1
 
 

Hello everyone! Mods here 😊

Tell us, what services do you selfhost? Extra points for selfhosted hardware infrastructure.

Feel free to take it as a chance to present yourself to the community!

🦎

2
 
 

i have been following Chinese models for about two years now because they are open-weight and qwen is fun to run on my kubernetes cluster, the news about this Apache licensed model complete with a recipe to make it again with potentially different ingredients is making we want to abandon them for something more ideologically sound and way more interesting

this new model, couldn't universities rebuild it with different contexts and study it in ways you can't reproduce in other models? like, is k2 horizons a good scientific foundation on which to study machine learning?

or am i just lacking way too much context and falling for hype?

3
 
 

I’m excited to share Kingdom Rising — a free strategy game where you build your kingdom, train your army, strengthen your defenses, raid real players, and compete for the top of the leaderboard.

Invite your friends, challenge each other, and see who can build the strongest kingdom. 🏰⚔️

🎮 Play in your browser: https://kingdomrising.sbs/

📱 Also available on the App Store: https://apps.apple.com/us/app/kingdom-rising/id6796983706

I’d really appreciate your support and feedback. Hope you enjoy playing!

4
 
 

I had an old Google Pixel 3a XL sitting around and decided to see if it could handle running as a fully offline, self-contained web server.

I flashed postmarketOS 26.06 (headless Alpine Linux base) to it and set up a portable media node that broadcasts its own Wi-Fi AP, serves static pages, and streams video over a captive portal - no cell data or upstream internet needed.

Quick Hardware/Tech Stack Breakdown:

  • Device: Google Pixel 3a XL (2019)
  • OS: postmarketOS 26.06 (CLI base with OpenRC)
  • Networking/AP: hostapd for the AP, dnsmasq for DHCP & wildcard DNS routing
  • Firewall: nftables redirecting port 80 requests to trigger the captive portal popup automatically
  • Web Server: Lighttpd handling HTTP requests and MP4 video range requests

Performance & Power Draw: Under a test load streaming 720p video to 4 concurrent devices, total CPU usage averaged around 5% (load avg 0.51). Power draw stayed around ~2.4W off the internal battery, with temps holding steady at 54°C.

Why build this? Mainly as an offline entertainment and information node. I run a non-profit foundation providing SCUBA training to young survivors of childhood abuse, and having a tiny, battery-powered web node lets us provide offline information and videos to people while traveling. I will also be able to use it to provide training videos if I am teaching in a location that does not have internet access available.

I wrote up a complete overview covering the setup, and performance metrics if anyone wants to replicate it or build something similar. Over the coming weeks I will be posting configs and some other information to Github with a link from my site.

https://www.muttmutt.us/geeky-stuff/portable-web-server-on-an-android-phone-for-offline-access/

Happy to answer any questions about postmarketOS setup or the networking config!

5
 
 

I know that I can simply make my own private certificate authority that only I and my family trust. But is there some public provider like letsencrypt that is in a free-er part of the world than the US?

6
submitted 18 hours ago* (last edited 14 hours ago) by to c/selfhosted@lemmy.world
 
 

I've been using Planka (https://planka.app/) for years, to manage my to-do lists and other general lists of things (like gifts given, movies I want to watch and so on). But it's been ages since I looked around for other, better apps. I really like the kanban board / trello approach they use as the lists are easy to maintain, add items to, and I can see the whole list in one glance.

I don't need fancy stuff (teams features, sharing, advanced triggers or other automation). It's just for me, running on my home server. Apps should be FOSS and installable via docker, ideally. I've looked at a few of the apps on selfh.st ( https://selfh.st/apps/?search=to-do ) but nothing stood out as really interesting.

Any apps you think of as new and interesting in this area?

Thanks!

