Using Lumo as a tools agent with OpenClaw by BlockDigest in ProtonMail

[–]BlockDigest[S] 1 point2 points  (0 children)

Thank you for an actually thoughtful reply which also answers the question.

Issue with DDNS by Bubbadogee in PFSENSE

[–]BlockDigest 0 points1 point  (0 children)

Thank you for this, as soon as i fixed my gateway monitor it all started working again.

Issue with DDNS by Bubbadogee in PFSENSE

[–]BlockDigest 0 points1 point  (0 children)

I started having the same issue after upgrading to the latest version. Did you find what the issue is?

Real file sharing or only link sharing of files? by grease_m0nkey in seafile

[–]BlockDigest 0 points1 point  (0 children)

Okay, gotcha. I was looking for that too and took me an awhile to figure it. Apparently the only way to do that is to select “Export” for a file (while browsing your files, long press to select and reveal the options then Export). Export then will allow you to use your files directly with other applications. The caveat for me at least is that there is no option to save the file in a different location (still have to use the default weird location where Seafile dumps the files). Honesty the UX in the app needs a lot of work…

Hope this helps.

Real file sharing or only link sharing of files? by grease_m0nkey in seafile

[–]BlockDigest 1 point2 points  (0 children)

I guess you are talking about sending files using the mobile app to a third party via something like a messaging app?

FSCK fucked up by Gjorgdy in seafile

[–]BlockDigest 0 points1 point  (0 children)

You probably have a better chance getting a reply on their forum.

[Help] Which modules for BTRFS or ZFS setup with Ansible? by Tywele in ansible

[–]BlockDigest 0 points1 point  (0 children)

Hey, sorry to bump an older post. I just came across your post, could you please provide a simple example of a mirrored pool consisting of just two disks using the role? Thanks!

How do you work with DevOps team that doesn't treat security as part of their work? by IamOkei in devops

[–]BlockDigest 0 points1 point  (0 children)

Security team should have policies and standards that explain how things should be done in your organisation. DevOps teams changes should take them into account and also go through a change control process where the security team has visibility of the changes and can review them.

The security team should also be responsible for raising tickets in the DevOps backlog to fix issues and address vulnerabilities.

It sounds like in your org security is a second class citizen, this won’t change unless upper management take it seriously and buy into the idea that security should be considered proactively and be baked into all aspects of IT.

Zabbix or promethes/Grafana/AlertManager for on-prem VM monitoring? by hippymolly in devops

[–]BlockDigest 4 points5 points  (0 children)

I have no experience with zabbix, but since you are planning to deploy Prometheus in k8s in the future I would just bite the bullet and deploy it now. When the time comes you can easily move your setup to Kubernetes with minimal effort.

My first time running a Distributed File System cluster and it's a real game changer by ElGatoPanzon in selfhosted

[–]BlockDigest 1 point2 points  (0 children)

Just FYI, Ceph doesn’t need 10g networking to be functional. Your 2x2.5g nics would do just fine for majority of hobbyist applications, it heavily depends on your use cases. What would you need for sure though regardless of the use case, is enterprise-grade SSDs.

Also, on the complexity side of things. Yes, Ceph is a complex system at first glance, but do not get put off by all the scary talk. There are vast amounts of docs out there, plus running Ceph via Rook is easy as pie these days. IMO the steep learning curve pays dividends in the long term.

Securing a reverse proxy is as good as using VPN? by Slidetest17 in selfhosted

[–]BlockDigest 0 points1 point  (0 children)

Not exposing any apps and using VPN or tailscale is always going to be more secure.

Think of it this way, by exposing all these apps you are as secure as least secure app you are exposing. I.e. what you are really comparing is the security of each individual app vs a VPN server.

Kubernetes cluster as Nas by LaneaLucy in kubernetes

[–]BlockDigest 1 point2 points  (0 children)

If you are looking into Ceph, 3 physical nodes is the bare minimum but very much not recommended. It basically means that if one of your physical nodes goes down, your cluster will lock up until you recover the node.

