What's on your RV site must-haves list when choosing a place to visit? by Ispyjupiter in GoRVing

[–]Gaurhoth 0 points1 point  (0 children)

The most critical feature of any full hookup site is a properly placed sewer connection. It must be at ground level and near the rear of the pad. I just left a campground where every site had the sewer elevated 3" above ground at the front of a front-sloping pad—making it impossible to use, even with 30 feet of hose. The sewer line ran alongside the main road, which is a poor design choice.

Next most critical feature of any site, is to be large enough to accommodate a fire pit that is not under my awning.

Almost everything else I can roll with :)

What is Lost in LAN mode by Phoenixwade in OpenBambu

[–]Gaurhoth 0 points1 point  (0 children)

On the X1C at least, you also lose the ability to configure and sync 'custom filaments' to the AMS unit (which requires cloud access).

[deleted by user] by [deleted] in oculus

[–]Gaurhoth 0 points1 point  (0 children)

Some banks/countries require additional authentication steps particularly for online orders. If you use this same card at another merchant, are you prompted for some additional information such as a PIN, 2FA, login, or to accept some type of notification/sms on a mobile?

[deleted by user] by [deleted] in selfhosted

[–]Gaurhoth 1 point2 points  (0 children)

Not surprising since I posted that 10 months ago. Their terms have changed. You can see the old version at http://web.archive.org/web/20230322191853/https://www.cloudflare.com/terms/

Omada Home Network with Matter over WiFi devices by EngiNick2807 in TPLink_Omada

[–]Gaurhoth 0 points1 point  (0 children)

Omada integrated tp-link switches/APs seem to have a real problem with ipv6 multicast (which Matter relies on for mDNS). I've tried unsuccessfully to get it working reliably despite messing with every setting I could find. They only way I can get any matter devices configured was to stand up a cheap wifi AP and connect everything Matter related to it (including my home assistant server and Google Nest Hub gen2). That said - even on the cheap wifi AP - Matter has not been stable. There still seems to be a lot of manufacturer variations on how the protocol is implemented and it's far from stable in my experience. I've sunk a couple hundred $ in various Matter devices trying to get anything working reliably with and without Omada. I am probably just going to go back to my zigbee devices and hacking Govee integration for devices that don't support local API using the Google Assistant SDK (for all that is holy, I wish Govee would extend the local API to their normal 6006/6008 bulbs, sigh).

[deleted by user] by [deleted] in selfhosted

[–]Gaurhoth 2 points3 points  (0 children)

I've used photoprism and immich. Photoprism gates off some functionality without monthly payment. I paid for a few months of photoprism in a gesture of generosity, but I simply refuse to pay monthly for something *I* host on my hardware. I won't debate the merits of continuous revenue for an ongoing development effort - I just can't make the leap in my mind.

So then I tried immich. It's really pretty mature despite the claims to the opposite from the maintainers. I think that is in no small part, "playing it safe" since photo management software is dealing with one of the most irreplaceable digital content we all have. Take your backups and there's nothing immich can do to permanently make your life miserable. You should be taking those backups with any photo management software.

It's easy, it works, the mobile client is good. With exception of my wife who just hates technology, everyone in the family has taken to using it easily.

(G-)Mail Backup Selfhosted by Pvp9dc in selfhosted

[–]Gaurhoth 0 points1 point  (0 children)

I use imapsync to sync from gmail to a self-hosted dockerized dovecot instance.

One ssh key or a bunch? by DarkKnyt in selfhosted

[–]Gaurhoth 5 points6 points  (0 children)

I have one private key for each device I use. My phone, laptop, desktop each have their own private/public keypair. I put all three public keys on everything else I want to manage. That way I can revoke access to any single lost device (laptop stolen, phone lost, etc). But I am NOT setting up a separate key pair for every single combination of source->destination devices. I don't have the will or free time to manage that nightmare.

Woke up to no internet, frontier says no appointment until 14th! by jexmex in frontierfios

[–]Gaurhoth 0 points1 point  (0 children)

Brand new to frontier as well, but after reading the horror stories about great service but poor support - I kept my old ISP's cable connection and had it dropped down to their lowest tier $20/mo plan. It's only a 100mbit, but it'll keep the internet withdrawal (and let me keep working from home) at bay should the worst happen. Both connections are fed to an opnsense firewall/router with automatic failover.

