There have been multiple accounts created with the sole purpose of posting advertisement posts or replies containing unsolicited advertising.

Accounts which solely post advertisements, or persistently post them may be terminated.

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Networking Gear Recommendations? (starting from scratch)

Hi, I hope its appropriate to ask this here, considering this is the most active community closest to this topic (Networking). I am moving places shortly and will need to start from scratch will all networking equipment. Including router and wifi-extenders. Am wondering what the general consencus is around networking gear, what...

TheHolm ,
@TheHolm@aussie.zone avatar

Stay with TP-Link. Ubiquity done some strange things recently.

TheHolm ,
@TheHolm@aussie.zone avatar

I do not see why it will cause any problems with exception of stacking mapping layer. I wonder can LVM do it natively without adding intermediate block device of 2 x 2G?

Have you ever bough an external hardrive only to take the disk out of it?

Hiya, so am looking to buy more storage and while browsing am seeing some external harddisks, such as Western Digital My Book and Seagate Expansion Desktop for cheaper than the internal harddisks themselves. Have seen this one video from KTZ Systems where he bought up multiple of these external ones just to open them up and use...

TheHolm ,
@TheHolm@aussie.zone avatar

Why create yourself a headache and still get substandard and no-warranty drive. If you want cheaper drives go for reconditioned/refurbished/used drives. Same risks, better product. Old enterprise SAS drives are cheap and many still have plenty of heath in them.

TheHolm ,
@TheHolm@aussie.zone avatar

Many sells, some just wipe them, some just contains encrypted data. If you happy with just used drive eBay is full of surprises.

TheHolm ,
@TheHolm@aussie.zone avatar

Some diagram would help. Are you trying to use your server as a switch?

TheHolm ,
@TheHolm@aussie.zone avatar

Do you plan to compress video ( which generally already compressed format) when saving to remote location? I do not see use case for it, as you ether use lossless compression and not compressing it in any meaningful way, or just re-encode to different format and loose quality. Second option is simpler to achieve by re-encoding before sending out.

How much does it matter what type of harddisk i buy for my server?

Hello, I’m relatively new to self-hosting and recently started using Unraid, which I find fantastic! I’m now considering upgrading my storage capacity by purchasing either an 8TB or 10TB hard drive. I’m exploring both new and used options to find the best deal. However, I’ve noticed that prices vary based on the specific...

TheHolm ,
@TheHolm@aussie.zone avatar

Yes, it will. Will it make any difference for you, depends of what are you doing. I would not use surveillance drive in to server, they are way too specific. Outside of that prices is pretty much same per TB/(Warranty Year) accross the board.

I done some excessive research couple of years back on the topic. you can find it here blog.holms.place/…/hdd-storage-cost-comparation-m…. I do not think situation have changed match since than. Price per TB/Year is nearly constant past 8GB size.

Also consider looking to re-certified drives, or even refurbished drives. you may save hips on them. But it depends on how much you value your data, how much redundancy in you storage pool and how good your backup strategy.

TheHolm ,
@TheHolm@aussie.zone avatar

Syncthing sync files, it is all does.

TheHolm ,
@TheHolm@aussie.zone avatar

Usually just plug/unplug couple of times is enough. No fancy chemicals.

TheHolm ,
@TheHolm@aussie.zone avatar

Look to other orchestrations solution too, like SALT. If you need to manage a lot of servers it is live saver. Setting up is only first step.

TheHolm ,
@TheHolm@aussie.zone avatar

Run long smart test on the disk and check smart data after that. Other possibility is ZFS pool is nearly full.

TheHolm ,
@TheHolm@aussie.zone avatar

Depends what are you doing. Something like keep base os patched is pretty much nil efforts. Some apps more problematic than others. Home Assistant is always a pain to upgrade and something like postfix is requires nearly 0 maintenance.

TheHolm ,
@TheHolm@aussie.zone avatar

circular dependency seems to be the case. I guess adding second external resolver to /etc/resolve.conf will help. Second entry will not be used unless first one ( pi-hole) is responding. But it need to be tested.
BTW, why do you want to send host’s DNS via pihole?

