posts
Fathom is an all-in-one client for Jellyfin, on Linux, Windows, and Android (with experimental Android TV). It puts movies, shows, music, and Live TV in one window, with most of Jellyfin's server-side management built in, plus optional Seerr requests and a full YouTube client. Everything plays through mpv (via media_kit), so you get direct play, hardware decoding, and real subtitle and audio track control. Free and open source (AGPL-3.0), built by one person. This is my first update post since the v0.11.0 rundown, so here's what's new across v0.11.1 and v0.12.0.
Feedback is very welcome: bug reports and feature requests on GitHub Issues, questions in Discussions.
Downloads
Downloads is now a full offline library instead of a flat list: separate Movies, TV Shows, Recordings, and Music sections, with the same poster covers and rating badges as the regular library.
A downloaded title opens the same detail page as its library page (backdrop, cast, ratings, overview), scoped to what's downloaded: only the episodes you have, with local-only play, mark watched, and remove that never touch the server.
Download a whole series or season in one go, picking a scope, plus a download option on every episode's own menu.
Download music too, a single track or a whole album or artist, and it plays in the music player with the familiar album view, fully offline.
Live TV recordings can be downloaded as well, and can be found in their own Recordings section.
YouTube
Fixed playback being blocked entirely by YouTube's "confirm you're not a bot" gate.
Fixed multi-language videos defaulting to a dubbed audio track instead of the original.
Shuffle and repeat for background audio, plus skip back to the previous track.
Live streams start in a couple of seconds instead of tens of seconds.
Account and updates
Change your own password from the Profile screen (current, new, confirm). Leaving the new password blank removes it, the same option the official Jellyfin clients offer.
Update checks now have a frequency setting: on or off, plus Every Launch, Daily, or Weekly.
A new build is announced with a floating banner and a native system notification on Linux and Android.
Also since v0.11.0
Tapping an episode row opens its page; the thumbnail or play icon plays it directly.
Background audio no longer freezes on an unplayable track, and recovers from brief network drops.
Saved radio stations are no longer left out of settings backups.
Importing YouTube subscriptions on Android no longer greys out cloud-storage files.
Settings and your Jellyfin login now persist on minimal Linux desktops where the system keyring starts cold, such as Hyprland.
In-app updates on Android work again; a build-numbering issue was rejecting newer builds as a downgrade.
A Nix flake for Linux, so you can build and run Fathom with nix build / nix run.
Platforms: Linux and Windows (self-contained downloads) and Android (APK; Android TV experimental). macOS and iOS still need Mac hardware I don't have yet.
Links
Repo: https://github.com/Fathom-Media/fathom
Latest release: https://github.com/Fathom-Media/fathom/releases/latest
Bugs and feature requests: https://github.com/Fathom-Media/fathom/issues
Docs: https://fathom-media.github.io/fathom
AI Disclosure
Per Rule 7 / [AIP] disclosure requirements, AI was used during development as a coding assistant. Level per category:
- Design (architecture, system design): Hint — I make the architectural calls; AI suggests trade-offs and edge cases I might have missed.
- Implementation (production code): Pair — roughly 50/50. AI drafts, I review, adjust, test on real hardware, and only commit what I've verified. Every commit is manually reviewed before it goes to my dev repo.
- Testing (writing tests, test plans, QA): Assisted — real-device testing is manual (I test on my own PC and mobile devices before every release). AI helps draft test plans and think through edge cases.
- Documentation (docs, comments, README, CHANGELOG): Pair — release notes and changelog entries are drafted with AI then edited for tone; comments and code docs are mostly Pair as well.
- Review (code review, PR feedback): Assisted — I'm the reviewer; AI helps with security sweeps, audit passes on complex changes, and consistency checks.
- Deployment (CI/CD, release pipeline): Hint — GitHub Actions and the release pipeline are largely conventional; AI-suggested improvements only.
Hello folks!
I would like to share an update about BentoPDF. It's an open source privacy first PDF toolkit that runs in your browser.
1. You can now actually edit text inside PDFs
BentoPDF now allows you to click existing text, edit it, and have the text reflow while preserving the original fonts and styling.
It also includes:
- Bold, italic, underline, strikethrough, superscript, subscript, font family/size, colours, outlines, character spacing and line spacing
- Left, centre, right and justified alignment
- Bulleted and numbered lists with indentation
- RTL and LTR text alignment
- Find and replace across the document
- Edit images by rotating, flipping, duplicating, resizing or deleting them
- Object alignment, distribution, rotation, flipping, duplication
Please note this is a work in progress. You may encounter bugs, which you can report and I will look into.
