view the rest of the comments
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
Containers = Yet Another Attack Surface.
So you're offering to manage my ~40 services, and make sure that all the dependencies are met - and none conflict...?
I mean, I enjoy hosting things myself, but I'm not going to invite issues that have been resolved by simple solutions. I've been around the block with dependency hell, fuck all of that. Now if I was getting paid like 6 figures instead of zero, sure boss, whatever the fuck you say boss, job security all day long. But unless you're offering, I'm sticking with the easy way.
I mean, that’s true regardless of how it is running. If the service is externally available, it will be probed for vulnerabilities. At least with a container, you can ward off what files it has access to, so an attacker can’t just ransomware your entire NAS with a single vulnerable service.
And thaaaat's why it's head/tailscale or nothing for me. I'm smart enough to know I don't know enough to be absolutely confident I won't get SHODAN'd and end up crying over a home network catastrophe, never feeling truly secure ever again.
Every now and then it's tempting to get those fun features in containers like Nextcloud, like public links and federation, but it's not worth the risk IMHO. Not when there's state-class adversarial bots written by stupidly smart people roaming the landscape. <_<
Eh, containers are fine if you know what you’re doing. Just run them in a VM if you want more isolation.
Definitely not for the average user though.