Oooh. I haven't updated it yet. Good to know as I will likely run into the same issue.
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
Why are permissions so damn confusing? I say this as someone who knows why permissions are needed, such as location to find nearby devices. But why must we keep track of "permission X is for thing unrelated to X" in our heads? Now I haven't tried to make a permissions system for the masses, so I guess I can't say too much, but it doesn't seem that difficult to just make the permission name relate to what it does and provide a short synopsis for it.
It's because people keep finding ways around them and they evolve in nonsensical ways.
I gave permission to Firefox, but honestly most of my services weren't affected because I connect to 99% of them via Tailscale which doesn't seem to trigger the permission. (Yes that was an absolute nightmare to figure out why only one service was failing to connect)
Luckily grapheneos allows a hybrid approach so allows just the lan subnet permission without the wider nearby devices permission.
I'm actually on GrapheneOS.
I've found that you can deny "Network" permissions and permit "Nearby devices". The app becomes LAN-only this way.
You're also handling bluetooth and wifi functionality with that permission, fyi.
Hey can you let me know where I can find more info on this? I am running GrapheneOS as I was having this exact same issue as OP a few day back.
On my browsers I have network access, but nearby devices was disabled.
I checked my private dns settings and granted nearby devices access to my browsers, which allowed me to hit my local self-hosted services.
Just wondering if there is a better way to achieve the same.
Haven't been brought to 17 yet thankfully.
My long term solution is to not use android. My short term solution will likely be to use android even less, and be even more pissed at Google.
Solution is to just enable the permission on apps that need it.
The solution is to avoid google going forward, for many reasons.
That's why I use graphene but the permission is still there in base android.
I'm actually using GrapheneOS.
How is this added permission not a good thing? Surely adding a local network only permission is a positive, you can allow apps internet permission and decline them access to your local services.
The permission structure sucks.
Its a silent drop (no errors are returned), webview breaks connected to WiFi even without a local resource being requested, it lives inside nearby_devices so giving permission there includes this (and gives a broader spectrum of access such as Bluetooth and WiFi).
Its just shuffling the problem around.
Also, fuck Google.
Linux phone?
Flip phone
Telephone

Bananaphone
Ring ring ring ring ring banana phooooone
It's cellular, modular, intellective, oddular!
Why not just grant the permission to the apps?
Relatedly, I think this is why Google Home and casting to Chromecast have stopped working reliably on my phone. Anyone figure those out? I've already tried granting permissions. Or it may be something GrapheneOS is doing.
IIRC you can't grant the permission if the app doesn't explicitly declare it in its manifest. I doubt most devs would care unless access to local network is required for app's functionality on typical user's setup (e.g. if it's a companion app for some device).
confused me when I suddenly had to give Firefox this permission to access websites on my LAN
More ways to control what can access what is a welcome change for me
(I'm on GrapheneOS but yeah, Android 17 based now)
Ran into this issue a few days ago, exactly the same way you described.
I am on GrapheneOS and figured it was something to do with a a setting where it's blocking network access for my specific browser app. After reading your post I see it's a android 17 feature.
Checked all the settings in my browsers related to DNS at first and was stumped for a bit, until I flipped on the nearby device setting and everything worked.
I also looked into the DNS settings under Network & Internet > Private DNS. Make sure your phone is using your local networks DNS server. Just make sure to understand the implications of changing this (especially when you disconnect from you're home networks DNS). Also making sure your home DNS is not defaulting to your ISP DNS.
Two websites that help me sanity check myself
- Dnscheck.tools
- dnsleaktest.com
I self-host a DoH/DoT server and my local DHCP advertises it to local clients. It's kinda cool because android phones on my wifi will use DoT when private DNS is set to "automatic".
Private DNS sort-of broke while I was tinkering with internal/external IP addresses for nearby devices. It wouldn't always connect when I specified my external IP (despite being available externally). I made it IPv6-only too. It wouldn't be the first time something couldn't handle it.
Haven't noticed it yet because my services are on a different network than my clients
Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I've seen in this thread:
| Fewer Letters | More Letters |
|---|---|
| DHCP | Dynamic Host Configuration Protocol, automates assignment of IPs when connecting to a network |
| DNS | Domain Name Service/System |
| ISP | Internet Service Provider |
| NAT | Network Address Translation |
| PiHole | Network-wide ad-blocker (DNS sinkhole) |
| XMPP | Extensible Messaging and Presence Protocol ('Jabber') for open instant messaging |
[Thread #115 for this comm, first seen 27th Sep 2026, 20:10] [FAQ] [Full list] [Contact] [Source code]
Thanks for the heads up. This would have been a nasty surprise followed by unknown duration of hair pulling.
My phone is still on 14 so uuuhhh I'm fine I guess?
I had this issue in firefox. And only firefox. Was pulling my hair for hours. Wish I had been warned.
Anyway I just gave firefox the permission and the issue was resolved. Native apps seem unaffected. Which makes me think maybe this is an opt in setting right now?
I think Firefox also gave me the first clue that something was up.
Native apps all have a backwards-compatible setting so it's allowed by default. That will surely get dropped when Google bumps the minimum Android target API so newly published apps need to explicitly configure it.
I actually went through my apps list and disabled nearby devices for all the apps that don't need it. It's a good security measure. I just don't like how it was rolled out.