Reannlegge
@Reannlegge@lemmy.ca
- Comment on What is your weirdest self-hosting problem you've had to solve? For me: Mouse inside the server. 5 days ago:
I am so afraid of an SD card dying and killing my HA so I have a HD setup. I have one good SD card of the 10’s of cards I have killed and it is now running my ssh honey pot on a pi 0 2.
- Comment on What is your weirdest self-hosting problem you've had to solve? For me: Mouse inside the server. 5 days ago:
I do not care to admit how many times when I was first getting into home labbing that I could not figure out why I could not reach a pi or the internet. All because I either killed an SD card for pihole or just plain out forgot to put one in!
- Comment on Selfhosting a printer (and scanner) server with UI 6 days ago:
I have always used cups and never had problems with what you are talking about, however using the web ui is relatively new to me. SANE I have always had issues with no matter the UI I use.
- Comment on Do you participate in this hobby without a formal IT education or a career in a 1 week ago:
I learnt basic HTML as a youngling in the 90’s so back before it got very complex, no formal training. I pretended to learn python for my 100 level comp sci in the mid 00’s but completely forgot it after the class was over. I just got into the hobby recently because I did not want to continue paying for stuff but not owning stuff, and it was getting silly expensive for my unlimited free trial hack and personal blog. Plus I wanted to start getting away from big tech, so learning about self hosting from the web and double checking my stuff with Claude really helps.
- Comment on Good resources for setting up a domain name to a local Caddy instance 1 week ago:
I have a flint 2 (glinet) as my firewall as well, I had read somewhere that I should install vanilla OpenWRT so I did (I have added stuff to it so I like coming up with different flavours when talking to people like rocky road). I have Caddy running in docker on a pi in my LAN I have a password file of some sort that Caddyfile references at the top. Don’t ask me how I formatted it because I do not remember that part but take my secondary pihole as an example of using a domain that cannot be reached, touched from outside of my lan.
‘pihole52.mydomain.ca { @allowed { remote_ip 10.0.0.0/8 } handle @allowed { redir / /admin{uri} reverse_proxy 10.0.69.52:31415 } handle { respond “Not available from this network” 403 } import easydns_tls log { output file /var/log/caddy/pihole52.log format json } }’
While other places on my domain can be reach outside of my vLANs. I have to secure some things up as I found that my SearXNG is open to the WAN.
- Comment on My Firewall was not putting out last night. So I could not get any pihole action. 1 week ago:
I use easyDNS and they have a wild card option for their email, so I have a formula whenever I am signing up for something my email addresses are always nameofservice_funSaskathchewanwordplusthreerandomnumbers@reannlegge.ca. When I started this I was on hosthero and they use cpannel with no wildcard options you have to go in and create the email address before you use it. When I left hosthero, because they cost to much and are not the friendliest company to deal with I had something approaching 300 unique email addresses after 4 or 5 years because I did just not bother closing them after I continued using the free trial of whatever or just stopped the forwarding to my main email address or whatever email it needed to be sorted into.
Now I just have everything automatically go into junk mail unless it is something I need than I make the effort to log into their easyMAIL web thingy and sort where it should go. I have it set to delete things that are a week old (I think it could be a month?) so if I do not need it I do not need to worry about it and it will just go away on its own other things are sorted into folders and very few things are sent to my inbox.
- Comment on My Firewall was not putting out last night. So I could not get any pihole action. 1 week ago:
I was never really a windows user, I grew up on Mac OS (Apple DOS, 7, 9, and X). I am stuck with an iPhone and an iPad because I do not have the money to replace them at the moment but as soon as there are no longer updates for them they are being stripped of most of the data, being put onto my IoT vLAN and being used as HA kiosks. I say so long to things as soon as updates are not being pushed because they become attack vectors. I have had my ID stolen once before, probably not because of out dated things but I want to limit the places bad actors can get to me (just know the process of making sure stuff doesn’t hurt you further is hell).
I have a Mac mini I am thinking of doing some actual work to get Debian installed on but I turned on the Mac just to get my iTunes purchased music off of it and than half assed an attempt to get refit installed and get Debian running, maybe some day I will get it working but that day is not now.
- Comment on My Firewall was not putting out last night. So I could not get any pihole action. 1 week ago:
I have 2 instances of pihole running in my LAN, I have wireguard on my firewall to get to those two ad blockers when I am away from home. I am so glad I was able to figure out how to get it back up and running without needing to redo all the work.
I have pihole do a lot more than just block ads; they also block a few different tlds (like .zip), they have different lists for different vLANs, and there are several different regex things I have in it.
They are not on the same pi, sure they are both docker images but they are on different pi’s
- Comment on My Firewall was not putting out last night. So I could not get any pihole action. 1 week ago:
Yeah I know it was a very iffy time luckily it was only one night and morning. I broke the protection many times today but I am all wrapped up now.