2. Hyper Compress
Hyper is an open source PDF compression engine built to solve specific problems.
- Compression sometimes returns a file larger than the original. Hyper's result is always binary: it either produces a smaller PDF or returns the original. This helps create predictable workflows.
- Hyper includes a true lossless mode. It preserves searchable text, document structure and PDF conformance, rather than rebuilding the document from scratch like Ghostscript.
- It runs everywhere: CLI, Node SDK, C API, self hosted service, and WebAssembly build.
Repository and benchmarks: https://github.com/alam00000/bentopdf-hyper-compress
I also compared it to Adobe's compression API, but only managed around 100 PDFs where results were within 5%. Testing on a bigger corpus got expensive.
3. Kura
Kura is a PDF standards, conversion and preflight engine.
It supports:
- All 11 PDF/A conformance levels: PDF/A-1a, PDF/A-1b, PDF/A-2a, PDF/A-2b, PDF/A-2u, PDF/A-3a, PDF/A-3b, PDF/A-3u, PDF/A-4, PDF/A-4e and PDF/A-4f
- Accessibility: PDF/UA-1 and PDF/UA-2
- Print production: PDF/X-1a, PDF/X-3, PDF/X-4, PDF/X-4p, PDF/X-5g, PDF/X-5n and PDF/X-5pg
- Engineering and variable data printing: PDF/E-1 and PDF/VT
- E-invoices: Factur-X, ZUGFeRD, XRechnung and Order-X
- 396 bundled print-preflight profiles
It has been tested against several standards suites, including the veraPDF corpus, Isartor, BFO, Ghent Output Suite 5.0, the PDF/UA Reference Suite and Cal Poly's PDF/VT suite.
Across 30,677 PDF conversions it had zero crashes and zero timeouts, with a 0.05 second median conversion time.
Like Hyper, it ships as a CLI, C library, npm package, Docker image and WebAssembly build.
Repository and benchmarks: https://github.com/alam00000/bentopdf-kura
The release also contains other improvements and bug fixes: https://github.com/alam00000/bentopdf/releases/tag/v2.8.8
Thank you and have a great weekend!
I'm interested to hear what do people use as their cloud backup and the cost of it. I currently use idrive e2 storage at 5$ per TB a month. Trying to see if there is any better deal anywhere and just curious on everyone's thoughts.
This seems like what I wanted on my first rpi over a decade ago.
Install, add ~15000 games from archive.org romsets, maybe a few bios files.
Shit just works.
~1970-2000, done
I was reading a homelab discussion about NUTs (Network UPS Tools) that left me scratching my head and wondering "...why? Is complexity for complexities sake part of homelabs? Isn't this a huge overkill for one machine? Just...use a UPS? "
Then I got to thinking more broadly about homelabbing and I started to wonder if there weren't maybe (at least) two different schools of thought.
Using home media as example -
- Store the original.
- Detect the client.
- Transcode when required.
- Monitor the GPU.
- Add reverse proxy et al
- Track bandwidth.
- Add user accounts
- Add failover.
- Graph the result.
- Dashboard.
Vs
- Store a common compatible file for your devices.
- Play it directly.
Which school of thought are you and why?
PS: not throwing shade. I get it; for some people, complexity, learning infrastructure, practicing skills for work etc is part of the why. For me, complexity as recreation is suspiciously like work after work.
Perhaps there's an odd Venn diagram between homelabbing, interest in ownership / useful capability and infrastructure that could make for a fun discussion. For you, is homelabbing a means to an end or is it an end in itself?
EDIT: Feel free to consider "home-lab" and "self hosted" as synonyms for the purpose of this discussion (although I am aware they are somewhat different in scope).
Hi,
I finally got around to migrate PdfDing from github to Codeberg. Hopefully, I will see some of you over there.
PdfDing is a PDF manager, viewer and editor that you can host yourself. It offers a seamless user experience on multiple devices. It's designed be to be minimal, fast, and easy to set up using Docker.
I'm looking to buy some security cameras for my mother in law. I currently have a small server with plenty of storage at my place that I'd prefer to use on at least a temporary basis to keep costs down. Are there any self hostable cameras that support a built in VPN? I currently use tailscale for my network but I'm open to learning something else. Alternatively, can they run over a tailscale subnet router? I don't use that yet but if I could place a cheap node in her place to help her access footage and my other services via subnet routing I'll do that too.
