Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)A
Posts
6
Comments
100
Joined
3 yr. ago

  • Grayjay by FUTO has been working well for me

  • A few reasons

    1. My partner has plenty of hobbies but sys-admin isn't one of them. I know I'll show them how to turn off wireguard to troubleshoot why "the internet isn't working" but eventually they would forget. Shit happens, sometimes servers go down and sometimes turning off wireguard would allow the internet to work lol
    2. I'm a worrier. If there was an emergency, my partner needed to access the internet but couldn't because my DNS server went down, my wireguard server went down, my ISP shit the bed, our home power went out, etc., and they forgot about the VPN, I'd feel terrible.
    3. I was a little too ambitious when I first got into self hosting. I set up services and shared them before I was ready and ended up resetting them constantly for various reasons. For example, my Plex server is on it's 12th iteration. My partner is understandably weary to try stuff I've set up. I'm at a point where I don't introduce them to a service I set up unless accessing it is no different than using an app (like the Homeassistant app) or visiting a website. That intermediary step of ensuring the VPN is on and functional before accessing the service is more than I'd prefer to ask of them

    Telling my partner to visit a website seems easy, they visit websites every day, but they don't use a VPN everyday and they don't care to.

  • Thanks for the info, I appreciate it

  • awesome, thanks for the info

  • That's interesting, I didn't know that was a thing. I'll look into it, thanks!

  • I know I should learn NixOS, I even tried for a few hours one evening but god damn, the barrier to entry is just a little too high for me at the moment 🫤

  • I appreciate the info, thanks

  • Ok so I currently have a cert set up to work with:

    domain.com

    www.domain.com (some browsers seemingly didn't like it if I didn't have www)

    subdomain.domain.com

    Are you saying I could just configure it like this:

    domain.com

    *.domain.com

    The idea of not having to keep updating the cert with new subdomains (and potentially break something in the process) is really appealing

  • Do you mind giving a high level overview of what a Cloudlfare tunnel is doing? Like, what's connected to what and how does the data flow? I've seen cloudflare mentioned a few other times in the comments here. I know Cloudflare offers DNS services via their 1.1.1.1 and 1.0.0.1 IPs and I also know they somehow offer DDoS protection (although I'm not sure how exactly. caching?). However, that's the limit of my knowledge of Cloudflare

  • I've run into a weird issue where on my phone, tailscale will disconnect and refuse to reconnect for a seemingly random amount of time but usually less than hour. It doesn't happen often but it is often enough that I've started to notice. I'm not sure if it's a network issue or app issue but during that time, I can't connect to my services. All that to say, my tolerance for that is higher than my partner's; the first time something didn't work, they would stop using it lol

  • You don’t even have to worry about setting up SSL on every individual service

    I probably need to look into it more but since traefik is the reverse proxy, doesn't it just get one ssl cert for a domain that all the other services use? I think that's how my current nginx proxy is set up; one cert configured to work with the main domain and a couple subdomains. If I want to add a subdomain, if I remember correctly, I just add it to the config, restart the containers, and certbot gets a new cert for all the domains

  • there's so many acronyms. Thanks

  • wildcard let’s encrypt cert

    I know what "wildcard" and "let's encrypt cert" are separately but not together. What's going on with that?

    How do you have your tailscale stuff working with ssl? And why did you set up ssl if you were accessing via tailscale anyway? I'm not grilling you here, just interested.

    I know enough about security to know that I don’t know enough to secure against much anything

    I feel that. I keep meaning to set up something like nagios for monitoring and just haven't gotten around to it yet.

  • "NPM" node package manager?

    1. Yeah I've been playing around with docker and a domain to see how all that worked. Got the subdomains to work and everything, just don't have them pointing to services yet.
    2. I'm definitely interested in the authentication part here. Do you have an tutorials you could share?
    3. Will do, thanks
    4. ❤️

    I don't know how markdown works. that should be 1,3,4,5

  • I currently have a nginx docker container and certbot docker container that I have working but don't have in production. No extra features, just a barebones reverse proxy with an ssl cert. Knowing that, I read through Caddy's homepage but since I've never put an internet facing service into production, it's not obvious to me what features I need or what I'm missing out on. Do you mind sharing what the quality of life improvements you benefit from with Caddy are?

  • Damn, I didn't realize they had public logs like that. Thanks for the heads up

  • I've played around with reverse proxies and ssl certs and the easiest method I've found so far was docker. Just haven't put anything in production yet. If you don't know how to use docker, learn, it's so worth it.

    Here is the tutorial I used and the note I left for myself. You'll need a domain to play around with. Once you figure out how to get NGINX and certbot set up, replacing the helloworld container with a different one is relatively straight forward.

     
        
    DO NOT FORGET, you must give certbot read write permissions in the docker-compose.yml file which isn't shown in this tutorial
    -----EXAMPLE, NOT PRODUCTION CODE----
    
        nginx:
            container_name: nginx
            restart: unless-stopped
            image: nginx
            depends_on:
                - helloworld
            ports:
                - 80:80
                - 443:443
            volumes:
                - ./nginx/nginx.conf:/etc/nginx/nginx.conf
                - ./certbot/conf:/etc/letsencrypt:ro
                - ./certbot/www:/var/www/certbot:ro
    
        certbot:
          image: certbot/certbot
          container_name: certbot
          volumes: 
            - ./certbot/conf:/etc/letsencrypt:rw
            - ./certbot/www:/var/www/certbot:rw
          command: certonly --webroot -w /var/www/certbot --keep-until-expiring --email *email* -d *domain1* -d *domain2* --agree-tos
    
      

  • They make display port cables without the locking feature. I don't have a link unfortunately but I have a few in my box of cables that I'm definitely going to use one day

  • Interesting. Well, when you get some numbers together, I'd be interested to see what you find out