habitualTartare
@habitualTartare@lemmy.world
- Comment on Issues setting my first Home lab as a total total beginner (no programming, coding, etc. related knowledge) 1 week ago:
looking at the install script it looks like casaOS is installed directly on the laptop. you can check by running
systemctl status casaosin a terminal. if that’s not found try
docker ps -ato list all docker containers including any not currently running. - Comment on Issues setting my first Home lab as a total total beginner (no programming, coding, etc. related knowledge) 2 weeks ago:
I’ve never used Netbird or casaOS. I run debian and docker containers. I would recommend looking at wg-easy as a VPN. it also uses wireguard but for me it just works. you open 1 port on UDP and route it to wireguard, it’s a secure way to access your network and is quite hard to detect from the outside.
I’ve heard good things about caddy.
“data at rest/LUKS” is something you should consider if your personally worried about someone physically trying to get information off your computer/server. if the server is running or an attacker gets into your system remotely, it doesn’t matter. as a beginner, I would determine if the data your saving is worth the extra headache of encrypted media, especially if something goes wrong/an update breaks something or your configs/setup messes something up. if you do, keep a copy of your decryption keys on a NEW USB drive (flash drives go bad) or printed out in addition to saved on your workstation/laptop/password manager.
Personally for new systems I recommend Proxmox hypervisor instead of running directly on the laptop. having your debian OS/casa or whatever you use virtualized gives you the ability to take snapshots in time of your OS, makes backups easier and can help when you expand later (backup and restore on the new computer running proxmox). mine is: proxmox on bare metal old office PC
- | debian > docker w/ portainer (I plan to replace portainer w/ komono)
- | TrueNAS > S3 bucket application (garage)
if Casa becomes limiting as you learn and grow, I would recommend docker compose stacks w/ a web gui like komono.
one final note, although AI can be very useful for troubleshooting and getting some code to fix a problem (albiet logic/problem solving isn’t their strength) it’s awful for retaining knowledge and learning in the same way that using a calculator or other tool before fully understanding how to do addition/multiplication manually. I would strongly recommend taking some time to learn the basics without ai if your goal is to understand how everything works. resources to start with are using and reading “man + command”, command help flags, online courses and websites: linuxbasecamp.com explainshell.com - copy paste a command with all arguments and it tells you what it does. …linuxfoundation.org/…/introduction-to-linux/
- Comment on Selfhosting as a Linux newbie - Ubuntu Server LTS or Debian 13? 3 weeks ago:
you could definitely run proxmox in a VPS but I was thinking more of debian in the cloud. Then exporting that computer from wherever you host it as a ova file then importing it into your local server: pve.proxmox.com/wiki/Migrate_to_Proxmox_VE#Automa…
and on the ram issue, I’m running on over 10 year old workstation hardware ddr3. it doesn’t take much to run.
NAS with zfs storage does typically want a lot of ram (e.g. truenas) but still for a small home environment it works fine with a lot less than 64gb.
- Comment on Selfhosting as a Linux newbie - Ubuntu Server LTS or Debian 13? 3 weeks ago:
I run proxmox bare metal (debian-based hypervisor) and virtualize debian which has all my docker containers.
with virtualization you can take a snapshot and backup everything that way. super simple to roll back if you mess something up. the added bonus is you could probably take a snapshot of your VPS and migrate it to a local vm.
Ubuntu is something I played with about a decade ago and I never felt like I was “missing” something for debian, especially on servers.
- Comment on Using a SSH tunnel/ port forward to connect a TV? 2 months ago:
I’m not entirely sure about the technical differences but from my understanding VPN connections are preferred. From a security perspective, ssh has some more considerations since it’s easier to detect it’s open, and you should lock down root access and other privileged accounts. but SSH seems simpler to actually get working vs a VPN solution which would probably require a reverse proxy or something to get the TV working.
For example, compromising a ssh service gives you access to the shell immediately vs wireguard or similar that historically (from my knowledge) has had fewer critical vulnerabilities that could lead to remote code injection or access. This is also why many corporate and best practices recommend layering ssh through a private VPN like IPsec, OpenVPN, wireguard, etc.
in practice it’s most likely fine as long as
- you don’t use root or an account with sudo to do the ssh forwarding
- require a ssh key for all connections (at minimum any remote/internet connections)
- update the system regularly. you can automate security updates with unattended upgrades on debian-based systems.
- Comment on Using a SSH tunnel/ port forward to connect a TV? 2 months ago:
Are you connecting from a public network or something? like a hotel wifi or other?
The easiest solution would be to setup the pi as your router and use a VPN like wireguard (wg-easy) or tailscale.
if it is a public network, you can double NAT. There’s dedicated boxes like the GL.inet travel routers that support wireguard/openVPN and beta for tailscale. they have some features that work well with captive portals.
If it’s a home network, you can probably use your PI as a entry/exit node or VPN client instead of using ssh.
- Comment on as a noob, should I connect jellyfin with tailscale using OIDC? 2 months ago:
wireguard is self hosted and you do have to “expose” one UDP port. From the outside it’s difficult to detect that this “opening” exists because wireguard just listens and ignores everything unless you send the encrypted credentials. Compared to hosting a webpage or jellyfin directly this is much more secure. As long as you keep wireguard relatively up to date you don’t really have to worry much about it.
I personally use wg-easy. It’s designed to be deployed into docker (using docker compose is by far the easiest).
Then you can either use your IP address, or ideally a dynamic DNS provider so you’d connect to myexample.com:51820. Duckdns is free, otherwise options are available like cloudflare. If you can get jellyfin working, this should be relatively straightforward.