- Submitted 1 week ago to selfhosted@lemmy.world | 14 comments
- Comment on Ways to Expose Services Publicly 2 weeks ago:
I have a Flint 2 with a vanilla install of openWRT, that hosts wireguard. I have 2 static IPs, because I thought hey running my own mail and smtp services cannot be that hard (turns out yes it is hard and not worth the time to deal). Any who I have Wireguard running on my firewall and Caddy running on one of my pi’s, it gets TLS from lets encrypt.
I have a couple of domains that Caddy uses to point things out to the world or my LAN/vLANs/VPNs. Very few of the things go out to the whole world, but if I wanted to share say a Jellyfin server with someone I could wip up a VPN that only allows Jellyfin through and points DNS to my piholes. Why do I mention my ad blocker? I mention pihole because that what hosts the prefix to my domain names that Caddy can serve up, I do not remember why I set it up like this, I would have to look through my notes but pihole points “service”.domain1or2.xyz to caddy which than points to the right service.
- Comment on FANTASTIC video on configuring Openwrt VLANs 2 weeks ago:
I use a Flint 2, I think I have something like 5 AP’s On it and it covers my whole home. I have a bunch of vLANs as well for the APs and VPN’s. It came with some custom OpenWRT install but I flashed it with a vanilla version instead. I was using an Apple Airport Extreme prior to getting the Flint 2, but my place flooded and I got board so I took up the hobby of home labbing while I wait on insurance to get things rolling (after a few months the flooring is finally going in tomorrow) my original plan was going to be use the Airport as an extender but I did not need that, but yes APs with the same SSID will work together. My Flint 2 has SMB setup to back up its settings to a pi I have on my LAN.
- Comment on Homelab discussion 3 weeks ago:
I decided that living on a hope and a dream of maybe someday seeing if my Mac Mini still worked I can now gleefully say it is working* if I cannot figure out how to update it further oh well I will just continue on with it as is and harden it the same way I do everything else. But right now it is downloading my music library, which I will promptly backup before trying to update it further.
*I need to figure out how to update it to the last OS version it can handle.
- Comment on Homelab discussion 3 weeks ago:
You should really have a good hardware firewall before you do that. Change ports, change ports for everything you can nothing I run is on the standard port I make sure of that.
- Comment on Homelab discussion 3 weeks ago:
Thanks for letting me know.
- Comment on Homelab discussion 3 weeks ago:
On all of my raspberry pi’s excluding my HAOS pi I have Docker; (I am thinking of adding something so I can see all my images visually, funny story I was looking on docker to see everything I have running and I guess I do have a service for this).
2 instances of pihole across 2 of my pi’s; (one primary, which has been migrated to docker and a secondary which is still running bare metal I have docker on that pi but just have not got around to migrating it yet maybe that is a today project) highly recommend you start with a linux distro that is right for you and start with docker and pihole (You could probably stick with windows or MacOS if you want but I highly recommend linux, there are other whole LAN ad blockers, pihole is just the one that works for me. Just to be funny I run them on port 31415!) on a device or two you are not afraid to leave running 24/7 that is why my homelab is spread across different 4 different pi’s and a Flint 2 router.
Maybe on two pi’s I have Nebula-sync; to keep my piholes in sync but I know I have it on one of them.
On my pi 5 with the most RAM I have:
Caddy; this could go on prior to pihole, but it is to give everything easy to remember domain names and to allow some to be open to the world while keeping others to the LAN/VPN
After those four things I would suggest searXNG; to replace whatever search engine you use when you go through and pick which engines it uses to do searches please do not select the Google. With searXNG you do not get all that AI crap I hear people get now, or the paid advertisement links at the top of the results, you also get to weigh which engine you want to use more.
Vaultwarden; with that I can use all of bitwarden’s services for free
Immich, because I am not paying a third party to store just my photos
Nextcloud, but I am getting off of that, it does all of the file sharing that I need with my devices that cannot use rsync calendars and contacts but it tries to do to much.
Down detector; to tell me if there are problems with my devices (sends me emails if one of my devices goes off line).
Paperless; to keep important documents in a easier place to find.
On another pi 5 I have:
The arr stack, I should really get jellyseeerr working!
Transmission, the bittorrent client it is running CLI with a web interface. I have it setup to download a copy of the raspberry pi OS every time there is a new release and to host it until the next new release, everything else I have a ratio of 3.
Jellyfin; (I will fight you if you think plex or emby are better), if I wanted to share my media with people I could create another VPN exit that only allows people to Jellyfin.
I guess I have Navidrone; for music streaming? I should probably remove that because I have Jellyfin that I plan on using.
Cowrie, is the honey pot sitting on port 22.
On another pi 5 I have
Ghost; for my blog/web design service, I am considering exploring more options as it is more geared towards people wanting to get money.
I guess I have matomo; to monitor my self hosted blog, did not know that.
On a pi 4 I have
HAOS; I have so many things running in HAOS, but the one service I am most proud of is my reminders. The reminders just started as a reminder for me to take my medication because the app I had purchased decided that the fact that I had purchased it was not good enough and they wanted to charge me a subscription, so I setup Home Assistant to remind me and that quickly became reminders to do other things as well all on my apple watch.
