endurance MicroSD was in use the first time the Pi wouldn't boot, but I was in town and it was just annoying. It was a big issue when the Pi wouldn't boot from the SSD while I was out of the country.

              We don't have high bandwidth demands so any decent OpenWRT router works fine and supports both Adguard Home and Wireguard. What I really like about putting WG in particular on the router is that if the router is up, WG is working, and the routers come back up without fail after every power outage. A 2nd Wireguard instance still runs on my Pi but since switching to WG on the router a year ago there hasn't been a reason to even connect to it.

              My problems with the Pi had me looking for other solutions and I ended up with a mini Dell laptop running Debian. (Can't easily run WG on it due to some software conflicts.) It alleviates the need for a UPS and runs for 6+ hours if the power goes out, rather the minutes provided by my small UPS.

              One of these days I'll find a bogus reason to talk myself into upgrading the router with more powerful hardware. Mikrotik looks like a great option and I'll take a look at RouterOS. Thanks for the info.

              R This user is from outside of this forum
              R This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #131

              RouterOS has WG built in as well as ZeroTier. RouterOS has become quite powerful lately, but make sure you have at least an ARM/ARM64 CPU for it.

              1 Reply Last reply
              0
              • T [email protected]

                What's up, what's down and what are you not sure about?

                Let us know what you set up lately, what kind of problems you currently think about or are running into, what new device you added to your homelab or what interesting service or article you found.

                A This user is from outside of this forum
                A This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #132

                I've setup Nextcloud on Hetzner, and have ordered a mini PC to run Immich and experiment with.

                Still trying to decide on a good cheap email host that I can also move my family on to eventually.

                ? 1 Reply Last reply
                0
                • gnulinuxdude@lemmy.mlG [email protected]

                  Does Incus allow you to use a VM with a GUI? One thing that's nice about Proxmox is I have one VM with a very basic lxqt setup for when I need that, and I can either use remote-viewer + the spice protocol to access it or access it through the Proxmox web ui. That's been very handy.

                  N This user is from outside of this forum
                  N This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #133

                  It can manage KVM, so I don't see why not .

                  1 Reply Last reply
                  0
                  • A [email protected]

                    I've setup Nextcloud on Hetzner, and have ordered a mini PC to run Immich and experiment with.

                    Still trying to decide on a good cheap email host that I can also move my family on to eventually.

                    ? Offline
                    ? Offline
                    Guest
                    wrote on last edited by
                    #134

                    I recently moved from Gmail to mailbox.org with my own domain. Works as it should so far. And for 2.5€ per month I can't complain about the price either.

                    And switching email addresses has actually been less painful than I expected. Most services let you change the associated Mail easily.

                    1 Reply Last reply
                    0
                    • I [email protected]

                      Shoutout to @Estebiu for helping me appreciate the joy of docker compose. I got to set up Navidrome and it's been great!

                      With that said, I have a security-related question: at what point in self-hosting am I exposed to the outside internet that warrants things like reverse proxies and other security measures? I'm currently typing router IPs (e.g. 192.168.x.x) to access the services, so is my machine exposed if the only people intending to connect are local on our wireless network?

                      Y This user is from outside of this forum
                      Y This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #135

                      There's nothing wrong with making a reverse proxy only for use inside your homelab. It's one way to resolve internal DNS queries and give addresses to your services. It's perhaps the best, because it's the only way I know that doesn't necessitate remembering port numbers.

                      E.g. You are hosting something at 192.168.1.20 on port 3310. Even if you set a local DNS record for pihole.itjust.donn to resolve to 192.168.1.20, you'll still have to type pihole.itjust.donn:3310 to access it. The same isn't true with a reverse proxy.

                      I 1 Reply Last reply
                      0
                      • jagged_circle@feddit.nlJ [email protected]

                        I do it for music

                        atheartengineer@lemmy.worldA This user is from outside of this forum
                        atheartengineer@lemmy.worldA This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #136

                        Damn ok that sucks it doesn't seem available on the client for apple tv.

                        jagged_circle@feddit.nlJ 1 Reply Last reply
                        0
                        • ironkrill@lemmy.caI [email protected]

                          I see it in the default WebUI, perhaps whatever app you're using doesn't support it?

                          atheartengineer@lemmy.worldA This user is from outside of this forum
                          atheartengineer@lemmy.worldA This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #137

                          Ya I don't think it's supported on the apple tv app. Damn.

                          1 Reply Last reply
                          0
                          • atheartengineer@lemmy.worldA [email protected]

                            Damn ok that sucks it doesn't seem available on the client for apple tv.

