Transparent_knoll

joined 2 months ago

Death road to Canada is always my groups go to for a couch co-op session.

I'd recommend creating a gateway service. You basically have two routes, managed gateways or self hosted using a rented virtual private server (VPS).

Managed

These are services that are managed by companies, that allow the setup of VPN tunnels with a public access point. Some examples are:

There's not too much to say on this approach, it's easy to setup, but depending on the level of ownership you're looking for, it may or may not be the correct route for you.

Self-Hosted via VPS

Reason you want to use a VPS as the gateway, is so that at no point is your home server exposed to the public. Instead, any potentially malicious actions (which is an inevitably when creating public facing services ) are directed at your VPS rather than your actual server.

There are a few different options, some examples are:

Both of these are designed to implement an access point (your VPS) and any number of devices to proxy (your homeserver). They are built upon wireguard, and are feature rich.

Personally, I opted for a more lightweight approach using selfhosted-gateway, which is definitely a bare bones Reverse Proxy over VPN, designed specifically for exposing docker containers on your homeserver. Much like the other options, it's built upon wireguard VPN. Theres no UI (which is why imo it's perfect for a tiny VPS), just a simple MAKE command thats run from your homeserver and generates the required docker compose files, then once spun up creates the link between your VPS and exposes the appropriate docker container.

Its a feature, not a bug.

I use prowlarr to manage my sources, and that container in its entirety is backed up, so if the whole unit were to die simultaneously. I would lose all content, but retain all setup.

The key part for my recovery method is my Arr stack (prowlarr, sonarr, radarr). Loading up sonarr/radarr shows the entire catalogue of content; and highlights/ can search for any that are missing; so once the media drives been replaced its as easy as pressing a button.

If you're just getting started. I'd recommend checking out yams.media. it provides a strong starting stack including arr containers, vpn setup etc... Its a strong foundation for a successful media server. I believe it also has media separated from app data, which makes a setup like this easy to achieve.

Haha, thanks; I'm certain I'm not the only techie fighting big tech in this way, and if I can help other self hosters on the journey, I'm more than happy to.

The real angels are the many unsung heroes that develop these open source projects. Without their dedication to the good fight, people like me wouldn't be able to do what we do.

Thanks, Glad to hear I'm not the only one and there's method to the madness! I did start out with building in redundancy into the media drives, but once space ran out I came to the same conclusion. Nobodies going to cry if the ~27 seasons of law and order need to be redownloaded, so there's no problem with a lack of redundancy.

Glad to hear others are doing the same! I actually started out with authentik, but just could not get emails to play ball. It was no doubt something I was doing wrong though, as I remember finding nobody else with the same issues when trawling support forums, which is why I ultimately jumped to keycloak.

I definitely prefer the customisation in authentik to keycloak. I have to use a git project for compiling my keycloak 'theme', that allows basic UI changes like logos. Safe to say the theme hasn't changed since it was first setup.

Its pretty rudimentary reverse proxy via VPN setup. Just Client - VPS - server, using a separate wireguard connection for each service for a zero trust setup.

I'm using an oldish github project called selfhosted-gateway for setup. It hasn't been updated in some time, but I'm still using it as the overhead on the VPS side is tiny compared to any other solution (like netbird for example) and honestly, it just works.

The setup is pretty simple, a docker container for the wireguard setup Is spun up on both sides creating a wireguard tunnel, with the home server container running nginx, that will expose the relevant container depending on config. The VPS side uses caddy which automatically handles TLS too, so its a quick and easy implementation once you get your head around it.

[–] Transparent_knoll@awful.systems 2 points 1 week ago (2 children)

Using ironwolf pros for the HDD space, they're enterprise grade high storage SATA HDDs that go as high as 32TB these days I believe.

If you use this approach, its important to make note of the workload rate of the drive you're looking at. Anything marked as a NAS drive should be designed for 24/7 operation, whereas standard HDDs will likely crap out far sooner, but connectivity wise, the only important step is to ensure the drive is SATA rather than SAS connection, otherwise you'll end up fiddling with PCI-e adapters which is wasteful IMO.

