Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)F
Posts
30
Comments
133
Joined
3 yr. ago

  • The problem is that I have a couple of services listening on different ports and I want to use the reverse proxy to listen to incoming requests and route the traffic to the corresponding ports. I also want to issue SSL certificates and serve the traffic over TCP port 443.

  • Yes, I know that, but I just don't want to remember the port numbers or create some bookmarks.

    I think I can create a CNAME record for *.media to point to the Tailscale address of the reverse proxy and then use the reverse proxy with Cloudflare API key to serve SSL certificates from my domain.

    I am currently struggling a bit with the setup though.

  • I have a registered domain name already, but I am behind CGNAT and I don't really have a public IP.

    I want to allow access to my services remotely only through Tailscale.

  • I will definitely do that, I just want to finish the whole setup.

  • I am playing around with Podman Quadlet and that's one hell of a rabbit hole. I have everything up and running, and now I need to configure the containers, and probably will deal with other pain points, etc.

    The good thing is that I have documented the whole process so it is reproducible but it took me quite some time to figure out everything.

  • Because it is beginner friendly and it has a lifetime license I guess and it is not yet enshittified.

  • Nice, thanks for sharing. How did you solve the file permission issue?

    Also I see you put all your services as a single pod quadlet what I am trying to achieve is to have every service as a separate systemd unit file, that I can control separately. In this case you also have a complication with the network setup.

  • You can actually set your user to linger with

     
        
    sudo loginctl enable-linger $USER
    
      

    I will test your setup and report back if it works.

    By the way what was the reason to switch back to Docker Compose?

  • There are no logs in journalctl, just when I check the status of the systemd services I see that the container service has crashed and after 5-6 restarts it gave up.

    I was thinking of installing the latest podman 5.7.0 and try with it, as there are quite a few updates between that one and 5.4.2 that comes as standard on Rocky.

  • I can try to upload my container services and network tomorrow and share the link here.

  • Absolutely plus I love the idea of having them as separate services. I just don't know how to configure them apparently.

    Did you create a separate systemd network for your Quadlets or are you using a bridge or host network?

  • I don't know, I tried even with uptime-kuma and Homepage but as soon as I start the service it kills it after 6 unsuccessful restarts. Maybe I will spin up a completely new VM tomorrow and start from scratch.

    I think the problem might be with the data directory permissions, even though I have added the subuid and the subgid to my user and enabled the lingering on the user.

    But I did so many things so there is a chance it is already quite messed up.

  • Obsidian with Syncthing running on both your Android and your server for syncing your notes.

  • I have a lifetime Plex pass, but recently I switched to Jellyfin because I got sick and tired of Plex' shenanigans.

  • Here you need to decide if you want to run Plex/Jellyfin on the same server or not. And how important power consumption is for you.

    You should also consider if you are planning to run only the NAS or some other VMs/containers on that machine. In that case you might consider 32 Gb of RAM to be more future proof.

  • The problem with unRAID is that you don't really know when their product will be enshittificated. A very fresh example is Plex which was great for years and now is a bloated utter mess. They have changed their licensing policy and made the product legitimately worse for the end customers. And don't want to be cynical but the chances are that unRAID will go that way too sooner or later.

  • Elasticsearch should work too

  • Do you have a GitHub repo? As I am building my system like this and was thinking of exactly using Podman and quadlets.

  • Technology @lemmy.world

    It looks a lot like VMware just lost a 24,000-VM customer • The Register

    www.theregister.com /2024/05/22/computershare_vm_migration_project/
  • Technology @lemmy.world

    Tesla recalls all 3,878 Cybertrucks over faulty accelerator pedal - The Verge

    www.theverge.com /2024/4/19/24134753/tesla-recall-cybertruck-faulty-accelerator-pedal-nhtsa-defect
  • Technology @lemmy.world

    Tesla starts shipping $3,000 Cybertruck tent, looks nothing like what was unveiled | Electrek

    electrek.co /2024/03/08/tesla-shipping-cybertruck-tent/
  • Ask Lemmy @lemmy.world

    Where are all those price cuts thanks to AI implementation m

  • Ask Lemmy @lemmy.world

    How come Republicans are the most fervent Christians?

  • Ask Lemmy @lemmy.world

    Are there r/WorldNews Israel bots or am I hallucinating

  • Selfhosted @lemmy.world

    Addressing Changes to pfSense Plus Home+Lab

    www.netgate.com /blog/addressing-changes-to-pfsense-plus-homelab
  • Ask Lemmy @lemmy.world

    Who's going to pay for the reconstruction of Gaza

  • Ask Lemmy @lemmy.world

    Do you think we will ever have affordable housing again in our lifetime?

  • Ask Lemmy @lemmy.world

    Are search engines indexing the fediverse?