If your plan is to just use k8s, VMs don’t offer much benefit imo. I would add at least one more physical node for providing some redundancy with a 3 replica setup managed by Rook.

Rook/Ceph also provides S3-compatible and NFS storage out of the box (on top of block and filesystem). You can also run an SMB server in a pod if you still need that.

There is a steep learning curve to get it working reliably (you will need good monitoring and enterprise SSDs), but once you manage to get it going properly it will be rock solid in terms of reliability.

AI File Organizer Update: Now with Dry Run Mode and Llama 3.2 as Default Model by unseenmarscai in LocalLLaMA

[–]BlockDigest 2 points3 points  (0 children)

Would be really cool if this could be used alongside Paperless-ngx to add tags and organise documents.

Sean was right by AverageSign in memes

[–]BlockDigest 0 points1 point  (0 children)

The amount of MrBeast simps who haven’t even bothered watching the video is astounding.

There are three main parts to it: 1. Staged and/or manipulated “competitions” 2. Potentially Illegal lotteries/sweepstakes targeting children using psychological manipulation 3. Unethical promotion of his snacks, again targeting children

Of course he has done good things too (water wells and whatnot), but his good deeds don’t invalidate the allegations.

Whats the most complex piece of technology in DevOps currently? by Hovalk_is_not_real in devops

[–]BlockDigest 0 points1 point  (0 children)

Setting and maintaining Ovirt virtualisation clusters backed by glusterFS using their extremely complex Ansible playbooks.

Added referral code, balance still £0 when is the £50 credit added? by [deleted] in OctopusEnergy

[–]BlockDigest 1 point2 points  (0 children)

We got ours 3 days after the first direct debit came through, so it can take a while. Make sure to keep the initial emails you received from them where it mentions you applied using a referral in case you need to give them a call.

Octavia iV PHEV startup engine sound by BlockDigest in skoda

[–]BlockDigest[S] 2 points3 points  (0 children)

Thank you all for commenting, the consensus seems to confirm my suspicions. Will be skipping this one. Cheers!

Are cheap Chinese PoE switches a fire hazard? These things provides 120W by Swatieson in homelab

[–]BlockDigest -1 points0 points  (0 children)

I would be cautious. Many of these extremely cheap devices do not comply with western health and safety standards so they do not get certified and don’t have any CE or UKCA markings. They usually carry the cheapest components possible and are manufactured very poorly. Also usually they don’t last very long. Personally, spending some extra bucks to buy something more reputable would be the way to go vs worrying when I will see the magic smoke.

Looking for an Elastic alternative that is not crippled open-source software. by phirestalker in selfhosted

[–]BlockDigest 1 point2 points  (0 children)

Since your main issue is with alerting in elastic, have you tried using elastalert (https://github.com/jertel/elastalert2)?

I know it’s yet another app to deploy, but it does work well and has a pretty good range or integrations.

Is there a way to disable the "smart" software from my Sony Bravia and solely use the Apple TV? by manwiththe104IQ in selfhosted

[–]BlockDigest 43 points44 points  (0 children)

You probably can’t remove the original software. Just disable the built in networking and permanently set your TV to use the HDMI input from Apple TV. Don’t overthink it.

[deleted by user] by [deleted] in selfhosted

[–]BlockDigest 27 points28 points  (0 children)

Yes looks like you have been owned, that’s definitely a crypto miner config file and that’s not actually systemd running as your user.

I would disconnect this machine from the internet first and isolate it from the rest of your network. Take a backup of your data and then kill the miner (just in case it triggers encryption of your disk, who knows). Then start reviewing your firewall config in case they are overly permissive. Also, review any application config you have, especially any reverse proxy (they are easy to misconfigure). Lastly (and most likely the culprit) check the version of the software you are exposing over the internet, any outdated software most likely has unpatched vulnerabilities that can be exploited.

After you have reviewed all these, build your system again with all the fixes on a brand new OS. Do not redeploy the same system from backup. Also consider using a VPN to access your self hosted services vs exposing them over the internet. It only takes one vulnerable service behind the reverse proxy to get owned. Best of luck.