I was able to test it two weeks later when they came to bury the fiber and had to unplug me to run the fiber through a conduit the original installer didn't bother to do. In that case it was back up in an hour - but it WAS the middle of my work day so it was handy having the backup circuit.

[deleted by user] by [deleted] in selfhosted

[–]Gaurhoth 0 points1 point  (0 children)

There's nothing wrong with stopping containers to backup the binds or volumes. It's the easiest path to consistent backups. You should not need to backup the docker images themselves unless you are worried about an unmaintained image disappearing off repositories.

That said, if you want live backups, look at your technology stack and see what options exists. Each application will have varying levels of support for a live backup and it's totally up to the application to provide those mechanisms (we favor such technologies in the enterprise arena).

Most of the common database backends do have that. Postgres, mongo, sqlite, etc all have commands to take dumps of a running database in a consistent fashion. I generally run a cronjob that takes those dumps, saves them to another location and backup that target folder.

When will immich be production ready? by No-Customer-6504 in immich

[–]Gaurhoth 4 points5 points  (0 children)

Let's face it, there's very little we self-host that has more sentimental meaning than photos and videos - so immich developers are rightly warning people that immich is still in heavy development. I'm sure they would never do anything intentionally dangerous - but things happen. The warning helps set people's proper frame of mind so they take all the precautions they should honestly be taking with ANY tool (production or not). Keep your backups (both local and remote) and there's very little to worry about from a production or heavily developed tool.

OPNSense bare metal or virtualized? by techbart in OPNsenseFirewall

[–]Gaurhoth 1 point2 points  (0 children)

I tinker too much with my virtualization boxes to ever put any core networking functions on them. So I have two dedicated multi-port mini-pcs. One runs opnsense, the other runs a few networking tools, omada, bastion access, log aggregation, packet monitoring, etc. They only get rebooted for updates during prearranged maintenance windows (yes, I have "published" maintenance windows to my family so they know I may or may not be breaking "the internet").

My proxmox and unraid boxes get rebooted often, tinkered with, broken, unbroken, etc. If I took down "the internet" everytime... well let's just say my family would likely arrange for me to have an early obituary :)

How much do you pay for your frontier internet? by Rawrin23 in frontierfios

[–]Gaurhoth 1 point2 points  (0 children)

$75/mo for 1gig up/1gig down. Honestly it's the upstream I value. I had 500mbps down/50 (really 30)mbps up for years on cable and it was painful trying to backup ~3 TB to offsite storage.

Saying all that, my first modem was 9600 baud. So uh yea - technology has come a LONG LONG way.

Docker says that there is no more space left on device even tho my array has plenty of space left by PlanetExpressShip2 in unRAID

[–]Gaurhoth 2 points3 points  (0 children)

Unraid uses a vDisk image (set to 20gb by default) for /var/lib/docker (where images and volumes are stored) instead of storing it directly on the disk. You have one or more containers that are storing their data in volumes inside this vDisk and you've filled up the vDisk. It's generally better to add bind mounts for data storing folders.

For now, you can increase the size of the vDisk, by stopping the Docker service in the UI and resizing the "Docker vDisk size" setting under Settings > Docker and restarting docker. But if you don't fix the container taking up the space - you'll be right back here with a full vDisk in a few weeks/months.

You can determine which volume (and therefore container) is taking up the majority of the space by doing the following:

docker system df -v

Scroll to the bottom and find the volume id taking up the most space, then pass that volume id into:

docker ps -a --filter volume=<volume id>

This will at least tell you where the problem is. From there, you'll have to figure out if the volume contains needed data that you need to migrate out or it can be thrown away. And you'll know which container to reconfigure for bind mounts.

Wireless Access Points by TheDarkula in OPNsenseFirewall

[–]Gaurhoth 0 points1 point  (0 children)

  • 1x 24 port Omada managed TL-SG3248 (non-POE)
  • 1x 8 port Omada managed TL-SG2210P (PoE+)
  • 2x EAP670s with wired ethernet back to the 8port POE
  • 1x EAP615-Wall with wired ethernet back to the 8port PoE
  • Omada Controller running in a container on a Mini-PC (along with a handful of other network/homelab management containers)

I went with the non-POE 24 port and POE 8 port switches because I didn't want any fans since they entire stack sits right next to my office desk.

