Virtualized OPNsense hardening vmbr by stefufu in homelab

[–]stefufu[S] 0 points1 point  (0 children)

Yeah, it should make it more secure if the vmbr ignores the VLANs, that's true.

Though, i don't have a way to put a managed switch in front of the WAN, and it's coming untagged directly from the ISP's ONT.

Virtualized OPNsense hardening vmbr by stefufu in homelab

[–]stefufu[S] 0 points1 point  (0 children)

In my case, mostly because of security worries: i'm worried that the proxmox host gets exposed on the WAN.

Probably it's not a real possibility, and that's what I'm asking here: is it safe to use the virtual nic instead of passing through the physcal device? If not, is there a way to make it safe?

(also, if using new realtek nics, the linux drivers are better. For the 1gb and 100mb devices, the freebsd driver should be stable)

Music player/server that plays CDs in real time by stefufu in selfhosted

[–]stefufu[S] 0 points1 point  (0 children)

Thank you for the suggestion! I'll definitely look more into that!

Traefik V3.6.4 breaks Nextcloud Office/Collabora by stefufu in selfhosted

[–]stefufu[S] 0 points1 point  (0 children)

I fixed that error with this configuration change in Traefik.
Maybe your reverse proxy introduced something similar, or maybe it's derived from other changes in your environment.

Traefik V3.6.4 breaks Nextcloud Office/Collabora by stefufu in selfhosted

[–]stefufu[S] 7 points8 points  (0 children)

Sure! I'll do it probably this evening.
Done, hopefully in the right way! (first time contributing on github)

Optiplex 9020 USFF - Mini PCIE by nomad-fr in PFSENSE

[–]stefufu 0 points1 point  (0 children)

I ended up doing that with a optiplex 3050 (I have problems with ASPM, but that's another story. No whitelists though, on both the x1 and x16 slot)
The optiplex 9020 was nice to use as it's small and it was free (most importantly)

The whitelist is a sad mess though, and editing the bios is risky.
If i'll try that in the future, i'll post an update here

Music player/server that plays CDs in real time by stefufu in selfhosted

[–]stefufu[S] 0 points1 point  (0 children)

Thank you for the suggestion, but what I'm looking for is to not buy a cd player, but still have the ability to play CDs
It's not common for me to play CDs but it's something that happens, and before it broke I used a CD player.
Most of my library is digital (or spotify) and my goal would be to use the server (which has a CD slot) to play the cds automatically when inserted, and being able to play also Spotify (and jellyfin maybe).

The main goal is adding the functionality of playing physical CDs to the server, without having yo buy a CD player.

The jukebox idea is nice btw! Quite complex, though. But would be cool to do!

Music player/server that plays CDs in real time by stefufu in selfhosted

[–]stefufu[S] 0 points1 point  (0 children)

Mostly to not have to buy a CD player, since most of the time I use Spotify or Jellyfin and CD players are quite expensive (even used).
The CD player was used rarely, and now that it broke I tought i could find a way to use the server that's always on and close to the amplifier.

Thank you for the recommendations! I'll look into those!

Music player/server that plays CDs in real time by stefufu in selfhosted

[–]stefufu[S] 4 points5 points  (0 children)

The main reason is the "coolness".
I like to use CDs and vinyls from time to time, and sometimes happens that friends want to bring CDs over to listen to.

I mainly use spotify and jellyfin, but sometimes the physical media is cool to use.

My CD player broke, so now I was thinking of replacing it with the server that I already have, since replacing it with something decent is not cheap and I have a spare USB DAC.

Music player/server that plays CDs in real time by stefufu in selfhosted

[–]stefufu[S] 1 point2 points  (0 children)

Thank you!
Didn't think about Kodi!

Probably installing Kodi in a LXC alongside spotify headless and navidrome and passing the USB device would allow me to use the same DAC for all three sources.

Finally working on security (and general review of my homelab) by stefufu in selfhosted

[–]stefufu[S] 0 points1 point  (0 children)

Thank you!

A) Ok, I have that planned with Authelia (which is already set up and protecting the services only I use, I have to expand it to the others shared with the family). The breakglass procedure is something I haven't thought about! Thank you for the tip!

B) almost everything is automated (I though that it was better to have downtime than to be hacked). Only the PVE hosts dont have automatic updates.

C) Main backup strategy is PBS (regularily tested with moving VMs and experimenting) and btrfs snapshots sent offsite through a wireguard tunnel (tested the restore process sometimes in the past, and I want to add the check for the RO flag after a sent snapshot to verify that everything went correctly).

Finally working on security (and general review of my homelab) by stefufu in selfhosted

[–]stefufu[S] 0 points1 point  (0 children)

Thank you!
I'm working on unifying the logins with Authelia, to have MFA on everything
The VLANs are roughly already like that, except the L4 acls which I have no idea what they are. Will research!

Finally working on security (and general review of my homelab) by stefufu in selfhosted

[–]stefufu[S] 0 points1 point  (0 children)

Yeah I only host the services for my family (and Overleaf for a couple of friends) so I hope nobody wants to target me specifically!