EDIT: I've installed Vikunja and I'm giving it a try. So far, it was super easy to install and get started with. We'll see how it looks after a few days, but thanks all for the ideas shared here. 👋🙂

7
 
 

It is so difficult to find modern electronics without telemetry and ads. Smartphones, laptops, TVs, home routers, security cameras, cars, game consoles, e-readers, projectors, 3D printers, fitness trackers, speakers, and even some printers. Why can’t customers be free from this data collection and advertising? It’s not that we don’t care about it. There simply aren’t many alternatives, and the few that do exist are either more expensive or offer fewer features. Seriously, we need a list of products we can buy and use directly without worrying about telemetry or advertising.

The following list is updated at https://lemmy.ml/post/52706206. Please note that this list may contain errors.

8
9
 
 

NoteTrace is a self-hosted alternative to Google Keep, Evernote and Apple Notes: notes, checklists and reminders in a card grid, on your own server. AGPL-3.0, a single Docker container, a web app that works offline, a native Android app, and a Wear OS app. No telemetry, no cloud. This is the first stable release.

Part of the TraceApps family: NutriTrace (nutrition), CookTrace (recipes / pantry / shopping), LiftTrace (strength / lifting).

What it does

  • Notes and checklists. Pins, colors, nested labels, archive, trash, version history, and full-text search that also finds words in voice transcripts and in photos.
  • Reminders and Tasks. Repeating reminders that keep their local time, exact alarms on Android, and one view of everything that's due.
  • Offline everywhere. The installed web app keeps editing with no connection and syncs later; Android and the watch work offline too.
  • Wear OS. Tick off lists, read notes, see what's due, and speak a note ("call the plumber tomorrow at nine" sets the reminder), with a tile and a watch face complication.
  • Voice notes and drawings. Record with the screen off and get a transcript you can tap to jump to.
  • Bring your notes with you. Import from Google Keep, Evernote, Memos, Blinko and Markdown vaults; export everything as Markdown with images.
  • Optional AI. Tidy up, summarise, or turn a note into a checklist, with the provider of your choice. Off unless you set it up.

Links


AI Disclosure

Per Rule 7 / [AIP] disclosure requirements AI was used during development as a coding assistant. Level per category:

  • Design (architecture, system design): Hint: I make the architectural calls; AI suggests trade-offs and edge cases I might have missed.
  • Implementation (production code): Pair: roughly 50/50. AI drafts, I review, adjust, test on real hardware, and only commit what I've verified. Every commit is manually reviewed before it goes to my dev repo.
  • Testing (writing tests, test plans, QA): Assisted: real-device testing is manual (I test on my own PC and mobile devices before every release). AI helps draft test plans and think through edge cases.
  • Documentation (docs, comments, README, CHANGELOG): Pair: release notes and changelog entries are drafted with AI then edited for tone; comments and code docs are mostly Pair as well.
  • Review (code review, PR feedback): Assisted: I'm the reviewer; AI helps with security sweeps, audit passes on complex changes, and consistency checks.
  • Deployment (CI/CD config): Hint: Docker/GitHub Actions/release pipeline is largely conventional; AI-suggested improvements only.
10
11
 
 

I have a server with desktop hardware (microATX motherboard and Core Ultra 7 265K CPU) which I use to run a Minecraft server. Its current physical location isn't ideal, so I'd like to put it in a rack mount chassis and move it to a server room I have access to through my university. However rack space in the room is limited, so it would be best if I can fit it into a 1U space.

From what I've heard the biggest issue with 1U is cooling, especially as the 265K can draw up to 250W. It seems like 1U microATX chassis do exist, like this one, but they don't look like they have good airflow, and I'm not sure where I would get a short enough heatsink. Could I realistically make 1U work, and if so what should I look for in terms of hardware? Or am I going to have to go with 2U?

12
submitted 2 days ago* (last edited 2 days ago) by to c/selfhosted@lemmy.world
 
 

Several of my self hosted services need to be able to send minor occasional emails for things like changing passwords or other notifications.

