12 ms·
My Homelab Setup
- kleebeesh 7mo agoNeat! > Right now, accessing my apps requires typing in the IP address of my machine (or Tailscale address) together with the app’s port number. You might try running Nginx as an application, and configure it as a reverse proxy to the other apps. In your router config you can setup foo.home and bar.home to point to the Nginx IP address. And then the Nginx config tells it to redirect foo.home to IP:8080 and bar.home to IP:9090. That's not a thorough explanation but I'm sure you can plug this into an LLM and it'll spell it out for you.
- verdverm 7mo agoCaddy is increasingly popular these days too. I use both and cannot decide which I prefer.
- victorio 7mo agoCaddy's configuration is so simple and straightforward, I love it. For sure a more comfortable experience for simple setups
- verdverm 7mo agoThe pain I've had with it is distributed configuration, i.e. multiple projects that want to config rules. I've been using the JSON API rather than their DSL. Do you know how I might approach this better?
- hk1337 7mo agoI like Caddy's integration with Cloudflare for handling SSL and when I originally saw the idea it was promoted as an easy way to have SSL for a homely but I don't use real domains for my internal apps and that is required with Cloudflare.
- cyberpunk 7mo agocaddy has tailscale integration i think too, so your foo.bar.ts.net “just works”
- windexh8er 7mo agoI think most homelabbers default to Caddy and/or Traefik these days. Nginx is still around with projects like NPM (the other NPM), but Caddy and Traefik are far more capable. DevOpsToolbox did a great video on many of the reasons why Caddy is so great (including performance) [0]. I think the only downside with Caddy right now is still how plugins work. Beyond that, however it's either Caddy or Traefik depending on my use case. Traefik is so easy to plug in and forget about and Caddy just has a ton of flexibility and ease of setup for quick solutions. [0] https://www.youtube.com/watch?v=Inu5VhrO1rE https://www.youtube.com/watch?v=Inu5VhrO1rE
- verdverm 7mo agofar more capable is an exaggeration I use both, they are by and large substitutable. Nginx has a much larger knowledge base and ecosystem, the main reason I stick with it.
- philsnow 7mo agoI agree with you that they're more or less equal. I don't like the idea of my reverse proxy dealing with letsencrypt for me, personally, but that's just a preference. One tricky thing about nginx though, from the "If is evil" nginx wiki [0]: > The if directive is part of the rewrite module which evaluates instructions imperatively. On the other hand, NGINX configuration in general is declarative. At some point due to user demand, an attempt was made to enable some non-rewrite directives inside if, and this led to the situation we have now. I use nginx for homelab things because my use-cases are simple, but I've run into issues at work with nginx in the past because of the above. [0] https://nginx-wiki.getpagespeed.com/config/if-is-evil https://nginx-wiki.getpagespeed.com/config/if-is-evil
- dwedge 7mo agoI'm not sure why Apache is so unpopular, it can also function as a reverse proxy and doesn't have the weird configuration issues nginx has. Some people take this way too far, for instance I've send places compiling (end of life) modsec support into nginx instead of using the webserver it was built for
- Frotag 7mo agoIME androids dont respect static routes published by the router. I guess self hosting DNS might be more robust but I usually just settle for bookmarking the ip:port
- frumiousirc 7mo agoThis (reverse proxy) is essentially what "tailscale serve" does.
- c-hendricks 7mo agoAlso recommending using a DNS server that points `*.yourdomain` do your reverse proxy's IP. That way requests skip going outside your network and helps for ISPs that don't work with "loopback" DNS (quotes because I don't know the proper term) You can then set your DNS in Tailscale to that machines tailnet IP and access your servers when away without having to open any ports. And bonus, if it's pihole for dns you now get network-level Adblock both in and outside the home.
- mnahkies 7mo agoPersonally I'm using haproxy for this purpose, with Lego to generate wildcard SSL certs using DNS validation on a public domain, then running coredns configured in the tailnet DNS resolvers to serve A records for internal names on a subdomain of the public one. I've found this to work quite well, and the SSL whilst somewhat meaningless from a security pov since the traffic was already encrypted by wire guard, makes the web browser happy so still worthwhile.
