WASTECH

joined 3 years ago
[–] WASTECH@lemmy.world 1 points 2 weeks ago

I have just recently started messing with Authentik. And I can confirm OIDC claims and whatnot are an absolute nightmare. I have some experience setting up SAML stuff from my work, but I only do that if our main guy is out and I always struggle with it there too.

Your setup sounds the most like what I am doing now, minus the DMZ. But all of my containers are rootless. I am running everything on TrueNAS right now.

I think I will lean more on Authentik, as the provisioning of users and giving them access to services through that is very easy. I will probably stick with Cloudflare for the time being, but I will look more into Pangolin.

[–] WASTECH@lemmy.world 1 points 2 weeks ago

My ISP is charging $20/mo for static IP’s, so almost any other solution would be cheaper.

I hate Oracle with the passion of a thousand suns, so I don’t want to touch them with a 10ft pole. I would happily pay anyone else to avoid using anything affiliated with Oracle.

[–] WASTECH@lemmy.world 2 points 2 weeks ago (1 children)

Thanks for the warning. My Plex server is currently behind a Cloudflare tunnel, so I probably need to look at moving that.

I mistook pangolin for netbird, so thanks for the clarification!

[–] WASTECH@lemmy.world 2 points 2 weeks ago (1 children)

I use NPM internally for SSL. DuckDNS won’t work for me since I am behind CGNAT. I also already own a domain.

[–] WASTECH@lemmy.world 2 points 2 weeks ago (6 children)

I would like to avoid paying for a VPS. I probably should have clarified in my post too that I am specifically looking for advise on securing public facing services. While I certainly could make everyone use a tailscale-like service, at this point I think securing an external service would be easier. Especially since most of these people would not be tech savvy and I don’t particularly want to play tech support for their VPN.

 

As I start to host more and more services on my home server, my family and friends are interested in using some of the services I host as well. Up to now, all of my services have been internal-only, and my wife and I just use Tailscale to access everything. Getting others set up with tailscale isn’t an issue, but I can only have up to 4 other users before I have to pay to add more, and I have more than 4 people I would like to have access to some of the things I host.

Right now I’m using cloudflare tunnels to make some services available externally. I’m behind CGNAT, so I’m forced to use something like tunnels or similar. I’ve always read that if you are going to open things up externally to use a reverse proxy (which I use internally), but does this still apply with cloudflare tunnels? What else should I be looking at to make sure I have everything secured properly?

[–] WASTECH@lemmy.world 2 points 5 months ago (1 children)

I haven’t looked into Asahi Linux in a while now, but I figured the experience would be pretty good by now. You don’t need to “hack” anything to get it to run. Last I read, there were just a few driver issues, but I haven’t looked into it in probably 2-3 years now.

[–] WASTECH@lemmy.world 1 points 5 months ago

Apples implementation of SMB has always been abysmal. I’ve been using Mac’s for close to 20 years now, and connecting to SMB shares has always been a pain. IMO, it’s gotten better recently (since they dumped AFP and were forced to work better with SMB). For whatever reason, it has always been slow to connect through Finder. Not sure there has been much progress on that front…

Really makes you wonder what Apple uses internally, because it must not be SMB!

[–] WASTECH@lemmy.world 5 points 10 months ago (1 children)

There is an iOS/macOS app called “Pi-hole Remote” that can manage multiple PiHole instances at once. I use that because it will make changes on both instances at once for me.

Other than that, I log in to each device and copy paste.

[–] WASTECH@lemmy.world 2 points 11 months ago (5 children)

I’m pretty out of the loop. Did something happen with Twitch?

[–] WASTECH@lemmy.world 8 points 11 months ago (2 children)

These contracts do not stipulate reimbursement for lost revenue. The “uptime guarantee” just gets you a partial discount or service refund for the impacted services.

It is on the customer to architect their environment for high availability (use multiple regions or even multiple hyperscalers, depending on the uptime need).

Source: I work at an enterprise that is bound by one of these agreements (although not with AWS).

[–] WASTECH@lemmy.world 3 points 11 months ago

I’ve tried both Unraid and TrueNAS. While I greatly prefer TrueNAS, Unraid is much easier to set up and get going for beginners. It’s been a while since I’ve set up TrueNAS from scratch, but last I tried, it wasn’t a very beginner friendly experience. If you weren’t already familiar with ZFS, you were in for a pretty difficult time.

[–] WASTECH@lemmy.world 2 points 11 months ago

I’ve never used your exact setup, but I have had issues with a web server behind a WAF not getting the client IP (all user traffic was shown as the WAF IP). In my case, the WAF was appending the client IP in a header, and I just had to tell web app to use that header as the client IP instead of the actual IP. Again, not sure if this helps since I have never used podman or caddy (this setup was with Wordpress and an Azure Application Gateway) but the same principles might apply.

 

Saw this bee that landed outside my window and had to go take a picture of it. I wanted to test out my new A7R V, and this was a great test to see the amazing resolution of this camera!

 

I’ve been out of the custom keyboard scene for several years, and recently dove back in with the Sat75x. I’ve built probably 15-20 custom keyboards over the years, but the last few I built before stepping away used the CreateKeebs SOTC Linear switches. I am a huge linear fan, and these switches ticked all the boxes for me. The factory lube was good enough that I didn’t feel the need to lube them myself (which I hate), they had a really good feel, and the sound was pretty good. Unfortunately, it looks like they no longer make these switches as I have been watching the Divinikey website (the only place I know sells them) for a few weeks now, and they haven’t come back in stock.

There are a ton of different switches on the market now, so I am looking for some recommendations for some good linears!

 

Please help! I have all the fancy espresso tools and a nice grinder, but I have no idea why I don’t get an even flow out of my machine. I have a Niche grinder, I use a WDT tool to distribute the grounds, I use the Normcore distributor, and a normal dose tamper. I replaced the shower screen on my espresso machine with the VST screen and I’m using a VST 18g basket with a puck screen. I am pulling 40g shots in about 28 seconds, so I believe my flow rate is right, but I can’t figure out what I’m doing wrong!

 

I set up SSL certificates for my internal services behind Traefik, but I was having some issues obtaining the certificates. I ended up having to add this line in my Docker compose file to bypass PiHole which is controlling the internal hostnames for my domain:

- --certificatesresolvers.letsencrypt.acme.dnschallenge.resolvers=1.1.1.1:53,1.0.0.1:53

After adding that, I was able to successfully pull a cert. The issue is, I have a firewall set up that blocks DNS requests from everywhere except my DNS servers (PiHole), so I had to pause that rule temporarily to get the request to go through.

Wondering what I can do here (if anything) to resolve this without having to disable my firewall rules regularly.

 

I finally decided that I wanted to be able to externally access some of my Docker containers from outside of my local network. I don’t want to deal with the security hassle of exposing ports on my router, so I decided to go with Tailscale.

All of my container web services are run through traefik and are accessed using hostnames I set up on my DNS server. How would I go about accessing the different web services externally since the hostnames don’t resolve?

 

Updated my dock to the latest firmware today. It worked fine until I restarted my deck to try and resolve some game streaming issues. After restarting the deck, the dock no longer works. When it is first connected to power, the ethernet lights strobe then go dark. Ethernet isn’t being detected by the deck and neither is the HDMI connection, but it still passes power on to the deck. Anyone else have any issues with this after the latest update?

 
view more: next ›