TheHolm , (edited )
@TheHolm@aussie.zone avatar

what exactly do you mena under subdomains? Any DNS provider will support adding NS entries for subdomains if you want to host you sub-zone somwhere, And any should allow you to use names with “.” in it for “fake” subzone, like
a.subzone1 IN A x.x.x.x
a.subzone2 IN A y.y.y.y

TheHolm ,
@TheHolm@aussie.zone avatar

Try VyOS. I run it on APU2 myself. No GUI no convolution.

TheHolm ,
@TheHolm@aussie.zone avatar

Open source projects need to make money somehow. I found VyOS method quite acceptable. They giving good instruction and tools to build your own stable ISO. So do not be lazy or contribute somehow. Unfortunately their paid support costs too much. I was considering trying to push VyOS to be used as virtual router at my work, but it costs more than Cisco C8000v

TheHolm ,
@TheHolm@aussie.zone avatar

nope, it is very deeply customized debian. Need to be installed from scratch.

TheHolm ,
@TheHolm@aussie.zone avatar

Very strange line from specs.
USB Driver Windows XP/7/8/10/11, Linux (driver free on Raspberry Pi Raspbian system)
Does it mean binary blob driver only? and you need to pay for it to use it on PC?

TheHolm ,
@TheHolm@aussie.zone avatar

using wildcards is really bad security practice. and at age of ACME absolutely unnecessary.

TheHolm ,
@TheHolm@aussie.zone avatar

If you still use HTTP for cert verification on ACME, you are doing it wrong. Use DNS-01 only, there is no need to allow any inbound traffic to your servers. and HTTP will not give you wildcard anyway.

TheHolm ,
@TheHolm@aussie.zone avatar

Stable is not “pay only” . Just build it yourself, all tools are available. it will take 30 minutes of your time if you have docker environment ready.

TheHolm ,
@TheHolm@aussie.zone avatar

VyOS: Debian based router + firewall. Linux makes it easier for people to pick up the CLI but I’ve heard complaints about it being difficult to follow. Currently CLI only, at least without third-party solutions, but is powerful and competes directly with OPNsense for features for the most part. Seems to be just as stable. my mistake, FOSS version is not LTS but a rolling release and needs to be compiled.

Very misleading statement. Both rolling and LTS are FOSS, they just do not provide LTS binaries for free. Want LTS? build it yourself , all tools and guides(bit outdated) is out there. It will took 30 min you your time to setup.

TheHolm ,
@TheHolm@aussie.zone avatar

Sorry, what do yo want to know? IT just a linux based router pretended to be a juniper FW. NAT/IPv6/PPPoE/VRFs are working as expected.

TheHolm ,
@TheHolm@aussie.zone avatar

No HA. Classic HA is evil, shared control plane is good way to loose both FWs. Need redundancy use 2 independent FW + routing protocols. Losing session states during fail-over is not a big problem these days. I did in-place upgrades, but I’m running LTS and not yet done any major version upgrades. So far no problems.

TheHolm ,
@TheHolm@aussie.zone avatar

All of them not equate in same league. Do you know any type 1 free supervises out there? Xen probably.

TheHolm ,
@TheHolm@aussie.zone avatar

Are you running it natively as “jail” ?

TheHolm ,
@TheHolm@aussie.zone avatar

Do not try to host outbound mail on residential IP blocks, delivery will be really bad. Cheap VPS is same story. You best bet is VPS from some not well know provider, they may be avoid to be in blacklist in M$ and Google. Inbound mail is fine anywhere as so long as you can have port 25 open. DDNS works too.

TheHolm ,
@TheHolm@aussie.zone avatar

I do not understand why everyone calling hosting email difficult? IT is like 5 RFC you need to read and implement. Sofware wise you will need mail agent, something for DKIM ( if it not build in in agent), “local delivery agent” ( probably presenting it as IMAP) + mail reader of your choice. Nothing too complex

TheHolm ,
@TheHolm@aussie.zone avatar

Can you promise a near 100% uptime? Otherwise, some email might not reach you. Just lol. Mail get queued just fine by everyone. If you really concern , setup second MX.

TheHolm ,
@TheHolm@aussie.zone avatar

Just weight your risks. Old drives can fail early, and enterprise drives consume more power. Old drives probably not for mirrors or RAID5. RAID6 and spare HDD on shelf may save your data one day. It is a lottery.

