15 ms·
Runtipi: Docker-based home server management
- franky47 3y agoI've been testing Coolify [1] for this, so far the experience has been smooth as a self-hostable Vercel/Netlify/PaaS replacement. Now onto finding/learning host management tools (Ansible, NixOS, Terraform and the like). [1] https://github.com/coollabsio/coolify https://github.com/coollabsio/coolify
- woopwoop24 3y agofor me it would be a lot of underlying complexity for "just" exposing docker-compose containers to the internet. I don't really understand the target audience here. If you need to manage dns, server hardening, backups, upgrades, internet exposing and evaluating the risks behind that, you should be able to do the rest yourself too. And it is single server only
- lucabs 3y ago[dead]
- hannofcart 3y agoThis looks great and I want something like this to run Vaultwarden, some 2FA manager, a media manager, Syncthing, Next cloud and so on. However I'm very worried about vulnerabilities in one of the applications getting my entire machine pwned and thus leaking my Vaultwarden data. It feels like this is just one CVE and Docker privilege escape away. What do others think about this? Am I being overly paranoid?
- psd1 3y agoYes; the framework itself doesn't really add vulnerability, if you were planning to run containers as root anyway. However. I used it for a year and moved off it. It starts out as a propeller but becomes an anchor. Just build your setup in Ansible; the increased initial effort pays off quickly the moment you want to do something like run rootless containers.
- razerbeans 3y agoAnyone have any experience using this? I've been managing most of my homelab infrastructure with a combination of saltstack and docker compose files and I'm curious how this would stack up.
- eightysixfour 3y agoI used to run it and generally liked it, but eventually felt limited in the things I could do. At the time it was a hassle to run non-tipi apps behind the traefik instance and eventually I wanted SSO. I ended up in a similar place with proxmox, docker-compose, and portainer but I have it on my backlog to try a competitor, Cosmos, which says many of the things I want to hear. User auth, bring your own apps and docker configs, etc. https://github.com/azukaar/Cosmos-Server/ https://github.com/azukaar/Cosmos-Server/
- pjerem 3y agoI tried it a few months and it was nice. But I think it lacks a way to configure mounting points for the apps storage. By default, each app have its own storage folder and not really a useful default in the use case of a home lab : you probably want, idk, Syncthing, Nextcloud and Transmission to be able to access the same folders. It’s doable but you have to edit the yaml files yourself which I thought removed most of the interest of the project.
- filmgirlcw 3y agoI've been evaluating it alongside Cosmos and Umbrel, in addition to tools I've used before like CapRover. I like it but I don't have any strong feelings yet. I will probably do some sort of writeup after I do more evaluations and tests and play with more things but I haven't had the time to dedicate to it. If you're already familiar with setting things up Salt/Ansible/whatever and Docker compose, you might not need something like this -- especially if you're already using a dashboard like Dashy or whatever. The biggest thing is that these types of tools make it a lot easier to set things up -- there are inherent security risks too if you don't know what you are doing, though I argue this is a great way to learn (and it isn't a guarantee that simply knowing how to use Salt or Ansible or another infrastructure as code tool will mean any of the stuff you deploy is any more secure) and a good entryway for people who don't want to do the Synology thing. I like these sorts of projects because even though I can do most of the stuff manually (I'd obv. automate using Ansible or something), I often don't want to if I just want to play with stuff on a box and the app store nature of these things is often preferable to finding the right docker image (or modifying it) for something. I'm lazy and I like turnkey solutions.
- apitman 3y ago> At its core, Tipi is designed to be easy to use and accessible for everyone > This guide will help you install Tipi on your server. Make sure your server is secured and you have followed basic security practices before installing Tipi. (e.g. firewall, ssh keys, root access, etc.) I love to see efforts like this, please keep it up. But expecting users to learn everything necessary to run a secure server is simply not going to achieve the stated goal of being accessible to everyone. We need something like an app that you can install on your laptop from the Windows store, with a quick OAuth flow to handle all networking through a service like Cloudflare Tunnel, and automatic updates and backups of all apps.
- mike_hearn 3y agoI toyed with the idea of creating something like that a year or so ago. I have a company that makes a tool which simplifies desktop development a ton, and that was previously the blocker to people trying to do this which is why there are so many products that claim to be targeted at everyone but start with a Linux CLI. So, can you make it brainless? Sure. Writing a nice desktop GUI that spins up a VM, logs in and administers it for you is easy. But ... who will buy it? The problem is that self-hosting isn't something that seems to solve a problem faced by non-technical people. Why do they want it? Privacy is not workable, because beyond most people just not caring, it's turtles all the way down: the moment you outsource administration of the service your data is accessible to those people. Whether that's a natty GUI or a cloud provider or a SaaS, unless it's a machine physically in your home someone can get at your data. And with supply chain attacks not even that is truly private really. Cost is clearly not viable. Companies give SaaS away for free. Even when they charge, other corps would rather pay Microsoft to store all their supposedly super-confidential internal docs, chats and emails than administer their own email servers. Usability: no. Big SaaS operations can invest in the best UI designers, so the self-hostable stuff is often derivative or behind. What's left?
- WhyNotHugo 3y agoIf someone doesn’t want to learn how to secure a server, then they shouldn’t be self hosting anyway. Or, as a car analogy: if someone doesn’t want to learn how to drive safely, they shouldn’t be driving anyway.
- Cieric 3y agoDoes anyone have any recommendations on top of this? I personally run portainer and would like more features like grouping containers post creation and container start order. I also have an issue where my VPN container if updated breaks all containers that depended on it. Portainer handles a lot, but I need the little bit more so I have to look at the panel less. I'm not sure if this would work for me since I build a lot of custom containers and this looks more like it's better for purpose built containers.
