arcayne

joined 7 months ago
[–] [email protected] 3 points 1 month ago

https://pulpproject.org/

Does docker, pypi, apt, ansible galaxy, etc. I use it at work as part of our undercloud for OpenStack. It's the go-to for StackHPC, too.

[–] [email protected] 2 points 1 month ago (3 children)

That's a fair take. The pricing model has changed dramatically since I last looked at it, but at the same time, the dev has obviously put a lot of thought into these changes, so I find it difficult to fault him. He's gotta make a living somehow.

In general, if someone has more than one Proxmox node to manage, chances are they've got some type of homelab, which isn't exactly the cheapest hobby out there to begin with. If XPipe enhances their experience, I'd say that's worth a few bucks. If not, they can always git gud in the terminal and do the legwork themselves, but time = $, so...

[–] [email protected] 8 points 1 month ago* (last edited 1 month ago) (6 children)

It's a free tool that is relevant to a lot of users in both of those communities, and because of the support from those communities, the author was able to pivot to working on xPipe full-time. That's no small feat for a solo dev, and I for one appreciate seeing these updates.

If you decided to devote all your time and energy to a project that was supposed to pay your bills, would you just sit and twiddle your thumbs thinking "if you build it, they will come"? ¯\_(ツ)_/¯

[–] [email protected] 2 points 1 month ago (1 children)

Not sure if it'd fit your use case 100%, but this has been a nice middle ground solution for LE certs in my lab: https://www.certwarden.com/

[–] [email protected] 1 points 2 months ago

My preferred way of solving this is to run a PowerDNS cluster with DNSDist and keepalived. You get all the redundancy via a single (V)IP.

Technitium is probably more user friendly for greenhorns, though.. and offers DHCP too. Beats pihole by a mile.

[–] [email protected] 4 points 2 months ago

I started hybrid, but luckily my boss noticed how much more productive I was when WFH. Now I only have to go in every once in a while, think it's been about a month since my last commute. I really wish more managers/employers would warm up to this concept.

[–] [email protected] 2 points 2 months ago (1 children)

For sure! If you do end up taking it for a spin, feel free to ping me with any questions.

[–] [email protected] 2 points 2 months ago (3 children)

I'd like to encourage you to take another look at Authentik, it sounds like their Proxy Provider is exactly what you're looking for: https://docs.goauthentik.io/docs/providers/proxy/

Authentik can certainly get complex, but only if you want/need it to. It is by far the most user-friendly IDP solution I've found, especially for what it offers. Their docs also have step-by-step guides for how to integrate a lot of popular self-hosted apps.

Only takes a couple mins to spin up a test environment using their Docker compose file: https://docs.goauthentik.io/docs/installation/docker-compose

[–] [email protected] 11 points 2 months ago* (last edited 2 months ago)

Apps: SSO via Authentik where I can, unique user/pass combo via Bitwarden where I can't (or, more realistically, don't want to).

General infra: Unique RSA keys, sometimes Ed25519

Core infra: Yubikey

This is overkill for most, but I'm a systems engineer with a homelab, so it works well for me.

If you're wanting to practice good security hygiene, the bare minimum would be using unique cred pairs (or at least unique passwords) per app/service, auto-filled via a proper password manager with a browser extension (like KeePassXC or Bitwarden).

Edit: On the network side, if your goal is to just do some basic internal self-hosting, there's nothing wrong with keeping your topo mostly flat (with the exception of a separate VLAN for IoT, if applicable). Outside of that, making good use of firewalls will help you keep things pretty tight. The networking rabbit hole is a deep one, not always worth the dive unless you're truly wanting to learn for the sake of a cert/job/etc.

[–] [email protected] 1 points 6 months ago

We're so tightly integrated with the M$ ecosystem at my work, it's painful. My department has even been going out of it's way to self host (F)OSS alternatives where we can, just to avoid as much of the cludge as possible.

Has anyone tried out the new Teams integration feature that Mattermost recently rolled out for Enterprise customers? If so, any good?

If we can seamlessly sync calls/meetings from Teams into Mattermost and ditch the Teams client for our day-to-day comms, I might have a fighting chance at convincing my supervisor to pivot my department.

[–] [email protected] 2 points 6 months ago

If you ever reach a point where self-hosting does become a possibility, I'd recommend checking out Mattermost.

view more: next ›