I've not built any redundancy into the media drives. Opting for maximum space possible instead. I don't consider any of the content to be irreplaceable. Config for the Arr stack (Sonarr, Radar etc..) is held on my RAID NVMes that also has non local backups, so theoretically, when a media drive is lost, any content can be redownloaded onto a replacement drive with little effort.

Looks like a skit from 'that Mitchell and Webb look'

[–] Transparent_knoll@awful.systems 9 points 1 week ago* (last edited 1 week ago) (2 children)

Sure, I'd be more than happy to! It's a home server build that started life as a gaming pc, so it's not a rack setup in any stretch of the imagination. I'm not at home currently so can't give exact specs offhand, but the setup is essentially:

OS: Ubuntu running on 256gb NVMe (not backed up I just replace if/when it fails)

Jellyfin/Navidrome Media: 3 SATA HDDs totalling ~60TB (2 x 15TBs, 1 30TB, no RAID, no backup. I call this my replaceable media, as I can simply redownload if a drive fails)

Config/compose files and 'irreplacable' data stores: 2 x 4TB NVMe (RAID 1, 7 rolling daily backups, 4 rolling weekly to a much more modest machine on the same network. This includes configuration/database etc. for jellyfin)

Entry points are all handled via a single VPS using a wire guard reverse proxy. So I'm using domain based access for all services I'm running. The only one that seems to struggle is Navidrome, which can lose sync. But jellyfin works flawlessly with this setup.

Off the top of my head, I believe the specs are something like:

  • 128GB DDR5 RAM (bought pre AI boom thankfully)
  • AMD Ryzen 7 9800x3d
  • Nvidia rtx 4080
  • 2 x fanxiang 4TB NVMe
  • 1 x Kingston(?) 256GB NVMe
  • 2 X Seagate ironwolf pro 15TB
  • 1 x Seagate ironwolf pro 30TB

The case itself is a fractal meshify 2 XL. I got it due to the lack of RGB way back when, but it fits everything listed quite comfortably, as well as an AIO cooling system for the CPU.

If you're looking for large storage solutions, NAS servers definitely fit the bill, and make setting up RAID a breeze. But you can quite easily find large scale SATA based drives, which fit into most mid to large cases, commercial or personal. My current build is nearly at its limit now (I think there's a single available sata port left... Maybe another M2, can't recall), so going forward I will likely invest in a decent NAS, but I've never felt the need for a rack solution if I'm honest.

Another thing worth mentioning is that the server is not quiet. The ironwolf drives in particular can drum up a fair bit of noise when busy. I've got the server setup in my home office, so it's no issue personally. But it would definitely cause me sleep issues if it were in my bedroom.

 

I'm a techie by trade who matured using proprietary technologies like Windows, but reached my breaking point once ads were introduced at the OS level. Since then I've been on something of a personal vendetta against big tech. It's been about 4 years now, and I thought I'd share my experience.

My first and predominant interest was securing a means of private communication that wasn't centralised. Like many before me, I stumbled upon Matrix. Adoption was problematic; I couldn't help people understand why using WhatsApp, Discord, etc. was a bad idea. But ultimately I managed to convince most of the people in my circle to migrate to my Matrix server by adding IdP (using Keycloak). The login is also tied to various other services, but the carrot that drew most of them in was my Jellyfin instance.

It's running on a home server with ~60TB of hard drive space, and each user also has access to Seerr for requesting content, so it's become quite an extensive library over time. Building the server cost somewhere in the region of 5k to set up (it hosts far more than just Jellyfin), plus a small monthly fee for the VPS I use as a reverse proxy. I offer everything free of charge as a labour of love for the people I care about.

I also provide free tech support to any of my users running any instance of Linux, both hardware and software. Windows users are advised to search their issues online, or allow me to install a dualboot Linux option to help them reach a resolution. I even go as far as offering a free 256GB NVMe for this purpose, provided they've a free M2 slot in their builds.

In my experience, bringing the layperson into the open source world is definitely possible, but it comes at great personal expense. People don't like change, but evidently they hate adverts even more so.

I'm keen to hear about others with similar experiences this far down the rabbit hole. what have you found that works in helping with wider adoption of open source technologies in your communities?

view more: next ›