node815

joined 2 years ago
[–] [email protected] 3 points 23 hours ago (1 children)

Hmmm... Interesting! I didn't realize there was a fork, but then again, this is one of those tools I've had running for several months close to a year or so and never thought about it. The original dev, Corentin, has been working on many more new projects: https://bsky.app/profile/corentin.tech .

[–] [email protected] 1 points 1 day ago (1 children)

I have several services. Home Assistant is not one as it's still a WIP for the person who's developing a solution. It works, but I'm sort of holding off until I can test it more with the mobile app.

https://github.com/christiaangoossens/hass-oidc-auth

But, to answer your question: I log into Tailscale with it. I also have it connected to Proxmox and Portainer Additionally, I have it connected to Pomerium so I can log into my FreshTomato Router with a fingerprint :) I also have a self hosted PasteBin connected to it.

[–] [email protected] 1 points 1 day ago (1 children)

I just tested my version of Firefox (Fresh from Play Store) and it worked without issues on my end to login to the server.

The only browser I'm aware of which doesn't support it is the Duck Duck Go Browser which is a shame. They don't seem to care about enabling WebAuthn support.

[–] [email protected] 10 points 2 days ago (8 children)

Pocket id is my go to. I used to use Authentik, but it was overkill for us. Pocket ID is pretty simple to use and has a very nice interface to add your users and clients. Uncluttered and straight and to the point. Pocket ID doesn't use UN/PW Combos. Instead, you use Passkeys as in webAuthn devices to log in, which IMHO is one of the better security paths.

https://github.com/pocket-id/pocket-id

[–] [email protected] 1 points 2 days ago

I work from home, however my two systems (home and work) are on the same LAN, they don't see each other for file sharing. I get paid via direct deposit like everyone else which means my pay stubs are all electronic. I print those out and then use WinSCP to copy those over to my desktop. No other files are ever sent.

At home, depending on the amount of files, I either use SFTP via Filezilla, or if the mood strikes me and for a single file, I will just use SCP if I'm already on the cli which is most of the time it seems anymore doing work on my personal servers. I've found that SFTP is faster at transferring than doing a copy/paste to the NFS share to the same drive.

[–] [email protected] 2 points 1 week ago

I have AdguardHome on my RPi4 (4GB) model, and it works perfectly fine. I have also hosted Pi-Hole v.5 and even their recent Pi-Hole v6 they just released on it and have even at times run TechnitiumDNS on it. Not all at once of course, but I wanted to let you know you can host any of these on a RPi without issues.

One think you get with the Pi-hole is you can set up a DNS entry where you could for example, set up "laptop" and any time you want to access it or ping it, anywhere on your network, you can simply just enter in http://laptop or ping laptop. With both AdguardHome and Technitium, you need to append the .local or .internal or .home subdomain to make it work. It's not really an issue for me since I just modify my hosts file on my computer to do the same thing, but is sort of cool when you use a system on the network to just go to http://homepage to reach your dashboard like Homarr or Flame on your phone where you can't adjust the hosts file as easily.

TechnitiumDNS is what you want if you are wanting to dive deep into your world of DNS configurations, from there, I was able to set up a redirect to my PXE boot server so when devices would grab their IP from the DHCP server, if they queried for a boot device, it would tell the device where to boot from. I'm pretty sure you can do that with PiHole, but I may be wrong. Additionally, with TechntiumDNS, I was able to set up an adblock for my IoT's VLAN network. without the need to add a second one to the network. As far as I can tell, with the other solutions, this is not as easy to do.

If you are wanting to determine which would be easier to run, I would say AdguardHome for the easiest. Next in line is PiHole v6. and lastly TechnitiumDNS if you really want to dive into the complexities. It is a good business class DNS server. The reason I'm on AdGuardHome right now is for as others stated simplicity. TechnitiumDNS is overkill for my home network, PiHole V6 took forever for them to release, but was a major re-write and if you want to set up your DHCP static mapping like I do, they kneecapped the entry a bit. It's still there, but not as easy to find and more of a thing like (I don't recall the order it goes on) MAC;IP;HOSTNAME or something like that instead of the easier method of just clicking in a row and entering those data points one per field like AdGuardHome, and TechnitiumDNS do. Pihole V5 included.

My Network pretty much has 3 layers of DNS filtering active, The first layer is on my router which has built in adblock (FreshTomato), then AdGuardHome, and finally, browser level blocking. I don't get Youtube Ads on my computers, but on the phones and TV I do. In the browser, I use U-Block Origin which is in the cat and mouse game with Youtube ad-blocking.