- anon7000 7mo agoOr just use Tailscale serve to put the app on a subdomain
- pajamasam 7mo agoThis worked for me to get subdomains and TLS certificates working on a similar setup: https://blog.mni.li/posts/internal-tls-with-caddy/ https://blog.mni.li/posts/internal-tls-with-caddy/
- ls612 7mo agoThe part you are leaving out is that you also need to set up something like a pihole (which you can just run in a container on the homelab rather than on a pi) to do the local DNS resolution.
- navigate8310 7mo agoWhy are you using restic, when TrueNAS offers native solutions to backup your data elsewhere?
- PunchyHamster 7mo agoexactly because it isn't trueNAS specific I'd imagine
- dizhn 7mo agoEncryption, deduplication, snapshots. Although if the poster has a zfs based system elsewhere zfs based backups would be fantastic.
- sgt 7mo agoThis is extremely light - not a bad setup, but I mean.. it's like 1% of typical Homelabs.
- switchbak 7mo agoIt feels like day 2 after you’ve received the new hard drives. It’s nice, modern enough but still a pretty bog standard home machine, not really “homelab” territory yet.
- sgt 7mo agoExactly. And I don't mind this being on the HN front page, but I'd like to see some proper Homelab setups here. Maybe someone can post the coolest setup they've seen so far?
- akerl_ 7mo agoWhy do we need to gatekeep “homelab”?
- PunchyHamster 7mo agoTerms making defined sense aid in conversation. Why do you need to dilute the term? There is nothing wrong with your NAS running 3 apps that you press update once a year not being called "homelab" but just "a NAS"
- anon7000 7mo agoI think if you’re playing around with apps & Tailscale on your NAS, it’s a homelab.
- akerl_ 7mo ago> Why do you need to dilute the term? Nobody is diluting anything. This person posted the setup they have in their home. It’s their homelab. It’s not diluting any terms for them to call it that. Their setup is just as much a homelab as somebody else’s 48U rack. It’s just a dick move, and against the rules of the site, to see somebody’s earnest post about their tech setup and post a shallow dismissal about how their setup isn’t deserving of your imagined barrier to entry.
- linsomniac 7mo ago>Because all of my services share the same IP address, my password manager has trouble distinguishing which login to use for each one. In Bitwarden they allow you to configure the matching algorithm, and switching from the default to "starts with" is what I do when I find that it is matching the wrong entries. So for this case just make sure that the URL for the service includes the port number and switch all items that are matching to "starts with". Though it does pop up a big scary "you probably didn't mean to do this" warning when you switch to "starts with"; would be nice to be able to turn that off.
- dewey 7mo agoThis is always annoying me with 1Password, before that I just always added subdomains but now I'm usually hosting everything behind Tailscale which makes this problem even worse as the differentiation is only the port.
- wrxd 7mo agoYou can still have subdomains with Tailscale. Point them at the tailscale IP address and run a reverse proxy in front of your services
- dewey 7mo agoGood point, but for simplicity i'd still like 1Password to use the full hostname + port a the primary key and not the hostname.
- domh 7mo agoYou can use tailscale services to do this now: https://tailscale.com/docs/features/tailscale-services https://tailscale.com/docs/features/tailscale-services Then you can access stuff on your tailnet by going to http://service instead of http://ip:port It works well! Only thing missing now is TLS
- avtar 7mo agoThis would be perfect with TLS. The docs don't make this clear... > tailscale serve --service=svc:web-server --https=443 127.0.0.1:8080 > http://web-server.<tailnet-name>.ts.net:443/ > |-- proxy http://127.0.0.1:8080 http://127.0.0.1:8080 > When you use the tailscale serve command with the HTTPS protocol, Tailscale automatically provisions a TLS certificate for your unique tailnet DNS name. So is the certificate not valid? The 'Limitations' section doesn't mention anything about TLS either: https://tailscale.com/docs/features/tailscale-services#limitations https://tailscale.com/docs/features/tailscale-services#limit...
