Incessant tinkerer since the 70’s. Staunch privacy advocate. SelfHoster. Musician of mediocre talent. https://soundcloud.com/hood-poet-608190196

  • 32 Posts
  • 1.57K Comments
Joined 1 year ago
cake
Cake day: March 24th, 2025

help-circle
  • Technically, using Cloudflare tunnels for Jellyfin is a ToS violation. You’re only allowed to do so if you have an enterprise account, which is quite expensive.

    I’ve heard people say this, and I’ve heard people say you can’t stream music. Tho I do not run the 'arr stack or Jellyfin, I do run Navidrome almost 24/7/365. But it’s something to keep in mind.

    ETA: I am the sole user


  • Well, you could do network segmentation:

    • Put the server in a DMZ or separate VLAN if your router supports it. This isolates it from your main devices (computers, phones, IoT). I’m not sure what router you have buy many consumer routers have a “guest network” that can serve this purpose.

    Utilize UFW rules. Mine are:

    • sudo ufw default deny incoming

    • sudo ufw default allow outgoing

    • Anywhere ALLOW IN 192.168.1.0/24

    • 22 ALLOW IN 192.168.1.0/24

    • 22 on tailscale0 ALLOW IN Anywhere

    • 22 (v6) on tailscale0 ALLOW IN Anywhere (v6)

    Also:

    • sudo ufw allow out to 1.0.0.1 port 53 # DNS only
    • sudo ufw allow out to 1.1.1.1 port 53
    • sudo ufw deny out to 192.168.1.0/24 # Block LAN access except admin

    So now I have SSH capability locally and through Tailscale installed on the server and this prevents the server from initiating connections to other LAN devices. You can do alot with UFW and Fail2Ban in conjunction with Cloudflare Tunnels/Zero Trust.


  • Have you considered Cloudflare Tunnels/Zero Trust. When you use Cloudflare Tunnels/Zero Trust, you don’t need to fiddle with NAT, open any ports, in fact you don’t need any open ports. You just install Cloudflare Tunnels/Zero Trust on your server, connect to your Cloudflare Tunnels/Zero Trust account, and Cloudflare does the rest. To deploy Cloudflare Tunnels/Zero Trust you will need a domain name. Cloudflare will sell you a domain name but I think most get something cheap from NamesCheap or Pork Bun. When you have secured a domain name, switch the nameservers to the ones that Cloudflare assigns you. Jacks a doughnut, Bob’s your uncle.

    ETA: Obviously you’ll need port 22 for administration.

    sudo ufw default deny incoming

    sudo ufw default allow outgoing


  • But my qualms and scruples are not your problem

    Me being uncomfortable with how you do it is immaterial

    I hope as a community we can start to just say “No thank you” when we are offered something that’s done in a way we don’t like

    anyone who is not doing that needs to analyse why they feel entitled to shit on someone else’s project.

    We goin’ to church today. Preach it my brother! Can I get an amen?

    I’m the one who has to die when it’s time for me to die, so let me live my life the way I want to. ~ Jimi Hendrix






  • I’ve got a drawer full of various models I’ve picked up here and there, mostly used that people were selling. I stumbled across a yard sale once where a guy and his son were selling a lot of computer equipment to raise money for his son to get some newer stuff for college. There was a whole box of them, maybe 10+ and I paid $100 for all of them. I use them from time to time for different projects. Good little learning boards.






  • People will buy intelligence from us on a meter’

    We have governmental surveillance and we have surveillance capitalism. Surveillance capitalism works so well that governments are now very interested in the data they collect, which is alarming. Unfounded conspiracy theory: It’s probably one of the reasons that governments don’t seem interested in AI’s regulation. If I had the proper equipment to run AI entirely local and efficiently so that the expenditure would justify it, I would.






  • call Spectrum for a quote so I can then call AT&T and harass them into giving me the correct price for another year.

    It’s a shitty business model. Over the years I’ve found that in order to get the most out of Spectrum it is necessary to be a royal asshole and live in their phones. Here in this locale, Spectrum contracted with the local schools to be their ISP, so Spectrum became a utility just like water, power, etc. We even have a complaint form on our official county’s website to facilitate being a royal asshole when necessary.


  • Wonky Coffee

    Never heard of them, checked it out. That’s a noble cause. I think we Americans especially, waste so much food it’s downright embarrassing. Yet we make laws that say it is prohibited to feed the homeless. That’s unconscionable imho. I strongly feel, we as a society, have a moral obligation to our fellow man to help when help is needed, no matter who they are or how they came to be in need.