SirMaple_

joined 10 months ago
[–] [email protected] 4 points 6 months ago

One of the main reasons I run my own instances (Mastodon and Lemmy). Keep the garbage blocked and out of sight.

[–] [email protected] 2 points 6 months ago* (last edited 6 months ago)

Devices at home are named after Autobots and remote devices are named after Deceptions.

[–] [email protected] 12 points 6 months ago (4 children)
  • crowdsec
  • SSH - change port, disable root login, disable password login, setup SSH keys using SK(YubiKey in my case)
  • nftables - I use https://github.com/etkaar/nftm to keep things quick and simple. I like the fact if will convert DNS entries to IPs. I then just use dynamic DNS update clients on all my endpoints
  • WireGuard for access to services other than SSH(in some cases port 443 will be open if its a web server or proxy)
  • rsyslog to forward auth logs to my central syslog server
[–] [email protected] 6 points 7 months ago
[–] [email protected] 13 points 7 months ago

Hard pass. Which ever vendor keeps making dumb appliances gets my money. I can live with basic "smart" appliances as well. The ones that connect to WiFi simply to tell when say the wash cycle is done by sending a message to your mobile. But I don't need no flipping AI crap in my house thank you.

[–] [email protected] 2 points 7 months ago* (last edited 7 months ago)

940/940 unlimited for ~$90/month in Western Canada

[–] [email protected] 1 points 8 months ago

IF it's possible you might be able to take the ISP SFP and put it in a SFP to RJ45 media converter and then you can use any 1gig capable router. I did this with my Telus SFP.

OPNsense or OpenWRT. I run multiple OPNsense firewalls for family members all connected together with a WireGuard Mesh.

Cisco is command line for the most part until get into the APIC NSX stuff. There's others but I'm only exposed to those 2 where I work.

[–] [email protected] 3 points 8 months ago

I selfhost both Lemmy and Mastodon. Lemmy is set and forget follow the communities you etc. Mastodon does need a little bit of tweeking after being setup. I have a script the removes remote content from my server after 7 days which keeps the used space down considerably. More details about the commands used can be found here -> https://docs.joinmastodon.org/admin/tootctl/#media-remove

[–] [email protected] 2 points 9 months ago* (last edited 9 months ago)

Nah don't use those. Get your own direct from Let's Encrypt. Less hoops to go through when its time to renew. Acme with a crontab entry takes care of renewals automatically. Don't forget to add to the crontab line to restart nginx right after the renewal so that the new certs are used.

Edit: spelling

view more: next ›