2.5 years ago, I migrated all my services hosted on a cloud provider to a homeserver.
This homeserver is also my workstation/gaming/dev/everything. I use QubesOS (an operating system based on the Xen hypervisor), and wrote some document about it: https://neowutran.ovh/qubes/articles/homeserver.pdf
Basically, I am hosting:
- DNS
- Matrix
- Jitsi
- Mumble
- Peertube
- Screego
- Nextcloud
- Searxng
- Tor
- Wireguard VPN
- Copy of wikipedia
- Personal website And others.
And for TLS, to have better security, and to avoid relying on third party company/providers, I am using DANE.
https://en.wikipedia.org/wiki/DNS-based_Authentication_of_Named_Entities
https://sr.ht/~yukikoo/dane_without_root/
https://github.com/buffrr/letsdane
The "dane_without_root" is one of my projects and I am welcoming review / feedback on it
( I also posted about it on the QubesOS forum: https://forum.qubes-os.org/t/highlighting-neowutrans-technical-doc-about-qubes )
I created a tool that's easy to set up and gives you fast and beautiful web UI and TUI from a single Go binary.
It can serve both as a cron replacement, or just as a cron supplement - let's say, to version control your cron tasks in a small team. It also has an alert system that allows you to send slack/discord/telegram/email when something bad happens.
I want your feedback. You can help me shape this product into something people will find pleasant to use.
This daemon is copyleft GPL-3.0-or-later - completely free to use.
RunWisp is currently in pre-release phase but is slowly approaching its v1.0 stable release.
Website: https://runwisp.com/
GitHub repo: https://github.com/runwisp/runwisp - feel free to open an issue!
Quick start: https://docs.runwisp.com/getting-started/quick-start/
AI Disclosure
- Design - Hint
- Implementation - Pair
- Testing - Assisted
- Documentation - Pair
- Review - Hint
Pic is how I feel acquiring more software to replace my Big Tech dependency.
(Not all services could be listed here, obviously. Just the ones I personally use)
Traefik v3.7.12 deprecates the previously introduced underscoreHeadersStrategy entrypoint option and introduces a new one called aliasHeadersStrategy that rejects even more potentially spoofed headers - not just with underscores.
Reminder to adjust your Traefik config.
Has anyone here had much success with automated book downloads and a self-hosted library? I've been pulling my hair out trying to get shelfmark and calibre-web automated to work for me.
I'm trying to use them for engineering textbooks which I realise is not the intended use-case, so any more appropriate suggestions would be appreciated. I want something that handles creating a searchable text layer on top on the book so I can search the textbooks more easily.
ShelfMark is having the following issues:
- not connecting to annas-archive.is. I can reach it from my browser
- the sources I want aren't covered by the indexers via prowlarr
CWA is struggling to ingest my engineering textbooks at all. I've just increased the time-out so hopefully that helps.
edit: increasing the CWA timeout setting let it get through the textbooks. shelfmark is my only problem now, assuming adding a text layer with stirling-pdf goes well 🤞
Edit: forgot to mention that I'm based in Europe, which might be relevant for which devices are easily available.
Hi, I am a newbie looking for a new router, one where I can block ads and tracking (with AdGuard, PiHole or something similar), I can choose my own DNS, and hopefully tinker more once I learn more about routers and networks. I have a home server currently running only locally and would like to access it from outside my home, but I'm afraid of letting the door open to bots, hackers, etc.
I am currently using the router provided by my ISP, which has poor customization options and is also failing a lot lately (it loses internet connection at least once a week and needs restarting).
I have searched a bit around and I think something where I can install OpenWRT or other open source firmware would be good. On the OpenWRT forum I have seen recommended the GL·INet Flint 2 GL-MT6000 https://openwrt.org/toh/gl.inet/gl-mt6000. I also looked a bit more on GL·INet's website and saw the GL·INet 3e (GL-BE6500) which has WiFi 7, and wondered if that could be a good upgrade, but seems it doesn't support (yet) installing official OpenWRT.