I've never been interested in the hassle of self-hosting my personal email, since I've heard about it being difficult. But for my little local services to have one admin@ or noreply@ to send from, with just a small handful of friends and family as users, maybe it's simpler than a full personal email replacement would be? I'm not too concerned, for example, if they have to check their spam folders. As long as the email still lands. And probably wouldn't need to worry about incoming emails.

What are you using for this type of thing? Hoping to have something not too complicated, and FOSS.

Edit: I also would like it to come from ____@mydomain.com

13
 
 

Hey everyone!

I have been building and maintaining my own infrastructure around self-hosted Linux services for months. Eventually I got annoyed with editing and deploying everything manually and having difficulties sharing what I'm doing with others. So I solved both of these problems with Infrastructure as Code.

Everyone is free to study this repository. Ever wanted to see IaC in practice? Curious how to self-host certain services, automate website deployment from Git to server, make TLS SNI-based router or automate container provisioning? Then this repository is for you.

Want to know how much CPU, RAM or other resources a certain service has? You can see it yourself on my own public dashboard.

This is the first time I share my infrastructure with anyone. I'd be more than happy to discuss it, receive feedback and answer question. In the meantime, I'm writing an article to complement the code with architecture, decisions and thought behind it.

14
 
 

I work with a mutual aid group that currently handles communications with Signal. This is acceptable from a security and privacy perspective, but severely lacking from a discoverability and reference perspective.

I'm looking for a text chat (it's okay if it also supports voice and or video, but we don't really need that) that is kinda similar to Slack or Discord regarding rooms, but that can be self hosted (obviously). Our general workflow is to allow new volunteers to join our "General chat" and then either be invited or join via open link any of the working groups they fancy. What I'm hoping for is a software that can allow us to have all those working groups in a side bar to increase engagement with some of the more behind the scenes options. I'd also love to have the ability to easily retain posts or bookmarks so we can build up quick references where we actually communicate. I haven't found a clean way to handle the general chat for 2 reasons: 1) we would like to keep it open in such a way that anyone who wants to can join, and 2) there's currently over 800 people and we regularly add more.

All told that makes the bulleted requirements for what I'm hoping for be:

  • text chat software
  • rooms/channels
  • ability to pin posts
  • ability to add arbitrary bookmarks or links
  • ability to have rooms either public or private
  • ability to have at least one room anyone can join without prior approval or invite
  • ability to support at least 1000 users (not necessarily concurrent client connections--that can probably be about 50)
  • ideally the communications can be encrypted

What I don't need but might be nice:

  • voice
  • video
  • file share
  • polling
  • reminders
  • plugins

We value data ownership extremely highly hence looking for self hosting options over Slack or Discord. It's okay if the general chat exists in a separate server so long as the main server with all the other rooms can federate with it somehow.

We do have some people with IT experience, and I am software engineer of over a decade so technical barriers in setting it up shouldn't be an issue, but account creation and use for volunteers needs to be dead simple.

If anyone knows of something like this (or even a FOSS tool we may be able to extend functionally to fit the last 1 or 2 bullet points) I would love to hear your suggestions.

Thanks so much!

15
 
 

So I recently quitted Google Drive and downloaded all my data and hoping to keep it on Hard drives myself, They are external plug in types and I want the files synced like it was on my computer. So when I plug it in it copies/syncs the things on my computer, anyone knows somethign like that?

16
 
 

What setups/softwares do you use to secure your server?

All I do is run the process as user with no login shell.

The topic came to mind after reading this post Is Authelia enough without fail2ban or crowdsec?

17
 
 

I'm posting this in case it'll help anyone else out that may have access to some of the old Datto switches.

I work for a business that previously used Datto extensively (before they were sold to Kaseya) and we had a lot of old Datto hardware because of that. We've since moved on to other hardware solutions for clients but we kinda got stuck with this old hardware and I ended up taking some of the switches we had (an S24 and a E48) - I took them with the expectation that I'll just use them as dumb unmanaged PoE switches. My employer tried to give these away for free through facebook marketplace and other similar sites just to get them out of their hair and would get people asking about them but nobody ultimately took them.