TheHolm ,
@TheHolm@aussie.zone avatar

Specks lookg good, Intel NIC, semi decent CPU. I would say it is even overspec for a router.

TheHolm OP ,
@TheHolm@aussie.zone avatar

Thank you. Intel now offer ECC on top processors like i7 and i9. It is a news development. Now biggest problem is to find motherboard supporting ECC.

TheHolm OP ,
@TheHolm@aussie.zone avatar

It is an option. But used from Ali? I’m not sure that I would trust them with my data.

TheHolm ,
@TheHolm@aussie.zone avatar

could you please elaborate? what is SFF hardware?

Should I move to Docker?

I’m a retired Unix admin. It was my job from the early '90s until the mid '10s. I’ve kept somewhat current ever since by running various machines at home. So far I’ve managed to avoid using Docker at home even though I have a decent understanding of how it works - I stopped being a sysadmin in the mid '10s, I still worked...

TheHolm ,
@TheHolm@aussie.zone avatar

Try other container technologies lie LXC or go right side and play with FreeBSD jails. Quality of dockers you can find around is horrendous, giving that Docker itself build for convenience not security. It is not something I will trust.

TheHolm ,
@TheHolm@aussie.zone avatar

HIkvision is great. Good value for money. Just do not use the app to configure them, use web gui. And yes, they need to be isolated from rest of network and the internet ( as pretty much any cameras).

Stuck behind nat, any way to get wireguard working?

Is there any possibility to get wireguard working to access my raspberry pi from outside my home? I’ve port forwarded the wireguard udp port and it doesn’t work… Likely because I’m behind a NAT. My wan public ip is like 10.x.x.x which is most likely a private ip. Running tailscale for now

TheHolm ,
@TheHolm@aussie.zone avatar

Just get VPS and use it to bounce traffic between nodes.

TheHolm ,
@TheHolm@aussie.zone avatar

But it usably getting dry over time and you can’t remove it cleanly.

TheHolm ,
@TheHolm@aussie.zone avatar

Blu Tac?

Wander , (edited ) to selfhosted
@Wander@packmates.org avatar

The future of selfhosted services is going to be... Android?

Wait, what?

Think about it. At some point everyone has had an old phone lying around. They are designed to be constantly connected, constantly on... and even have a battery and potentially still a SIM card to survive power outages.

We just need to make it easy to create APK packaged servers that can avoid battery-optimization kills and automatically configure an outbound tunnel like ngrok, zerotrust, etc...

The goal: hosting services like , , !? should be as easy as installing an APK and leaving an old phone connected to a spare charger / outlet.

It would be tempting to have an optimized ROM, but if self-hosting is meant to become more commonplace, installing an APK should be all that's needed. can do SSH, VPN and other tunnels without the need for root, so there should be no problem in using tunnels to publicly expose a phone/server in a secure manner.

In regards to the suitability of home-grade broadband, I believe that it should not be a huge problem at least in Europe where home connections are most often unmetered: "At the end of June 2021, 70.2% of EU homes were passed by either FTTP or cable DOCSIS
3.1 networks, i.e. those technologies currently capable of supporting gigabit speeds."

Source: https://digital-strategy.ec.europa.eu/en/library/broadband-coverage-europe-2021

PS. syncthing actually already has an APK and is easy to use. Although I had to sort out some battery optimization stuff, it's a good example of what should become much more commonplace.

cc: @selfhosted

TheHolm ,
@TheHolm@aussie.zone avatar

Ethernet is not a problem. Plug USB-to-Ethernet adapter to your phone ( there are some requirements to both) , and you will be surprised.

TheHolm ,
@TheHolm@aussie.zone avatar

Is it tame for selfhosted to switch to DANE?

TheHolm ,
@TheHolm@aussie.zone avatar

Symphonium is another good mobile client.

TheHolm ,
@TheHolm@aussie.zone avatar

you can always add Makefile to traverse directories.

TheHolm ,
@TheHolm@aussie.zone avatar

Do not access volumes directly on filesystem. path may change. If you need access data on a volume just spawn temporary container an mount that volume.

TheHolm ,
@TheHolm@aussie.zone avatar

Damn, I’m doing *nixes for nearly 30 years. But never went to that level of minimalism. Nice trick.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • lifeLocal
  • goranko
  • All magazines