As for me and my use case: I am comfortable with the Linux command line, my personal computer runs Linux and I have a home server running OpenMediaVault with a couple of services on Docker (Jellyfin, Navidrome, Radicale, Trilium, Calibre-Web, Wanderer), but I barely know anything about routers and networks. The router will serve to connect that server via Ethernet and use several devices (laptops, desktop PC, phones, tablets, AndroidTV...) via WiFi.
I wonder what the thoughts of people who know about routers and networks are.
- Are these good options for a first non-ISP router?
- Is the 3e (GL-BE6500) worth the update for WiFi 7 or is it overkill for my use-case? Maybe even a bad idea if it doesn't support the official OpenWRT?
- Anything else I missed and should take into account?
In addition to the physical router recommendation, I have 2 more questions:
-
from what I have read in other threads I believe I might need to keep my ISP's router, or get another device to use as a modem before the router (I don't know how to do that). Is that correct or can I just replace my ISP's router with a router running OpenWRT (or similar) and be set?
-
does anyone have any good resources to learn more about networks, modems, routers, etc.? for a newbie who is comfortable with the Linux command line but otherwise knows nothing about the topic.
nitter.net is currently replaced with a message about the C&D until zedeus (lead dev) gets legal advice on how to proceed. Other instances are probably ok for now (or at least until an API break). Not a great sign for anyone else who hosts it, but hopefully it gets resolved without development permanently stopping.
If it helps others this was my config. To be honest I have a weak grasp of what it actually does so there might be some security issues with it.
Apparently you can also add lemmy as a search engine. Will work on that later.
config
# docker-compose.yml
name: searxng
services:
core:
container_name: searxng-core
image: docker.io/searxng/searxng:latest
restart: always
network_mode: "service:gluetun"
volumes:
- ./core-config:/etc/searxng
- core-data:/var/cache/searxng
gluetun:
image: qmcgaw/gluetun:v3.41.3
container_name: gluetun
cap_add:
- NET_ADMIN
environment:
- VPN_SERVICE_PROVIDER=custom
- VPN_TYPE=openvpn
- OPENVPN_CUSTOM_CONFIG=/gluetun/custom.conf
ports:
- 8080:8080
restart: always
volumes:
- ./gluetun:/gluetun
devices:
- /dev/net/tun:/dev/net/tun
nginx:
container_name: nginx
image: nginx:latest
ports:
- 80:80
- 443:443
volumes:
- ./nginx:/etc/nginx/conf.d
- ./cert:/etc/nginx/cert
valkey:
container_name: searxng-valkey
image: docker.io/valkey/valkey:9-alpine
command: valkey-server --save 30 1 --loglevel warning
restart: always
volumes:
- valkey-data:/data/
volumes:
core-data:
valkey-data:
# nginx/default.conf
server {
server_name localhost;
listen 443 ssl;
ssl_certificate /etc/nginx/cert/cert.pem;
ssl_certificate_key /etc/nginx/cert/private.key;
location / {
proxy_pass http://gluetun:8080/;
proxy_set_header Host $host;
proxy_set_header Connection $http_connection;
proxy_set_header X-Forwarded-Proto $scheme;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
}
}
server {
server_name localhost;
listen 80;
location / {
return 301 https://$host$request_uri;
}
}
Update your Keycloak
For community, version 26.7.2 has the fix:
https://www.keycloak.org/2026/08/keycloak-2672-released
Good day everyone!
I finally got arround to hosting my own lemmy instance and I decided to make it all about my island. You are free to look (TW: Spanish).
So to help start things up I decided I'd grab an RSS bot and populate a couple communities with local newspapers. This one seems to be very promising as all the others I've found had the typical unmaintained errors and had 2+ years on their belt.
So now that I've had one tool on my belt I wonder what's in everyone's toolbelt. What do you use to manage the instances?
What do others use for ensuring the authenticity of images after downloading them with docker pull?
We’ve setup our CI build process to use docker for consistent, cross-platform builds. To ensure that our builds don’t use a malicious docker image (because the surface area of attack with TLS is enormous if you’re using X.509), we’ve been using DCT (Docker Content Trust).
Unfortunately, I just discovered that the official docker documentation says that DCT is being deprecated. Apparently this was announced last year, and in June this blog post was published with advice:
Cosign is not secure
We spent some time looking into cosign, but we discovered that the private keys aren't actually in the hands of the developer.
Rather, they use this complicated setup using very insecure X.509 to issue temporary certificates.