Well I did use them as unmanaged switches for a bit; I blocked internet access for them on my firewall just in case it was reaching out to the cloud, so nothing could potentially be modified suddenly. I recently spent some time looking into the console access on them to see if there's anything there. After a bit of searching I found that if you factory reset them and prevent access to the cloud, they have a default openmesh password ( 0p3nm3$h! ) on the admin account which you can use to gain full access to the CLI and thus some level of management of the switch.

I then examined the running config and discovered they have a local web interface (and ssh and telnet) which is disabled by default and you can enable, you can also create other users on it for management. So, through the console I obviously enabled those to see if they function and to my surprise they indeed do function. So now I have proper 24 and 48 port managed PoE switches at my disposal which made me pretty happy.

Anyway, if anyone happens to stumble upon these switches (at least the S24 and E48 models) and you can use them, know that you can now fully manage them on your own if you so desire. The console connection requires a baud rate of 115200 and then you can just login with username admin and password 0p3nm3$h!. From there you can use the contextual help (?) to figure out the commands. To enable the web interface, after logging in you can do this:

configure  
ip https  
exit  
save  

then you can simply access it in a browser at https://{ip-address-of-switch} using an existing user account. For reference, to create an account you can use a command like this:

configure  
username {USERNAMEHERE} secret {PASSWORDHERE}  
exit  
save  

I did verify that changes made via the web interface do actually work and change the configuration, I half-expected it wouldn't work but was pleasantly surprised it does.

18
 
 
A screenshot of an email from Crowdsec saying they blocked 137k bots last week
19
 
 

Podman is no longer supporting iptables so I am trying to learn how to set up nftables in its place. It's been a struggle to get it to work properly. I can not ping my own server after starting the nftables rules. I am using Alpine Linux v2.24.1 and nftables v1.1.6 (Commodore Bullmoose #7).

nftables has a config file with basic rules which include receiving pings:
/etc/nftables.nft

#!/usr/sbin/nft -f
# vim: set ts=4 sw=4:
# You can find examples in /usr/share/nftables/.

# Clear all prior state
flush ruleset

# Basic IPv4/IPv6 stateful firewall for server/workstation.
table inet filter {
	chain input {
		type filter hook input priority 0; policy drop;

		iifname lo accept \
		comment "Accept any localhost traffic"

		ct state { established, related } accept \
		comment "Accept traffic originated from us"

		ct state invalid drop \
		comment "Drop invalid connections"

		tcp dport 113 reject with icmpx type port-unreachable \
		comment "Reject AUTH to make it fail fast"

		# ICMPv4

		ip protocol icmp icmp type {
			echo-reply,  # type 0
			destination-unreachable,  # type 3
			echo-request,  # type 8
			time-exceeded,  # type 11
			parameter-problem,  # type 12
		} accept \
		comment "Accept ICMP"

		# ICMPv6

		icmpv6 type {
			destination-unreachable,  # type 1
			packet-too-big,  # type 2
			time-exceeded,  # type 3
			parameter-problem,  # type 4
			echo-request,  # type 128
			echo-reply,  # type 129
		} accept \
		comment "Accept basic IPv6 functionality"

		icmpv6 type {
			nd-router-solicit,  # type 133
			nd-router-advert,  # type 134
			nd-neighbor-solicit,  # type 135
			nd-neighbor-advert,  # type 136
		} ip6 hoplimit 255 accept \
		comment "Allow IPv6 SLAAC"

		icmpv6 type {
			mld-listener-query,  # type 130
			mld-listener-report,  # type 131
			mld-listener-reduction,  # type 132
			mld2-listener-report,  # type 143
		} ip6 saddr fe80::/10 accept \
		comment "Allow IPv6 multicast listener discovery on link-local"

		ip6 saddr fe80::/10 udp sport 547 udp dport 546 accept \
		comment "Accept DHCPv6 replies from IPv6 link-local addresses"
	}

