• 0 Posts
  • 24 Comments
Joined 1 year ago
cake
Cake day: July 1st, 2023

help-circle
  • If you have docker containers and other stuff all on that USB drive I’d really reccomend getting it all off that USB (not just logging) and onto a proper drive of some kind. USB thumb sticks are not reliable long term storage, you will wake up to find the drive failing one day and good chance you lose everything on it with little to no warning.




  • Games need to live closer to the bleeding edge than a lot of other software.

    Also, for wine/proton, and the other customisations built into the deck, it makes sense to pick a starting point that is more built for customisation. By that I mean there was probably less things they needed to add or remove at the start.

    As mentioned, it’s also likely there was personal bias internally. But even that can be a valid reason as they need to be familiar/comfortable with the starting distro.

    Not saying that Debian cannot do it, but doing it this way probably made valve’s employees lives easier.




  • Mine is nice and quick in regards to the web interface and general functions. However I run it on a server at home and my upload speed isn’t the best, so if I need to pull a larger file (Files On Demand enabled) then obviously the transfer speed of the file is a bit sluggish.

    Hosted on a VM with 16GB RAM, 4 cores. Using the NextcloudAIO docker deployment option, all behind an Apache reverse proxy (I have a bunch of other services on another VM that all have reverse proxy access in place as well).


  • SGG@lemmy.worldtoSelfhosted@lemmy.worldvpn on nextcloud?
    link
    fedilink
    English
    arrow-up
    3
    ·
    5 months ago

    In very basic terms, and why you want to do them:

    Attack surface is the ports and services you are exposing to the internet. Keep this as small as possible to reduce the ways your setup can be attacked.

    Network topology is the layout of your home network. Do you have multiple vlans/subnets, firewalls that restrict traffic between internal networks, a DMZ is probably a simple enough approach that is available on some home grade routers. This is so if your server gets breached it minimises the amount of damage that can be done to other devices in the network.



  • The first year price is a “loss leader” discount. Get you in the door, then make a profit from you in future.

    Namecheap have a bit of a reputation (as can be seen here with a few people warning of poor support), Spaceship seems to be a bit of a offshoot/addition they have created, partly as it doesn’t seem to be a 1-1 comparison, and partly maybe to avoid their existing reputation?

    However, it’s not entirely a bad idea to separate your registrar from your DNS provider. If one goes down, you still have access to the other to make changes. I used namecheap in the past because it was cheap, and cloudflare for DNS. If you are using both for only your registrar, it probably won’t matter much at all as you are probably not changing nameservers often, if at all, once set.


  • If you are going to use your desktop, I would suggest putting all of the self-hosted services into a VM.

    This means if you decide you do want to move it over to dedicated hardware later on, you just migrate the VM to the new host.

    This is how I started out before I had a dedicated server box (refurb office PC repurposed to a hypervisor).

    Then host whatever/however you want to on the VM.


  • A sane firewall configuration should have no/minimal impact on a desktop focused OS.

    On the other hand, sometimes programs are really badly made and expect stupid things like there being no firewall.

    You should have one yes, but to each their own.

    I manage a bunch of windows computers and regularly make adding firewall rules part of install scripts, good example: Dreamweaver.




  • SGG@lemmy.worldtoOpen Source@lemmy.mlFOSS-alt to Authy?
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    10 months ago

    Losing things is one of the risks of any setup. With paid for services you are putting trust that the provider has put in place methods to prevent downtime/data loss. Self-hosting means the onus is on you. Make sure you document things, make sure you have some kind of backup in place, and update things regularly (but maybe not straight away, just in case).

    Also expect to occasionally run into weird issues that you need to figure out a fix for. I am 99% sure it was for my NextCloud-AIO setup a year or so ago, but there was an update to it that broke the setup if you had created the containers previousy at a certian time. You needed to run a particular command inside one of the containers to fix it up.

    There was also the time where I migrated things off a physical server to a VM, but missed the script that was doing my certbot DNS challenge renewal. I had not documented things back then and a few months later all my services stopped working, that took a bit to re-do.

    I do make sure to keep backups of my VM’s, and for the VPS I run I pay a bit extra for vultr to keep backups/snapshots there. Along with actual documentation of how I did the setup, I’ve got things stable for the most part.

    Here’s my Heimdall homepage to give an example of different services I run, as well as some links to other websites. Blanked out a few things for privacy and eyepatch reasons (not sure if that’s allowed here).


  • SGG@lemmy.worldtoOpen Source@lemmy.mlFOSS-alt to Authy?
    link
    fedilink
    English
    arrow-up
    14
    arrow-down
    1
    ·
    10 months ago

    I use vaultwarden (open source implementation of bitwarden server). Yes it’s a seperate service to manage, but it’s a dedicated password/secrets manager that can do otp codes.

    I’ve been running the docker container for a few years now and it’s been rock solid.