[–] [email protected] 7 points 1 week ago (3 children)

Maybe your own adblocker, I thought about doing that myself, I use the public one from adguard on my phone (dns.aguard-dns.com) but having it on your own device would be pretty slick perhaps. But thinking about it more, Google wouldn't just let you use an internal IP for the private DNS. I have tried it with my locally hosted adblocker and it rejects it.

Or you could set up a dashboard like Homepage or Dashy, or Flame or ? Ultimately, your imagination would do! :)

[–] [email protected] 1 points 1 week ago

NFS4 I don't think its obsolete.

I use it for my Desktop computers to connect to the server. All of my systems use Linux so that's my primary use. They backup to the server nightly.

[–] [email protected] 6 points 1 week ago (3 children)

I discovered about a few months ago that XCP-NG does not support NFS shares which was a huge dealbreaker for me. Additionally, my notes from my last test indicated that I could not mount existing drives without erasing them. I'm aware that I could have spun up a TrueNAS or other file sharing server to bypass this, but maybe not if the system won't mount the drives in the first place so it can pass them to the TrueNAS . I also had issues with their xen-orchestra which I will talk about below shortly. They also at the time, used an out of date CentOS build which unless I'm missing something, is no longer supported under that branding.

For the one test I did which was for a KVM setup, was my Home Assistant installation, I have that running in Proxmox and ccomparativelyit did seem to run faster than my Proxmox instance does. But that may be attributed to Home Assistant being the sole KVM on the system and no other services running (Aside from XCP-NG's).

Their Xen-Orchestra for me was a bit frustrating to install as well, and being locked behind a 14 day trial for some of the services was a drawback for me. They are working on the front end gui to negate the need for this I believe, but the last time I tried to get things to work, it didn't let me access it.

[–] [email protected] 1 points 2 weeks ago (1 children)

Along this line what about how it compares to Threema or Session?

[–] [email protected] 5 points 2 weeks ago

Pushed Wireguard back onto my network. I've been a Tailscale user for a couple of years, but never really saw the need for it for me as I'm the only user of the service. :)

I will freely admit though, there's nothing wrong with the service and honestly is great if you are behind a CGNAT router or don't want to use Cloudflare for your tunneling.

[–] [email protected] 1 points 3 weeks ago

You said

I'm only really running a caddy reverse proxy on the VPS which forwards my home server's services through Tailscale. "

It seems then that you are using a Tailscale Funnel to expose your services to the public web. Is this the case? I ask because the basic premise of Tailscale is that you have to be logged into your Tailscale network to access the services and if you are not logged in, then the site you try to access won't even appear to exist. Unless it's setup via the Funnel.

Assuming then that you setup a funnel, then you are now 100% exposed to the WWW. AI Bots and bots in general crawl the WWW daily and eventually your site will be found. You have a few choices here, rely on a Web Application Firewall (WAF) such as Bunkerweb which would replace Caddy, but would provide a decent firewall of sorts. Or..you can use something like Config Server Firewall but I'm not sure if they have AI Bot protection. The last I used them was before AI was a thing.

 

Let me be clear, I'm absolutely NOT promoting this brand, company or otherwise, and I am also not receiving payment or gratis products.

I have been fighting Tuya lights for some time (Costco Feit branded color bulbs). I had picked them up at something like $5/each there in a 4 pack and overall have been happy with them. This started to change about a few months ago, it seemed that they would lose their pairing with Tuya's servers in China and would randomly and usually just when I needed them the most, become unavailable. I had placed all 4 of them in the apartment, 3 in the living room and one in the bedroom. The one where I felt it the most - the bedroom. 5 minutes before I retire for the evening, it's set to turn on the light, and then after 30 minutes, if I haven't already, turns it off. I also have the living room lights programmed to turn on during certain times of the day and off using the Simple Scheduler plugin (I highly recommend it!)

Fast forward to last week, I was sick and tired of the random connectivity issues so I went on the hunt and settled with a pack 6 Matter color bulbs and jumped at the chance. So, I bought them, and they arrived today. I can honestly tell you, that there was absolutely NO problem paring them to Home Assistant and the color control is amazingly accurate! The comfort of knowing that I shouldn't have to worry about losing my light connectivity is priceless now. :) If anyone is curious, this is the brand and so far I can say they are simply amazing!

https://www.amazon.com/dp/B0BLTWFJWY?psc=1

About Tuya and Tuya Local

I'm not totally abandoning Tuya itself, but the goal is to eventually be independent from their devices. Right now, I have a dehumidifier and all of my old lights and a massively long 400 light string light all connected via Tuya. The bulbs, will probably be stored as a "backup" or filed away for use in non-essential areas where connectivity is not as important.

