10 ms·
FreedomBox: Run your digital services from your home
- foolinaround 6y agohow does this compare to sandstorm.io?
- deleted 6y ago[deleted]
- ekianjo 6y agoIn my (limited) experience, it all boils down to how well the services actually run in such solutions. Yunohost had many services that were completely broken and not well integrated (to be fair it's really complex to do it well) so the user experience at the end of the day will vary from one to another.
- clankyclanker 6y agoI’ve tried it, and it works surprisingly well. They even have pagekite integration if you’re stuck behind a crappy residential internet provider, like any of the main US providers.
- anderspitman 6y ago> They even have pagekite integration Nice, I was wondering if/how they handle tunneling.
- toyg 6y agoInteresting that they now sell prebuilt kits on new hardware, after years targeting the now-defunct Globalscale Dreamplug. https://www.olimex.com/Products/OLinuXino/Home-Server/Pioneer-FreedomBox-HSK/ https://www.olimex.com/Products/OLinuXino/Home-Server/Pionee...
- 3np 6y ago"New" A lot has happened in the SBC market since - with (for example) Odroid C4 you'll get significantly more bang for not much more buck. Just an idea if anyoine feels inspired: Organize with Pine64 to make an upgraded version based on their new architecture slated for release this year. With their strong focus on openness it seems like a perfect match to me.
- anderspitman 6y agoMan I would love to see pine get into the home NAS space.
- darknavi 6y agoNot my preferred setup but I hope products like this help people get into "homelabbing" and self-hosting more of their stuff.
- Forge36 6y agoWhat's your preferred setup?
- andrewzah 6y agoI'm not the parent, but I use a debian VM inside of a proxmox cluster to run docker services. The config and data services for the various docker images are mounted via NFS, and live in a ZFS pool configured in RAID10. For non-technical users I could see freedombox (or sandstorm.io) being useful, but if you have enough knowledge to manage a vm + use docker-compose, the flexibility is much better.
- foolinaround 6y agocan you please explain how is this flexibility better? Wont more apps be supported in freedombox? maybe it does not allow plugins?
- andrewzah 6y ago> Wont more apps be supported in freedombox? I can support any app that I have either the source for, or a binary. I just write my own docker images [0] if one doesn't exist already on dockerhub, or install the binary directly on a VM or LXC as needed. For example, I set up Jellyfin on its own LXC. For me, stuff like freedombox/sandstorm directly limit me as I would have to spend time learning their GUI, etc, for no gain. All I need is an ssh session into my docker VM and I can set up pretty much anything I need exactly how I want. This lets me be very particular about services accessing files, networking, versioning, and so on. [0]: https://github.com/andrewzah/caddy-webdav https://github.com/andrewzah/caddy-webdav
- anderspitman 6y ago
- m00dy 6y agoEmail service would be cool to have on this
- ericls 6y agoYunohost does comes with a complete stack of email services. Haven’t used in depth tho.
- xupybd 6y agoWhile I agree I'm not sure about building trust in my home IP. Won't you be flagged as spam?
- atomicnumber3 6y agoMany email servers (e.g. gmail) won't even accept email from residential IPs. I have a janky setup where I proxy mail from my home network to my VPS and then send it from there (outbound-only, and only to myself - for notices like "backup started", "backup finished" etc)
- nebulon 6y agoCloudron also has a full email stack ready to go, however you are totally right about the residential IPs. They are basically all blacklisted by default, which is also why we had to add easy relay-provider support.
- dvfjsdhgfv 6y ago> They are basically all blacklisted by default, which is also why we had to add easy relay-provider support. While I understand why people are doing this, I believe it's not the right way to deal with the problem - basically we're handing over e-mail (as a service) to a few big corps. Each time I have this problem I go through the long and painstaking process of whitelisting the IP and fight to make it work. Usually having it work with Gmail, Yahoo and Microsoft is enough - many smaller orgs don't use balcklisting by default because they have enough problems with mail deliverability already.