- freetonik 7mo agoThe author uses Restic + Backblaze B2 storage. I was recently setting up backups for my homebase as well, and went with Restic + BorgBase [0]. Not affiliated, just wanted to share that I think they have a nice service with a straight-forward pricing model. They are the company behind excellent Pikapods [1], which may be interesting to the homelab crowd. [0] https://www.borgbase.com https://www.borgbase.com [1] https://www.pikapods.com https://www.pikapods.com
- natterangell 7mo agoI also use backrest/restic on my NAS, but I went with a Hetzner StorageBox instead, a little cheaper for 1TB (I pay 5USD monthly including VAT, billed monthly too).
- reddalo 7mo agoMe too, I highly recommend Hetzner Storage Box. It's cheap, and it works great (unlike their S3-compatible storage, which has been a huge fiasco since they launched it).
- bluehatbrit 7mo agoCould you elaborate on the issues with their S3 compatible storage? I've been considering it and haven't seen too many issues in my testing, beyond the lack of identity control.
- lowdude 7mo agoI cannot say much about the quality, but I am also testing around with it at the moment. As for the identity control, you may be able to achieve this with a few extra steps, if you set up bucket policies for the credentials. For this, it would be a bit cleaner to move the storage box to a project of its own. I still have to check if this actually works in practice, but I am hopeful. I based it off their documentation here: https://docs.hetzner.com/storage/object-storage/faq/s3-credentials https://docs.hetzner.com/storage/object-storage/faq/s3-crede...
- deleted 7mo ago[deleted]
- tokyobreakfast 7mo ago[flagged]
- deleted 7mo ago[deleted]
- acidburnNSA 7mo agoI have something like this, in the same case. I have beefier specs b/c I use it as a daily workstation in addition to running all my stuff. * nginx with letsencrypt wildcard so I have lots of subdomains * No tailscale, just pure wireguard between a few family houses and for remote access * Jellyfin for movies and TV, serving to my Samsung TV via the Tizen jellyfin app * Mopidy holding my music collection, serving to my home stereo and numerous other speakers around the house via snapcast (raspberry pi 3 as the client) * Just using ubuntu as the os with ZFS mirroring for NAS, serving over samba and NFS * Home assistant for home automation, with Zigbee and Z-wave dongles * Frigate as my NVR, recording from my security cams, doing local object detection, and sending out alerts via Home Assistant * Forgejo for my personal repository host * tar1090 hooked to a SDR for local airplane tracking (antenna in attic) This all pairs nicely with my two openwrt routers, one being the main one and a dumb AP, connected via hardwire trunk line with a bunch of VLANs. Other things in the house include an iotawatt whole-house energy monitor, a bunch of ESPs running holiday light strips, indoor and outdoor homebrew weather stations with laser particulate sensors and CO2 monitors (alongside the usual sensors), a water-main cutoff (zwave), smart bulbs, door sensors, motion sensors, sirens/doorbells, and a thing that listens for my fire alarm and sends alerts. Oh and I just flashed the pura scent diffuser my wife bought and lobotomized it so it can't talk to the cloud anymore, but I can still automate it. I love it and have tons of fun fiddling with things.
- pajamasam 7mo agoImpressive that all that can run on one machine. Mind sharing the specs?
- cyberpunk 7mo agoYou could easily run all of that on a rpi…
- tclancy 7mo agoNo, you definitely can’t. Or at least, not 3B+. I wound up buying https://www.amazon.com/ACEMAGICIAN-M1-Computers-Computer-3-2Type-C/dp/B0FQNGZD5D https://www.amazon.com/ACEMAGICIAN-M1-Computers-Computer-3-2... which was $50 less a month ago (!!) because so many things don’t fit well. Immich is amazing, but you wouldn’t get a lot of the coolness of it if you can’t run the ai bits, which are quite heavy.