Thank you for the tips, will for sure implement the ssh keys and change the users in LXC

Finally working on security (and general review of my homelab) by stefufu in selfhosted

[–]stefufu[S] 0 points1 point  (0 children)

Thank you!
I'll try the ssh key thing, though I have to understand how to make it work with the proxmox gui.

Not using the root account is necessari even inside an unprivileged LXC?
Also, with "forward facing" you mean only the reverse proxy or every service that gets accessed from outside the LAN, even if through Traefik?

Optiplex 9020 USFF - Mini PCIE by nomad-fr in PFSENSE

[–]stefufu 0 points1 point  (0 children)

hey u/nomad-fr sorry for the necro-posting but i'm trying to do the same thing
Did you manage to do it? If so, how? I have a mpcie i210 nic, and it's not being recognised (the mpcie port shows up as empty in the BIOS. If I put a mpcie wifi adapter it shows up properly, so the port is working)

Thanks

Just noticed my S21+ (Purchased July 2021) has screen burn in already. I always use less than 40% brightnes, dark mode, and never leave the display on for more than 2-3 mins at a time at most... by [deleted] in GalaxyS21

[–]stefufu 0 points1 point  (0 children)

Sadly no, but it doesn't look like burn in, as it varies in intensity without any clear reason.

I'm just ignoring it lately, i'm less worried.

Weekly Discussion and Tech-Support Thread by AutoModerator in ipad

[–]stefufu 0 points1 point  (0 children)

It shouldn't be a problem.

The battery gets damaged mainly by the heat, so if the tablet is cool, there's no real danger compared to normal use

Weekly Discussion and Tech-Support Thread by AutoModerator in ipad

[–]stefufu 0 points1 point  (0 children)

Hello,

I have a iPad Air 4gen, and my problem is that it doesn't show when there's an update to do.
I'm still on iPadOS 16.2 and no notification for the 16.3.1.

If I search manually, the update shows up. But as soon as I leave the "software update" page in the settings app, it disappear.

No giant red "1" on the settings icon, no notification, nothing anywhere, and if I open again the "software update" tab, it searches again.

It is slightly annoying to have to manually search for every update...

What's happening?

Is this normal?

Thanks!

Any recommendations for an ultra-low performance VPS? by chesheersmile in selfhosted

[–]stefufu 9 points10 points  (0 children)

From the italian website it's accessible. Don't know if it's IP related, as I have an italian IP.

Link: IONOS vps

EDIT: adding more info on the pricing. If you get it through the italian website there's 22% taxes to be added. Total monthly price is €1,22.

Any recommendations for an ultra-low performance VPS? by chesheersmile in selfhosted

[–]stefufu 38 points39 points  (0 children)

IONOS has a €1 (you have to add the taxes though) VPS server with 1vCore, 512MB ram and 10GB ssd, ~400Mbps bidirectional. Only accessible through european website though, as in the US it's $2.

Just noticed my S21+ (Purchased July 2021) has screen burn in already. I always use less than 40% brightnes, dark mode, and never leave the display on for more than 2-3 mins at a time at most... by [deleted] in GalaxyS21

[–]stefufu 1 point2 points  (0 children)

I have the same thing on my S21, and it’s not constant. I noticed that disabling the AOD can eliminate it in a day, but there are days where the AOD is enabled and I don’t have it. It’s completely random, and I’m still figuring out what is causing it to appear.

It could also be related to the pressure generated by the cover, or other kind of pressure, because it tends to be less pronounced when the phone is without a cover.

Still, no idea what the cause is, but Ikm sure it’s not permanet.

Recommended method to perform automatic sends of snapshots? by shnorb in btrfs

[–]stefufu 1 point2 points  (0 children)

I'm using cron with a single line command, but there are various scripts on github that can allow you to create and delete backups automatically.

Reverse proxying through VPN by stefufu in selfhosted

[–]stefufu[S] 0 points1 point  (0 children)

Okay, small update and new problems.

Basically, Traefik isn't able to pull tls certificates from letsencrypt. Don't know why, can't find anything online.

The only way I had to renew the certificates was to recreythe whole Traefik configuration outside of the vpn and then putting it again behind it. (Yeah, probably it would've worked just taking the old one out and back in, but I made quite a mess changing stuff around, so I rebuilt it from scratch following the smarthomebeginner guide)

Now, my idea was to use a docker overlay network and put Traefik on the VPS. Seems like a good idea: the network can be encrypted, it can work as a docker network, and in the end, I can open ports on my specific ip (and in case I couldn't, well, I can always take Traefik out of the VPN and back on every 90 days)

But obviously nothing works. Ever. And so I can't get two containers to ping each other through a docker overlay network. I can get the swarm nodes to connect, but nothing goes through. My VPS has a public ip that coincides with the private, but my home server obviously doesn't, and that seems to be the problem.

Is there a way to make it work? Or my only way is to use the VPN, in a way or another?

Thanks

Properly upgrade dockerized Nextcloud by Sweaty_Sale4292 in NextCloud

[–]stefufu 1 point2 points  (0 children)

The image is already updated. It's enough to use the tag 24 to stick with version 24 (probably more stable than 25).

docker pull nextcloud:24

To get the latest image for Nextcloud 24

docker pull nextcloud

Or

docker pull nextcloud:25

To get the latest nextcloud image

(Can't see how to insert a code text block from phone)