stratself
@stratself@lemdro.id
- Comment on Looking to move from Caddy 1 week ago:
You can use
caddy reload -c /path/to/Caddyfileto reload the config midway through - Comment on Looking to move from Caddy 1 week ago:
For TLS I am looking into using CertBot and it appears there’s a module (github.com/desec-io/certbot-dns-desec) I can use that works for desec.io to handle my certs.
You can consider using lego-acme as well. It’s not too different, just that it comes prepackaged with a bunch of DNS providers including desec, so you don’t need to install an additional module.
Since Caddy is handling my certs automatically, how often would I want to renew my certs?
By default, certs are valid for 90 days so you’d wanna renew a bit earlier than that. There’s also the option to use 45-day certs or 6-day certs, depending on the profile chosen.
Would I be required to run the same command periodically to renew my cert?
Yes, but it’s better if you automate them, like Caddy did, and both Certbot and lego can do this well. I run lego via a cronjob which checks for the certs’ expiry, and renew it when it passes a certain deadline.
I am looking to hear any suggestions or experiences about different reverse proxies that are preferably free of AI
Not sure I can recommend anything from that list because I’m not familiar with them, but I’ve heard haproxy to be very performant.
- Comment on miniflux vs matrix-rss 1 week ago:
You can consider selfhosting maubot + RSS plugin if you wanna keep using Matrix
- Comment on Looking for a chat app with specific requirements 2 weeks ago:
I wrote this by myself using anectodal sources from the community, and no, it never passed through any LLMs. Perhaps I should approach things with a less upbeat and more cynically curt tone.
- Comment on Looking for a chat app with specific requirements 2 weeks ago:
Hello,
I believe Matrix would be the most suitable candidate for your use case. The protocol supports both public and private (invite-only) rooms. It also has spaces, which are collections of rooms that helps with organisation (and yes they do exist in the sidebar). Voice/video calls can be done through Element Call which is integrated in many clients, and are usually quite performant. Pinned messages and polls are natively supported, and there exist various bots for reminders and other little neat features (see the Maubot plugins).
Matrix is also federatable like email, so you can extend your community to people on other servers in the network, too. Be sure to employ moderation tooling though, of which the ecosystem has plenty of and are improving every day. I also recommend testing out non-Element clients (such as Sable, Cinny, or SchildiNext) to see which one fits best with your organisation.
In another comment, you have mentioned the limit of 100 users. I believe this only applies for the Element Server Suite freemium solution, and so I ask, why not use another open source solution? My suggestion would be Continuwuity, a homeserver written in Rust with a very active community behind it. Continuwuity is generally considered much more lightweight than alternatives, and have been seen supporting sub-500 users just fine on a machine with 8 gigs of memory.
There’s some other QoL features you may be interested in, like auto-joining to a room after account creation, and . and it can also integrate with your favorite single-sign-on solution via OIDC as well. So yeah, feel free to ask more here about it, or take the next steps in the support room!
There exists other solutions as well, but I think they are not the best candidates for few reasons. XMPP (i.e. the protocol behind Snikket) is more lightweight, but its clients still generally lack support for group calls, pinned messages, and polls. Fluxer may have a better UI, but it is not federated from the ground up which can lead to problems. I don’t think Nextcloud Talk offers federation either(?), but I believe Nextcloud to be a quite heavy, “bells and whistles included” software suite in general which may be too much for your use case.
- Comment on Issues with https certs locally 3 weeks ago:
Caddy does certs by responding to ACME challenges on port 80 and 443. You need to forward those ports from the public internet back to Caddy, have you done that?
- Comment on Replacing Cloudflare Tunnel with a Selfhosted Towonel Tunnel 4 weeks ago:
It bundles WireGuard transport layer and a SNI reverse proxy natively, along with optional authentication. Good enough for beginners or people who need quick deployments.
- Comment on QubesOS workstation + homeserver, and DANE for TLS without 3rd party company 5 weeks ago:
Hi, the sourcehut seems to be pretty interesting. If I understand it correctly, this DANE-without-root provides a TOFU model as an alternative to the normal case of verifying up all the parts of the domain levels, right? If feasible, maybe that could be nice to extend with other methods for OOB verification and key rollover
- Submitted 5 weeks ago to selfhosted@lemmy.world | 5 comments
- Comment on I measured the idle RAM of 19 self-hosted apps on identical hardware so you can size a VPS without guessing 1 month ago:
Most of the software are old versions, Forgejo 7 is like years ago now. Why are you running benchmarks on these versions and not the latest ones?
