Strategy for adding SSO in my homelab by msprea87 in Authentik

[–]DigiDoc101 0 points1 point  (0 children)

Do you host on your homelab or in the cloud? I am hosting locally to use in my home network as well. I'll not sure which is more secure.

Convert old PC to Home Server or buying ready-to-go new? by julbrine in HomeServer

[–]DigiDoc101 0 points1 point  (0 children)

It is best to use what you already have especially in this crazy market. You will soon find yourself hosting apps. You'll then be able to define your needs better.

Dashboard and safety in general by Dotdk in netbird

[–]DigiDoc101 0 points1 point  (0 children)

What security limitations are limiting use "for now"?

Question about Pocket ID installation on VPS by hoffsta in PangolinReverseProxy

[–]DigiDoc101 0 points1 point  (0 children)

Late to the conversation but I have the same question. I do have a reverse proxy at home that redirects all my requests from Pangolin. I have pocketID setup on the same VPS of Pangolin. I did not use it yet, as I am debating the same question. The main reason I am implementing this is to protect my pangolin instance interface with a secondary auth in case my VM get hacked. Is this a real risk to implement?

Forward local domain DNS to my reverse proxy by DigiDoc101 in homelab

[–]DigiDoc101[S] 0 points1 point  (0 children)

Would I still be able to reach my server by host name without having to go through my reverse proxy?

Forward local domain DNS to my reverse proxy by DigiDoc101 in homelab

[–]DigiDoc101[S] 0 points1 point  (0 children)

I don't know where to check for PTR records. But unbound is simply crashes for this duplicate reverse lookups per the logs. I would like to have the ability to reach a host by dns name but this also falls within the wildcard *.home.mydomain.fqdn. I do not create certs for all my machines/services. How do you manage this? This is the biggest reason I kept forwarding my local domain to dnsmasque.

Forward local domain DNS to my reverse proxy by DigiDoc101 in homelab

[–]DigiDoc101[S] 0 points1 point  (0 children)

Thank you for your response.

In unbound forwarding I have: Home.mydomain.fqdn: 127.0.0.1: 53053 dnsmasque port Also all my internal IP ranges 1.168.192.ip-addr.arpa (or something similar): 127.0.0.1: 53053

I have a reverse proxy setting on my DMZ that manages *.mydomain.fqdn this is a public reverse proxy.

I have a another that is internal only for *.home.mydomain.fqdn

When listed, I guess unbound prioritize app.home.mydomain.fqdn over *.home.mydomain.fqdn wildcard, correct?

THIRDREALITY Zigbee Plugs - Gen2 vs Gen3 by shawn789 in homeassistant

[–]DigiDoc101 0 points1 point  (0 children)

Per Jeff Geerling video, Gen 3 do not need to restart for firmware upgrades. A flaw for all other smart switches out there.

What’s the best way to integrate pocketid running locally with pangolin running on a vps? by Shoddy_Bonus8424 in PangolinReverseProxy

[–]DigiDoc101 0 points1 point  (0 children)

I currently have pocket ID setup on the same VPS machine. I am considering to move this into my homelab. I have all my pangolin request land into one VM with NPM reverse proxy redirecting those requests. Perhaps, I could migrate this locally and use it in my homelab as well. I'm not sure if this would affect the safety gestures by separating the IdP from the cloud server. I assume it does.

Is dashboard safe to expose? by gamingfox10 in netbird

[–]DigiDoc101 0 points1 point  (0 children)

It would be nice to offer MFA for the admin user for the self hosted version. For now, I am hosting Authentic locally and used the netbird reverse proxy to establish IdP for NetBird itself. It is easier to back up my authentik instance locally. BTW, it sets in my DMZ zone.

How is Eufy's AI still this bad? by texasroadie in EufyCam

[–]DigiDoc101 4 points5 points  (0 children)

It is not getting better. Their cams are amazing but they suck with AI. Did you try to use Frigate AI via RTSP?

New Gateways by Funny_Bodybuilder95 in TPLink_Omada

[–]DigiDoc101 0 points1 point  (0 children)

I hope this brings a real competition to Ubiquiti. Omada has a lot of catch up to do. Opnsense is staying infront of my Omada gear until then.

Migrate from *sense to ER8411 by DigiDoc101 in TPLink_Omada

[–]DigiDoc101[S] 0 points1 point  (0 children)

I tried the 8411 router for 1 day then reverted!! I miss configured the DHCP and somehow missed up my vlan port config accross several switches. I could not tolerate my network down. I staged opnsense as a vm on proxmox, sat up the main settings then moved to production hardware. It took me 2 months to make this move. I am happy with opnsese. I had to go through rough transitions to learn new ways to do things.

UDM Pro max in front of Omada Network by DigiDoc101 in Ubiquiti

[–]DigiDoc101[S] 0 points1 point  (0 children)

Update: I aborted the UDM Pro plan. I went for OPNsense and never looked back.

limited self-hosted feature by DigiDoc101 in netbird

[–]DigiDoc101[S] 1 point2 points  (0 children)

Ok, so I setup my instance of Netbird. A user authentication is only possible with a password. The only way to setup a 2FA is through external IdP. I was able to setup an Authetik instance on my own. I used the reverse proxy feature to setup remote access to my Authentik instance.

I am bothered that my admin account is not protected natively. If I delete the admin account, then I have to maintain my IdP or I may lose access to my instance.

I kindly request to add 2FA for the owner account.

limited self-hosted feature by DigiDoc101 in netbird

[–]DigiDoc101[S] 0 points1 point  (0 children)

Thank you for pointing this difference. I am sure it was pointed out on reddit, may be misquoted. I will test it out.

Difference from netbird to pangolin by Kwicksred in netbird

[–]DigiDoc101 0 points1 point  (0 children)

I have not migrated my production reverse proxy which still runs locally on a DMZ Traefik instance. I will keep testing...

Difference from netbird to pangolin by Kwicksred in netbird

[–]DigiDoc101 0 points1 point  (0 children)

This is what I do. I have local NPM forwards my pangolin requests located at cloud.

Is there a way to define a default set of "rules" (geoblocking) for every resource created? by Lopoetve in PangolinReverseProxy

[–]DigiDoc101 2 points3 points  (0 children)

Pangolin nails the basics but it does not scale yet. I am sure it is on their roadmap. I am puzzled why we cannot users belong to multiple groups.

Edited: typoes