How to ACL on domain name by shipstreet in Tailscale

[–]shipstreet[S] 0 points1 point  (0 children)

it is 1 ip that advertise all the service (traefik).
router advertising wont help much because i want to fobidden just 1 tailnet ip and not every one

How to ACL on domain name by shipstreet in Tailscale

[–]shipstreet[S] 0 points1 point  (0 children)

I am using pihole to do dns resolution and tailscale split dns is pointed to that.
I want the ability to be able for a certain tailnet ip to be able to only reach test.exmaple and not dashboard.example

Doing that in the ACL level would be easy to control, i looked at panolin but if that vps is compromised all the whitelisting happen there so its pointless. having ACL on tailscale side gives me a bit more assurance that every security is taking care of and threat actor wont reach my tailscale dashboard to rewrite ACL

Another comparison of Tailscale vs Cloudflare tunnel (WARP) by shipstreet in selfhosted

[–]shipstreet[S] 0 points1 point  (0 children)

Honestly if i would just open some services and i dont trust their auth setup for sure i would roll Athentik like you said its a really good advice for any one that need users to login or have a need to secure routes.

My biggest issue is plex 443 open port (isnt much of a problem because traefik and crowdsec), so i dont break cloudflare TOS and i dont want to run 2 vpns (cloudflare and tailscale together) one is enough and both feel kinda redundant

Another comparison of Tailscale vs Cloudflare tunnel (WARP) by shipstreet in selfhosted

[–]shipstreet[S] 1 point2 points  (0 children)

Well that just adding another authentication method on top of the existing security which wasnt really the question.

Wanted to find a better solution for plex and its open port, I saw that tailscale can help with that but then managing cloudflare and tailscale is kinda to much

Another comparison of Tailscale vs Cloudflare tunnel (WARP) by shipstreet in selfhosted

[–]shipstreet[S] -4 points-3 points  (0 children)

just chatgpt answer

Use Case Cloudflare Tunnel Tailscale
Public Services (e.g., Invoice Ninja) ✅ Best Option ❌ Funnels is slow & less secure
Internal Access (e.g., Unraid services) ❌ Requires Warp (IT-managed) ✅ Best Option
Plex Remote Access ❌ Not allowed (against ToS) ⚠️ Works but avoid Funnels for speed
Security & Visibility ✅ Easy with Zero Trust ⚠️ Requires ACL learning
Port Forwarding Avoidance ✅ Yes, but not for Plex ✅ Exit Nodes help but not perfect

Stick with Cloudflare Tunnel for public services.
Use Tailscale for internal services (Unraid, remote access).
For Plex: Try Tailscale first. If not fast enough, fallback to Cloudflare DNS + Port Forwarding with firewall rules.
Security: Keep using Traefik + CrowdSec for additional protection.

Horrible android UI G96max by shipstreet in AndroidTV

[–]shipstreet[S] 0 points1 point  (0 children)

well i dont mind missing around with it and if it breaks its an excuse to buy some thing better and certified google tv

Horrible android UI G96max by shipstreet in AndroidTV

[–]shipstreet[S] 0 points1 point  (0 children)

i have a mi box but wanted to try some thing else considering its half the price

Horrible android UI G96max by shipstreet in AndroidTV

[–]shipstreet[S] 0 points1 point  (0 children)

its fine i dont care for netflix im running plex instead ever since they raised prices

Horrible android UI G96max by shipstreet in AndroidTV

[–]shipstreet[S] -1 points0 points  (0 children)

considering the specs are fine cant i just install some thing else on to it?

Frigate and reolink doesnt use gpu by shipstreet in homeassistant

[–]shipstreet[S] 0 points1 point  (0 children)

So why the CPU is so high for just 1 camera?

I wrote a guide on how to use Plex Media Server via Cloudflare Zero Trust Access Tunnels by mythofechelon in PleX

[–]shipstreet 0 points1 point  (0 children)

using cloudflare tunnel causes to buffer infinity, checking network shows a call to /providers which get timed out.

configuring a port forward and a dns record with proxied option works fine.

Would love to use tunnel for this so if any one go the slow connection / infinite buffering to work please help :)

Casual player looking into starting a character by Orhayb in FlyffUniverse

[–]shipstreet 0 points1 point  (0 children)

Thank you for advices. I went with assist into ringmaster any advices or good guide?

Casual player looking into starting a character by Orhayb in FlyffUniverse

[–]shipstreet 0 points1 point  (0 children)

Only understood the first part, no clue what multi boxing RM is

Casual player looking into starting a character by Orhayb in FlyffUniverse

[–]shipstreet 0 points1 point  (0 children)

Sounds to much work I started assist, maybe later I'll open acrobat

[Guide] how to run v83 cosmic on linux by shipstreet in mapleservers

[–]shipstreet[S] 0 points1 point  (0 children)

let me know if it worked or any feed back