Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)B
Posts
38
Comments
142
Joined
3 yr. ago

  • I personally use my home lab to test and learn, and I try to mimic a corporate environment. I have multiple instances of DNS, proxy, etc and I have a "prod" and a separate "staging" k8s environment. I try as much as possible, without going nuts about it, to update and try new changes that might be breaking in the staging cluster.

  • Right, but I have wireguard on my opnsense. So when I want to reach https://jellyfin.example.com/ , if I am at home, it goes phone -> DNS -> proxy -> jellyfin (on the same network). If I am connected to the VPN, it goes from phone -> internet -> opnsense public ip -> wireguard subnet -> local subnet -> DNS -> proxy -> jellyfin. I see some unneeded extra steps here... Am I wrong?

  • Oh, I get that, but it just doesn't make any sense to me to be physically next to the server, and connect to it via VPN...

  • My network is not publicly accessible. I can only access the internal services while connected to my VPN or when I'm physically at home. I connect to WG to use the local DNS (pihole) or to access the selfhosted stuff. I don't need to be connected while I'm at home... In a way, I am always using the home DNS.

    Maybe I'm misunderstanding what you're saying...

  • I can stay connected, still works, but I don't think I need the extra hoops.

  • I also have a different subnet for WG. Not sure I understand what you're saying...

  • Same, wireguard with the 'WG Tunnel" app, which adds conditional Auto-Connect. If not on home wifi, connect to the tunnel.

  • It was rather recent for me, a couple months ago. I have trouble sleeping in general, but during a really stressful period at work, I had no sleep for about 49h, then 2h of sleep, then no sleep again for about 17h. I was pretty messed up.

  • I immediately ordered a new one from another vendor, as I really needed to build a workstation, and let the purchasing department handle the case. All I know was that the seller did not believe/accept the "wrong cpu story". From their perspective, it was a sealed box...

  • It happened to me a few years ago, when I ordered for work an i9 9900k, and inside the sealed box was a core 2 duo... After the seller (not Amazon) refused the return, I looked up a bit online, and it's a common practice. I even found rolls of "Intel original" seals for 5€ on eBay.

  • 60k stars for a free open source self hosted project? I'd say that's a really healthy number. Jellyfin has 37k.

  • I did have backups, it was an easy fix. I had a pihole -up on a crontab for years, probably not the best idea :)

    FW rule accept :53 from pihole only, deny :53 from all. I had some devices with hardcored DNS settings (8.8.8.8).

  • Pihole 6 broke my DNS (dnsmasq), and since I had a fw rule in opnsense to only use pihole's DNS, and deny public DNS access, it was an early rise for me :)

  • Why not just use forgejo's actions and runner?

  • They've owned it since 2011. When they did buy it, they had Lync, which sucked pretty bad. Now they have Teams, probably the result of merging Lync and Skype.

  • I use lidarr + jellyfin + symfonium (android), and that works for me. I mainly listen to full albums, and don't play around with playlists or recommendations though. I get flac quality and lyrics, remote access to my home-lab via VPN (no offline sync), Android Auto support...

  • I listen to the Diablo 2 & 3 or Skyrim OST when reading.

  • Check out crowdsec. Like fail2ban, but with crowdsourced lists on top.