mschae
@mschae@discuss.mschae23.de
- Comment on Email for self hosted services? (Not personal email) 2 weeks ago:
On residential connections, that’s probably the case, yes. I’m hosting it on a VPS though and have had no problems with blocked ports so far. I imagine it depends on the provider?
- Comment on Email for self hosted services? (Not personal email) 2 weeks ago:
I’m not too concerned, for example, if they have to check their spam folders. As long as the email still lands.
In that case, it really isn’t that much of a hassle. A basic mail system isn’t that complicated to set up (just make sure you have proper authentication and such, don’t host an open proxy!). I actually did this not too long ago, using maddy, which unlike the traditional postfix+dovecot setup (which I had also been looking into) means you don’t even have to host separate services for SMTP and IMAP, and it also automates most additional things that are necessary nowadays for you, like TLS, DKIM, DMARC, and so on. Not quite everything though, there’s still stuff needed to do manually, mostly to set the SPF and DMARC records in the DNS, but it’s been working really well so far.
And really, the only mail provider you have to worry about for putting your mails into spam is gmail. They’re the worst. (maybe microsoft-hosted outlook too, but I haven’t encountered anyone using that)
- Comment on Forgejo Scraping Protection: Nginx and Anubis 3 weeks ago:
Unrelated to the actual anti-bot topic discussed here, but I would just like to mention this point:
PROTOCOL = http+unix: because UNIX sockets are said to be faster locally but also because this avoids the painful management of ports. Also feels safer [as] there is no way to connect from outside.This is really underrated. I try to use this for all the server software I host, and not having to manage ports is absolutely great, along with knowing that nothing can connect to the service internally when it’s not supposed to.
Except I actually go a step further and use systemd’s socket activation feature, which has a few additional benefits (like seamless restarts, no need for
CAP_NET_BIND_SERVICE(my webserver and reverse proxy runs as a completely unprivileged user!), only starting the service once there is a request (this one is admittedly less useful), and having a quick overview of bound ports and Unix socket paths listed in the.socketfile). Unfortunately, most programs need to be patched to support this, including forgejo (outdated codeberg link here because I had to set the forgejo repository on my own code forge to private earlier today because of scrapers…). - Comment on How do people handle authoritative DNS redundancy for their self-hosted workloads? 4 weeks ago:
Interesting, that’s much more sophisticated than my setup (though to be fair, I host my services on a rented VPS instead of home)!
The issue only occurs with my externally-facing DNS, which is needed to, for example, to reach my Lemmy backend instance (lemmy.pootis.network) and the pictrs deployment. But yeah, internal DNS works perfectly for me and it easily survives a node failure.
Could still set up a recursive resolver for external DNS, but I guess that wouldn’t help other people who use a bad resolver. Tricky situation.
- Comment on How do people handle authoritative DNS redundancy for their self-hosted workloads? 4 weeks ago:
But even if I query
1.1.1.1directly formy-website’s record, it just doesn’t work most of the time because the resolver pins itself tons1which is currently failing, or it selectsns1and does not even care to tryns2.That sounds bad. They really shouldn’t do that.
moving my DNS infra somewhere else (Cloudflare, for example)
And it would also mean this isn’t a solution either. If the problem is on the resolvers’ side, moving to a different DNS hoster would not change anything. Hm. And the other two potential solutions you’ve listed would be extremely overkill for this use case…
Personally, I only host one authoritative namserver and do redundancy by using some free secondary DNS services (although a friend has also recently set up an authoritative nameserver, so maybe we’ll host secondary DNS for each other in the future). I haven’t encountered this issue before, but my server also hasn’t been down a lot.
There’s a lot of custom machinery that keeps my workloads running and accessible after a node failure, but all of this becomes completely moot when authoritative DNS is the bottleneck.
If it’s only necessary for your own stuff, maybe you should set up a local DNS resolver that works correctly which your services can use?