- ekianjo 6y agoThere's also yunohost which is pretty much along the same lines: https://yunohost.org/ https://yunohost.org/
- talhah 6y agoTo add to the list there's also Sandstorm: https://sandstorm.io https://sandstorm.io
- ocdtrekkie 6y agoAnd it's noteworthy that AFAIK, FreedomBox and YunoHost merely install apps on your server directly, whereas Sandstorm and Cloudron both containerize apps in a more secure environment. I don't think it's a good idea to install a dozen plus web apps directly on a server, such that a bug in one can compromise the entire server.
- artonge 6y agoAnd also FLAP, my personal project: https://gitlab.com/flap-box/flap https://gitlab.com/flap-box/flap
- dnpp123 6y agoI'm pretty sad this project never lifted off. The talk at its origin is now a classic: https://www.youtube.com/watch?v=QOEMv0S8AcA https://www.youtube.com/watch?v=QOEMv0S8AcA
- elago 6y agoThat talk was inspirational, as was the follow up ~10 years in progress video that came up next. I'm going to give FreedomBox a try. It is sad that I've never heard of this until now.
- imwillofficial 6y agoCloudron.io is by far the most developed homelab in a box kit. Worth a look!
- m463 6y agoSo $15 or $30/month to self-host? What are the benefits?
- dvfjsdhgfv 6y agoFor me paying $15/$30 a month for the ability to self-host is ridiculous (I'd consider it if it was 10 times less, just for the conenience of 1-click installs). However, when you need to install a more complex app like Taiga, it's often simpler to use the free Cloudron account to do it rather than install it by hand.
- nebulon 6y agoIndeed as you mention, complex apps like Taiga are quite time-consuming to package in a way to ensure proper updates for the future. In fact I am right now in the process to iron out the update to Taiga v6 and that price-tag allows us to focus on such things so our users get a smooth experience without missing out on updates (disclaimer, I am one of the Cloudron founders :D ) For sake of our vision we surely would like to make it more cost-effective in the long run, however we are bootstrapped and thus walk a thin line with a focus more on long-term sustainability not just blind growth. (10x cheaper though would realistically even pose an accounting problem with micro-payments or plain transaction fees taking large chunks)
- imwillofficial 6y ago“ridiculous” is a strong word. Sure if you’re addicted to free, and being used as a product, $15 sounds crazy. If you want to take control of your data and don’t have the time or inclination to do it all yourself, $15 isn’t so bad.
- infogulch 6y agoI tried the demo a few months ago and decided to give it a shot this weekend, and I'm pretty happy so far. These are some things that drew me to it: Dozens of actively maintained deployments of (mostly) popular open source apps, a functional multi-user system with app SSO and ACS where possible, an integrated email server, multiple app instances, easy encrypted backup configuration to off-site s3/b2/nas/etc, simple automatic backup and retention policies, restore/clone down to a per-app basis, broad and deep documentation, complete published api, active forum There is a recent thread on the forum where a few users espoused their reasons: https://forum.cloudron.io/topic/4372/what-are-you-favourite-things-features-about-cloudron/7 https://forum.cloudron.io/topic/4372/what-are-you-favourite-...
- anderspitman 6y agoIf you're interested in self hosting I keep a list of ngrok-like tunnel proxies: https://github.com/anderspitman/awesome-tunneling https://github.com/anderspitman/awesome-tunneling
- blu_ 6y agoHey, just discovered boringproxy from your link. Looks like a really slick solution!
- clan 6y agoSeems to be hugged to death Get "http://localhost:36169/": dial tcp 127.0.0.1:36169: connect: connection refused
- anderspitman 6y agoWeird, the initial traffic when I announced it on /r/selfhosting was bigger than this. Must have gotten in a bad state. Anyway, thanks, it's back now.
- anderspitman 6y agoThanks. It's not quite production-ready, but I do think it offers some unique features. There are reasons I decided to make it even after discovering 20+ alternatives that all do pretty much the same thing.
- farisjarrah 6y agoThat's very cool, I've seen many requests for an open source self hosted ngrok around here. I'll take a deeper look at this a bit later. Good stuff, and thanks for the contribution!
- MayeulC 6y agoWhile that's not really clearnet, I quite like yggdasil for that: https://yggdrasil-network.github.io/2018/07/15/remote-access.html https://yggdrasil-network.github.io/2018/07/15/remote-access... I didn't see it on your list. It isn't clearnet again, but so are others, such as Zeronet :)
- lgdishwasher 6y agoI read my ISPs terms of service (the biggest ISP in Australia), and it specifically says you can't host servers on your residential connection. They expect you to buy an extremely expensive small business service to do that. I would assume this is the same for many ISPs, and I think it is terrible.