- Comment on Ways to Expose Services Publicly 1 month ago:
I do this albeit with Tailscale. Netbird/Tailscale would act as a node of your VPN and you can configure reverse proxy routes (via
tailscale serveor Netbird’s equivalent) from the VPS edge to the homelab. You can even do SNI passthrough and have TLS terminated at your home, if you want, though this can be a bit slowerAlternatively you can even expose stuff via their servers. Tailscale Inc calls this service Funnels, and Netbird should have similar offerings. It’s kinda like Tunnels, though a VPS is greater as a dedicated entrypoint.
Lastly yes you’d be exposing the service to the general public internet, so some basic security is needed. Netbird has a Crowdsec module integration, might wanna look at that one and set up rules/detections. Consider putting extra auth in front of Jellyfin, use Authelia or something with an auth screen. And only expose the stuff you need, not your internal dashboard or whatever admin UI.
- Comment on Reliable messenger for family use? 2 months ago:
yeah, it’s consuming. I believe a big part of this is due to Matrix’s HTTP sync-polling being more expensive than simply maintaining a TCP stream (which is what XMPP does)
In fact, since XMPP syncs in the background so well, I use Conversations as a UnifiedPush backend for Matrix. You can find another article here as well
- Comment on I am selfhosting Active Matrix Rooms which is helping users find activity in the matrix network 2 months ago:
Since this is a selfhosting sub can you actually explain how you’re hosting it?
- Comment on Reliable messenger for family use? 2 months ago:
Hi, ntfy/another unified push backend is the third party
- Comment on Reliable messenger for family use? 2 months ago:
Android notifications are notoriously difficult to get right. May I ask how is Nextcloud Talk currently implementing notifications? Is it through ntfy, a background service, or Google’s Firebase? Have you allowed background usage for both the push app and the chat app?
I use Matrix with Continuwuity and Element X, and it’s doable most of the time except for small bugs. If you disable federation, the resource usage should be minimal too. But it also requires a third party for push service which can be unreliable.
On the XMPP side, there is also Snikket which you could look into. It offers both a server (running modified Prosody) and a mobile client (modified Conversations). XMPP can run as an efficient background service on Android, so it’ll receive in-band notifications.
Regardless of options, one of the main problem I’m aware of is that Android variants tend to overkill various background app, leading to missed notifications. I think it’s better to debug on that aspect as well
- Comment on Thoughts on crowdsec 2 months ago:
I don’t think geoblocking would be a great fit for Matrix, since you’d be contacted by servers from all over the world. It’s more suitable for something like a static website
- Comment on Whats a good alternative to Instagram? 2 months ago:
There are various technical alternatives (ActivityPub-based stuff like PixelFed/Loops/Mastodon/GotoSocial/Sharkey/Akkoma/something else on the Fediverse)
But would you take the plunge of self-discovering different content, which might as well be none of your topics of interests? Would you be acquainted of vastly different UI/UX such as the lack of recommendations, and the technicality of federation? And lastly, will you find it a place with communities to socialize and content to enjoy from in the long run?
I think trying out on a public instance would be a good way to answer those questions. PixelFed most closely resembles Insta, but the other ones can do too. Then you can consider selfhosting your own
- Comment on NutriTrace v1.0.0-rc.54 released: Health Connect sync fix, local LLM proxy support, backup fidelity pass [AIP] 2 months ago:
How on earth do you have 54 release candidates, each of them adding significant feature, and not bumping your versions? Wouldn’t it be nicer to just put them on the main branch and cut a semver release every now and then? At least that’ll save on the frequency of posts here
- Comment on what's the simple way to map services to subdomains instead of specifying the port number? 2 months ago:
When you say “on each device” you mean this configuration would refer to the services running on that device right? Not that every client device needs to have this set up?
The device that runs multiple services will set that up, yes. Not the client.
All my web services use apache or lighttd. Do I use caddy just for this or do I have to figure out how to move each of them to use this web server?
Apache and lighttpd can both do the same thing that Caddy does (multiplex many services via subdomain names on port 80). Caddy is just simpler and hence recommended.
You can move all services to use Caddy, takes some learning but overall better. Alternatively, if you already set up apache/lighttpd for each of your services, you can put Caddy in front and do something like
http://service1.devicename.lan/ { tls off reverse_proxy localhost:<port-that-apache-listens-on> }
Also does it work for non-web services, like ssh or samba? (Which wasn’t in my original question, I only thought of it now.)
