Blaster M
The Post Ninja
- 0 Posts
- 17 Comments
copyparty
Blaster M@lemmy.worldto
Selfhosted@lemmy.world•Router suggestions for a complete noobEnglish
7·1 year agoLet me go out on a limb and rec a cheap mini computer with 2 mini gigabit (or more) ethernets, and either pfsense or opnsense. Those two run on anything that has an x86_64 cpu and easily update. Not any harder to learn to setup than mikrotik, and has lots more capability.
0/10 worst movie ever, no City Escape
Blaster M@lemmy.worldto
Selfhosted@lemmy.world•How to use a domain I own to self-host services?English
2·1 year agoWhen you put your server’s tailscale IP in the dns, anything that looks up that dns gets the tailscale IP. You only need to connect the devices you want to have connect to the server to the same tailscale network, and your system will handle the routing.
Blaster M@lemmy.worldto
Selfhosted@lemmy.world•How to use a domain I own to self-host services?English
3·1 year agoOn your DNS provider, make an A record with your IP address, AAAA record with your IPv6 address. If these addresses change often, either setup a dyndns (your DNS provider needs to support this) or pay for a Static IP from your ISP. Firewall the hell out of your network, have a default deny (drop) new inbound rule, and only open ports for your service. Use an nginx reverse proxy if possible to keep direct connections out of your service, and use containers (docker?) for your service(s). Don’t forget to setup certbot and fail2ban. You need certbot to auto update your certs, and you need fail2ban to keep the automated login hacker bots from getting in.
That’s the minimum. You can do more with ip region blocking and such, as well as more advanced firewalling and isolation. Also possible to use Tailscale and point the DNS A record to the Tailscale IP, which will eliminate exposing your public IP to the internet.
Blaster M@lemmy.worldto
Selfhosted@lemmy.world•Cloudreve -Self-hosted file management system with muilt-cloud supportEnglish
13·1 year agolatest release on 10/2023?
Ah yes, Line of Sight Name, The Pretender’s mo
Every system I can run headscale on I need to do it via an nginx reverse proxy
I have yet to get headscale to work with my system. No turnkey setup, instructions that lack clarity, and in the end… idk how it’s supposed to do the thing.
Blaster M@lemmy.worldto
Selfhosted@lemmy.world•Thoughts and feelings on AOOSTAR WTR PRO AMD Ryzen 7 5825u hardware?English
4·2 years agoIt does, as DDR5 comes with rudimentary ECC protection builtin.
Blaster M@lemmy.worldto
Selfhosted@lemmy.world•Thoughts and feelings on AOOSTAR WTR PRO AMD Ryzen 7 5825u hardware?English
4·2 years agoMy problem is this is an AM4 system using DDR4 memory… already outdated.
Blaster M@lemmy.worldto
Selfhosted@lemmy.world•Does setting/reserving a static IP via router prevent its allocation to other devices in its network?English
3·2 years agoDHCP, when set up properly, makes for less work. Reservations will have the DHCP server hand out the same IP to the same hardware (MAC address) when it asks. If you have a device that is from the dinosaur age that doesn’t play nice with DHCP, then make sure you give it an address that is outside the DHCP range on the same subnet. ex: Some home routers use 192.168.1.100 to 192.168.1.200 as the dhcp range. Setting anything from 192.168.1.1 (or 2 if the router is on 1) to 192.168.1.99 is fine, as is 192.168.1.201-192.168.1.254 (or 253 if the router is on 254). However, by setting static ips, you have to remember those ips specifically to interconnect devices on the lan, whereas reserving via dhcp allows you to use local dns resolution to connect to devices via their hostname instead. In additon, you run the risk of ip conflicts from forgetting which device has what ip in an increasingly complex system, and if you change internet providers or routers, you have a lot of extra work to do to fix the network settings to get those static ips to connect.
Alternately, just use the link-local ipv6 address to interconnect on the lan. That doesn’t change on most devices, as it is based on the MAC address, and is always reachable on the lan.
Blaster M@lemmy.worldto
Boston, MA@lemmy.world•MCAS: The debate over Question 2, an effort to drop the high school 'exit exam'English
1·2 years agoI know this is about school tests, but I see MCAS and think of something else
IPv6 does not do NAT - you allow the ports for a device instead in the firewall.
Little do they know, the scriptures have prophesied their downfall…


The game is still actively developed, with the primary focus on bug-fixing. The price is one-time, and there is no intent to sell another expansion, as the game is pretty much at its technical limits as to what you can add to the game with the current expansion.
Also it has a ridiculously good mod repo and management system built into the game.