smiletolerantly

joined 10 months ago
[โ€“] [email protected] 3 points 1 week ago

In that case I can really highly recommend it. Nixos on the server is fantastic anyways, and the only hurdle to recommending simple-nixos-mailserver is that most people are not familiar with nix... ๐Ÿ˜„

[โ€“] [email protected] 13 points 1 week ago* (last edited 1 week ago) (2 children)

It's a bit unconventional maybe, but I vote simple-nixos-mailserver - IF you are curious / willing to learn nix. It's essentially just sanely configured dovecot, postfix, rspamd.

My config for those three combined is about 15 lines, and I have never had an issue with them. Slap on another 5-10 lines for Roundcube as a webmail client.

Since it's Nix, everything is declarative, so should SOMETHING happen to the server, you can be up and running again super quickly, with the exact same setup.

[โ€“] [email protected] 3 points 1 week ago

Yep, that's right. In theory you could share the encrypted DB with the public and not degrade security. (Still don't do that though...)

[โ€“] [email protected] 14 points 1 week ago (1 children)

Fail2ban allows you set different actions for different infringements, as well as multiple ones. So in addition to being put in a "local" jail, the offending IP also gets added to the cloudflare rules (? Is that what its called?) via their API. It's a premade action called "cloudflare-token-multi"

[โ€“] [email protected] 10 points 1 week ago (3 children)

We expose about a dozen services to the open web. Haven't bothered with something like Authentik yet, just strong passwords.

We use a solid OPNSense Firewall config with rather fine-grained permissions to allow/forbid traffic to the respective VMs, between the VMs, between VMs and the NAS, and so on.

We also have a wireguard tunnel to home for all the services that don't need to be available on the internet publicly. That one also allows access to the management interface of the firewall.

In OPNSense, you get quite good logging capabilities, should you suspect someone is trying to gain access, you'll be able to read it from there.

I am also considering setting up Prometheus and Grafana for all our services, which could point out some anomalies, though that would not be the main usecase.

Lastly, I also have a server at a hoster for some stuff that is not practical to host at home. The hoster provided a very rudimentary firewall, so I'm using that to only open necessary ports, and then Fail2Ban to insta-ban IPs for a week on the first offense. Have also set it up so they get banned on Cloudflare's side, so before another malicious request ever reaches me.

Have not had any issues, ever.

[โ€“] [email protected] 9 points 2 weeks ago (8 children)

I am using both and this somehow made it to my phone, wtaf

[โ€“] [email protected] 4 points 2 weeks ago

When I first switched to nix, I made an error copy-pasting my hashed password into a secrets file.

Reninstalled the system 5 times, each time immediately locking myself out, almost

Managing ~35 machines without issues now though.

[โ€“] [email protected] 2 points 2 weeks ago (2 children)

FWIW, Lidarr works the worst out of the arr stack for me too. I don't know if there's just not enough well indexed material in my sources or what, but yeah, not great.

If your entire experience with the arr stack has been Lidarr so far, give it another shot! Sonarr and Radarr work absolutely perfectly. It's just such a nice feeling to open Jellyfin (or I guess Plex) on the TV and go "oh nice new episode is out!"

[โ€“] [email protected] 14 points 4 weeks ago* (last edited 4 weeks ago) (2 children)

I have been scrolling on the front page for a couple of minutes now, and I was going to write that it's literally all conspiracy theories, but that's not true, there's also some "sponsored" posts AKA ads sprinkled in.

What a sad joke.

If you think the fediverse is too centralized, you can always host your own instance. You get all the same "free speech" benefits (plus no free-speech ban on drugs and porn), without having to put one foot into that cesspit of a site.

Edit: oh, and that has to be the worst moderation system ever devised - at least if you are a woman or any kind of minority. Good fucking luck in finding a random jury of users who will ever, ever ban a racist or sexist piece of shit on a platform like this. Come to think of it, that's probably the idea and justification behind the system: being able to loudly proclaim "we have a democratized ban system ensuring moderator overreach is impossible!" does make a great dogwhistle for "you can be a terrible human on here, don't worry"

[โ€“] [email protected] 3 points 1 month ago

I recommend using Usenet for German stuff, all the private trackers I have tried in the past were... seedy.

Yes, you need to pay for access to the Usenet, but it's worth it for German language audio IMO.

Check out scenenzbs.com, no need to pay to search there. Check if everything you need is available, though likely, it will be.

I have not had a failed download yet.

[โ€“] [email protected] 17 points 2 months ago* (last edited 2 months ago)

Matrix does have stickers

[โ€“] [email protected] 8 points 2 months ago (1 children)

As others have said, you can completely disable the stock launcher through ADB commands. At that point, if you hit home, you'll be asked which app to perform that action with. Select your launcher, click "Always", and done.

 

Basically, the title. After years of inactivty, I'll be taking music (cello) lessons again, with my teacher of yesteryear, from whom I've moved half a country away.

She has suggested Zoom but is open to alternatives. I don't particularly like Zoom, plus I have a feeling better quality can be had through a custom solution - but I'm at a bit of a loss as to what exactly would be a good fit for this project.

Maybe Jitsi? Does someone here have experience with it and could tell me if it's possible to set something like a "target" audio quality?

For hardware, I basically have two options. Both are already in use, for different things, and have sufficient processing capabilities - albeit no GPU:

  • host everything at home. Plus: lowest possible latency from me to the server. Not sure how much that is worth though.
  • root server in the Hetzner cloud: much faster network speed. Again though, not sure how beneficial that is, the ultimate bottleneck will always be my upload speed (40Mbit)

OK, I realize that this post is a but of a random assortment of thoughts. I'd be really happy about suggestions and / or hearing about other's experiences with similar use-cases!

28
submitted 8 months ago* (last edited 7 months ago) by [email protected] to c/[email protected]
 

Hi,

not sure where else to post this. For a while now, I've unsuccessfully been trying to get WireGuard to work with Crunchyroll.

Setup is as follows:

  • dedicated server hosts a wg-quick instance in [neighboring country]
  • OPNSense acts as peer on a single IP
  • I have a rule for routing the entire traffic of some source device via that IP

This works just fine. Handshake successful, traffic is routed via the server. traceroute shows the server as the hop immediately after my device's local gateway. The connection is stable, and fast.

...except for Crunchyroll. The site / app itself is fine, but I can not, for the life of me, get a video to play. It just keeps loading forever.

I don't think this is an issue with CR recognizing that I'm not where I say I am - looking online, it seems pretty easy to use CR with a VPN. I've also tried from multiple other devices, all with the same symptom.

If anyone has suggestions, I'd love to hear them ๐Ÿ˜…

EDIT: ~~It was MTU. Had to manually set it to 1500 on both devices.~~

Nope, still the same issues. I was using the fallback interface there briefly.

EDIT: It WAS MTU related, I had to enable MSS clamping on the OPNSense.

view more: next โ€บ