I hear the 3rd best is tomorrow, and that fits with my energy levels
I hear that the US has oil and WMDs
You can't hide your public IP. It's public.
I presume your servers sit on your home network, and it's a basic flat network. And you have a basic home router. And you forward a port on your router to your server that's running wireguard.
Sound about right?
You already use a VPN to access your homelab/home-servers.
So the only ports you are forwarding (presumably) relate to wireguard. So the only accessable ports are secured sensibly (by wireguard, cause thats what it is).
So you are already doing everything right.
If you want a fancier router/firewall, then OpnSense or OpenWRT are good options.
But I wouldn't run everything through your server. Let your server serve. And use a router to do network things.
If you really want to hyperconverge onto a single server like that, then I'd do it inside different VMs (probably running on a proxmox host). Have a VM running OpnSense that only does network and routing. Then VMs for other services.
You're directly coupling your home internet access to the proxmox host and the VM, tho.
Which is why I prefer using a more embedded/dedicated router appliance (I'm a huge fan of mikrotik stuff, but my home network is TP-Link Omada. Tho I think I'll move to Unifi)
Servers: one. No need to make the log a distributed system, CT itself is a distributed system.
The uptime target is 99%3 over three months, which allows for nearly 22h of downtime. That’s more than three motherboard failures per month.
CPU and memory: whatever, as long as it’s ECC memory. Four cores and 2 GB will do.
Bandwidth: 2 – 3 Gbps outbound.
Storage:
3 – 5 TB of usable redundant filesystem space on SSD or.
3 – 5 TB of S3-compatible object storage, and 200 GB of cache on SSD.
People: at least two. The Google policy requires two contacts, and generally who wants to carry a pager alone.
Seems beyond you typical homelab self hoster, except for the countries that have 5gbps symmetric home broadband.
If anyone can sneak 2-3gbps outbound pass their employer, I imagine the rest is trivial.
Altho... "At least 2 [people]" isn't the typical self hosting
Edit:
Tried to fix the copy/paste.
Also will add:
https://crt.sh/
Has a list of all certificates issued.
If you are using LE for every subdomain of your homelab (including internal), maybe think about a wildcard cert?
One of those "obscurity isn't security", but why advertise your endpoints? Also increases privacy (IE not advertising porn(dot)example(dot)com)
Upgrading to miniwaves
Related by the virtue of both being TLAs?
(three letter acronyms)
That's fascinating! You should update the Wiki on trebuchets.
https://wikipedia.org/wiki/Trebuchet
Clearly someone has pulled a Scots Language Wiki and has been writing bullshit on that article for years
for kiss in love:
Closed source Nvidia binaries.
Linux is very open source oriented. So the idea of blindly installing a binary rubs a lot of people the wrong way.
I think it also makes it harder to debug issues, and you are completely at the mercy of Nvidia.
So, open source (even partially) is a step in the right direction.
I think AMD has open source drivers
If I could access Reddit ad free via my own 3rd party app with no restrictions based on some monthly or yearly fee, I probably would pay that.
Reddit has issues which the fediverse solves. The fediverse has issues that Reddit solves.
Now that I am here tho, I wouldn't go back
Edit for typos
What does the CI/CD pipeline look like for this?
towerful
0 post score0 comment score
Let me honest with ourselves.... https://isitdns.com/