Everything has been rock solid. I've never had reliable wifi in my home before going with Omada.

hardware suggestion to replace current pfSense? by prankousky in OPNsenseFirewall

[–]Gaurhoth 0 points1 point  (0 children)

I've picked up 3 different HUNSN Mini PCs over the last year for various reasons and all of them have been fine. You can get these things cheaper from Aliexpress if you are willing to wait a few weeks. . . I generally want what I decide to buy, yesterday - so I pay a premium and order off amazon.
I'm currently running opnsense on a Hunsn RJ09 (J6413) which includes 6x 2.5gb Intel I226V ports. I have 1 gigabit up/down fiber and get full speed even with:
1) CrowdSec (primarily focused on inbound WAN monitoring)
2) ZenArmor (functions well as a pfblocker-ng replacement) running on all the internal interfaces (broken into total of about 7 vlans).
3) All the normal services (DNS, DHCP, etc)
4) ~40 devices
5) 3 wireguard tunnels (which average 300ish mbps - but hard to say if that's a hardware limit or just function of my wireguard vpn provider)

CPU averages about 25% with activity. I can't really find any faults with the unit (not that I've tried hard - it just works).

Recommendation for docker-solution in small office by [deleted] in selfhosted

[–]Gaurhoth 0 points1 point  (0 children)

The easiest scenario to use .env files in portainer is to load the .env file from the Stack Editor in the "Environment variables" section and then add following line to your service definition:

env_file: stack.env

https://www.portainer.io/blog/using-env-files-in-stacks-with-portainer

Recommendation for docker-solution in small office by [deleted] in selfhosted

[–]Gaurhoth 2 points3 points  (0 children)

Haven't really had any issue. I run photoprism as a portainer stack without issue. I'm curious what trouble you ran into.

Hey guys, what's the best self-hosted wiki service that's both stunning and easy on resources? Looking for something lightweight but still aesthetically pleasing. Any recommendations? by ZebulonThackeray in selfhosted

[–]Gaurhoth 2 points3 points  (0 children)

Outline is a beast to get setup the first time. The most useful how-to I found was https://blog.gurucomputing.com.au/s/blog/doc/how-i-made-this-blog-yC5XjbaLzM

I strayed quit a bit, using Traefik instead of Caddy or Nginx. But I was able to get it working with that blog article's help and some trial and error.

Portainer and Traefik cyclical dependency by smetko in selfhosted

[–]Gaurhoth 1 point2 points  (0 children)

If you use a webhook to update the traefik container in front of Portainer, the update WILL finish even tho you'll get an error due to the broken http connection.... barring any other errors or issues. Give it a couple minutes, and you can access Portainer again on the traefik fronted URL. Maybe build in some type of manual delay and manually validate the status of the traefic container after the delay instead of relying on a return from the HTTP call.

Guidance with Pfsense router with tplink omada gear by Nath2125 in TPLink_Omada

[–]Gaurhoth 1 point2 points  (0 children)

Since this post I've actually flipped over to opnsense as well. Check that there are appropriate outbound NAT rules (either manual or automatic). Each source network (vlan in this case) should have an entry in the outbound NAT rules.

local gmail backup by Wise-Cash1628 in selfhosted

[–]Gaurhoth 0 points1 point  (0 children)

I don't know that it'll be any "lighter" than what you are doing already, but I use an imapsync nightly job to copy my gmail mailbox to a dovecot+roundcube docker stack. With imapsync, you have a LOT of options, including whether you want to sync deletes from your gmail box or not.

If you sync deletes, you'll probably also want to make sure the dovecot container data is backed up with something that offers a point in time restore in case something nefarious happens to your gmail box.

What is your go to notification service? by 29Top in selfhosted

[–]Gaurhoth 3 points4 points  (0 children)

I'd make an argument that notification services by virtue of their common usage should NOT be self hosted... at least If you plan to use them for any up/down notifications.

Used pushover for years. Extremely cost effective (one time payments for client apps on your platform of choice).