[-] iodine0320@lemmy.world 1 points 10 months ago* (last edited 10 months ago)

Agreed. Northridgefix is the new Rossman

[-] iodine0320@lemmy.world 6 points 1 year ago* (last edited 1 year ago)

I've been quite happy after recently switching to Hagezi https://github.com/hagezi/dns-blocklists

[-] iodine0320@lemmy.world 5 points 1 year ago

Alot of useful info in this guide if your new to OPNsense.

50
submitted 1 year ago* (last edited 1 year ago) by iodine0320@lemmy.world to c/selfhosted@lemmy.world

Today I decided I would create some way of visualizing my unbound DNS requests/blocks on OPNsense. Adguard does a good job at this but I have issue with added third party repos and plugins, especially at the router level.

Anyway...since the last time I've dug into this OPNsense has built in Unbound DNS reporting (since 23.1) and it's amazing! Arguably just as good as Pihole or Adguard. Graphs, lists of top blocked and allowed domains, query logs, quick buttons to block or whitelist next to each domain. I'm impressed.

Not sure if this is the right community, but just wanted to share if some of you weren't aware of this option.

[-] iodine0320@lemmy.world 3 points 1 year ago

If your running behind OPN/PFsense I've found the easiest solution for internal only SSL is to use the router to create the certificate chains. Yes you'll have to import 1 CA cert on each end user device but only the one then you can crank out internal certs without and https warnings or domain constraints/challenges.

[-] iodine0320@lemmy.world 3 points 1 year ago

I've had relatively good luck with docker in containers but eventually decided to run docker in VMs as I only semi trust most docker apps and like the added security I get from having it in a full VM in full isolation. Some of the workarounds for docker in LXCs are far from security best practices.

[-] iodine0320@lemmy.world 1 points 1 year ago* (last edited 1 year ago)

Yes, Alpine maintains Nextcloud in their repos. I mount my NFS share to the Proxmox host (you can mount using the gui and set it to any form of storage you want) then bind mount the share folder to the LXC. I moved from docker in a VM to this LXC with no disruption to my data.

[-] iodine0320@lemmy.world 2 points 1 year ago

Alpine packages services like Gitea and Nextcloud which Debian does not. This makes keeping up to date alot simpler for myself but that's personal preference.

61

I recently moved Nextcloud and Gitea from Containers on a Debian VM to Alpine LXCs running Alpine's packages. I've never had Nextcloud's web interface so snappy and my resource usage for both is next to 0. If you're running Proxmox I'd highly recommend trying out Alpine LXCs if they package your services.

[-] iodine0320@lemmy.world 2 points 1 year ago

Quadlet looks very interested, I'm reading the docs now. Thanks

[-] iodine0320@lemmy.world 5 points 1 year ago

The simplicity of docker with much better security. Honestly the main appeal of having my homelab is to play with technologies and learn new things. The couple times I've skimmed the docs for Kubernetes it seemed over complicated for a personal homelab.

[-] iodine0320@lemmy.world 2 points 1 year ago

This is extremely helpful and gives me all the answers I was looking for. Thank you

52
Migrating to Podman (lemmy.world)

I'm looking to migrate all of my containers to rootless podman but need some advice.

All of my services are currently running docker compose. I've played arount with podman but I am unsure of best practice: I have the option of installing podman-docker, podman-compose, or docker-compose connected to a podman socket. What's the recommended way here?

I also can't seem to find any information on setting up a systemd unit for rootless podman compose. How are you all auto starting podman (compose) files?

iodine0320

joined 1 year ago