(me too i did #2 at home…)
- 0 Posts
- 21 Comments
Proxmox is a virtualization solution: let it do its job and run a vm with opnsense.
It is simple both from a virtualization and a networking perspective; your hypervisor is ‘hypervisoring’ and the firewall is firewalling, easier to maintain and debug, no custom thinkering required.
If you are at home go with #1, more fun and lots of discoveries; if you have to pay the bills, go with #2, tested, solid, easier to handoff to your colleagues.
pgo_lemmy@feddit.itto
Selfhosted@lemmy.world•Immich bridge to google photos shared albumsEnglish
44·25 days agoIMHO you should look/ask for such a feature in a google group because big g may have a business case for such a feature: it would pull back in those users who try to escape.
and that should not be an immich feature but a google one.
as a self-hoster I prefer to have control on my data; a solution to feed my data to google through a third party (that may do whatever it wants while performing the transfer) is the exact opposite of what i’m trying to achieve and would have little to no value for me.
pgo_lemmy@feddit.itto
Selfhosted@lemmy.world•How do you protect a remote backup from a compromised account?English
6·1 month agoIf the main site gets compromised the credentials there must be considered lost and known to che attackers.
with a pull backup that’s not an issue because the main site has no access to the remote system; it is a process on the remote site that has credentials to access the main site and not the other way around.
the remote system may
receiveretrieve a compromised copy of the data, but the attacker cannot tamper with previous backups so recovery is still possible.
pgo_lemmy@feddit.itto
Technology@lemmy.world•I Could've Rickrolled the Entire FIFA World Cup. All I Needed Was My ID.English
16·1 month agoFifa Agent Platform -> FAP pun intended?
pgo_lemmy@feddit.itto
Technology@lemmy.world•Euro-Office, Europe's open-source alternative to Microsoft Office and Google Docs, launches June 9English
21·2 months agolast thing missing in your post is a complaint for slow migration on a 1gbit link…
you can complain as much as you want because proxmox is not vmware or you can embrace proxmox and make the effort to move/update/refresh your knowlwdge on to the new environment.
pgo_lemmy@feddit.itto
Selfhosted@lemmy.world•Moving a Proxmoc 256 MB NVMe install to larger NVMeEnglish
1·2 months agoThis is the way. 🤭
The second install should be easier since is done just after a test one.
pgo_lemmy@feddit.itto
Selfhosted@lemmy.world•Moving a Proxmoc 256 MB NVMe install to larger NVMeEnglish
7·2 months agoAdd a second node using the new drive, move all vm to the new node, decommission old node, rebuild the old node with the new drive.
You can get away with a disk clone but in my opinion a vm move is the proper way to go.
Adding a new node you start with a clean install, any quirk you have on the old hw will be finally washed away (or will bite you back and be properly documented), you have a quick way back should anything go sideways (the clone too provides a quick way back, but i like this way much more ^^), you get some hands on multi node experience that will be useful for ha setup.
pgo_lemmy@feddit.itto
Selfhosted@lemmy.world•First VPS — Is 54 SSH bans in 12 hours normal?English
59·3 months agoNormal background noise. ssh is a well known protocol/port and scanning is automated.
my home router is the stock one from my isp and have no vpn capabilities.
I put a port forward on the router and then configured everything on the internal node; in my case it is an opnsense vm running on proxmox.
I wouch for the VPN route… VPN servers are built to be exposed, are hardened/engineered to resist the harshness of the net and are somewhat safe even with default settings.
Should you publish on the wild a few web apps, you would have to harden, monitor and manage a bunch of environments and/or frameworks with a load of quirks each.
A VPN is easier to maintain and safer for your data with a lower effort.
pgo_lemmy@feddit.itto
Technology@lemmy.world•Microsoft alternative: Nextcloud and Ionos develop open-source ‘Euro-Office’English
171·4 months agoThe article is on a ‘pay or ok’ site.
pgo_lemmy@feddit.itto
Technology@lemmy.world•[The Economist] Why software stocks are getting pummelledEnglish
16·6 months agoMaybe there is some relation with orange man erratic behaviour, canadian pm speech in davos, europe considering to abandon usa cloud and other countries that may follow suit?
Just sayin’…
In proxmox you create a vlan on the physical interface and not on a bridge.
Once the physical port has tagged traffic for all vlan but LAN, leave vmbr0 alone, create the new DMZ vlan in proxmox networking and a new vmbr on that vlan, that’s it.
pgo_lemmy@feddit.itto
Selfhosted@lemmy.world•What are the benefits of a server having multiple public IP addresses?English
3·1 year agoIf your vps is a firewall, you could use it as an exit point for different private networks: ip1 to mask the traffic for a guest subnet that you don’t trust and if the ip gets blacklisted there are no issues for lan traffic behind ip2 while ip3 is reserved for server traffic with specific rulesets on supplier’s systems for updates/backup/whatnot. Should you have more than one mail server because of reasons, if one is blacklisted the other could remain clean (in this situation you usually put them on different subnets but whatever).
pgo_lemmy@feddit.itto
Selfhosted@lemmy.world•Spit Balling A Work Around For Blocked Email PortEnglish
2·1 year agoMailu is a mail server so it is suitable for the task.
pgo_lemmy@feddit.itto
Selfhosted@lemmy.world•Spit Balling A Work Around For Blocked Email PortEnglish
4·1 year agoYou need a mail server somewhere, a mail client cannot listen for incoming messages. A possible workaround: you could activate your own mail server accessible only inside tailscale and use it to send and receive your local alerts.
pgo_lemmy@feddit.itto
Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ@lemmy.dbzer0.com•Piracy Shield may reduce illegal sports streaming, traffic analysis suggests.English
1·2 years agoBecause it is bullshit…
They have been forced to release a ‘try2’ after less than a year from the first one because v1 was at capacity: there was no more room to add more blocked ip/domains.
And is today’s news that a google subdomain has been blocked.
In try 1 the workflow was:
- they block
- if you think the block is an error, you must appeal within 5 days
- after 5 days the block is final and there is no way to undo it
You may notice that there is no ‘send a warning to the blocked party’.
As often happens, people with the money want a solution to their problem paid for by someone else: unfortunately for them, in this case the only solution with a minimal chance of success is a ‘lock’ on their systems (managed, maintained and paid for by them).
…or someone in the soccer food chain could reduce their profits and propose an affordable subscription…
Oh! Maybe you’re not from Italy and you miss this key piece of information! All this massively useless system has been proposed and happily provided for free (how nice) to the country by the major italian soccer league to defend their right to upsell the streaming rights. When you read ‘illegal sport streaming’ you should get ‘illegal soccer match streaming’ instead.

For me it depends on the hw on site; if it is properly setup and in an adequate environment i have no issue anywhere.