- xoa 7mo agoI'll admit I've still stuck with the original FreeBSD based TrueNAS, and still am kinda bummed they swapped it. So it's interesting to see a direct example of someone for whom the new Linux based version is clearly superior. I'm long since far, far more at the "self-hosted" vs "homelab" end of the spectrum at this point, and in turn have ended up splitting my roles back out again more vs all-in-one boxes. My NAS is just a NAS, my virtualization is done via proxmox on separate hardware with storage backing to the NAS via iSCSI, and I've got a third box for OPNsense to handle the routing functions. When I first compared, the new TrueNAS was slower (presumably that is at parity or better now?) and missing certain things of the old one, but already was much easier to have Synology or Docker style or the like "apps" AIO. That didn't interest me because I didn't want my NAS to have any duty but being a NAS, but I can see how it'd be far more friendly to someone getting going, or many small business setups. A sort of better truly open and supported "open Synology" (as opposed the xpenology project). Clearly it's worked for them here, and I'm happy to see it. Maybe the bug will truly bite them but there's so much incredibly capable hardware now available for a song and it's great to see anyone new experiment with bringing stuff back out of centralized providers in an appropriately judicious way. Edit: I'll add as well, that this is one of those happy things that can build on itself. As you develop infrastructure, the marginal cost of doing new things drops. Like, if you already have a cheap managed switch setup and your own router setup whatever it is, now when you do something like the author describes you can give all your services IPs and DNS and so on, reverse proxy, put different things on their own VLANs and start doing network isolation that way, etc for "free". The bar of giving something new a shot drops. So I don't think there is any wrong way to get into it, it's all helpful. And if you don't have previous ops or old sysadmin experience or the like then various snags you solve along the way all build knowledge and skills to solve new problems that arise.
- lostlogin 7mo ago> splitting my roles back out again more The fiasco you can cause when you try fix, update, change etc makes this my favourite too. Household life is generally in some form of ‘relax’ mode in evening and at weekends. Having no internet or movies or whatever is poorly tolerated. I wish Apple was even slightly supportive of servers and Linux as the mini is such a wicked little box. I went to it to save power. Just checked - it averaged 4.7w over the past 30 days. It runs Ubuntu server in UTM which notably raises power usage but it has the advantage that Docker desktop isn’t there.
- hk1337 7mo agoThis is a lot of my similar setup in hardware. I just repurposed a PC I was using for windows that I barely used anyways. I would like to move that to a Framework Desktop mounted in my mini rack at some point though. I ended up making my own dashboard app, not as detailed as Scrutiny because I just wanted a central place that linked to all my internal apps so I didn't have to remember them all and have a simple status check. I made my own in Go though because main ones I found were NodeJS and were huge resource hogs.
- deleted 7mo ago[deleted]
- BitsAndObjects 7mo agoHave a look at Headscale to avoid the cost of Tailscale for small home setups.
- drnick1 7mo agoThis, or simply expose a VPN (Wireguard) port on a public IP. I don't see why you need to involve any third parties in such a setup.
- BitsAndObjects 7mo agoFor a single machine, yeah Wireguard is fine. For my multi-user multi-machine many-service home lab, it’s quite helpful to have the extra small features that Headscale offers (and some it exposes in a more convenient way). Edit: Tailscale has a fairly frank page on Wireguard vs Tailscale with suggestions on when to use which: https://tailscale.com/compare/wireguard https://tailscale.com/compare/wireguard
- SauntSolaire 7mo agoI believe Tailscale is free to use for small home setups. It's limited to 3 users and 100 devices which has been plenty for my homelab setup.
- miloschwartz 7mo agoPangolin is also a good choice. Can be fully self-hosted. Also based on WireGuard. Handles both browser-based reverse proxy access and client-based P2P connections like a VPN.
