erev

joined 1 year ago
[–] [email protected] 7 points 1 week ago

Sprinkle cat litter after you shovel and salt, it'll provide traction and prevent ice from reforming. You can get one good and warm set of winter clothes, or you can do a fuckton of layers. The former is simpler but can leave you with less flexibility and will probably be more expensive than wearing 3-5 layers of clothes you probably already own. If you don't have them, long johns/thermal pants are a godsend. Gloves and a hat that covers the ears are also godsends, but if you're willing to tough it out (and maybe lose a few extremities) you can do without them as eventually you'll stop feeling the sting. Tuck your shirt and/or jacket into your pants, this will trap heat. Tuck your gloves into your coat or vice versa. Get good boots, i cannot stress this enough. It is not fun or a good idea dealing with snow in sneakers.

[–] [email protected] 3 points 2 weeks ago (11 children)

Yeah that's insanely wasteful

[–] [email protected] 6 points 3 weeks ago (1 children)

I agree with you but that doesn't mean everyone does. Whether you like it or not, social media platforms are going to be used. OP is just sharing a tool they built and believe may be useful to others for free. There's no need to shit on their work just because you ideologically disagree with the underlying services managed. Again, I feel the same way as you but OP is contributing a useful tool to the people; that is seldom a bad thing. I could see myself using this to boost my LinkedIn presence, because it's one of the few things I have and need in my early career. Would I like to get rid of my LinkedIn? Absolutely. Do I despise most social media platforms (including Lemmy to a degree)? Definitely. Do I appreciate OP for making and sharing this? You bet I do.

[–] [email protected] 1 points 1 month ago

Have you made the effort and forced yourself to test your own assumptions?

[–] [email protected] 24 points 1 month ago (1 children)

None of these are unique by any means (i wish the second was but fascism is rising globally).

The styles of it tho, I'll give you that.

[–] [email protected] 5 points 1 month ago

If he wins you resist. If he doesn't win you resist. Either way America is headed down the road Trump wants to take us down. The only real difference is whether it's sooner or later, which is a big difference but it's an even bigger difference to the next generation. We live under an oppressive and tyrannical system aimed only at extracting as much of life's beauty and enjoyment from people as possible in the form of capital. The only ethical thing to do is fight and resist. To stand against the tyranny. To build our communities and to build up each other so we can resist. To teach and learn so we all know that we must resist.

The Palestinian Genocide is obviously a controversial topic right now, but the Palestinian people are telling us and showing us what we need to see, hear, and know: fascism is here and it will take us all. We must resist and fight until either our bones are ground to dust under their feet, or until we are liberated. The term "intifada" has been politicized but all it means is struggle. Because while their land is occupied, while their lives are lost, while the joy of life is stolen from them, they must struggle. Struggle is just.

So while they take our rights, while they steal our joy of life, while they continue to trample us expecting nothing, we must struggle. Because while our struggle is not the same as the Palestinian struggle, when we resist together we can hope to lift each other up. That is the point of the global intifada. Together we stand taller and stronger. Together we can protect and help each other unlike the system at hand. Resistance is just.

So resist, struggle, and fight. Learn new skills,acquire resources, and build the means to survive so that when they come to take what they want, you can stand resilient. Build mutual aid networks and strong communities so that when they come to take what they want, you can stand together. Arm yourself and train your body and mind so when they come to take what they want, you can stand strong. And fight so that when they come to take what they want, they know that they cannot come again. Resist, struggle, and fight.

We will never see freedom and equality as we dream of, but our children might. The people of Palestine, of Sudan, of the Congo, of Haiti may not see the brighter future they are fighting and struggling for, but they will continue to do so so that their children can. We must continue to do so so that all our children can. Our plights are not equal, but in resisting this tyranny we can hope to bring about change for all of us. That is the global intifada.


Sorry if this was a bit unhinged I'm having a little bit of trouble putting what i want to say into a coherent message. I also hope nobody is seeing this and thinking that I'm equating the struggles in the US to all these other places. Just that when people resist, anywhere and everywhere, we can hope to break our chains and the chains of our fellow humans.

[–] [email protected] 3 points 1 month ago (3 children)

I actually think thats ideal. None of us could function in a proper utopia. We could not live in Star Trek. We have been far too corrupted by society, capitalism, and bigotry to ever properly function in such a society. Some could adapt better than others, but at the end of the day we'd be antithetical to such an advanced society. As such, we should prepare the world to transition towards such a society with the knowledge that it will be our grandchildren who truly bear the fruits of our work. A society grows great when old men plant trees whose shade they will never sit under.