                            jagged_circle@feddit.nlJ This user is from outside of this forum
                            jagged_circle@feddit.nlJ This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #138

                            Yeah I dont know why any Dev wouldn't choose a cross platform framework

                            atheartengineer@lemmy.worldA 1 Reply Last reply
                            0
                            • T [email protected]

                              What's up, what's down and what are you not sure about?

                              Let us know what you set up lately, what kind of problems you currently think about or are running into, what new device you added to your homelab or what interesting service or article you found.

                              presi300@lemmy.worldP This user is from outside of this forum
                              presi300@lemmy.worldP This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #139

                              Finished my migration from Plex to Jellyfin

                              1 Reply Last reply
                              0
                              • jagged_circle@feddit.nlJ [email protected]

                                Yeah I dont know why any Dev wouldn't choose a cross platform framework

                                atheartengineer@lemmy.worldA This user is from outside of this forum
                                atheartengineer@lemmy.worldA This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #140

                                I've never done dev for apple stuff, but I think it's probably just not that friendly with more open/cross platform frameworks

                                1 Reply Last reply
                                0
                                • T [email protected]

                                  What's up, what's down and what are you not sure about?

                                  Let us know what you set up lately, what kind of problems you currently think about or are running into, what new device you added to your homelab or what interesting service or article you found.

                                  B This user is from outside of this forum
                                  B This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #141

                                  Was using realvnc to vnc from remote, it was easy and cloud driven.

                                  Fully swapped to tailscale and normal VNC sever now.

                                  Performance is good and works great for the troubleshooting and small GUI stuff I need to do.

                                  1 Reply Last reply
                                  0
                                  • P [email protected]

                                    Debatting with myself and to a lesser degree what to do in terms of our homeserver situation.
                                    While the proxmox node has more than enough CPU and RAM capacity left, the NAS, an older Synology, is full to the brim, EOL and needs replacement.And sadly being a mini PC the proxmox node is unable to get the HDs connected.

                                    So something new is needed and I would rather have my setup streamlined and combine the two.

                                    But that is... More difficult than anticipated.
                                    I really would like something power saving with ECC ram that can take at least two PCI-e (SFP+ and a potential graphic card for AI later on). That can take 4,better 6 HDs. And at least one,better two NVMe.
                                    ...that basically means self building which I am happy with, but all current builds I calculate come out somewhere south of 2000€ (including two new HDs, as two old ones need to go).
                                    And that's sadly out of the financial possibility at the moment.

                                    If only the fucking Ugreen (DXP6800)would support ECC. While not ideal in terms of PCI-e it would be enough to do the trick.

                                    P This user is from outside of this forum
                                    P This user is from outside of this forum
                                    [email protected]
                                    wrote on last edited by
                                    #142

                                    I use a little mini PC with a DAS connected via USB. So you don't need to go full server to expand the storage.

                                    P 1 Reply Last reply
                                    0
                                    • P [email protected]

                                      I use a little mini PC with a DAS connected via USB. So you don't need to go full server to expand the storage.

                                      P This user is from outside of this forum
                                      P This user is from outside of this forum
                                      [email protected]
                                      wrote on last edited by
                                      #143

                                      That's a bit below the level of reliability I need,sadly - before doing that I could also go for a non ECC solution.

                                      1 Reply Last reply
                                      0
                                      • G [email protected]

                                        I've been fending off AI bots the last week or so; wrote about it here:

                                        https://gerowen.substack.com/p/the-ai-data-scraping-is-getting-out

                                        T This user is from outside of this forum
                                        T This user is from outside of this forum
                                        [email protected]
                                        wrote on last edited by
                                        #144

                                        Interesting writeup, thanks! I thought maybe dropping connections with those user agents would be the best but idk. My sites have not been targeted yet fortunately.

                                        G 1 Reply Last reply
                                        0
                                        • Y [email protected]

                                          There's nothing wrong with making a reverse proxy only for use inside your homelab. It's one way to resolve internal DNS queries and give addresses to your services. It's perhaps the best, because it's the only way I know that doesn't necessitate remembering port numbers.

                                          E.g. You are hosting something at 192.168.1.20 on port 3310. Even if you set a local DNS record for pihole.itjust.donn to resolve to 192.168.1.20, you'll still have to type pihole.itjust.donn:3310 to access it. The same isn't true with a reverse proxy.

                                          I This user is from outside of this forum
                                          I This user is from outside of this forum
                                          [email protected]
                                          wrote on last edited by
                                          #145

                                          This is good to know because I'm learning about nginx currently, so I'm glad it has practical use without opening up my network 🤘

                                          Y 1 Reply Last reply
                                          0
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups