NixOS in LXC works great, although I switched to bare metal NixOS a few months ago. I didn't see the need for proxmox as it hindered my ability of declaring the whole system.
Creating NixOS LXC's is a bit of a pita. Some links that helped me two years ago:
"given the same source code, build environment and build instructions, any party can recreate bit-by-bit identical copies of all specified artifacts"
NixOS does not guarantee bit-by-bit identical results. NixOS hashes the inputs and provides a reproducible build environment but this does not necessarily mean the artifacts are identical.
E.g. if a build somehow includes a timestamp, each build will have a different checksum.
It's great to see another open source OIDC provider (with more features). I've set up Pocket ID which is awesome because of it's simplicity and it's great.
Yes. 127.0.0.0 is the localhost. This is the IP the container is listening on. Even if there was no firewall it wouldn't allow any connection except from the host. If it's set to 0.0.0.0 it means it'll allow connections from any IP (which might not be an issue depending on your setup).
The reverse proxy runs on localhost anyway, so any other IPs have no reason to ever have access.
Trying to actually restore is the best way to ensure the backup works. But it's annoying so I never do it.
I usually trust restic to do it's job. Validating that files are there and are readable can be done with restic mount, and you've mentioned restic check.
The best way to ensure your data is safe is to do a second backup with another tool. And keep your keys safe and accessible. A remote backup has no use of the keys burned down.
Sadly it's not possible to provide links using Firefox Translate. People would have to translate it themselves (i.e. opening in a browser and clicking translate). Depending on the device they likely wouldn't bother.
Agreed. In general people seem to like centralised platforms. They don't want to sign up on another site for a specific purpose. They stick to what they know unless there's good reason to change (mostly peer/ad/social media pressure I feel like).
In a way Lemmy is similar in that it's a single platform to access all types of content. Given most people don't care about the technical "how", I can see why they like Discord and Reddit.
I use Findroid for its great UI but also its ability to download and watch offline. It's a better experience and I was surprised Jellyfin Android didn't support it.
I wonder how much money Plex still makes through their lifetime purchases. Is it that they were struggling and then made bad business decisions with the aim on increasing revenue (ad supported video on demand)? Or was it the other way around?
In the 80s new systems usually came with new OSs, which required porting software it. Thus a lifetime license was practically limited.
I wouldn't be as opposed to a subscription model if it was cheaper and they focused on their actual core product, not all the other fluff around. 5€/m is a bit much given they don't pay for my bandwidth. And if they didn't store my media info, history etc...
To me there's a major difference depending on the cost of the provided service. I don't know what features crowdsec provides, but if it's mostly providing lists and all the blocking etc happens locally, I don't see how they lose much money on this free service. Gathering the lists is something they'd have to do anyway to service their paying customers.
If Cloudflare stopped making Cloudflare Tunnels free to use, I'd be more understanding since bandwidth costs them relevant amounts of money.
NixOS container is using systemd-nspawn/systemd container. Both are using Linux namespaces and cgroups.
A disadvantage of NixOS container is that it only supports rootful containers, i.e. root inside the container has the same privileges as root outside the container. This is also true for docker unless configured otherwise.
OCI containers (Docker, Podman) are often created by upstream themselves, which you might prefer.
I configure containers by using the podman backend (default) and virtualisation.oci-containers.conrainers, which supports rootless podman [1]. Imo rootless is the best and most secure way to run containers on NixOS.
Edit: I prefer NixOS packages if available and only use OCI (Docker) containers if not. The main reason being the simplified declarative configuration through NixOS options, which can also be used inside NixOS container.
Streamlining cross posting is a good idea, as long as someone actually read the post and posts it with a purpose. On second thought, I think cross posting is simple enough, given that titles are usually auto completed.
I'm generally against automatic cross posting bots, as they usually post duplicates, bad articles (instead of a proper source). Additionally, they often flood communities with an amount of content they are too small to handle. I.e. a lack of users to vote on posts let's good articles drown in a flood of mediocre posts. This can kill communities as they feel even more empty than with fewer posts but more comments.
If the person would answer almost instantly, 24/7, without being annoyed: Yes. Checking important information is easier once you know, what exactly to type.
NixOS in LXC works great, although I switched to bare metal NixOS a few months ago. I didn't see the need for proxmox as it hindered my ability of declaring the whole system.
Creating NixOS LXC's is a bit of a pita. Some links that helped me two years ago: