Comments

This profile is from a federated server and may be incomplete. Browse more on the original instance.

Dempf, to piracy in Random requests to my private Jellyfin instance

VPN drains my phone battery like crazy, plus eventually I’d like to be able to share my services with some less technical people, and want to keep the barrier to entry low for them, so I’ve been looking at what I’d want in order to be comfortable exposing services publicly.

Services are running on Truenas Scale (k3s).

What I’ve been thinking is:

  1. Isolate services’ network access to each other and to my local network.
  2. Reverse proxy in front of all services (probably Caddy)
  3. Coraza as a WAF
  4. Crowdsec Caddy module
  5. Some sort of auth layer in the proxy, like oauth2-proxy (kind of tricky because not every service would work well with this, especially without client support). Probably would start with a 3rd party identity provider rather than rolling my own, especially since 3rd party will probably do a lot more monitoring around logins, patterns, etc.

Thinking of hosting the reverse proxy piece on a VPS. Probably not completely necessary because I don’t think hiding my home IP really buys me much security, but Caddy might be easier to configure on the VPS compared to Truenas (though I guess I could run it in a VM on Truenas).

Each app could run a wireguard sidecar to connect it to the VPS.

Curious what others think about this setup, or if the recommendation is still to keep things behind a VPN.

Dempf, to lemmyshitpost in Task failed successfully

Sure, I have an idea. How about we talk about beans…

https://lemmy.zip/pictrs/image/a392c9f1-27c2-4191-8ad6-d10543d5b19a.webp

Dempf, to piracy in Mangadex and Batoto extensions have been removed due complaints from copyright holders

Wow, I was wondering why those were 404ing, saw the repo was deleted and a new one was just created, and saw this post from 15mins ago:

old.reddit.com/r/…/2024_there_is_the_end/

TLDR: they purging all extensions.

Dempf, to privacy in Pornhub pulls out of Montana, NC as age-verification battle rages on

That was the opinion of the Supreme Court nearly 20 years ago in Ashcroft vs. ACLU, but here we are.

Dempf, to memes in Why? Are we not doing enough?

Large portions of Lemmy feel similar to places like /r/sino on Reddit. Personally I like to look at that stuff from time to time just to keep tabs on that flavor of propaganda, but it’s pretty detached from reality.

Dempf, to memes in Take back the memes!

It’s basically like the beans thing.

Dempf, to piracy in The complete guide to building your personal self hosted server for streaming and ad-blocking powered by Plex, Jellyfin, Adguard Home and Docker.

You could do it, especially if you’re running Truenas Scale since that’s Linux. On Core you could do it inside a VM (I have Jellyfin set up inside an Ubuntu VM with persistent samba mounts to access my media).

On Scale the recommended way would probably be through helm charts, though config might look a bit different than the Docker Compose files here. There are charts for I think all the services mentioned: truecharts.org/charts/description_list

Personally I’m planning on waiting just a little bit longer for Scale to become more stable and then I’m going to migrate, rather than trying to set up all these services in a VM on my Core machine today.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • localhost
  • All magazines
  • Loading…
    Loading the web debug toolbar…
    Attempt #