- exabyte 3y agoUmbrel, citadel, start9, MASH playbook. Sorry, on mobile right now, but these are great alternative projects
- BirAdam 3y agoPersonal opinion, a home lab is the perfect place to learn how to actually configure things and properly set them up: no docker, no ansible, no salt… take off the training wheels and learn it. Then, learn to write your own playbooks, your own compose files, etc. Additionally, if people think that learning how to configure and deploy stuff is too tedious and/or too difficult, write software that has better UI, not more layers of configuration and administration. Final thought, git is better than ansible/salt/chef/puppet, and containers are silly.
- xyst 3y agoI personally like learning this way. Have a single server with at least 20 physical cores available. Use qemu to create VMs. Personally, had nixOS (minimal) installed on the VMs. Scripted the setup (live cd created with my ssh key so I can remotely setup the VM such as disk partitioning). Then had a nix configuration to setup environment. A bit of a learning curve but the benefit here is repeatable environments. Was even able to learn more about k8s using a small mini cluster. Host machine was the controller node while VMs were nodes. By injecting latency between nodes to distance between different data center regions (ie, us-east vs us-west), actually able to reproduce some distributed app issues. All of this while not having to give up $$$ to the major server resellers (or "cloud" providers). No worries about forgetting to tear down the cluster and receiving a surprise bill at the end of the month.
- ghnws 3y ago"Containers are silly" What a silly take
- ktosobcy 3y agoI love containers - I have tiny RPi under the desk, run debian in it and everything is in containers - I don't have to deal that some software requires some version and other different. Or if something crashes it brings everything else with it. I have some space to toy with it, but for the purpose of running something utterly low maintenance, docker and containers are awesome.
- apitman 3y agoI think this is good advice for technical people, but I also think we need to drastically lower the barrier of entry for people who would benefit from owning their compute and data but don't have the skills or interest necessary.
- raggi 3y agoThis appears to suffer from the same mistake as many of these things do in this space: it focuses on making it really easy to run lots of software, but has a very poor story when it comes to making the data and time you put in safe across upgrades and issues. The only documented page on backing up requires taking the entire system down, and there appears to be no guidance or provision for safely handling software upgrades. This sets people up for the worst kind of self-hosting failure: they get all excited about setting up a bunch of potentially really useful applications, invest time and data into them, then get burned really badly when it all comes crashing down in an upgrade or hardware failure, with improper preparation. This is how people move back to saas and never look back again, it's utterly critical to get right, and completely missing here.
- yonixw 3y agoThat's exactly how I feel. Not to mention that I am always looking for how to monitor the system, and there is no uniform standard, if it is possible to monitor at all. As if there is a hidden message that apart from monitoring how much disk space is left or CPU everything else is irrelevant. But for such VMs that share many processes, it is exactly the opposite! I must know when there is a problem who exactly is responsible!
- everforward 3y agoI'm working on something similar, and the crux of that issue is configurability vs automation. I.e. it's very easy to make backups for a system that users can't configure at all. You just ship the image with some rsync commands or something and done. Once you start letting people edit the config files, you get into a spot where now you basically need to be able to parse the config files to read file paths. That often means making version-specific parsers for configuration options that are introduced or removed in some versions, or have differing defaults (i.e. in 1.2 if they don't set "storage_path" it's at /x/, but in 1.3 if they don't set it, it defaults to /y/). That gets to be a lot of work. Then it gets even worse when the users can edit the Docker config for the images, because all bets are off at that point. The user could do all kinds of weird, fucky shit that infinitely loops naive backup scripts because of host volume mounts or have one of the mounts actually be part of NFS mount on the host with like 200ms of latency so backups just hang for forever and etc. It's just begging for an infinite series of bugs from people who did something weird with their config and ended up backing up their whole drive instead of the Docker folder, or removing their whole root drive because they mount their host FS root in the backups folder and it got deleted by the "old backup cleanup" script, or who knows what. At some point, it's easier to just make your own setup where you define the limitations of that setup than it is to use someone else's setup but have to find the limitations on your own.
- xjlin0 3y agoIs this dockerized alternative to https://yunohost.org/ https://yunohost.org/ ?
- riedel 3y agoQuite a few out there, I guess. I always liked the idea of sandbox.io .
- birdman3131 3y agoHow does this differ from Caprover?
- TechDebtDevin 3y agoThese services are cool but I almost always end up doing it myself anyways. Doing it yourself is more fun anyways. Typically I just make my own one click deploys that fit my preferences. Not knowing how your container starts and runs is a recipe for disaster.
- angra_mainyu 3y agoI find terraform + acme provider + docker provider (w/ ssh uri) to be the best combo. All my images live on a private GitLab registry, and terraform provisions them. Keeping my infra up-to-date is as simple as "terraform plan -out infra.plan && terraform apply infra.plan" (yes, I know I shouldn't blindly accept, but it's my home lab and I'll accept if I want to). Note: SSH access is only allowed from my IP address, and I have a one-liner that updates the allowed IP address in my infra's L3 firewall.
- Cyph0n 3y agoI think this is useful for less tech oriented people to get a basic homelab setup. But I personally find it much more straightforward and maintainable to just use Compose). Virtually every service you would want to run has first-class support for Docker/Podman and Compose.
- soared 3y agoThe top section of the site matches very closely another project posted on HN a couple weeks ago - no negative opinion from me, because I also thought it was incredible design and borrowed a ton of it for one of my sites.
- daz00t 3y agoWhich site did it take inspiration from? It looks great. I'm always amazed how people pull off minimalist designs. It just ends up looking empty and boring when I try.