Tuya Local is an amazing and awesome option, which completely lets you control your devices locally and I use that on the dehumidifer. I also had the old bulbs on there as well. The string lights, I tried, but it's a major process of learning what 'DP' Codes correspond to what color you want. I just left those paired to the cloud as Tuya provided the necessary mapping.

You may ask why then, if I had them on Tuya Local, why didn't I just use that to control my lights? The answer lies within the process of obtaining the local key from Tuya. If anyone who has done this knows, Tuya loves to change up their site's navigation and settings and it's seemingly random when they do. I finally got smart though and mapped out the device ID and the super secret and important "Local Key" and recorded those in Joplin. I lived with them like this for a couple of years, but I started to encounter random "crashing" of the lights if you will, where they would go offline and in spite of switching to Tuya Cloud (I have the app on my phone), they would refuse to become available, so I had to factory reset the bulbs to the ever familiar blinking lights process. What I didn't realize at the time, but I later did, when you reset the lights, the local key also resets to a new one. There was a time too, where more recently and was my final decision when within a 72 hour period, I had to reset a light three times.

Matter

It's encouraging to finally be able to use the Matter integration in Home Assistant, it's justifiably flagged as (Beta). Simply put, there is a slight delay from when you trigger the light before it turns on or reacts. This really isn't a big deal for us though. Additionally, I was able to add these to Google Home effortlessly which also makes them Wife Approved. :) The lights do not have a delay there, also, the app they want you to use experiences no delay.

Overall, for my first experience with the Matter devices, I was simply amazed at how easy it was to connect. I discovered that Home Assistant asks you to use the phone app to scan the QR code on the box (The bulb in this case) to obtain the pairing code and it seamlessly integrated it. My phone is a Pixel 8a which has Android 15 on it and before I even got to Home Assistant, it was asking me to scan the QR Code for matter setup.

**Light Quality and impressions

I will say these are pretty bright and not blindly so, but they are plenty bright. :) They have great color to them and the color temperature is awesomely simple. Ours are set to a nice 4000k.

Construction of the bulbs feel to be of decent quality. At least with Amazon, where I bought these, finding locally controlled bulbs was not too easy, and this brand (OREIN) was the only seller which sold Matter devices. If you are looking for a supported Matter light bulb, this may be what you need. :)

 

Instead of a less than useful search engine.

 

I've noticed that when 6.6.1 came out and it came time to reboot after it installed, I couldn't boot into the OS anymore, it simply hangs on a black screen for about 10-15 minutes then reboots after selecting it. I'm currently on the LTS kernel which is 6.1.67-1-lts (64-bit) with no issues. I figured after updating to the latest one 6.6.6. things may be better but no. Each new kernel release, I test it with the same results.

CPU is CPU: quad core Intel Core i7-2600S (-MT MCP-) on Dell Optiplex 990 SFF PC with 16GB Ram in UEFI mode. Via either Grub or Systemd-boot. On one hand, I'm thinking that my computer's time may have finally come up once the LTS moves to 6.6.1 but, until then, and I can procure a newer system, I'd like to see if anyone else has encountered such a thing.

44
submitted 1 year ago* (last edited 1 year ago) by [email protected] to c/[email protected]
 

Someone here brought up that they were able to replace Cloudflare Tunnels with Tailscale - I can't seem to find the post, as it was a comment and deeply buried in a thread I've since forgotten the title of. :)

Can anyone explain the process for doing this? I assume it's through the use of their Funnel? I have three primary services I require to be accessible through Authentik (that's one of them) via my domain name.

EDIT

To answer the question of why I want to leave Cloudflare Tunnels - is basically that I have several services behind it (I forgot one so make that 4 I wish to have exposed). Two password managers, Psono for my special needs daughter which finds it easier than Bitwarden and Vaultwarden for myself and my work logins. So, I can't just set up a VPN or Tailscale at work to connect my work passwords to. :) I also have Authentik and Home Assistant tunneled at present. That doesn't explain the reason why though so let me start here:

My step-daughter is learning video production and editing, we don't want to share her videos on Youtube or other sites, but would like to keep it more local to home. With that said, Cloudflare may not notice it at first, bit it's against their TOS to stream videos, not to mention their just over 100mb cap for file xfers which leads me to the next reason. Early in May of this year, we were in an auto accident, and we are frequently sending forms, accident photos and paperwork etc to the Attorneys, I want to have control of the ownership of the files and would prefer not to email them, but link them to my server, frequently, those files even zipped can be over 100mb.