	chain forward {
		type filter hook forward priority 0; policy drop;
	}

	chain output {
		type filter hook output priority 0; policy accept;
	}
}

# The state of stateful objects saved on the nftables service stop.
include "/var/lib/nftables/*.nft"

# Rules
include "/etc/nftables.d/*.nft"

I also have a small config file:
/etc/nftables.d/firewall.nft

#!/usr/sbin/nft -f

define WIREGUARD_PORT = 51820
define WIREGUARD_ADDRESS = 10.0.0.0/24
define SSH_PORT = 5025
define SSH_ADDRESSES = { $WIREGUARD_ADDRESS . $SSH_PORT, 192.168.40.204 . $SSH_PORT }
define PUBLIC_PORTS = { 5050 }

table inet filter {
	chain input {
		udp dport $WIREGUARD_PORT accept \
		comment "Accept WireGuard connections"

		ip saddr . tcp dport $SSH_ADDRESSES accept \
		comment "Accept SSH connections from known devices or WireGuard"

		tcp dport $PUBLIC_PORTS accept \
		comment "Accept public connections"
	}
}

After loading the new rules, I get the following output while listing the ruleset:

21:23 server-pi:~ $ doas nft list ruleset
table inet filter {
	chain input {
		type filter hook input priority filter; policy drop;
		iifname "lo" accept comment "Accept any localhost traffic"
		ct state { established, related } accept comment "Accept traffic originated from us"
		ct state invalid drop comment "Drop invalid connections"
		tcp dport 113 reject comment "Reject AUTH to make it fail fast"
		ip protocol icmp icmp type { echo-reply, destination-unreachable, echo-request, time-exceeded, parameter-problem } accept comment "Accept ICMP"
		icmpv6 type { destination-unreachable, packet-too-big, time-exceeded, parameter-problem, echo-request, echo-reply } accept comment "Accept basic IPv6 functionality"
		icmpv6 type { nd-router-solicit, nd-router-advert, nd-neighbor-solicit, nd-neighbor-advert } ip6 hoplimit 255 accept comment "Allow IPv6 SLAAC"
		icmpv6 type { mld-listener-query, mld-listener-report, mld-listener-done, mld2-listener-report } ip6 saddr fe80::/10 accept comment "Allow IPv6 multicast listener discovery on link-local"
		ip6 saddr fe80::/10 udp sport 547 udp dport 546 accept comment "Accept DHCPv6 replies from IPv6 link-local addresses"
		udp dport 51820 accept comment "Accept WireGuard connections"
		ip saddr . tcp dport { 10.0.0.0/24 . 5025, 192.168.40.204 . 5025 } accept comment "Accept SSH connections from known devices or WireGuard"
		tcp dport 5050 accept comment "Accept public connections"
	}

	chain forward {
		type filter hook forward priority filter; policy drop;
	}

	chain output {
		type filter hook output priority filter; policy accept;
	}
}
21:23 server-pi:~ $ doas netstat -tunlp
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name    
tcp        0      0 127.0.0.1:8000          0.0.0.0:*               LISTEN      3515/rootlessport   
tcp        0      0 127.0.0.1:8080          0.0.0.0:*               LISTEN      3584/rootlessport   
tcp        0      0 0.0.0.0:5025            0.0.0.0:*               LISTEN      3743/sshd: /usr/sbi 
tcp6       0      0 :::5025                 :::*                    LISTEN      3743/sshd: /usr/sbi 
tcp6       0      0 :::5050                 :::*                    LISTEN      3515/rootlessport   
udp        0      0 0.0.0.0:51820           0.0.0.0:*                           -                   
udp6       0      0 :::51820                :::*                                -                   
21:23 server-pi:~ $ 

I can connect perfectly fine with SSH, WireGuard and my reverse proxy on port 5050 but if I ping the server I don't get any response at all. Pings worked as normal when I was using iptables so I am not sure what I am doing wrong with nftables. I've tried to keep the rules as simple as possible to figure out what is happening but I have not been able to make any progress. Any help would be appreciated.

