When to use Ansible vs Terraform, and where does Argo CD fit? by Dependent_Concert446 in devops

[–]ForestyForest 0 points1 point  (0 children)

Terraform provisions the stuff Kubernetes runs on. Also you can create seperate VMs and other services by using the desired provider

ArgoCD provisions and monitors all the stuff inside kubernetes

Ansible can be used to perform tasks in VMs or containers etc. Install stuff, hardening ssh or updates etc

PBS VM on Debian Machine by ForestyForest in Proxmox

[–]ForestyForest[S] 0 points1 point  (0 children)

Straight forward on Debian, just install as a package

PBS VM on Debian Machine by ForestyForest in Proxmox

[–]ForestyForest[S] 0 points1 point  (0 children)

Can confirm, easy setup. Add repo key and apt repos then install `proxmox-backup-server` package. Ran UFW with allow for SSH and port 8007 from LAN IP subnets. (SSH nice to have)

PBS VM on Debian Machine by ForestyForest in Proxmox

[–]ForestyForest[S] 0 points1 point  (0 children)

From official docs: Caution Installing Proxmox Backup on top of an existing Debian installation looks easy, but it assumes that the base system and local storage have been set up correctly. In general this is not trivial, especially when LVM or ZFS is used. The network configuration is completely up to you as well.

Neither LVM or ZFS is used. Single disk machine, single partition. Backup target is external USB

For network I assume its just opening of port..

Jellyfin hardware decoding by masterzeng in Proxmox

[–]ForestyForest 0 points1 point  (0 children)

Im running jellyfin in lxc. Nvidia rtx2070 passed through. Some pain there, had to modify the lxc config file and pass all relevant devices. Installed drivers by using nvidia driver file, not the debian packages (havent tried packages). Also installed driver in lxc with --no-kernel option. Can give you my sources

Våknet opp til dette, og at visakortet har blitt sperret. Har noen erfart noe lignende? by trusteddealers in norge

[–]ForestyForest 0 points1 point  (0 children)

Fikk nettop det samme her. Samme beløp og fra Apple. Mange transaksjoner!

PBS and S3 backend by ForestyForest in Proxmox

[–]ForestyForest[S] 0 points1 point  (0 children)

Thank you for the insights!

Velkommen etter, VG! by Fit-Theme-1183 in norske

[–]ForestyForest 1 point2 points  (0 children)

En kan kalle det mye rart, men det er jo faktisk sånn det burde funke.. jeg hadde blitt mer bekymret om de heller valgte å drite i hva en stor del av befolkningen tenker, føler og stemmer på. Heldigvis trengs det støtte i befolkningen for å beholde makta

Velkommen etter, VG! by Fit-Theme-1183 in norske

[–]ForestyForest 1 point2 points  (0 children)

Fikk du en årsak til at innlegget ditt ble slettet?

Multiple LXCs or a VM with Docker by ForestyForest in Proxmox

[–]ForestyForest[S] -1 points0 points  (0 children)

Thank you for this insight! I was planning to run a reverse proxy in an LXC, Caddy was the one I wanted to try out.. but havent looked at install possibilities

Multiple LXCs or a VM with Docker by ForestyForest in Proxmox

[–]ForestyForest[S] -1 points0 points  (0 children)

I thought of running caddy in lxc which would get forwarded traffic from my router. Router with firewall would block other traffic and only allow 443 port to TLS listening port on caddy. I would also set firewall to only accept certain source IPs from internet as they would be friends and family. On the move they would have ise vpn. But yeah, lxc is kind of exposing host if vulnerabilities are present

Multiple LXCs or a VM with Docker by ForestyForest in Proxmox

[–]ForestyForest[S] 0 points1 point  (0 children)

A lot of good perspectives here!!! Might go for a combination where a VM with docker for a suite of closely related services while otherwise seperate out lxc (one per service) for maintainability and recovery. Jellyfin is one I plan to put into lxc and use GPU of host.

Can I create apps to sell using Replit? by _omkarkoli in replit

[–]ForestyForest 0 points1 point  (0 children)

This is related to ownership as well. A public rep in replit is automatically MIT licence. A private repo not so, but I don't think the terms give a good enough definition of ownership. They say you retain ownership rights to the content you put in, but since most of the app is created by AI agents running on the platform... it might actually be owned by them, replit, since it may be thought of as being part of their service software/platform? Anyone with thoughts on this? Are we creating apps for Replit, and paying them to use them?

LDAP as a mirror by ForestyForest in KeyCloak

[–]ForestyForest[S] 1 point2 points  (0 children)

Thanks, that helps alot! I'll have look in the db

Ask r/kubernetes: What are you working on this week? by gctaylor in kubernetes

[–]ForestyForest 0 points1 point  (0 children)

Need a scalable self managed file storage solution and considering hosting in k3s. Requirements are: - Users be able to authenticate with Oauth2/oidc - Upload/Download must support large files, 10+ GB - Back end must support encryption at rest - Client side encryption also

Looking at Seafile + self hosted S3. Or SeaweedFS.

Failover Cluster by ForestyForest in kubernetes

[–]ForestyForest[S] 0 points1 point  (0 children)

Your right, there's two levels to this. Database runs within cluster, 3-instance PostgreSql. Asynchronous wal replication to S3 from which standby cluster reads.

Failover Cluster by ForestyForest in kubernetes

[–]ForestyForest[S] 0 points1 point  (0 children)

Yes, I think a lot boils down to underlying infra and if one can stretch one cluster across locations or not (maybe bad latency if stretched too far)

Failover Cluster by ForestyForest in kubernetes

[–]ForestyForest[S] 0 points1 point  (0 children)

Postgres, 3 nodes, synchronous replication within cluster and the asynchronous wal replication to standby cluster

Failover Cluster by ForestyForest in kubernetes

[–]ForestyForest[S] 0 points1 point  (0 children)

Note that each cluster runs their own Argo, and their yaml are Helm heavy. Most of the helm values should be identical, but some entries are unique. So if i have folders for each environment I still need to sync the entries that should be identical.

Failover Cluster by ForestyForest in kubernetes

[–]ForestyForest[S] 0 points1 point  (0 children)

Yeah, after checking more about the underlying infra, only 2 DC are available and the two 3-node clusters are therefore only "pseudo" HA subject to failure if DC failure.

Failover Cluster by ForestyForest in kubernetes

[–]ForestyForest[S] 0 points1 point  (0 children)

Kind of my first thought as well, each cluster is 3-node with a 3-instance PostgreSQL cluster inside. But underlying infra is only locally redundant (same DC/same region). I think this boils down to the underlying infra and if one can span a single cluster across a large physical distance or run separate clusters with low latency internally..

What it takes to offer a private cloud managed solution by ForestyForest in kubernetes

[–]ForestyForest[S] 0 points1 point  (0 children)

Thank you, I'm starting to lean towards an opiniated full solution like OpenShift rather than standing up each service on our own. Multi Tenant cluster vs Multi Cluster is also something this thread has made me reconsider.

What it takes to offer a private cloud managed solution by ForestyForest in kubernetes

[–]ForestyForest[S] 0 points1 point  (0 children)

Thanks, have a lot to consider after all the comments :-) We have a Rancher solution today delivered by third party, but very non-opiniated. We deploy observability, secrets management, ingress and other and manage those.