dragnucs

joined 3 years ago
[–] [email protected] 2 points 2 days ago

The only two important columns are "Local address: port" and "process". The later is what process is listening whille the former is the interface that process is listening on and the port.

So you see that I don't have any process listening on any port other than 80 and 443 iin the host and the regular ones.

That said, you containers will still listen on the ports you want but only on a virtual network interface.

Basically you only need to publish ports 80 amd 443 on the container or pod you have your reverse proxy on. Other containers need to only be attached to the same network as you already did.

[–] [email protected] 1 points 2 days ago

Yes this is very important.

[–] [email protected] 10 points 4 days ago (3 children)

For spending, calculate your daily spend limit (monthly income divided by 31) and try not to spend anything more than that any given day. If you need to spend more then you have to save that money from thee day before. Do not lend money from future days. Only accumulate from money not spent in the past. For example your monthly income 3100, then your daily spend limit is 100. You cannot spend 150 and hope that tomorrow you will only spend 50. Do it I. Reverse. Today spend 50. If you manage it, tomorrow spend 100. Only if necessary that you can spend 100 + the 50 you saved the day before.

Also try getting rid of the pets. I can't believe you pay insurance for the pet. We do have people that have no insurance even for themselves. I know you love them, but it times are hard. Maybe be give them to someone you know so you can get them back once you are doing better.

You haven't spoken much about food but you have cook your own food and snacks. Do not eat out. Do not but snacks. Your health and pocket will thank you. You can have snacks for really cheap. Just find inspiration in the internet or your relatives.

[–] [email protected] 3 points 1 week ago (2 children)

It is good you have solved you initial issue. However, as you say, your rules are too permissive. You should not publish ports from containers to the host. Your container ports should only be accessible over reverse-proxy network. Said otherwise :3000 should not resolve to anything.

This can be simply acheive by not publishing any port on your service containers.

Here is an example of my VPS:

Exposed ports:

$ ss -ntlp
State                Recv-Q               Send-Q                             Local Address:Port                             Peer Address:Port              Process                                                  
LISTEN               0                    128                                      0.0.0.0:22                                    0.0.0.0:*                  users:(("sshd",pid=4084094,fd=3))                       
LISTEN               0                    4096                                     0.0.0.0:443                                   0.0.0.0:*                  users:(("conmon",pid=3436659,fd=6))                     
LISTEN               0                    4096                                     0.0.0.0:5355                                  0.0.0.0:*                  users:(("systemd-resolve",pid=723,fd=11))               
LISTEN               0                    4096                                     0.0.0.0:80                                    0.0.0.0:*                  users:(("conmon",pid=3436659,fd=5))                     
LISTEN               0                    4096                                  127.0.0.54:53                                    0.0.0.0:*                  users:(("systemd-resolve",pid=723,fd=19))               
LISTEN               0                    4096                               127.0.0.53%lo:53                                    0.0.0.0:*                  users:(("systemd-resolve",pid=723,fd=17))  

Redacted list of containers:

$ podman container ls
CONTAINER ID  IMAGE                                        COMMAND               CREATED        STATUS                 PORTS                                     NAMES
[...]
docker.io/tootsuite/mastodon-streaming:v4.3  node ./streaming      2 months ago   Up 2 months (healthy)                                            social_streaming
docker.io/eqalpha/keydb:alpine               keydb-server /etc...  2 months ago   Up 2 months (healthy)                                            cloud_cache
localhost/podman-pause:4.4.1-1111111111                            2 months ago   Up 2 months            0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp  1111111111-infra
docker.io/library/traefik:3.2                traefik               2 months ago   Up 2 months            0.0.0.0:80->80/tcp, 0.0.0.0:443->443/tcp  traefik
docker.io/library/nginx:1.27-alpine          nginx -g daemon o...  3 weeks ago    Up 3 weeks                                                       cloud_web
docker.io/library/nginx:1.27-alpine          nginx -g daemon o...  3 weeks ago    Up 3 weeks                                                       social_front
[...]
[–] [email protected] 2 points 1 week ago* (last edited 1 week ago)

@noclue I guess the dress is just three hundred fifty five dollars.

[–] [email protected] 1 points 1 week ago* (last edited 1 week ago)

I guess they say $335,000 with a coma si it is just three hunder thirty five dollars while the interest rate is 6.95% with a dot so it is almost a seven?

[–] [email protected] 3 points 2 weeks ago (3 children)

Why should the drives be sneakily deposited. If he trusts his relative or friend he may just tell them to keep it safe until new gets out.

However the bigger challenge would be to read the files using newer technology since those drive connectors might get obsolete. Maybe you need to store technology you can read it with. For example an external disk drive with USB 3 cables and Somme USB C adapters. If using internal drives this gets a bit complicated since you would need also some cables and motherboards. So external hard drives would be easier.

[–] [email protected] 6 points 2 weeks ago* (last edited 2 weeks ago) (1 children)

Maybe you could delete Reddit. But you can self-host your own lemmy instance in addition to you website. It does not hurt to have your own website in addition to social media.

However, you cannot host a lemmy on github pages.

[–] [email protected] 1 points 1 month ago

How can it be both a marathon and a gamble?

[–] [email protected] 1 points 1 month ago

Fixed. Thanks.

[–] [email protected] 13 points 1 month ago* (last edited 1 month ago) (7 children)

You should try Thunder. It is available on Izzysoft. Its is FOSS (AGPL) but I don't know why it is not in official f-droid repository.

[–] [email protected] 5 points 1 month ago (1 children)

Literally a barn owl.

 

In PHP ecosystem there is a tool called Rector. It helps a lot in automated refactoring. It helps a lot in updating from a bad design pattern to another, update code to match a given framework updates, etc.

Maybe we could create a similar tool for client side Javascript to migrate away from jQuery to vanilla Javascript. Websites youmightnotneedjquery.com have a good collections of vanilla JS alternatives to jQuery.

While one could do it manually, on larger code bases, it is extremely tedious.

Maybe such tool exists and I am unaware of it?

At first, I thought about having such transformation as an optimization step in the bundler, but this is unnecessarily redundant and might cause a lot of troubles.

 

I want to setup a camera monitoring for my house and some rooms. I need to bee able to view the cameras remotely and and also do recording if possible. I could find some camera brands like dahua cams but having briefly tested them they. Seem to rely on acwmtralized cloud and proprietary visualization software.

What are you recommendation? This is not a professional setup I would at max have 3 cameras.

 

For all my needs of temporary android devices, I use a temporary VM instead. where I install android-x86. Now I am looking for alternatives to this distro. It is a bit slow to use and now dated. Still on android 9.

Any recommendation that are FLOSS? A guide how to install Lineage OS on QEmu or KVM is also a good alternative.

 
 
 
 
 
 
 
 

I searched for this audiobook on most known siutes, but could not find it. Does any body have a torrent or magnet to get this audiobook?

view more: next ›