20
 
 

I have everything I host and expose behind authelia (which requires 2fa) as middleware or as the only login method with oicd, thus far it seems to work well, of course I get a bunch of malicious traffic and spam but this gets to authelia and stops there, I don't even see multiple tried login tries ever so I felt pretty safe. However it does seem that everyone uses either fail2ban or crowdsec in addition so I have been wondering if it would really add any security in my setup or if I'm missing something. I'm sure it wouldn't hurt but crowdsec always seemed a little too complex for me and I don't want something I don't fully understand in my security layer and I never saw a nice way to setup fail2ban so never bothered. Afaik there's no webui or such things and you have to manually make working regex for everything. I'd like to know if I'm missing something or if anyone has tipps to give

21
 
 

cross-posted from: https://discuss.online/post/45517222

Over the last year I've been customizing my applications like Castopod and Dokuwiki, in order to make them easier to navigate by my users. I'm trying to build a sustainable setup where upgrades don't break things I've manually customized in a text editor and I don't waste hours reapplying changes. I'd rather invest time in doing it right this time.

This is my first time managing a self-hosted wiki long-term, so I want to establish good practices early... before I start telling everyone to join up. I also intend to share my findings with the larger Dokuwiki and Castopod projects, because I can see where I could submit some pull requests eventually.

Thanks for any advice!

22
 
 

Purely a hypothetical for me; I don't have the means for a VPS or that many files. But in the future, if I'd want to use the 3-2-1 rule with a VPS subscription, what sort of software would I need to ensure that my files can't be accessed on the VPS and need off-site decryption keys? What kind of setup would allow you to access said files from a different device if the decryption keys are stored locally on it? People who've done something similar, how has that gone for you?

23
 
 

This is something that seems to happen randomly to my little RaspberryPi 4B homeserver, like once every few months maybe.

What happens is that out of nowhere (meaning I didn't make any change to config or installation) I cannot reach any services I host on it (i.e. Jellyfin, Anchor notes...). I cannot access it via SSH at all, connection keeps timing out.

Ping however gives a signal. I can see/hear its running and doing something, since I hear the external HDD working. It is running headless and I have no monitor and/or keyboard I could connect.

So far my only way out is to just switch its power off, which is obviously not good for the hard drive. It has happened now like half a dozen times over the past few years, so I am wondering what a better way is to handle this. This was on RPI OS and now its happening on DietPi, so seems not related to the OS version.

I tried sending a shutdown signal via SSH but that also just times out, so how do I get it to shutdown properly?

Secondly, what kind of logs could I look at or start collecting to make sense of this?

24
 
 

I've now managed to get the stream of my HiWatch Series, model HWI- T641H-Z 2.8-12 mm by accessing via browser to rtsp://USERNAME:PASSWORD@192.168.30.50:554/Streaming/Channels/101. Working nice. But on its own, very unusful unless I get storage and image detection going. So, I need something like Frigate.

I believe the Frigate docs suggest running in a docker container installed on a VM. Very convienient as I have Proxmox (installed on a optiples 7070 micropc with 32MB ram) running a VM on which i have a few containers. The idea is to mount a "frigate" dataset created on my Truenas server on Proxmox which is then mounted to the VM. Lots of layers but hoping it should be ok.

I heard that the Google Coral TPU is not sold anymore. Is this going to be a problem for Frigate image recognition? Are there alternatives to the Coral TPU?

25
 
 

It was way easier than I thought it would be to get started. I put Sparky Linux on an 18 year old laptop and moved a bunch of movies and shows over to it, got Tailscale squared away, and now I can watch my media ANY WHERE IN THE WORLD. The only problem is storage. Jellyfin doesn't recognize my external drive for some reason and says the path is invalid. Is there a simple solution I'm missing?

Also I'm just stoked I was able to do this. I know I just followed a recipe, but it's a pretty cool feeling having all my music and shows right there, and I don't have to pay some middle man one red can't to access media I already own.

view more: next ›