No. Also, those should be running on their dedicated ports anyways
- Comment on what's the simple way to map services to subdomains instead of specifying the port number? 2 months ago:
Use Caddy on each device, with tls turned off. Basically
http://service1.devicename.lan/ { tls off reverse_proxy localhost:8000 } http://service2.devicename.lan/ { tls off reverse_proxy localhost:8096 }
- Comment on Where is the love for conduit? Everybody is preferring continuwuity or tuwunel? 3 months ago:
If you are running a conduit fork, what is your reason for leaving conduit, and if you are running conduit, why didn’t you switch?
Conduwuit (predecessor of Continuwuity and Tuwunel) hard-forked fron Conduit and introduced breaking database changes. That is a significant people don’t easily “switch over”
It may be slow in development, taking a bit longer to implement a new feature, but not too much longer.
I would say its pace of development is very slow compared to the pace of Matrix in general. But if you only want the barebones features, you can use it.
Or am I missing something the others have to offer?
Feature-wise, Continuwuity offers email support, single-use registration token, policy server integration, user suspending, a ton more of admin commands, and some extra endpoints for Element Call. It is also actively working on OIDC-OAuth (so you can login with your IDP), and an ecosystem-wide Admin API. It also has an active community. I can’t speak for the other fork.
Lastly, I don’t think anyone “hate” conduit, the project is alright. It’s just not the topmost option.
- Comment on Where is the love for conduit? Everybody is preferring continuwuity or tuwunel? 3 months ago:
As to answer your questions, threaded conversations are mostly a client issue. The UX for them are still not very good so not a lot of people use it.
SSO/Auth is actually quite hard to support. There’s the “legacy SSO” option which is deprecated in favor of native OIDC, and afaict only Synapse supports it for now. But Continuwuity is activeltly working on it.
- Comment on What are your self–hosted alternatives for inter device communication? 3 months ago:
Taildrop if you use Tailscale.
<offtopic> It’d be nice if there’s a Syncthing built into Tailscale or some of the mesh VPN solutions. Taildrop is good but it’s not entire directory sync with proper conflict resolution.
Surely I can use Syncthing inside Tailscale but 1. I have to depend on their public discoservers, or 2. I have to host and configure the discoserv myself for every client which is tedious to do </offtopic>
- Comment on Messaging apps - XMPP vs Matrix vs ??? 8 months ago:
I’m running continuwuity, and ejabberd as text-only IM servers to talk to some communities. The latter (and XMPP in general) has more moving parts (more ports, SRV records, etc) to set up, but messages deliver much faster and take much less resources. They’d probably both run fine on a VPS with the proper tweaks anyhow - the Rust-based server makes Matrix actually not suck after all
For bridges, I’ve used maunium-discord as a Matrix bridge in the past, and trying out slidcord right now. I think Matrix bridges still got better UI/UX due to more supported features (spaces/threads) and coherent clients, though let it be known Slidge is a hobbyist project. If your chat server is mainly for bridges, stick to Matrix and consider disabling federation. Also Matrix if you’d like your friends to switch over from Discord - it has more Discordesque features like custom emojis/stickers and SFU-backed group calls
Though this doesn’t mean I’m unrecommending XMPP. I do appreciate its clients’ snappiness, in-band notifications, and unrivaled efficiency. I kinda wanna write a blogpost comparing both software and protocols, but right now I don’t have an opinion about one over the other. They’re both cool albeit they both leak different metadata differently
- Comment on PSA: If you are running a Matrix homeserver written in Rust, you'll need to upgrade NOW 8 months ago:
- Submitted 9 months ago to selfhosting@slrpnk.net | 1 comment
- Comment on What is the current state of Matrix? 1 year ago:
- DNS adjustments aren’t needed if you do .well-known delegations which is easier
- Can recommend continuwuity, it runs much better on less resources. Lacks certain features compared to Synapse but overall good
- Notifications (and read markers) depend on client-specific black magic to work
- Federation do sometimes silent-fail completely, you can reset continuwuity’s cache when that happens. But full room history convergence needs patience
- Don’t join large rooms unless your server can handle the load
- Don’t host public rooms without modbots
The many small bugs make Matrix still bad - I wouldn’t recommend a non-tech user unless accompanied by a 24/7 admin. It is trying to improve but very slow because of reasons
- Comment on 18% of people running Nextcloud don't know what database they are using 1 year ago:
Should’ve specifically asked the operators/hosters if they need a better answer. But this has more engagement so