this post was submitted on 26 Sep 2026
106 points (95.7% liked)

Selfhosted

62378 readers
498 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
 

I usually connect with my server via ssh in a terminal and run basic commands. What's a better, more efficient and modern way of doing that? Especially considering ai and documentation along the way? I wonder if there's a better approach than "connect from remote and act local". Is there a method to "code local and push to remote"?

I use a fedora server with podman, caddyfile and vi.

you are viewing a single comment's thread
view the rest of the comments
[โ€“] KyuubiNoKitsune@lemmy.blahaj.zone 2 points 1 day ago (1 children)

I assume this is on your own physical hardware? What parts do you set up with terraform?

[โ€“] silenium_dev@feddit.org 2 points 1 day ago* (last edited 1 day ago)

Yes, my own hardware. But before I decided to build my own server last September, I was on a similar setup on a dedicated server at Hetzner, just less powerful (I'm so goddamn glad I bought the memory and storage back then, I probably wouldn't even get the 192GB DDR5 right now for the price I paid for all memory and storage combined).

Terraform starts at the Talos initial machine config and cluster bootstrap including CNI setup and routing configuration (I have an opnsense in front that handles ingress routing) until FluxCD is fully set up and takes over.

Ingress traffic works via a small Hetzner VPS, and BGP through Wireguard, so there is no DNAT or SNAT between the open Internet and my Kubernetes load balancers and all services see the actual client IP. This took a shit load of time to get right, because wireguard only has an mtu of 1420, but the regular uplink is usually 1500, so pmtu discovery in my load balancers implementation (Cilium) and mss clamping in opnsense had to all be configured