I do have a private DDNS provider I have my domain CNAME pointed to so it resolves to the home IP that way, so the ultimate plan is to untie my site from Cloudflare's DNS to a offload to a VPS or two for (NS1 and NS2) With a recent issue with Oracle Cloud, I'm not motivated to use them for this basic purpose.

And just a small part of me is starting to get tin hat against the idea that Cloudflare can decrypt the data before it hits my site before it encrypts it. Just just isn't sitting well with me at the moment. I can't verify this data yet, but I like to play it safe than sorry.

EDIT 2

So, I ran a funnel test and yes it works, but still have to use the ts.net like others said, so at best, I can figure this to be a good backup service. I can't forward a CNAME to my TS DNS. I checked /r/tailscale (Duckduckgo sent me there), and about a month ago, someone asked if you could use your own domain, the answer was "not yet" but there seems to be some interest.

What I found pretty fascinating is the mobile app does work quite well on Android and is so far so good, I can at least feel better knowing that the phones are on WG full time now through Tailscale. I had issues with the official WG client and another one staying on with our phones full time, so this so far has been a good improvement.

 

Let me preface this with I was reinstalling my Arch system when Linux 6.6.1 killed the computer's boot cycle. (Dell Optiplex 990 i7) system. Anyway, I needed to get this back up and running and since I couldn't even get it to boot, I did a reinstall relying on my backups and on the Linux LTS for now. I am an early adopter with software and wanted to modify my repo to use the KDE-Unstable branch. To my surprise, upon rebooting after running an update, I was looking at the shiny new KDE 6 desktop! I was thinking maybe just a newer point release.

The Good

It looks surprisingly nice! You can certainly tell that a lot of work has been put into this version.
The new Dolphin interface is looking quite awesome! Nate Graham on his site details the changes, but it looks and feels more cohesive and unified across the board.

I had a crash while browsing SDDM screens in their system settings, by canceling it and it killed it, but the reporting system for the failure seemed to be extra fluid and submitted it without much input from my end. Nice Touch!

Interestingly enough

They have done some major work on the system settings and I think this will take some training of muscle learning from KDE Plasma 5. It seems a bit more logical if you will. And the change from single click to double click by default is a huge bonus for me. The KDE version number indicated something around 5.27.11 (If I remember correctly), so it isn't quite 6 , but I expect that to change once the desktop is finalized in Feb 2024.

The Bad

It's feature incomplete, If you need to change your desktop wallpaper, the option to right click in discover on the picture to set it is no longer there.
The sound settings, and other functions listed in Nate's blog just don't exist in the build I tried, but I respect that with it being Alpha.

The Ugly

This will probably apply to Arch only, but if you update it through KDE-UNSTABLE's repo in Arch, there is no way that I could find to fully remove it and reinstall it easily even by using the sudo pacman -Syuu command. So, be forewarned.

Disclaimer

Yes, I know, this is Alpha and not meant for daily use. I never intended for it to be installed through their unstable repo, but lesson learned. :) I'm glad I was able to take a glimpse at it and I now feel confident in knowing that on my 12 yr old machine, it ran nice and fluid and smoothly. It can only get better from there!

For now, I'll for sure stick with deploying it in a VM for further testing. :)

 

Invariably, when I try to install themes, or anything from Plasma's menu's I get the following error, If I'm lucky, I get get a few pages in, other times it's right off the bat like this time. Is this due to an overwhelming of the servers or something else?

 

Prerequisites

  • Costco Feit Color Bulb :)
  • Tuya Local API Key (Online has some good resources to obtain that)
  • Tuya Local plugin via the HACS store.

The Seemingly impossible to find settings

I struggled with this for a good while and believe I came up with the correct settings when adding this in Tuya Local, below are my notes:

Tuya Local Settings for the bulbs:

  • Brightness 3
  • Color Temp 3
  • Brightness Lower Value: 23
  • Brightness Upper Value 255
  • Color Mode 2
  • Color 2
  • Minimum Color Temp in K 2700
  • Maximum Color Temp in K 6500
  • Color Temp Reverse Unchecked
  • Scene 1
  • Music Mode Available Unchecked

Using the above settings, we have near accurate color and control of the bulbs. I'm aware that some firmware may change this as I had one new bulb I put in not match the color settings until I updated it to the most current at the time I took these notes (about 6 months ago). But I think and hope that if you are struggling with getting these to work with Home Assistant, this will help!

