-
Point the hostname of your service to the IP of the proxy in the DNS.
-
For the certs you need an internal CA. I use Step CA which has ACME support so the proxy can get certificates easily.
-
Add the root CA certificate to your computer certificate trust store.
-
Profit!!
- 0 Posts
- 22 Comments
borax7385@lemmy.worldto
You Should Know@lemmy.world•YSK: there's a browser extension called "SingleFile", which allows you to save any page into a single HTML file.
78·1 month agoTry to avoid installing extensions, they have too much privilege in the browser.
borax7385@lemmy.worldto
Selfhosted@lemmy.world•Changes to Bitnami Catalog on August 28thEnglish
1·3 months agoI see, thank you.
borax7385@lemmy.worldto
Selfhosted@lemmy.world•Changes to Bitnami Catalog on August 28thEnglish
1·3 months agoI use Bitnami SealedSecrets. Does anyone know if that’s going down the shitter too?
I have had Jellyfin directly open to the Internet with a reverse proxy for years. No problems.
borax7385@lemmy.worldto
Linux@lemmy.ml•Pipewire can now be run as root, improving accessibility as it allows for screenreaders to start much earlier
11·5 months agoIncorrect. Not run as root, but launched by root in a system service (runs as the pipewire user).
borax7385@lemmy.worldto
Selfhosted@lemmy.world•Garage - S3-compatible Object Storage alternative to MinioEnglish
3·5 months agoFor my simple use case (storing Velero backups), it works perfectly and with a resource footprint ridiculously low (~ 3 MiB memory when idle). In comparison MinIO used 100 times more memory.
Don’t forget the Silverbullet users.
Oh, I didn’t realize this was for plain containers, sorry.
For that I use Ansible to deploy the containers in my server. The secrets are stored encrypted in my local machine with passwordstore and I use the passwordstore lookup plugin to load them in the playbooks/templates.
borax7385@lemmy.worldto
Selfhosted@lemmy.world•How do you document your Homelab?English
4·6 months agoThe Ansible playbooks I use to deploy it are the documentation.
In my homelab I use Bitnami’s sealed secrets to commit the encrypted secrets to git and deploy with ArgoCD.
Which user do you use to run the podman command? Confirm with
whoamiNote that the sysctl
net.ipv4.ip_unprivileged_port_startcan be used to allow non-root users to bind to ports <1024, this might be configured in MicroOS, I don’t know.
borax7385@lemmy.worldto
Selfhosted@lemmy.world•Am I the only one interested in Fedora based containers?English
1·7 months agoI run some containers based on Fedora, mainly because I know the userspace and I don’t care about the size.
We don’t know how big is the universe beyond the observable universe.
borax7385@lemmy.worldto
Selfhosted@lemmy.world•How to secure Jellyfin hosted over the internet?English
211·7 months agoI use fail2ban to ban IPs that fall to login and also IPs that perform common scans in the reverse proxy
borax7385@lemmy.worldto
Selfhosted@lemmy.world•Authelia 4.39 has been released with massive changesEnglish
17·8 months agoOn the other hand I value Authelia single configuration file which I can version control in git. Authentik is a click-ops burden.
borax7385@lemmy.worldto
Android@lemmy.world•what do you hate the most about Android 15?English
2·8 months agoI’ve tried the official WireGuard app and WG Tunnel, enabling unrestricted battery use, always on VPN, allowing notifications, etc. But since I upgraded to LineageOS 22.1, the app is always killed overnight.
borax7385@lemmy.worldto
Android@lemmy.world•what do you hate the most about Android 15?English
1·8 months agoIt kills my VPN app every night.



Can’t wait!