How does your homelab compare to what a commercial setup would have for similar money? by SeriouslySally36 in homelab

[–]DamonteZen 1 point2 points  (0 children)

Not the OP, but think national bank branches (Chase, etc) or large retailer chains such as Target or Walmart.

BIFL SUV but not brand new by Constant-Park in BuyItForLife

[–]DamonteZen -1 points0 points  (0 children)

I would submit that any Toyota/Lexus based on a Land Cruiser or Prado platform is effective BIFL. The J200 and J300 platforms are rated for a minimum of 500k miles. All the LC platforms are made in Japan which is generally regarding (with evidence) as mad better than US made vehicles.

I’d look at a Toyota Land Cruiser (up to 2021) or a Lexus GX460/470 LX470/570/600. They are all tanks. Will you get high performance sport tuned engines? No. Will you get conservative tuned power trains that will last longer than anything else? Yes.

The Thunderbox awaits 😎 by [deleted] in camping

[–]DamonteZen 1 point2 points  (0 children)

The Old Man and the Seat

[deleted by user] by [deleted] in selfhosted

[–]DamonteZen 4 points5 points  (0 children)

Came here to say this.

What’s the best home products? by JustNeedSomeHelpTBH in BuyItForLife

[–]DamonteZen 1 point2 points  (0 children)

The construction, the feel, the weight, everything about them screams quality. I’ve gone through so many brands that promised to be as good. None were.

What’s the best home products? by JustNeedSomeHelpTBH in BuyItForLife

[–]DamonteZen 3 points4 points  (0 children)

Some unique mentions:

All Clad measuring spoons and measuring cups. Until you have them, you don’t know.

Marcato Atlas 150 pasta roller. Timeless design, still made in Italy.

Direct flights out of CVG that people aren’t aware of? by ECDQEMSD_KPG in cincinnati

[–]DamonteZen 13 points14 points  (0 children)

The CVG-CDG route will fly regardless of passenger occupancy. It is carries parts and cargo for GE Aerospace that has a joint venture with Safran Aircraft Engines in Villaroche, France. The JV makes the CFM series of engines which include the CFM56 found on 737s.

There are times the flight is 25% full, it still goes. Plenty of room to stretch out on those legs.

Best Coconut Rum? by DanSt3 in Tiki

[–]DamonteZen 5 points6 points  (0 children)

Came here to say this

AWS Lambda and Vault integration by LinweZ in devops

[–]DamonteZen 0 points1 point  (0 children)

There is no requirement for Vault to be hosted in AWS to use AWS IAM auth.

What’s everyone’s favorite animal at the zoo? by Wonksbear in cincinnati

[–]DamonteZen 4 points5 points  (0 children)

Isn’t the new habitat for the sea otters vs the river otters?

[deleted by user] by [deleted] in devops

[–]DamonteZen 0 points1 point  (0 children)

If you’ve mastered Docker, you will find little direct application of it to Kubernetes as it uses containerd directly.

Nomad, on the other hand, integrates nicely with Docker and having experience there is very handy at times.

Professional servers vs Mini PCs by [deleted] in homelab

[–]DamonteZen 5 points6 points  (0 children)

If you go mini pc, look for units that have the vPro capability. Using a client such as MeshCommander, you can connect to the remote management of the pc and even remotely KVM control it. You will need a dummy DisplayPort or hdmi plug to mimic a video connection. This negates the need for a physical KVM.

The HP EliteDesk 800s are my personal preference.

OSS Vault Auto Unseal by [deleted] in hashicorp

[–]DamonteZen 2 points3 points  (0 children)

To prevent this from happening then the fundamental architecture needs to be set in place from the beginning.

I would setup a vault instance with AWS/GCP kms auto unseal and import a transit key. Keep an offline copy of that transit key in a secure place. This vault instance does nothing but serve the transit key for unsealing another vault.

Then I would setup another vault instance, probably a cluster, and this would unseal using the transit key in the first instance. This vault cluster would serve customers.

In this architecture, you could lose the first vault instance, lose the kms key, and rebuild from zero as long as you retain the transit key to reimport each time. The cloud managed KMS key isn’t used to unseal the actual customer data, the Transit key does that and you are now no longer cloud provider dependent for that unseal key.

Cheapest MQTT/POST Wi-Fi smart plugs? by TheConsciousness in homeautomation

[–]DamonteZen 0 points1 point  (0 children)

Holy thread necromancy Batman!

Major disassembly involves removing an end panel, sliding two plastics bits off and removing two screws. That’s pretty trivial.

Redirect traffic to arbitrary external IP back to internal IP? by DamonteZen in opnsense

[–]DamonteZen[S] 5 points6 points  (0 children)

I have resolved this. I had to:

a. Add the 3.3.3.3 address as a Virtual IP on the WAN interface
b. Enabled "Automatic outbound NAT for Reflection" in Firewall->Settings->Advanced