 

While using KDE Wayland latest version, Flatpak apps always want to display an alert letting me know that the application is running in the background until I dismiss it. Is there a way to disable this? (Using Arch BTW)

With X11, it works without issue.

 

As I've gotten older, I find myself doing the old ughs and groan while getting off the couch or say things to my kids that my parents told me. I also truly appreciate the coveted chair or spot on the couch which is "Dad's Spot!"

 

Let me preface this with this was a dormant account with no instances set up, and I put it into place maybe 4 or 5 years ago while getting into the Self Hosted space. I don't recall if I had MFA setup, but don't think I did as it was a test space. In fact, I forgot I even had it up until now.

So this weekend, we were out of town and I get this alert from Oracle Cloud saying that my account was locked with a password reset link/ This was set to an email I've had since 2004 and has been sold many many times on the dark web as evidenced by the amount of SPAM I get on it and as my monitoring services confirm. I figured it was a weak ploy at a fishing to get my credentials so I ignored it. Then about 3 or 4 or so minutes later, the account was unlocked with another email to confirm this. (Without my touching anything)

So, last night when I returned home, I went to Oracle ignoring the email links and used my browse's address bar. To no surprise of my own, I can't log in or reset my credentials. Somehow, the attackers were able to exploit their platform to intercept the password reset and change everything to their credentials.

It's no real loss on my end honestly, Oracle had an old canceled debit card number for re-occurring billing if I should have ever used their services anyway. It just bugs me that they allowed it to happen so easily. Having the lack of MFA, I'm sure didn't help the matter, but honestly, what gets me the most - their password reset email and the one saying it was unlocked with no links or contact information to correct the situation if this was incorrect. Further proof on my end that oracle doesn't care about anything other than the money grab.

tl:dr My lack of MFA enabled hackers to attack my formerly dormant and forgotten Oracle account, and locked me out and Oracle doesn't seem to mind.

 

As in no internet, cell phones or computers. Being born in '74, I was lucky enough to know what it meant to go outside, build a fort, play and mess around. Getting the exercise without knowing it. (riding a bike for example, or running to a friend's house). Drinking out of the hose on a hot summer day after running around in the heat. I swear! there's something extra tasty about that!

Then, being sick from school and laying on the couch watching Bob Barker on the Price is Right before the soaps came on. BORING!!! lol

Don't get me wrong, I'd probably be lost without all the technology we have today since it's gotten so ingrained in our lives, but I am thankful that I will probably be one of the older folks which can survive driving a manual car, reading cursive, and operating a soon to be antique store item, VCR with the VCR + capability. :)

 

My weekly airing of Alf was coming on and I was 14 years old at the time. My dad, an ex firefighter and dispatcher had his trusty scanner relaxing in his favorite easy chair and the call came down at 8pm - a massive fire was happening downtown. We all scrambled out of the house excitedly to go "chase" the fire. It was his favorite past time to relive the old days of firefighting and boy this was the fire of all fires for him!

So, we drove downtown to where it was, about 2 blocks away, you could see the flames shooting out of the 5 story brick building and the closer you got to it, the hotter the heat was. We found a place to park and watched the firefighters do their best. By now, the fire was melting the lamp poles across the street and everyone had to move away from the intense heat. Firefighters turned to surrounding buildings and sprayed water on the old post office, library and other historic buildings to keep them cool and wet against the embers. Sometime later during that time, the entire side of the building collapsed in the street blanketing anything below in red hot bricks. Later on that night, the news showed footage and didn't bleep out the "Oh Shit!" comment from the camera man filming it.

More about the fire here: (Sorry, it's a very small entry for them) https://en.wikipedia.org/wiki/Medford_Hotel

Unfortunately, the archive that would have the most information no longer exists, the local news paper closed down earlier this year and took the site with it.

The story goes, they tracked down the source of the fire to a torch accidentally setting the building ablaze. For the years prior to this, it was an old historic Hotel and was being renovated to be converted for low income housing. During this process, they think someone set a hot torch down and wasn't thinking about the safety at the time and that's all it took to light up the old wood and materials inside.

For a while longer after that, the shell of the building stayed in place while they rebuilt the building with brick and matched it to the original look.

view more: next ›