- xandrius 7mo agoOne thing to consider before doing the same, a computer done for homelab has a much lower consumption. The setup mentioned in the article has an avg 600 kWh/year as opposed to a pretty solid HP EliteDesk (my own homelab) which uses 100 kWh/year. Sure you don't get a GPU but for what it is used for, you might as well use a laptop for that.
- Havoc 7mo agoMinipcs are nice but they’re not really like for like comparable. A good AM4 board can do 7 nvme, 8 sata and ecc ram.
- hparadiz 7mo agoI've been thinking of tearing down my old gaming desktop (same as OP) and using a 2014 Macbook Pro instead for exactly this reason.
- firecall 7mo agoOne reason to repurpose desktops is that you get a full ATX Motherboard with SATA ports! If you are doing a DIY NAS with HDDs then you want real SATA ports. Or a well supported PCI card with SATA Ports, which you cant sensibly connect to a Laptop or micro PC. Sure, you might be able to use Thunderbolt to reliably hook up an external PCI chassis, but then you might as well buy a NAS at that point or use a full tower case with an ATX mobo! Using an older Gaming PC you already have is actually a very good option for TrueNAS or OMV. I took an older 10th Gen Intel Gaming PC we had, sold the core i9 CPU, and replaced it with an i7-10700T I found used on eBay. I'm finding this setup to be better for my needs than various ex-lease Dell Micro PCs I've used in the past, mainly because of the reliability of the SATA ports. I've found quality external Samsung T5 SSDs to be very reliable over USB with TrueNAS. But HDDs are a nightmare over USB for a NAS, in my experience. I was hoping this might be the year that I can finally get rid of the spinning rust. But looks like AI data centres had other ideas! :-) However, I will say that if you just want to run some virtualized Linux servers or similar, then ex-lease micro PCs are a fantastic deal and can be fun to setup and learn Proxmox and Truenas etc..
- 7mo ago
- polairscience 7mo agoA lot of people are talking about their backup storage solutions in here, but it's mostly about corporate cloud providers. I'm curious if anyone is going more rogue with their solution and using off-prem storage at a friend's house. Which is to say, hardware is cheap, software is open, and privacy is very hard to come by. Thus I've been thinking I'd like to not use cloud providers and just keep a duplicate system at a friends, and then of course return the favor. This adds a lot of privacy and quite a bit of redundancy. With the rise of wireguard (and tailscale I suppose), keeping things connected and private has never been easier. I know that leaning on social relationships is never a hot trend in tech circles but is anyone else considering doing this? Anyone done it? I've never seen it talked about around here.
- nine_k 7mo ago> hardware is cheap Hardware was cheap a year ago. Whoever managed to build their boxes full of cheap RAM and HDDs, great, they did the right thing. It will be some time until such an opportunity presents itself again.
- nsbk 7mo agoMy off-prem backups are in a Tailscale connected NAS at my parent's house. I'm in the process of talking a friend into having Tailscale configured to host more off-prem backups at his place as well. I'm moving out of iCloud for photo library management and into Immich. I really don't want to lose my photos and videos hence the off-prem backups. Tailscale has been a blessing for this kind of use case
- polairscience 7mo agoOooo. That's the other thing I need to figure out, because it's 90% for my photography. How have you liked immich? Have you tried any other options?
- Root_Denied 7mo agoI'm in the process of moving all my backups to Immich - honestly it's best in class software. I'm able to set it up so that my SO and I can view all the pictures taken by the other (mostly cute photos of our dog and kid, but makes it easier to share them with others when we don't have to worry about what device they're on), have it set to auto-backup, and routed through my VPS so it's available effectively worldwide. The only issue that I run into is a recent one, which is hard drive space - I've got it on a NAS/RAID setup with backups sent to another NAS at my parents' place, but it's an expensive drive replacement in current market conditions.
- ritcgab 7mo agoHard pass whenever you host long-term storage without ECC memory.
- benlivengood 7mo agoI've started building a kubernetes cluster (Talos Linux) across town with wireguard between various houses. ZFS boxes for persistent volumes (democratic-csi) in each "zone" with cross-site snapshot replication and Gateway (Traefik) running at each site behind the ISP. CrunchyPGO allows separate StorageClasses to easily split the leader/followers up.
