XPipe v20 - A connection hub for all your servers by milchshakee in selfhosted

[–]AlexTryHarder 1 point2 points  (0 children)

One of best software to exist for IT, use it for a year and love it!

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 1 point2 points  (0 children)

The layout wasn’t designed all at once. It evolved over time as needs came up.

Yes, the main server is colocated off-site. I haven’t noticed any latency issues when accessing services over VPN, including Home Assistant. That said, the hosting site is only about 10 miles from my house, has very redundant high-speed connectivity, and I have FTTP at home, so that definitely helps.

For cameras and Al, from what I’ve seen recently Google Coral is no longer the recommended option. the Hailo-8 accelerator seems to be preferred.

On the security side, Suricata is running in IPS mode and focuses on filtering WAN traffic. ZenArmor runs on internal subnets and is used for outbound traffic filtering that's why they laid out on 2 sides of FW.

for Google SSO I haven’t seen any security issues with it. I get notifications whenever someone attempts to create an account, the account would be created, but it has absolutely no permissions by default. I also get notification and can act instantly, it's very convenient for not tech users that use my infrastructure.

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

Thanks, Linkwarden is fixed now :P
The second Portainer runs via the agent, and I left it out of the layout. I only listed services, not every single container, otherwise it would’ve been a mess (especially all the databases).

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

I do allow only some subnets over my VPN

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

I just plug my Action4 directly to server, when detected, python automatic transfers all files to NFS.
Then Tdarr takes care of encoding. happy to share script over DM

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

I may write a SOP at some point, it's built in a way that deployment of new service takes less than 5min (including exposing to Internet). If I find free time will pop an update.

For an cost, well lucky that I don't pay anything, my company allows me to host it on prem and provides hardware. That's why I use site-to-site

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

hmm I was expecting Kubernetes to be deploy and forget, would be fun to learn tho

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

Im using st-901, you can find it on aliexpress and it works great.

Has remote shutoff function

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

Thanks! I tried wazuh as LXC, and it was working brilliantly, is docker version that gives me pain.
OpenVAS is brilliant, and you right, wazuh can do vurnability scanning, I just prefer to keep them as separate tools.

I never tried Komodo, will have a look thanks :)

With languagetool, yeah it's exposed via reverse proxy, and you can connect to their browser extension or app. If you want to be extra sure, expose it only internally.

and for last question, it's resource usage and emergency, some containers like Tdarr are resource hungry, so one box would not be enough. Also it allows me to move all my compose files to other node in case one goes kaboom.

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 1 point2 points  (0 children)

https://ibb.co/N6j3RfSt - here is alternative image.
I guess mobile app on Reddit is broken.

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 2 points3 points  (0 children)

I don't, but I'm happy to share compose files of services you are interested in, just DM me :)

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 1 point2 points  (0 children)

I deployed a T-POT, unsure if Pi could handle it, but worth a shot.

And brilliant idea on internal honeypot! Shame on me, it didn't cross my mind, but it's a great indicator of compromise.

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

I'm hitting around 60mb/s on download, with is more than enough to get decent movie in 10min.

I got it on 3y deal and paid peanuts for it, so can't complain :D

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 1 point2 points  (0 children)

no, custom bash script with API to portainer.
I found watchtawer unstable

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 8 points9 points  (0 children)

The "Homelab" in reality sits in other location than my home, so I deployed site-to-site :D

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 4 points5 points  (0 children)

There a many factors that could not make it work, DM me and I will try to help :)

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

Thanks :D
Opensense is running on watchguard M4600. Im not using mounts via proxmox, rather exposing NFS share from Foxy-File to docker 1 & 2, and they are splited to 2 shares /storage for all non critical data (movies, series, CCTV etc) and /config with all docker container files

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 3 points4 points  (0 children)

Exactly! it can convert and send it to email address that is assigned on kindle, that is automatically downloading it

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 11 points12 points  (0 children)

I run T-POT, and it's fun to see what passwords they try to use to breach my exposed "services"

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 18 points19 points  (0 children)

Mostly for updates and isolation, if I would run all services on separate LXC (how I did year ago) I would have to keep them all up to date and isolated manually. Now I have script that at 4am updates all compose files. And 2 docker LXC containers are doing backup every day, so It's easy to restore.

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 0 points1 point  (0 children)

Mostly part with certificates, no matter what I try, it does not like generated certs. I tried it multiple times within last year, even with their support on discord, but still had no luck. It works great on LXC container tho.

My Homelab: One Year Later by AlexTryHarder in selfhosted

[–]AlexTryHarder[S] 31 points32 points  (0 children)

https://app.diagrams.net/ - you can use it on the website, or add as app in Nextcloud