[–] [email protected] 3 points 1 month ago

My brother in Christ, im sorry to inform you but the upcoming fiscal crisis are gonna be some of the least of your kids worries. I'm still probably closer in age to you rather than them, but i grew up knowing that money is gonna mean jack shit once the water starts boiling (metaphorically, but hyperbolically realistic). We're the frogs in the pot and the economy is gonna be the least of our troubles. We're seeing a global rise in fascism, climate disasters, war, inequity, and yes financial instability. If you wanna help your kids, get involved in the community and organize. Start unions at your work places and march in protests for a better future. I'm not talking about a stronger or more fashy future, but one where we work together. Join or make mutual aid networks where you live. The best thing you can do for your children (imo, coming from a young person) is help set up the future you want for them. I would hope that's one of community and mutual aid where we help each other not because we expect a reward or are paid to, but because together we stand taller and can hoist up those who cannot stand on their own. I hope i don't sound too preachy, but it sounds like you love your kids so I implore you to get involved further. The future did not look kind to me when I was a child, and it looks even less hospitable now. We can change that. Direct action and mutual aid are the way forward to a better future imo.

[–] [email protected] 1 points 1 month ago (1 children)

I believe we can make security mutual aid. Everyone in the community has a role to play in the security and safety of the community. When we work together we can prevent a lot of issues

[–] [email protected] 2 points 1 month ago (1 children)

I disagree that economic growth is a prerequisite for political freedom. I think that type of thinking has been perpetuated by capitalists to keep capital flowing. Communes and mutual aid don't have great or any economic growth but can allow for political freedoms that we don't even have now.

[–] [email protected] 11 points 1 month ago

hey, amab masc nb person here, i appreciated your write up, thought it was interesting, and cared.

[–] [email protected] 15 points 1 month ago (1 children)

I mean i definitely do in a sense of the word

 

I've been around selfhosting most of my life and have seen a variety of different setups and reasons for selfhosting. For myself, I don't really self host as mant services for myself as I do infrastructure. I like to build out the things that are usually invisible to people. I host some stuff that's relatively visible, but most of my time is spent building an over engineered backbone for all the services I could theoretically host. For instance, full domain authentication and oversight with kerberized network storage, and both internal and public DNS.

The actual services I host? Mail and vaultwarden, with a few (i.e. < 3) more to come.

I absolutely do not need the level of infrastructure I need, but I honestly prefer that to the majority of possible things I could host. That's the fun stuff to me; the meat and potatoes. But I know some people do focus more on the actual useful services they can host, or on achieving specific things with their self hosting. What types of things do you host and why?

 

Hello! I am migrating some services from an old cloud instance to my homelab. The cloud instance was running NextCloud and as I don't really need the entirety of NextCloud, I'm moving to individual services. It's now time for me to move the most important thing from this NextCloud instance: my calendars and contacts.

I'm looking for a good containerized service to run this. I've taken a look at both Baikal and Davis, but both seem to have issues running rootless. As I have Kerberos throughout my network and am storing the persistent volumes on an NFS share, I prefer to run all my containers under dedicated service accounts. This also means that I would like the DAV server to have LDAP or IMAP authentication. I am also using podman quadlets rather than docker compose, but I can figure out the translation on my own. Worst case scenario here is I just run Davis and talk to the dev about the issues I have (which will probably be done anyways), but I'd like to get something up and running sooner rather than later. Any solutions would be greatly helpful. If there isn't a good containerized solution, I'm also willing to make an LXC or VM but I'd prefer to stick to containers. Thank you!

 

So this is an interesting one I can't figure out myself. I have Proxmox on a PowerEdge R730 with 5 NICs (4 + management). The management interface is doing its own thing so don't worry about that. Currently I have all 4 other interfaces bonded and bridged to a single IP. This IP is for my internal network (192.168.1.0/24, VLAN 1). This has been working great. I have no issues with any containers on this network. One of those containers happens to be one of two FreeIPA replicas, the other living in the cloud. I have had no issues using DNS or anything else for FreeIPA from this internal network nor from my cloud network or VPN networks.

Now, I finally have some stuff I want to toss in my DMZ network (192.168.5.0/24, VLAN 5) and so I'll just use my nice R730 to do so, right? Nope! I can get internet, I can even use the DNS server normally, but the second I go near my FreeIPA domains it all falls apart. For instance, I can get the records for example.local just fine, but the second i request ipa.example.local or ds.ipa.example.local, i get EDE 22: No Reachable Authority. This is despite the server that's being requested from being the authority for this zone. I can query the same internal DNS server from either the same internal network or a different network and it works handy dandy, but not from the R730 on another network. I can't even see the NS glue records on my public DNS root server.

