[–] 1 point 5 minutes ago*

Washer/dryer getting their signal to start from an outside source according to electricity price (with a dynamic plan) or weather (with your own solar) actually makes sense. I really don't care when it does my laundry as long as it's done between me leaving the house in the morning and coming back in the evening.

The main point is that even smart appliances barely ever need their own connection to the internet. Getting (meaningful) communication from inside your home network (including from the one device that acts as your access point from the outside that has a connection) is absolutely enough.

  • source
  • parent
  • context
  • [–] 1 point 9 hours ago

    He actually fulfilled all expectations of his donors as well as all people with at least two working brain cells. Sadly the latter group does not include the majority of voters who just parrot any shit right media is pouring into their empty heads.

  • source
  • parent
  • context
  • [–] 1 point 9 hours ago* (1 child)

    Against the Israel support specifically? No, because there are constant protests against that moron and his government already. Also his party is losing support so hard that they recently got kicked out of a parliament on a state election. The very first time this happened ever.

    But Merz and his cronies being totally corrupt idiots only working on behalf of his rich donors simply doesn't give a fuck and reacts to any public rejection of his policies with "we need to stay on course and implement our planned reforms more radically even!" ("reforms" that aren't any but just gutting social support and implementing higher taxes on low incomes so he can do some more tax cuts for the ultra-rich).

  • source
  • parent
  • context
  • [–] 2 points 9 hours ago

    OP seems to use the systemd hooks anyway. And with them all disks get decrypted with the first given password (or at least try and only ask for additional passwords if that fails). So it's not neccessary anymore to have everything on the root partition. Several encrypted with the same password will do. (For example I unlock a classic swap partition and 3 differently sized disks creating one btrfs raid1 for root with one password.)

  • source
  • parent
  • context
  • [–] 3 points 9 hours ago*

    I asked the same as resume= should still work in general, but strictly speaking it's not neccesarry anymore. Modern UEFI systems work without it by saving the information where to locate the saved state in an HibernateLocation EFI variable.

  • source
  • parent
  • context
  • [–] 2 points 9 hours ago (1 child)

    Die Werke werden geschlossen, weil der Verkauf der dort produzierten Produkte eingebrochen ist. Und das kann natürlich nicht daran liegen, dass Leute nicht von einem Nazi-Unterstützer kaufen wollen (das würde ja Selbstreflexion erfordern...), sondern liegt daran, dass die Nachfrage schlicht gesunken ist. Rein zufällig natürlich nur für die von Müller angebotene Verpackungsform im Glas. 🤣

  • source
  • parent
  • context
  • [–] 1 point 9 hours ago

    I know that I could easily change my config. My point is that a) they are failing to advertise this and b) I don't see any reason to do it. I understand the arguments about security benefits of shorter certificates on their side and iirc they are already planning to change it from 3 months to 1.5 months in the future. But in what scenario do I benefit from a short-term certificate as long as the regular ones are still available anyway?

  • source
  • parent
  • context
  • [–] 3 points 22 hours ago

    Wenn man russischen Einfluss und weniger Absicherung und mehr Elend in der Bevölkerung, damit das faule Pack freiwillig für weniger Geld mehr arbeitet, als DAS Zukunftsmodell ansieht, das umgesetzt werden soll, ist deren Denken doch sehr modern. Okay, ziemlich geisteskrank, aber immerhin zukunftsorientiert, auch wenn diese Zukunft scheiße ist.

  • source
  • parent
  • context
  •  

    As this will -thanks to me being quite clueless- be a very open question I will start with the setup:

    One nginx server on an old Raspi getting ports 80 and 443 routed from the access point and serving several pages as well as some reverse proxies for other sevices.

    So a (very simplified) nginx server-block that looks like this:

    # serve stuff internally (without a hostname) via http
    server {
    	listen 80 default_server;
    	http2 on;
    	server_name _; 
    	location / {
    		proxy_pass http://localhost:5555/;
                    \# that's where all actual stuff is located
    	}
    }
    # reroute http traffic with hostname to https
    server {
    	listen 80;
    	http2 on;
    	server_name server_a.bla;
    	location / {
    		return 301 https://$host$request_uri;
    	}
    }
    server {
    	listen 443 ssl default_server;
    	http2 on;
    	server_name server_a.bla;
       	ssl_certificate     A_fullchain.pem;
        	ssl_certificate_key A_privkey.pem;
    	location / {
    		proxy_pass http://localhost:5555/;
    	}
    }
    #actual content here...
    server {
    	listen 5555;
    	http2 on;
        	root /srv/http;
    	location / {
            	index index.html;
       	} 
        	location = /page1 {
    		return 301 page1.html;
    	}
        	location = /page2 {
    		return 301 page2.html;
    	}
            #reverse proxy for an example webdav server 
    	location /dav/ {
    		proxy_pass        http://localhost:6666/;
    	}
    }
    

    Which works well.

    And intuitively it looked like putting Anubis into the chain should be simple. Just point the proxy_pass (and the required headers) in the "port 443"-section to Anubis and set it to pass along to localhost:5555 again.

    Which really worked just as expected... but only for server_a.bla, server_a.bla/page1 or server_a.bla/page2.

    server_a.bla/dav just hangs and hangs, to then time out, seemingly trying to open server_a.bla:6666/dav.

    So long story short...

    How does proxy_pass actually work that the first setup works, yet the second breaks? How does a call for localhost:6666 (already behind earlier proxy passes in both cases) somehow end up querying the hostname instead?

    And what do I need to configure -or what information/header do I need to pass on- to keep the internal communication intact?

    view more: next ›