- nickorlow 7mo agoHave had issues w/ doing k8s over residential wan once I had enough hosts in my cluster (though they were halfway across the US from each other, and not town)
- benlivengood 7mo agoSo far everything is under 15ms apart, but it is a small number of nodes so far. Did you mostly have trouble with etcd?
- nickorlow 7mo agoYeah, etcd was the main culprit, but latency was 150-300ms in my case. At 3 nodes, it was relatively stable (had an issue every week or so that lasted < 5 min), but at 4 the camel's back broke.
- gehsty 7mo agoI’m using a refurbed m4 Mac mini, connected to a unifi nas pro 8, super fun and straightforward. Feels like I only have to do the tinkering I want to do.
- garyfirestorm 7mo agoyou can use https://nginxproxymanager.com/ https://nginxproxymanager.com/ to manage various services on your homelab. it works flawlessly with Tailscale - I can connect to my tailnet and simply type http://service.mylocaldomain http://service.mylocaldomain to open the service. you will also need adguard -> adguard dns rewrite -> *.mylocaldomain forwards to the NPM instance and NPM instance has all the information of which IP:PORT has which service Also tailscale DNS should be configured to use adguard -> you can turnoff adblock features if it interferes with any of your stuff. I would also suggest to use two instances of adguards - one as backup two instances of NPM.
- ivanjermakov 7mo agoI never understood using a NAS OS and hosting non-NAS services there, it feels upside down. I would rather have a general purpose server OS with running NAS services. Same applies to Proxmox.
- denkmoon 7mo agoProxmox is just Debian with a qemu and lxc webui. You can do anything with it
- drnick1 7mo agoAgreed, I just don't see the point for a "homelab." Unlike many, I like very straightforward setups based on a regular distro like Debian. I also run many services bare metal. This includes nginx, email stack, DNS server, game servers, etc. I use use virtualization/containers for things that I treat as an appliance. This includes Home Assistance, Nextcloud, Matrix, Jellyfin, among others.
- buybackoff 7mo agoTrueNAS works perfectly as a VM eg on Proxmox with passing through a SATA controller from the motherboard. It may not work always with bad IOMMU groups, but I have this on an old Xeon Precision Tower 3420 and not so old Asus Z690 motherboard. NVMe passthrough should be straightforward as well. No need for LSIs or cheap PCI-to-SATA cards if the number of existing physical slots is enough. And as far as TrueNAS is concerned, it's baremetal disk access. Even the latest TrueNAS is not in the same league as Proxmox for managing VMs/containers, not even close.
- sbinnee 7mo agoI learned about Mealie.io, thanks.
- mcbuilder 7mo agoI did the exact same thing except a virtualized opensense router and bare metal kubernetes on one host. The kubernetes broke and I downgraded from 32GB of RAM to 16GB . I actually may revisit the setup since opensense FRR and Cilium BGP to peer your cluster and home LAN is actually a really seamless way to self host things in kubernetes. Maybe there are other ways, maybe there is something simpler, but a homelab is about fun more than pure function.
- tuananh 7mo ago*most* of the homelab setup doesn't have much load so it's mostly matter of ram available and then power consumption. many people with setup like this probably needs maybe a 4 cores low powered machine with idle consumption at ~5-10w
- Semaphor 7mo agoYeah, this is the AI tax. I have several times as many services (28) on a vastly smaller machine (N100 fanless), but besides some very light AI for image detection which runs on CPU, I have no AI there, so I don’t need a desktop PC.
- buckle8017 7mo agoGet yourself a custom domain and just use subdomains. Nothing says a public dns server has to return public ips. Bonus you can get https certs with certbot and dns challenge.
- Prabhapa 7mo agouse cloudflare & cloudflare tunnels for exposing your apps over internet via custom domains. Its free of costs. Tailscale only allows 3 devices i suppose. If we have more devices to be able to connect to , then cloudflare is the best .
