This profile is from a federated server and may be incomplete. View on remote instance

Help with deployment

Hello nerds! I'm hosting a lot of things on my home lab using docker compose. I have a private repo in GitHub for the config files. This is working fine for me, but every time I want to make a change I have to push the changes, then ssh to the lab, pull the changes, and run docker compose up. This is of course working fine, but...

Im_old ,

Why not host your own git repo (e.g. gitea) so you can do 2 or 4 without opening services outside?

Im_old ,

I've been using matrix for years to this purpose, but moving to xmpp/prosody now

Im_old ,

No.

Yeah ok. First of all, because I can 😁. I mean z what's good being an IT nerd if I can't change stuff when I want?

Jokes aside, I've been reading more recently on matrix and looks like there are some security issues in the design of the app/protocol. I'm on mobile now, I'll look for sources when I'm on pc.
Also I don't like that it is a server centric system (so data is primarily on the server instead of the clients).
Also it takes more resources than I was expecting. For less than 10 users I can't have less than 4gb of ram (on a dedicated debian server, running docker) or it swaps so much it kills the system.

So basically I'm testing out if xmpp is a better system for those issues.

Im_old ,

I know exactly what you mean. Just for general information, I've found another android client that I think it's better than Conversations. It's called Monocles chat (and it's on f-droid).
On matrix/xmpp I install the whatsapp bridge. I can convert a few close family members but no way everyone. For me it's an acceptable compromise. I get the close members to use my servers/apps, everyone else through the bridge so I can at least have all the chat in one place

Im_old ,

for the downvoters, it's a song from a Monthy Python movie, so comedy (and great one at that!)

Im_old ,

Having multiple interfaces in each vm can lead to issues with routing if you screw something up.

Like you said I'd expose the services via reverse proxy in the public vlan, and enable ssh access on the firewall only from a jumpbox or the ip of your pc (or maybe the vlan you are in).

Im_old , (edited )

Proton a few years ago disclosed the IP address of the user of a certain mailbox upon request by LEA. That was enough to get the person found and arrested (I don't remember what the case was about). They HAVE to comply with these requests, but they DON'T need to log/retain those info ETA: and I was wrong, thanks @Cheradenine to set me straight. But I think the point still stands. I don't want to be ALWAYS be tied to a VPN, there are some scenarios where I can't use a VPN.

That was the moment I decided to selfhost my email server.

Im_old ,

Agree with you, that's why I buy my butt plugs (and similar toys) with my gmail account! 😁

Im_old ,

They can get my encrypted drive. My domain name is registered to me so that's clear it's my email. But no content.

Im_old ,

and maybe do a little self-analysis and think WHY that happened. If they all react that way, maybe it's you.
ETA: or maybe you are in the wrong crowd as well!

Im_old ,

oh man, you made me think so many bad jokes about this... 😅

Im_old ,

Quit smoking.

Apart from that, it's been a clusterfuck.

Im_old ,

my 6 months old nephew wailing scream. Once I left the phone on my desk and walked to the copier. The phone started wailing. My desk buddy knew what that scream meant, and brought me the phone, thus filling the whole office with baby screams.

Im_old ,

I'm self hosting headscale (foss implementation of tailscale control server) for this scenario. Works great!

Im_old ,

I've been told that zerotier is even better. Haven't tried it myself (it looks more complicated to selfhost) but the guy suggesting it knows waaaaay more than me on these things. Just if you want to look into another option.

For what it's worth (from a random guy on the internet) selt-hosting tailscale is quite easy! 🙂

Im_old ,

I have been using opnsense on a very cheap celeron nuc for a few years, very happy with it

  • All
  • Subscribed
  • Moderated
  • Favorites
  • kbinchat
  • All magazines