The result is that the OIDC identity provider (e.g., GitHub) extends the vector of attack significantly -- to probably tens of thousands of people -- that can publish a malicious image that will be accepted by cosign as "trusted"
Notation (Notary v2)
I also looked at Notation (aka “Notary v2”), but there’s no way to bootstrap the software safely, since (perplexingly) their tool for verifying the authenticity of images using cryptographic signatures itself can’t be verified using a cryptographic signature.
Alternatives
Are there any other alternatives that I can use to replace DCT to ensure the authenticity (using cryptography) of the container images that I download -- where the keys are actually held by the developer (thus significantly reducing the "insider threat" risk)?
What do you (or does your org do) to ensure that you’re not using maliciously-modified containers after pulling a new docker image?
Unusual request, so let me be straight about what it is before I ask for anything.
The short version: I pay for MLB.tv, but the league geo-restricts games depending on the IP you watch from. The one setup that unlocks every game (no local blackouts, and none of the "this game is a Netflix/Roku/Peacock exclusive" carve-outs) is MLB.tv International, which needs a UK or EU IP. I've built a small Raspberry Pi that lets my stream appear to originate from a home internet connection over there, and I'm looking for someone willing to plug one into a spare ethernet port and forget it exists.
The honest part: this works around MLB's geo-restrictions, which is against their terms of service. I'm doing it with a fully paid subscription to watch games I've already paid for, but if that's not something you want on your connection, totally fair, no hard feelings, stop reading here. I'd rather you pass than feel misled.
Still with me? Here's everything.
First, the thing you actually care about: it barely touches your connection
It is NOT a 24/7 relay, and it does NOT stream whole games through your line. MLB only checks your location at the moment a stream starts. So my usage is:
- I switch it on only at game time, for a game I'm actually blocked from.
- The stream starts, the check passes, and after under ~5 minutes I switch it back off
- The game then keeps playing over my own connection, not yours.
Net effect on you: a WireGuard handshake and a few minutes of video per game I watch. A few MB, not hours. I use a Home Assistant script to enable/disable the VPN Client in UniFi, so it's guaranteed to shut off after a few minutes. No accidentally leaving it on forever and using your connection
Why a residential UK/EU IP, specifically
I've already done the homework, and residential is the only door left open:
- I already run this through a family member's connection in the US, and it works flawlessly. But a US IP still leaves me blocked from national-broadcast games (the ESPN/Fox/Peacock/Apple/Netflix exclusives), because those are carved out of US MLB.tv at the product level no US IP fixes them. MLB.tv International has no such carve-outs, hence UK/EU.
- Commercial VPNs are blocked. I tried Mullvad, Proton, Nord and others... MLB blocks their IP ranges outright; streams fail to start.
- Datacenter/VPS IPs are blocked too. Hetzner, OVH, etc... same story, flagged as non-residential and refused.
A real residential connection is the only thing MLB treats as a legitimate viewer. That's why I need a person with a spare port, not a server I can rent.
How it works (the technical bit)
- The Pi runs WireGuard, dialing outbound to a small cloud relay I rent (it never listens for inbound, so your router never needs to forward a port to it).
- It also runs Tailscale as an independent, outbound-only management door, so I can maintain it without ever asking you to touch it.
- The OS is a hardened Raspberry Pi: deny-all-inbound firewall, key-only SSH, no passwords over the wire, automatic security updates, and self-healing tunnel watchdogs.
[ my home, Starlink / CGNat ]
│ WireGuard (encrypted, outbound)
▼
[ small VPS I rent ] ◀─ only forwards encrypted frames; sees nothing
│ WireGuard (encrypted)
▼
[ My Pi in your home ] ── dials OUT only, never listens; firewall blocks your LAN entirely
│
▼
[ your home internet ] ──▶ MLB.tv (only ever sees your residential UK/EU IP)
( my paid stream flows back up the same path to my TV — I switch the tunnel
off after the first few minutes, so most of it never crosses your line )
What I'd send, and what you'd do
A Raspberry Pi in a small case. You give it power (~3–5 W, ~£0.50/month of electricity) and one ethernet port. That's the entire job... no router config, no port forwarding, no software on your devices, no accounts.
What it can't do on your network
The firewall denies all inbound, and for forwarded traffic it drops every private-network destination before allowing anything out. In plain terms: traffic from my tunnel physically cannot reach your LAN... not your PCs, NAS, printer, or router admin page. It can only reach the public internet.
