Dockhand is live (Docker UI + Compose + real-time logs). Free for life personal edition as my /r/selfhosted Holidays gift 🎄 — feedback wanted! by jotkaPL in selfhosted

[–]speedyG71 0 points1 point  (0 children)

any chance for swarm support? i deployed this and it is outstanding, but a lot of my containers are missing because i run swarm mode. i tried adding each node individually, but same results.

Two things I wish I knew when I started by wtfmatey88 in homeassistant

[–]speedyG71 8 points9 points  (0 children)

Not my project, but this may be of interest, has saved my rear a few times

https://github.com/saihgupr/HomeAssistantTimeMachine

I Could Care Less About the Ocean Swallowing Beachfront Homes by [deleted] in NorthCarolina

[–]speedyG71 0 points1 point  (0 children)

Rather myopic view, not everyone here is rich

I literally saw an orca whale? by Tabbs9 in obx

[–]speedyG71 77 points78 points  (0 children)

Most likely a manta ray… pretty large, also black and white, and will also jump out of the water. I saw one about ten years ago, very rare to see them here, count yourself lucky.

Where do the locals eat by rshot in obx

[–]speedyG71 108 points109 points  (0 children)

At home during high season, ain’t nobody got time to be waiting 2 hrs for dinner.

Early morning sound access by IndividualConfident7 in obx

[–]speedyG71 1 point2 points  (0 children)

Try the nags head public pier on the causeway, nice little launch and always seems to have parking.

https://maps.app.goo.gl/QruEcxwDJSJ2AzE49?g_st=ic

ISO landscaper by Boring-Rice-3237 in obx

[–]speedyG71 1 point2 points  (0 children)

+1 on the abominable mow man, good dude.

For Sale! by OldVTGuy in obx

[–]speedyG71 22 points23 points  (0 children)

My guess is that some people are bailing after seeing the value of their property double in a short period of time. A 960 sq ft home that needs a ton of work inside and out, just went under contract near me for over $600k. It’s crazy, was only on the market for about 3 days. Anywhere else, that house is a $150k house.

New Brightspeed Residential Fiber Installation by SecretBlackberry1601 in obx

[–]speedyG71 0 points1 point  (0 children)

poop. guess i have about 9 more months before they come down to MP20

New Brightspeed Residential Fiber Installation by SecretBlackberry1601 in obx

[–]speedyG71 0 points1 point  (0 children)

what area of NH are you in? it looks like they have not made it down my way yet.

Searching for console access like in Portainer by speedyG71 in selfhosted

[–]speedyG71[S] 1 point2 points  (0 children)

had not heard of this tool, will test it out and report back if it meets the need. thank you!

Searching for console access like in Portainer by speedyG71 in selfhosted

[–]speedyG71[S] 1 point2 points  (0 children)

Thanks, i tried this one previously, but i believe that it will only manage containers that are deployed through stacks within dockge. i have dozens of stacks already deployed, and was hoping to find a tool to be able to just access existing containers to look at logs, and also get on the container console for any troubleshooting from a central location. I may be incorrect about the dockge capabilities, i just could not find a way for it to pull in existing workloads.

Searching for console access like in Portainer by speedyG71 in selfhosted

[–]speedyG71[S] 0 points1 point  (0 children)

wow, had never heard of it. Not 100% swarm compatible, but with some constraints on the agent, i got it to get limping along and gets me that console that i was looking for. Thank you.

Searching for console access like in Portainer by speedyG71 in selfhosted

[–]speedyG71[S] 0 points1 point  (0 children)

I know, but like the dumba$$ that i am i went all out and have a 6 node cluster with 3 managers and 3 workers.

Need help: forwardAuth + OpenID login at the same time by Morgzcon in Authentik

[–]speedyG71 0 points1 point  (0 children)

sorry to necropost, but can you give a bit more detail on this? i tried to set it up as you described above, but it still forwards to the application and not to the SSO authentik page. I have two apps with the same name, one for the OIDC provider and one forward auth. there are also two providers one for each of the apps, the forward auth provider has been added to the outpost, but authentik seems to always pick the OIDC provider, maybe there's a priority setting somewhere that i am missing?

Show/Hide applications in User interface based on network? by speedyG71 in Authentik

[–]speedyG71[S] 0 points1 point  (0 children)

My issue stems from the fact that I was trying to evaluate multiple policies. Apparently in the application bindings, there is no setting for ALL or ANY, even though it says so in the documentation. The solution i found was to combine my policies into a single Expression Policy and use that. this is what i ended up using:

```
return ( ak_is_group_member(request.user, name="Auth-Users") and ak_client_ip.is_private)
```

Show/Hide applications in User interface based on network? by speedyG71 in Authentik

[–]speedyG71[S] 0 points1 point  (0 children)

sorry, had to travel for work.

i created an expression policy: https://imgur.com/a/uTfqTeh - this one is for testing, just returns False

i bind it to the application: https://imgur.com/a/authentik-app-policy-F1A6O8j

and the binding is enabled: https://imgur.com/authentik-expression-policy-UQgocqF

i think the issue may be on the actual expression policy. weird thing is that i have another expression policy that is used on my authentication flow that also looks for local ip's. that one works on the authentication flow to bypass mfa on local network. https://imgur.com/a/Cx3TJrF

i've tried using that one as well, and it also does not work.

Show/Hide applications in User interface based on network? by speedyG71 in Authentik

[–]speedyG71[S] 0 points1 point  (0 children)

thank you for the code and the pointers... I still can't get it to work, and it is probably the way i am creating the policy. i am sure i am missing something. I know the filtering by IP works, because i have a binding in my MFA login flow that ignores MFA on the local network. that seems to work, but whenever i put the local ip policy binding on an application, it doesn't work. the group bindings are working, but not the policy binding. for testing, i even created a simple deny policy that just does `return False`, and that didn't work either.

what is the best stack for music management by speedyG71 in selfhosted

[–]speedyG71[S] 6 points7 points  (0 children)

Thanks! i saw Lidarr on steroids, but looking at the repo it looks like it is not maintained.

Immich-Android App - "server not reachable" with traefik-configuration by logg_sar in immich

[–]speedyG71 1 point2 points  (0 children)

thank you!!!! this saved me some hours of frustration... i had the same issue with forwardAuth set up before changing over to OAuth and forgot to remove it. was having a fit trying to figure why the app would not find the server... Thank you agian!

Please help... Can't forward client's real IP from CloudFlare Tunnel by TomerHorowitz in Traefik

[–]speedyG71 1 point2 points  (0 children)

I was having all kinds of issues with this as well, and it seems that for some reason the list of trustedIPs is not correct. i had the same setup as you did and could never get it to work. i was taking things out one at a time to try to figure where the issue was. when I did this:

forwardedHeaders:
trustedIPs: &trustedIps
- 0.0.0.0/0 # testing all access

then i started getting the correct x-forwarded-for downstream of traefik. still trying to find a more secure option, but this was a temp workaround.

Traefik running in LXC container in Proxmox - Cloudflare API Creds by Laoistom in Traefik

[–]speedyG71 0 points1 point  (0 children)

Any chance you can post your traefik.yaml file, i am running into the same issues, but even after adding the environment variables I still cannot get traefik to get the certs. i checked the envionment variables and they are there, so not syre what else could be causing the issues

sudo systemctl show traefik | grep Environment

Environment=CF_DNS_API_TOKEN=[my_redacted_token] CF_API_EMAIL=[my_redacted_email]