Lem453

@Lem453@lemmy.ca

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Secure portal between Internet and internal services

I thought I was going to use Authentik for this purpose but it just seems to redirect to an otherwise Internet accessible page. I’m looking for a way to remotely access my home network at a site like remote.mywebsite.com. I have Nginx proxy forwarding with SSL working appropriately, so I need an internal service that receives...

Lem453,

This is the way. This is the video I followed.

www.youtube.com/watch?v=liV3c9m_OX8

I use traefik as reverse proxy. I have externally accessible domains for and then extra secure internal only domains that require wireguard connection first as an extra layer of security.

Authentik can be used as a forward auth proxy and doesn’t care if it’s an internal or external domain.

Apps that don’t have good login or user management just get Authentik proxy for single sign on (sonarr, radar etc).

Apps that have oAuth integration get that for single sign on (seafile, immich, etc)

To make it work the video will talk about adding both the internal and external domains to the local DNS so that if you access it from outside it works and if you access from wireguard or inside the lan it also works.

Lem453,

What is the app running on? Can a browser on that device find the URL?

Lem453,

Is anyone else getting crazy battery drain on Android? Like 15mins use causing 30% battery drain on my pixel 8?

Microsoft is testing Game Pass ads on the Windows 11 Settings homepage (www.ghacks.net)

Microsoft’s announcement: “We are introducing a new Game Pass recommendation card on the Settings homepage. The Game Pass recommendation card on Settings Homepage will be shown to you if you actively play games on your PC. As a reminder – the Settings homepage will be shown only on the Home and Pro editions of Windows 11...

Lem453, (edited )

If you don’t want to think about your computer and just want a tool to use there is Aurora. It’s a variant of fedora but it uses an immutable file system which makes it super stable and reliable. If there are any issues you can easily roll back the entire os to a previous version.

This is true of all fedora atomic desktops. Aurora is a variant that takes it to the next level by making all updates and everything require as little human interaction as possible so you don’t have to worry about how the computer runs and just use the computer for your actual tasks.

getaurora.dev

Lem453,

They advertise as being zero maintenance which is a huge deal with many windows and Mac users than don’t want to think about the tool itself, they just want to use it. From the site:

What’s the difference between Vanilla Kinoite and Aurora? Vanilla Kinoite is a very stock experience. Aurora includes many enhancements and tweaks, like included drivers for various printers, network adapters and more as well as included codecs. Aurora also features tweaks to enhance your battery life on a laptop.

Lem453,

By zero maintenance they mean you don’t even have to hit the update button. It all just happens automatically. Many Linux users won’t like that but many windows and Mac users will.

Lem453,

Fedora atomic or it’s more streamlined cousin silverblue. They both have gnome and kde versions depending on your preference but as a base they work really well for a workstation

Lem453,

I’m curious how using ansible to deploy docker containers is easier than just using docker compose?

Ansible makes sense to setup the OS the way it needs to be (file systems, folder structure etc), but why make every container through ansible instead of just making a docker compose and maybe having ansible deploy that?

Even easier is probably to just run something like portainer and run the compose file through there

Lem453,

What makes butter better than btrfs for ostree systems?

Lem453,

Fedora atomic with kde (kionite) has been amazing on my laptop so far (recently moved from mint)

Lem453, (edited )

How do I install this on fedora? I’m not to keen on curling a bash script and running it. Thanks!

Edit: for fedora atomic, the answer is to download the rpm and overlay it with rpm-ostree install

Lem453,

If you submit the rpm to rpm-ostree then users can just find it from there with rpm-ostree install xpipe.

That requires an overlay but the alternative is a flatpak which won’t work for an app like this I think anyways.

Users that install brew can just get it from here as a proper containerized install rather than an overlay.

The script is definitely not great as he primary way to install, everyone doing that should be doing so very reluctantly. Getting the rpm into package managers will go a long way.

That being said, xpipe is amazing. Only used it for a few hours and already love it and can’t believe I didn’t have it sooner.

Lem453,

Sounds like they actually changed it to Go language regex syntax instead of pearl syntax.

The documentation certainly makes it sounds like they just got rid of regex but this forum post seems to show otherwise.

community.traefik.io/t/pathprefix-regex/21819

I’m definitely in the wait for a month at least before attempting this upgrade camp…

Lem453,

This seems like an issue where the wireguard is not using the correct DNS server. Does the wireguard DNS setting point to the router?

A diagrams might help me to see what is going on more clearly.

Lem453,

If you’re only using nextdoor for fine sync, seafile or synching will be vastly superior

Lem453,

Seafile has been great for me.

400gb, multiple users. Single sign in with Authentik.

Just recently setup only office integration

Lem453,

I moved form next cloud to seafile. The file sync is so much better than next cloud and own cloud.

It has a normal windows client and also a mount type client (seadrive) which is also amazing for large libraries.

I have mine setup with oAuth via Authentik and it works super well.

Lem453,

Maybe 1 hr every month or two to update things.

Thinks like my opnsense router are best updated when no one else is using the network.

The docker containers I like to update manually after checking the release logs. Doesn’t take long and I often find out about cool new features perusing the release notes.

Projects will sometimes have major updates that break things and I strongly prefer having everything super stable until I have time to sit down and update.

11 stacks, 30+ containers. Borg backups runs automatically to various repositories. Zfs auto snap snot also runs automatically to create rapid backups.

I use unraid as a nas and proxmox for dockers and VMs.

Lem453,

Are you changing the same files at the same time?

I have multiple computers syncing into the same library all the time without issue.

Lem453,

This looks amazing, that you for this.

Suggestions:

Use the authjs.dev library to implement SSO for user management. This will automatically give the ability to use any login protocol any user could ever want.

I have numerous self hosted apps with multiple users, running them all through authentik is very important for users that are doing something similar.

Every homelabber will have a slightly different setup but the above library will essentially just support everything right away.

You will never need to worry about users requesting whatever protocol they are using because if you check the list of providers it’s basically everything.

Lem453,

That last point is the important one. For important data, I want the setup to be as easily accessible and system agnostic as possible.

Lem453,

Ok…so it should be easy to understand why for many people :latest is not a good idea

Lem453,

It’s not unusual for an update to have breaking changes that require some manual intervention to fix.

If you are on latest, it can also be hard to know which version you used to be on if you want to roll back.

For important things, I used specific version tags and then check the release notes before upgrading.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • tacticalgear
  • DreamBathrooms
  • InstantRegret
  • magazineikmin
  • Youngstown
  • everett
  • anitta
  • slotface
  • GTA5RPClips
  • rosin
  • thenastyranch
  • kavyap
  • mdbf
  • Leos
  • modclub
  • osvaldo12
  • Durango
  • khanakhh
  • provamag3
  • cisconetworking
  • ngwrru68w68
  • cubers
  • tester
  • ethstaker
  • megavids
  • normalnudes
  • lostlight
  • All magazines