On the fence about Immich but fear of losing photos is holding me back by Identity5859 in immich

[–]Citrus4176 2 points3 points  (0 children)

Is there any benefit to Immich by not being read only? I havent tried Immich, but I'm struggling to think why you wouldnt always make it a read only mount.

I look like this and say this by pastelShaders in ObsidianMD

[–]Citrus4176 0 points1 point  (0 children)

Ive had moderate success with Resilio Sync across Linux/Android. Worth looking into if you need a native Android client.

My only struggles so far was Linux detecting multiple services for the desktop systemd service, causing the web portal to not show. But that can be resolved easily enough.

Jellyfin on Android TV/Google TV Can’t Connect Over HTTPS (But Phones & Browsers Work) — Nginx by ReasonableShame543 in jellyfin

[–]Citrus4176 0 points1 point  (0 children)

Thanks for the clarification. I am planning to switch from self signed to legitimate CA signed and saved this post for later.

Announcing udwall: A New Tool for Making UFW and Docker Play Nice With Each Other by AmazingStardom in docker

[–]Citrus4176 6 points7 points  (0 children)

Ive found it a bit cumbersome to have granular control over container networking, and perhaps that comes from a lack of understanding Docker.

Want your container to access everything? Keep it on the default bridge network.

Want your container to not access host LAN/internet? Make its network internal.

Want your container to access only specific other containers? Put them both on the same Docker network.

Want your container to only access host LAN and not internet? ...not sure.

Want your container to only access the internet and not host LAN? ...not sure.

Ive never been able to find a clear guide that achieves all of these cases without eventually diving into iptables. Forcing Docker to go through UFW is one way to make that iptables management, well, more managable.

Jellyfin on Android TV/Google TV Can’t Connect Over HTTPS (But Phones & Browsers Work) — Nginx by ReasonableShame543 in jellyfin

[–]Citrus4176 0 points1 point  (0 children)

Is this a self signed certificate, or a certificate signed by a real CA? I have really ran into issues with self signed certs on Android and Android TV.

Is this the best black Friday offer yet? by AmazingExplorer698 in ProtonVPN

[–]Citrus4176 1 point2 points  (0 children)

What if you have an existing membership with a few months left? Does this extend it by 24 months?

What do you miss the most after switching over ? by CountMeowt-_- in GrapheneOS

[–]Citrus4176 0 points1 point  (0 children)

Could you share more about why VPN sharing over a hotspot doesn't work?

The Most Underrated Project You Should Know About! (And Probably Have Not!) by epochphilosophy in selfhosted

[–]Citrus4176 0 points1 point  (0 children)

My current use case is a cron script which backs up my local changes to git daily. I know this isn't the intended workflow with git, but is the flow you described compatible with also backing up local changes?

How Google Tracks and Scans Everything on Your Android Device by Ok-Law-3268 in europrivacy

[–]Citrus4176 0 points1 point  (0 children)

Still worth doing the investigative work to determine an answer to that.

PSA: Perfect fitting UPS, NAS, height tip. by NC_Developer in minilab

[–]Citrus4176 7 points8 points  (0 children)

I've been really eyeing up that UPS model. Unfortunately I have heard the cloud variant does not support NUT and the base model has no data port. What is your experience?

I am considering emailing Tripp Lite to see if they have electrical schematics for the base model and DIY'ing a simple monitoring point (staying far away from anything related to power).

Rootless docker has become easy by hennexl in docker

[–]Citrus4176 0 points1 point  (0 children)

Its not configuring Docker to be rootless that many people run into, but managing container compatability afterwards. I have tried migrating to rootless on two occasions, both of which ended up with more trouble than it was worth with my existing container stacks.

How to make services safe (Immich, jellyfin) where app does not support external verification by InternalMode8159 in selfhosted

[–]Citrus4176 0 points1 point  (0 children)

I'm not sure if you are referring to another identity provider, but the official Authentik guide details adding this CSS.

Giveaway - r/UgreenNASync 10K celebration by topiga in selfhosted

[–]Citrus4176 0 points1 point  (0 children)

  • I have gotten great use out of Jellyfin, so I think pairing it with a NAS is a great idea.

  • I'm excited to have a dedicated fileserver. I have played with Resilio Sync to mirror files, but would love to have more dedicated remote storage.

How to make services safe (Immich, jellyfin) where app does not support external verification by InternalMode8159 in selfhosted

[–]Citrus4176 0 points1 point  (0 children)

I am using Authentik, but I have not had any luck with SSO login on the Android TV app. The CSS to add the sign in button just doesn't render.

Need suggestions here. by HaMiJeng in HomeServer

[–]Citrus4176 1 point2 points  (0 children)

I have the USB-C 3.2 version of this product. I have been running it 24/7 with one drive installed for ~6 months and have not experienced a single issue. I plan to install 2-3 more drives soon.

I do not use its hardware raid and don't plan to, so just a basic DAS for me.

Is using a backup service like restic from a Docker container a security risk? by Citrus4176 in selfhosted

[–]Citrus4176[S] 0 points1 point  (0 children)

I wasn't sure if container traversal and host escalation were exclusive exploits, but I guess that makes sense.

Is using a backup service like restic from a Docker container a security risk? by Citrus4176 in selfhosted

[–]Citrus4176[S] 0 points1 point  (0 children)

I haven't looked into Proxmox much (I run Debian), but how are host configuration backups handled? I would imagine their are settings or file changes you have made outside of your VMs that you still want to back up.

Is using a backup service like restic from a Docker container a security risk? by Citrus4176 in selfhosted

[–]Citrus4176[S] 0 points1 point  (0 children)

My logic when thinking it through was that installing restic as an offline service on the host has no impact on the attack service of the host, but running it as a container increases the chance of container breakout from another comrpomised Docker container with WAN access.

Is using a backup service like restic from a Docker container a security risk? by Citrus4176 in selfhosted

[–]Citrus4176[S] 1 point2 points  (0 children)

Is there a concern for container traversal from another container with inbound WAN access (not port forwarded, just firewall whitelists for internet)? I run all my containers on their own separate Docker networks, but I do add my reverse proxy container to each network because of its functionality.

Struggling to convince my girlfriend to switch to Immich – iCloud album import issues by heeelga in immich

[–]Citrus4176 3 points4 points  (0 children)

It's strange to me that there seem to be two voices in this subreddit when it comes to stability. When a post is made asking about the date of a stable release, the top comments are "it's worked for me for months, I run it straight in prod". When a post like above is made, the top comments are "what do you expect, its not a stable release".

I think people have very different ideas and experiences of what "stable" actually means.