Two things make trusting me cheap:
- Put it on a guest/IoT VLAN if you have one. Isolating it costs it nothing and then the guarantee above is enforced by your gear, not my word.
- Unplug it whenever. Nothing on your end depends on it.
Trust but verify
Send me your SSH public key and I'll set you up a read-only account. One command, sudo host-verify, prints the live firewall rules, the tunnel status, and every connection the box currently has open — so you can confirm all of the above any time. That account can't change anything or reach the rest of the box; it's there purely so you don't have to trust me blind. Happy to walk through the whole config with you too.
What's in it for you
Mostly my genuine gratitude willingness to reciprocate in kind: host something for you, help on a homelab project, or whatever feels fair.
If you're in the UK or EU and up for it (or just have questions) reply or DM. Cheers, and thanks for reading either way.
DISCLAIMER: All the code was written by humans until December 2025. Since then, we have started using AI as an assistant, mainly to speed up debugging and for low-value-added tasks (UI and some simple logic). However, all code is reviewed by a human, and the architecture is designed exclusively by humans.
Hi everyone,
We’ve just released Portabase 1.29, with another round of improvements focused on configuration, reliability and reducing the amount of manual setup required.
Repo: https://github.com/Portabase/portabase
Quick recap if you’re new to Portabase
Portabase is an open-source, self-hosted backup and restore platform designed for data retention, disaster recovery and homogeneous database migrations. It uses a central dashboard with lightweight agents deployed close to your databases and workloads.
We currently support 9 database engines (PostgreSQL, MySQL, MariaDB, MongoDB, SQLite, Redis, Valkey, Firebird SQL and Microsoft SQL Server) as well as Docker volume backups.
What’s new
You can now add new databases directly from the dashboard! Until now, databases were only declared through the agent's configuration file (databases.json). Both approaches can be used depending on how you prefer to manage your infrastructure.
Portabase now checks whether backup files are actually still available in the configured storage. If a file has been deleted, moved, or is otherwise unavailable, it is now marked as unavailable instead of being presented as a valid restore candidate.
The new version of the agent (v1.19) adds support for MongoDB SRV connections, making it easier to connect to MongoDB deployments using mongodb+srv://, including managed/cloud MongoDB environments.
What’s next
We’re now working on several areas:
- Deploying a public Portabase demo
- Improving and restructuring the documentation
- Enhancing the agent retry and resilience system
- Additional dashboard UX/UI improvements
- A database-specific options system, allowing advanced parameters to be configured for each supported engine
- Audit logs across the ecosystem for better traceability
As usual, feedback is welcome. If you find bugs, have trouble with the new dashboard-based configuration, or need database-specific options we don’t support yet, feel free to open an issue on GitHub.
Thanks!
Are mini stick PCs practical to set up as a media player, eg with jellyfin? Some advantages are the small form factor that plugs straight into the HDMI port, and flexibility/privacy vs using a dongle from a shitty company like amazon/google/roku.
Are there any things to watch out for to ensure it has enough compute power and hardware decoding? I just want it to play HD video with a jellyfin app/browser page.
I'm assuming it's no big deal to install Linux on (x86 hardware?), do you need to watch out for specific device support? Thanks
I read today about VyOS and I really like the idea and approach but I am not sure how it compares to Opnsense in terms of performance and features. I know it doesn't have a GUI, which is a bit of a bummer for me.
I have purchased a mini router PC and I was thinking to build a dedicated router and firewall on it. I also have another PC that I am planning to run as a Proxmox host and install a couple of VMs and LXC containers, as well as Home Assistant along with Omada, as I am thinking of purchasing some TP-Link AP compatible with Omada.
But would love to hear some feedback from people who used both what they think.
Keep in mind that although I am technical and have a fair understanding of networking and VLANs I am not exactly an expert in networking. Does it make sense to go into the VyOS route in that case?
The end goal is to have a dedicated network and routing for the IoT network, dedicated Wireguard, guest WiFi, etc.
This questions goes to the immich-wise people around here.
I have just some pics from my wife's google phoots that I want to import on our immich account. What's the best way to bring it with the correct metadata? Just save locally onthe desktop than import into immich?
another doubt is how adequately import old scanned photos on immich. I have scanne some thru an self-loader scanner. they are somewhat bent, in the wrong direction and need cropping and other minor adjusts. Would be better to make this on the desktop with some tool and than import to immich OR import everything in the way they are and then edit them inside immich?