• 3 Posts
  • 396 Comments
Joined 2 years ago
cake
Cake day: February 14th, 2025

help-circle





  • I’ve never used tailscale but use wireguard extensively.

    There’s not much of a learning curve for you as the administrator. You have to discard some misconceptions you might bring from other VPNs but really after 30 minutes of looking at configs you’ll get it.

    I use wireguard for my small team of 5 people to access self hosted services. You install wireguard, load the config, and then it just works.

    The trick, if it can be called that, is using public dns for private services.

    On your server, suppose you have service-a service-b and service-c in containers with ip addresses in the 10.0.2.0/24 range. Then you’d have a reverse proxy like traefik at 10.0.2.1. You’d also create a wireguard container with an IP in that same 10.0.2.0/24 range, and configure it’s wireguard adapter to be 10.0.12.1 or soomething so you have “2” for the containers and “12” for the wireguard clients.

    Then in wireguard configurations you direct all traffic for 10.0.2.0/24 through the tunnel but everything else just uses their devices normal internet connection.

    Finally create a public dns record pointing to the reverse proxy like *.mydomain.com > 10.0.12.1

    now whatever.mydomain.com will resolve to your reverse proxy but is still only available to devices connected to the wireguard container on your server.








  • But its always the dumbest fear.

    Its not like “im worried about some idiot POTUS destroying my livelihood through his own ego and a misunderstanding of economic policy” or “im not going to be able to afford health care when i inevitably get sick”.

    Its always “if you let gay people get married then people will marry their pets and that would be an atrocity because reasons”.




  • services:
      qbittorrent:
        image: lscr.io/linuxserver/qbittorrent
        container_name: qbittorrent
        environment:
          - PUID=888
          - PGID=888
          - TZ=Australia/Perth
          - WEBUI_PORT=8080
        volumes:
          - ./config:/config
          - /srv/downloads:/downloads
        restart: unless-stopped
        network_mode: "container:wg_out"
    

    this is my compose.yml for a qbittorrent instance.

    the part you’re interested in is the final line. There’s another container with the wireguard instance called “wg_out”. This network mode attaches this qbittorrent container to that wireguard container’s network stack.


  • I’d seen gluetun mentioned but didn’t know what it was for until a moment ago.

    I’ve heard of tailscale and at least know what that does but never used it.

    I personally have a mullvad subscription. I have a container connected to that with wireguard, and then for services I want to use that VPN I just configure them to use the network stack from that container.

    I’m not suggesting that my way is the best but it’s worked well for several years now.


  • You’re right, but I think this falls into the “don’t obey in advance” rule of resistance to autocracy.

    I’ve long since lost the will to support this type of action, like yourself I suppose. Everything is fucked all the way down. You can’t not-lose in a corrupt court system.

    However, I think it’s important that every authoritarian action is challenged, because if you don’t challenge then you really are kind of obeying in advance.


  • Sorry I’m still not really sure what you’re asking for.

    I use Open Web UI, which is the worst name ever, but it’s a web ui for interacting with chat format gen AI models.

    You can install that locally and point it at any of the models hosted remotely by an inference provider.

    So you host the UI but someone else is doing the GPU intensive “inference”.

    There seems to be some models for t his task available on huggingface like this one:

    https://huggingface.co/fakespot-ai/roberta-base-ai-text-detection-v1

    The difficulty may be finding a model which is hosted by an inference provider. Most of the models available on huggingface are just the binary model which you can download and run locally. The popular ones are hosted by inference providers so you can just point a query at their API and get a response.

    As an aside, it’s possible or likely that you know more about how Gen AI works than I do, but I think this type of “probability table for the next token” is from the earlier generations. Or, this type of probability inference might be a foundational concept, but there’s a lot more sophistication layered on top now. I genuinely don’t know. I’m super interested in these technologies but there’s a lot to learn.