- seriocomic 7mo agoWith AI/LLM assistants the barrier to setting up and running a homelab is so much lower - in the past 6 months I've had Claude help me completely reconfigure the (now) 5 RPis that were sitting around severely underutilized, I have 3 running Docker, some split between home stuff, production testing and a separate management layer (along with backups that were just in the too hard basket previously). Not to forget all the documentation that goes with it. Fun times!
- yowang 7mo ago[dead]
- luzionlighting 7mo agoClean setup. It's interesting how much attention people give to cable management and layout in tech setups. In architectural lighting projects we often think in a similar way about fixture placement, wiring access and maintenance because poor planning becomes very visible once a space is finished.
- izacus 7mo agoFolks that use restic - how does it handle laptop backups? That is - handling laptop going to sleep during backup, laptop being on only for shorter periods of time, etc.? Because I had issues with backup tooling which wouldn't resume if it got interrupted and expected for the machine to always run at certain hour of the day. I had examples where laptops wouldn't backup for months because they were only on for a short 30-60min bursts at the time and the backup tools couldn't handle piece-meal resume. How does restic handle that?
- dizhn 7mo agohttps://restic.readthedocs.io/en/stable/faq.html https://restic.readthedocs.io/en/stable/faq.html It will resume from where it got interrupted. The only exception is the initial backup where it doesn't have a snapshot yet.
- calcifer 7mo agoI invoke backups from a systemd timer. If the schedule is missed (due to sleep, power off etc.) it runs it at the next earliest opportunity.
- izacus 7mo agoHow does it handle restart after the machine wakes up again?
- predkambrij 7mo ago
- ErneX 7mo agoI run (among many other VMs) TrueNAS on a VM of an xcp-ng host (Supermicro board with a Xeon and ECC ram). Passing a dedicated SAS controller to it. Before that I was using esxi but migrated all my VMs and hosts to xcp-ng. TrueNAS has been pretty good so far, been running this for many years already. I also have another xcp-ng host for other VMs running on a Dell OptiPlex Micro. OP should configure DNS locally and reverse proxy each service, I use bind 9 and nginx for that.
- adrien_dev 7mo ago[dead]
- adrien_dev 7mo ago[dead]
- succo 7mo agoFor remote acces I use NetBird, I think is the best and secure option to not expose stuff directly on the web and put all your resources under a vpn. Is super easy to setup and it supports also sso with 2fa
- kelvinjps10 7mo agoI decided that instead of having to deal with self hosting or cloud solutions to just use local apps and sync them. Syncing Syncthing manages the syncing Passwords Keepassxc for desktop Keepassdx Mobile Note taking and documents Obsidian Neovim and PAndoc doc Photos Native gallery apps Mpv I might do a post about it
- ryukoposting 7mo agoSyncthing is the way, especially for OP's photography. My film scans spit out TIF files that can be north of 100MB. Editing those files on a network share is unpleasant. But Syncthing keeps local copies of the files, so editing a photo inside a Synthing folder is like editing a normal file on your computer - because it is.
- mattschaller 7mo agoAdd an *arr stack to that bad boy.
- monkaiju 7mo agoI ran TrueNAS for years but now that I've discovered immutable OSes, and uCore specifically, I'm never going back! Sauce: https://github.com/ublue-os/ucore https://github.com/ublue-os/ucore
- hazrmard 7mo agoI should read up on Tailscale more. I have been using ddclient[1] or the router's built-in dynamic DNS[2] to set up my servers / homelab. This leaves the endpoints exposed to the public internet, as the author says. [1]: https://github.com/ddclient/ddclient [2]: https://kb.netgear.com/1058/What-is-Dynamic-DNS-DDNS
- canbus 7mo agoi have similar on an old dell optiplex, which works really well. I've got lots of raw files in a zfs pool, but they aren't currently backed up anywhere else. any suggestions for cloud storage which works well with rsync?