- BLKNSLVR 6y agoTelstra? Yeah, they're about as consumer unfriendly as it's possible to be. I went out of my way to avoid paying them any money a few years ago, including moving my workplace (>10 branches around Australia) off Telstra comms infrastructure and onto a competitors whilst also saving about 30% per year.
- vxNsr 6y ago> I went out of my way to avoid paying them any money [...] whilst also saving about 30% per year. Just curious, how did you go out of your way by saving money? "going out of your way" is usually associated with being inconvenienced. but saving money is hardly an inconvenience.
- BLKNSLVR 6y agoHaving to convince older, management types to roll the incumbent provider. 30% savings helped, but they were still quite nervous for the integrity of the new network. Had to do a fair bit of convincing and putting my neck on the line. Just thinking about it (it was 10+ years ago), it would have been much easier to just sign contract extension with Telstra, no management involvement, no additional research, no putting my reputation in danger. That's what Telstra relies on.
- anderspitman 6y agoIMO that should be illegal, assuming there aren't any competitor ISPs available.
- ibudiallo 6y agoHmmm many years ago I was wishful thinking about this very box [1]. This is gonna be a fun week playing with and testing it. [1]: https://idiallo.com/blog/bringing-back-the-pc https://idiallo.com/blog/bringing-back-the-pc
- debarshri 6y agoI have a feeling that tunneling might just be a better option that creating VPN in enterprise setting. For instance, if you have confluence, jira etc running in your enterprise private network, instead of creating a VPN and asking endusers to connect to that VPN. They could expose each app with a authenticated tunnel. In this way the threat matrix reduces down to the application that is exposed and not whole private network. I wondering if something like this exists.
- ignoramous 6y agoPerhaps, you're looking for BeyondCorp style networks? https://research.google.com/pubs/pub45728.html https://research.google.com/pubs/pub45728.html https://tailscale.com https://tailscale.com and https://cloudflare.com/cloudflare-one https://cloudflare.com/cloudflare-one come to mind, though there are likely to be several implementations at this point.
- anderspitman 6y agoI think tunneling is a good way for individuals and small companies to implement BeyondCorps-type systems. That's what I personally do rather than using WireGuard, ZeroTier, etc. Obviously there are tradeoffs either way.
- skocznymroczny 6y agoI use DietPi on my Raspberry Pi (other small boards are supported too). It's easy to install, and provides a simple TUI installer for all the common services, from Git and Syncthing to various game emulators. https://dietpi.com/dietpi-software.html https://dietpi.com/dietpi-software.html
- seanieb 6y agoHow does it handle updates? Can the non-expert user just click a button? Mediawiki strikes me as a service that would absolutely need command line access to upgrade?
- oaguy1 6y agoHas anyone here tried using WireGuard as a VPN for selfhosting? It is built into the Linux kernel (starting in 5.4?) and has lots of tutorials. Thinking of using it for my next project.
- hakeberio 6y agoI use Wireguard regularly when I'm out to access my home LAN where I have some VM's running various things like pihole (DNS server to block ads), mail server, hobby dev server, etc. Wireguard is very light (cf: OpenVPN) and easy to setup/use- highly recommend using it.
- Terretta 6y agoWhy would one market a device to non-experts as a Dropbox alternative, a NAS to backup for all your computers, and a Bittorrent client, when it ships with a 32GB SD card?
- waah 6y agoAs a newbie to this, I got one of the olimex units with ready-to-go SD Card. I've had it for a couple of years, I think. I've tried various of the apps and have settled on using it as an always-on syncthing node and to run Privoxy on my home network. To access away from home, it is running a Tor hidden service. Wireguard is also provided, so I'm thinking of trying that out as well. It snapshots, so if I get into trouble with a new app... I roll back. I keep all my syncthing data on an attached usb drive. I realize the SD card won't last indefinitely. What makes it feasible for me is that installation, configuration, and backup is handled by its web interface. I haven't needed to edit config files.