I have a retired ipad running a HA kiosk in my kitchen; it tells me things like what lights are on, how many times I have had bots try to penetrate me, speedtest, transmission stats, and my ecobee settings. I am thinking of setting up an old phone to run as a separate kiosk in my bedroom as a clock/weather screen on my bedside table and I am hoping to get a hand me down old ipad to act as another kiosk in my living room, more to watch for docker containers needing updates, maybe the also the weather and bandwidth monitor.
OpenWRT on a Flint 2 because the firewall my ISP’s firewall/modem like most ISP’s is a joke so I have it set to pass through to my own with 2 static IP’s one of them was originally going to be for mail but I quickly discovered how silly of an idea that was.
Wireguard; I think it is on my firewall, on one of the IPs I was going to host mail on the other but I came so close to ripping out my hair trying to do that so I got a hosted service through easydns it has a wildcard function so I can still get unlimited free trials to whatever instead of going into hosthero’s cpannel and spinning up a new address)
Crowdsec so I get to watch how many bots try to penetrate me in a day, week, month, or ever. It is in the 100’s a day, before I knew I could/should change my SSH port I had port 22 open to the WAN, this was long ago but still it was a bad idea. 22 is now open as a honey pot.
I have Crowdsec-bouncer that stops known bad actors from trying to get in.
I am sure I have other services on my firewall but I cannot tell what is an actual openwrt service and what is something I have added, but it is a vanilla install with all kinds of things added extra. .
Don’t know if you would count CUPS or scanjs as self hosted but those are run for my printer/scanner on a pi.
I have an old mac mini I am thinking of plugging in so that I can download all my music and add it to Jellyfin, than I am debating on if I want to install debian on part of the drive and keep MacOS on part of the drive so that I can actually use the bluray drive I have as far as I know there are no bluray drivers for linux because the big movie producers are scared of piracy, not like they are trying to rape us consumers over the hot coals.
- Comment on What do you do with your old iPad mini? 4 weeks ago:
Huh if I ever get around to it I will look up guided access to lock it to my HA kiosk. Hell I will forget by the time I hit submit I need to stretch my legs and see about it now.
- Comment on What do you do with your old iPad mini? 4 weeks ago:
Came here to say this I have an old iPad sitting in my kitchen with HA in kiosk mode. Uninstalled as much as I could and it just sits there with a clock if I press the screen I can see fun stats like speedtest, crowdsec, pihole, or the forcast for the next few days or even what my thermostat says the indoor temperature is.
- Comment on Self hosted photo options for the family? 4 weeks ago:
As many have suggested immich is the answer I have tried a few others but immich is the answers.
- Comment on My selfhosting setup so far 4 weeks ago:
What do you have against pihole? If it is you want to see ads you can turn off the adblocking and see ads but you can use it for internal dns naming for services with Caddy as I find it more reliable than just Caddy across multiple systems.
- Comment on Thoughts on crowdsec 5 weeks ago:
Yes the self hosted webui is awesome, I get to see that I am getting the warm embrace from China for the most part. I still use my vibe coded thing for my quick monitor on an old ipad in my kitchen but if I want to see it in more detail I use the webui.
- Comment on Thoughts on crowdsec 5 weeks ago:
Fine tuning is a great thing to keep in mind, just like a bloated pihole lots of false positives and over looked spots.
- Comment on Thoughts on crowdsec 5 weeks ago:
My first baby step into self hosting (years before I realized self hosting was the answer) was pihole. I realized it got most of the ads and I was happy with that, years went by and I realized more ads were getting through, so I learnt about fine tuning my ad list and regex lists. A little while went by and I heard that the google was selling .zip tlds so I learnt a little more about regex, not because I was worried I would unleash something on my LAN but just incase someone else did.
Layers there are layers of things I needed to do to prevent the ads, and than layers of things I needed to do to prevent spam. So I knew there was going to be layers of things I would need to do to protect myself when I got a “real” home lab on the Wild Wild WAN. Home Labbing is like sex, sure it is fun but it can be dangerous if you do not protect yourself and there are layers of protection you should use.
- Comment on Thoughts on crowdsec 5 weeks ago:
I did not mean to through shade onto you this webui is a lot better than my ha vibe code.
- Comment on Thoughts on crowdsec 5 weeks ago:
I am using HA
- Submitted 5 weeks ago to selfhosted@lemmy.world | 27 comments
- Comment on State of the Discord - A Lesson 5 weeks ago:
Why, use Redddit if you are in a self hosting community, I understand the community of curious people are there but are you really going to be selling yourself short like that? Than to be using discord as a self hosting community messanger?
- Comment on Google pays $250K for Linux vulnerability allowing guest VM escapes 1 month ago:
If they leave it out someone else will find it, the days of leaving things out deliberately past.
- Comment on what's the simple way to map services to subdomains instead of specifying the port number? 1 month ago:
I wanted to say I know this one, but a lot of people beat me to it use caddy.
- Comment on just realized whoogle is dead now 1 month ago:
I to am on a residential static IP and have been loving searxng. It is fairly vanilla running on a pi 5 in docker.