Skip Navigation

Posts
3
Comments
103
Joined
3 yr. ago

  • I use beets to add synced lyrics to my library automatically.

    To display them in the web browser interface, click the lyrics button (looks like a book).

  • Have you explored any other options?

    Yeah. I briefly explored some other possibilities in the post, including a potential self-hosted option, but ultimately landed on CF as a practical compromise.

  • Crowdsec does it by using crowd-sourced blocklists (hence the name). So if an IP triggers a scenario on other machines, that malicious address will be proactively added to your blocklist before it ever gets a chance to impact your machine.

    That is the big advantage of crowdsec over reactive-only solutions, like fail2ban.

  • What is the advantage of this over just dropping HTML files onto a USB drive?

  • Not often, but there's a niche. I wish I could remember the details, but I saw someone earlier this year that was hosting a public BBS on a c64.

  • Same experience. 🫤

  • Personally, whenever I need to process anything text-based, I use perl.

    Read the json into a hash, parse the values if desired, then plug the values into an html template.

    It's pretty quick to write, much easier to learn than python (in my opinion), and super powerful.

  • I'm a bit torn on the hardware bit, myself.

    On one hand, hardware is a fundamental aspect of self hosting. There's already a portion of the community who considers self-hosting to include using commercially-hosted cloud services (as long as it's not Google), so prohibiting hardware discussion just reinforces that concept. Plus, it can be really fun to see what creative hardware people come up. I'm pretty sure I posted about my Fediverse server running on a WiFi router here, for example. The focus was on the unusual hardware, but it was also clearly related to self-hosting.

    On the other hand, looking at what is posted in other communities, I don't think there's a ton of value in seeing a dozen photos of a bone-stock rpi or a closed laptop sitting on a desk. Same with the nth post asking if their 30-year-old 1u would be a good choice for Jellyfin; so I see why the rule exists.

    Overall, though, I think hardware should be allowed, but maybe add a rule along the lines of "if you're posting a question, please include what resources you've already reviewed or troubleshooting steps you've already taken."

    Heck, that might be a good rule for all questions, regardless of topic...

  • The first one. The service is owned by root, but the application is running as an unprivileged system user.

  • Quadlets work like any other systemd service.

    You create the user/group you want to run as on the underlying system, then just specify that user/group in the quadlet file.

    If you look at my *arr examples, you can see the user and groups they're running as.

  • Podman quadlets can also auto-update and auto rollback, if needed.

  • Same here.

    Pulling doesn't work if you don't know when a system will be online, so it only makes sense for my laptop to push.

  • Seems to be specific to rewrites using an un-named capture.

    grep -rnE "\$[0-9.*].*\?" /etc/ngnix

    should show if you have any potentially vulnerable directives in your config.

  • I'll second podman quadlets. Good security, full integration with systemd, pods allow applications to easily share a namespace, and you can manage graphically through Cockpit if you really want to.

  • The only systems with ip6v in my network are Wi-Fi devices and my public-facing reverse proxy. I use a prefix delegated by my ISP.

    All of my non-public servers have ipv4 only.

  • I use Wireguard.

    For my phone, I use the "WG Tunnel" app: https://github.com/wgtunnel/android

    It's nice because it'll automatically enable/disable it as I move between networks.

    Before that, though I used the official client and I just kept it on 24/7. It's not like it uses extra data or battery or anything.

  • Selfhosted @lemmy.world

    A sneaky demonstration of the dangers of curl bash

    blog.k3can.us /posts/2026/feb/dontcurlbash/
  • Selfhosted @lemmy.world

    Running GoToSocial on an old wifi router