I'm honestly not sure why everything except these FreeIPA domains works. Yes, I have the firewall open for it and I have added a trusted_networks ACL to Bind and allowed queries, recursion, and query_cache for this ACL. The fact it only breaks on these FreeIPA subdomains makes me think it's a forwarding issue, but shouldn't it see the NS records and keep going? It can ping all the addresses that might come up from DNS, it's showing the same SOA when I query the root domain, it just refuses to work from my IPA domains. Can someone provide any insight on this please, I'm sick and tired of trying to debug it.

32
submitted 6 months ago* (last edited 6 months ago) by [email protected] to c/[email protected]
 

Hello! I have Proxmox VE running on a Dell R730 with an H730. Proxmox manages the disks in a ZFS RAID which is exactly how I want it. Because I intend for this server to have a NAS/file server, I want to set up a container or VM in proxmox that will provide network storage shares to domain-joined systems. Pretty much everything in my lab is joined to FreeIPA, so I'd like to use the IdM features with my file server. I have given TKL FileServer a shot but it really didn't seem up to snuff with what I wanted. I am not looking for a NAS solution that will require me to pass through the RAID controller and disks to Proxmox, as I want Proxmox managing the ZFS pool. I can set up an NFS/Samba server in a container, however in trying to do so I was running into issues (due to it being an unprivileged container) that I can probably figure out but I want to see if anyone has any recommendations first.

 

For me it's driving while under the influence. If you couldn't tell, I like me some ganja. However I have long since held the belief that it is utterly insane to drive while under the influence of most substances, with maybe nicotine and caffeine being the exception. All too often I see other stoners smoking and driving, which I simply can't fathom. I've only operated a vehicle once under the influence and it was just to move a U-Haul around the block to a different parking spot, which was such a scary experience while high that I refuse to even consider getting behind the wheel again while high.

 

I recently purchased a Dell PowerEdge R730 at a killer price, and intend it to be the cornerstone of my home lab. I plan to use it as both a NAS and a container server so I can set up whatever I want with it. I'm a bit unsure of what a good setup here looks like, so I'm hoping for a bit of guidance.

As my R730 has 16 drive bays, I intend for 10 of those to be high capacity HDDs for the NAS with the remaining spots for SSDs for the containers. The R730 will also have a PERC H730 RAID controller. I want a full featured NAS solution (although I am open to more lightweight solutions) so my go to thought is TrueNAS. My plan was to install Proxmox and run TrueNAS on top of it, but I am unsure if this is the best method. Does anyone have any insight on how well this works or if there's a cleaner solution?

Addendum: Anyone have any recommendations for RAID setups? I currently have 4x900 GB 10k SAS Dell Enterprise drives but I intend to bump that up to 10x900 GB over time. I'd like to be able to add these without much hassle, but I'm unsure what to go with. It seems that ZFS can handle it well alone, but I don't want to have gotten the good raid controller for nothing so I'm wondering if using ZFS with the RAID controller in HBA mode will be more worth it than a dedicated RAID setup. And if I'm using a RAID setup, should I go RAID or unRAID? If I go RAID, is RAID 01, 10, or 60 a better option here? Based on my research, it sounds like I'll need a lot more drives for a proper RAID setup and it'll be less flexible, but I would like some second opinions.

 

Cross Posted from one of the Ubiquiti communities

 

I have an existing website that I use for all sorts of things. I was a bit more of a sucker when I bought the domain so I also bought a wildcard SSL cert for my domain instead of using LetsEncrypt. I use the home subdomain to link back to my home network where I'm in the process of setting up a FreeIPA domain. In order to make sure the SSSD works properly, I read that I need to LDAPS, and for that I'll need some certs. I know FreeIPA generates its own certs, but these are self signed. I'd like to have my certs actually be trusted as theres a reason this is on an actual domain. However when i try to add my certs with

sudo ipa-cacert-manage -t 'C,,' CERT_BUNDLE

I get an issue with one of the certs (I know which one) for using an insecure algorithm. And (expectedly) I can't add the other certs as this is part of the CA chain. So I read to try renewing with the external-ca option, and now I have a CSR from FreeIPA but I'm unsure if I can sign it with my SSL cert. Any guidance or help is vert much appreciated. I may have buggered my install in trying to figure this out, but I suppose we'll find out.

Update: It looks like I wasn't doing anything wrong; the root CA cert is SHA1 signed which seems to be my issue. I'm setting up everything with lets encrypt going forward and won't be buying a cert again unless i genuinely have a reason to.

view more: next ›