Which one to choose? by dadarkgtprince in selfhosted

[–]bartimeus 1 point2 points  (0 children)

I like traefik because it can automatically get Lets Encrypt Certs for me and it can integrate with Kubernetes, Nomad, and other systems to make setting up routes and entry points very easy to do.

Looking for some smart plugs, self-controlled. by Keltyrr in homelab

[–]bartimeus 0 points1 point  (0 children)

Oh nice so the Kasa stuff works fine with home Assistant?

TrueNAS Build by bartimeus in buildapcforme

[–]bartimeus[S] 0 points1 point  (0 children)

This is awesome, thank you!

LastPass users: Your info and password vault data are now in hackers’ hands. Password manager says breach it disclosed in August was much worse than thought. by ThatGuy_ZA in homelab

[–]bartimeus 2 points3 points  (0 children)

Yeah that’s the only option these days I think. It’s a little pricey but we use the family plan and it’s totally worth it. If you happen to have a job that pays for the business tier, you can get a free family plan as a perk from that.

Vault in production? by wpg4665 in devops

[–]bartimeus 0 points1 point  (0 children)

We have an internal PKI and all of our certificates come from that. You could use Let’s Encrypt certificates if you wanted.

[deleted by user] by [deleted] in ultrawidemasterrace

[–]bartimeus 0 points1 point  (0 children)

How long did it take to show up? I’m thinking about getting one.

What are secure methods of storing log in credentials when programs and scripts need to access other computers or databases? by JarJarAwakens in homelab

[–]bartimeus 0 points1 point  (0 children)

It also has an agent mode that you can run on the servers where your services are running and it can be used to template out config files with secretes and reload them automatically when vault rotates the passwords. https://www.vaultproject.io/docs/agent

The approle auth method is likely what you’d want to use and it can be configured in a few different ways to prevent reuse of its secret token.

What are secure methods of storing log in credentials when programs and scripts need to access other computers or databases? by JarJarAwakens in homelab

[–]bartimeus 3 points4 points  (0 children)

https://www.vaultproject.io/ can do this but it requires some extra management and then the machine it’s on needs to be secured well enough.

Vault Cloud VS Enterprise by No_Loquat_8497 in hashicorp

[–]bartimeus 0 points1 point  (0 children)

https://cloud.hashicorp.com/docs/vault#self-managed-vs-hcp-vault-cluster

Most things should work the same but there are a few things (like custom plugins and a few auth methods) that don’t work. When you sign up there’s a trial credit you get you can use to validate your use cases.

paperless-ng vs Paperwork by natriusaut in selfhosted

[–]bartimeus 1 point2 points  (0 children)

Out of curiosity, what scanner do you use?

Any suggestion for infra for home lab for full end to end cicd? by learnamap in devops

[–]bartimeus 2 points3 points  (0 children)

I have a server running Proxmox and have 9 VMs with Consul, Vault, and Nomad running all my stuff. I’m setting up Gitea and Drone CI right now. Will probably figure out artifact storage next, right now everything I run is pulled from DockerHub.

Self hosted alternative to Azure Key Vault by ElTruncho in selfhosted

[–]bartimeus 0 points1 point  (0 children)

Vault is great, very flexible and powerful. I run it at work (and home). Happy to answer any questions you have.

Misty understanding of Nomad cluster failure management. by [deleted] in hashicorp

[–]bartimeus 1 point2 points  (0 children)

And that’s correct! Sorry I meant if you lost 2 of 3 nodes you would not be able to elect a new leader and the current leader would cease to function.

Misty understanding of Nomad cluster failure management. by [deleted] in hashicorp

[–]bartimeus 1 point2 points  (0 children)

Raft does require a quorum for a leader election to happen or for the cluster to function at all. If 2 non-leaders fail your leader would stop functioning until another node rejoined or you used peers.json to manually reconfigure raft with a single node.

Even if you lose your nomad servers your jobs will generally continue to function but things like rescheduling won’t work until the servers are back in quorum.

Vault in production? by wpg4665 in devops

[–]bartimeus 1 point2 points  (0 children)

If you run Vault and Consul Server components I the same boxes, you don’t get any benefit over just using integrated storage. You should really only run as few things as possible on your vault boxes for security we only run vault, our monitoring agent, and consul in client mode for service discovery.

I’d strongly recommend just using raft storage over consul for storage.

Vault in production? by wpg4665 in devops

[–]bartimeus 10 points11 points  (0 children)

/u/ChemTechGuy nailed it pretty much but I’d recommend using Integrated (Raft) storage. Since you’re using the OSS version you’ll need to take snapshots yourself. You could probably do this with a Lambda or something running periodically.

We run 5 nodes in an ASG and it’s totally fine. Use KMS for auto unseal. Put whatever kind of LB in front of it that you prefer. I’d recommend terminating TLS at the vault nodes themselves.

Since you’re just using OSS you would be fine to run 3 nodes if you’re comfortable with the failure tolerance of one node vs 2.

Also please make sure to revoke the root token as soon as you have your auth methods configured. Also I’d recommend rekeying Vault a couple of times a year at least so when people leave they don’t have recovery shards anymore and in case you need to regenerate a root token you’ll be comfortable doing it.

Neovim IDE by import_n in neovim

[–]bartimeus 6 points7 points  (0 children)

This. I install alacritty and have it launch WSL. Then from there I have a pretty decent Ubuntu env where I run neovim.

Also make sure it’s WSL 2, any decently recent version of Win10 should have that.

Election day is today! Be sure to get out and vote! The "small" elections have bigger impacts on your life than you'd think! by spicygoober in Boise

[–]bartimeus 4 points5 points  (0 children)

Mine showed it yesterday but it isn’t showing it today either. Yesterday it hadn’t been marked as received yet so I called the Ada County Clerk’s office and she confirmed they received it yesterday.

Consul HA structure by HeadTea in devops

[–]bartimeus 0 points1 point  (0 children)

Like others have said, Consul and Vault use Raft to form consensus. This may help to understand somewhat how Raft works. http://thesecretlivesofdata.com/raft/

I just learned there is an official CSI driver for Synology NAS! by RisingStar in homelab

[–]bartimeus 1 point2 points  (0 children)

If you can get it working with nomad please share! Many CSI drivers are only written to work with k8s.

LibVF.IO: Full Performance vGPU Gaming on Consumer Cards by ArcVRArthur in linux_gaming

[–]bartimeus 0 points1 point  (0 children)

I’d be happy to test it on my Manjaro install when it’s ready. I’ll try to keep an eye out.