brewery

joined 2 years ago
[–] brewery 11 points 6 days ago (1 children)

Came to say this. Most people in the UK have to pay tuition for university. There is a govt loan but you're still paying it, plus interest

[–] brewery 3 points 2 weeks ago

Oh Ok. Sorry, it just can't across really negative rather than pointing out a potential flaw. I can see difficulties enforcing it by the workers like you mention

[–] brewery 4 points 2 weeks ago

Thanks for taking the time to reply. Will have to reconsider my choices here!

[–] brewery 16 points 2 weeks ago (2 children)

Im curious about your argument because this would justify not putting any rules at any time. No cigarettes for under age in shops (might attack a shop keeper), no alcohol in pubs (might attack a bartender), no fines for speeding (might attack cameras or police), no parking restrictions (might attack ticket wardens), etc.

Maybe the threat of fines are not enough to change this behaviour (which I can understand in India after spending a lot of time there) so they are trying a novel approach. One thing Indian police will take more seriously is attacking a worker for applying the rules compared to risking your own life.

[–] brewery 16 points 2 weeks ago (8 children)

Why is it shitty? I am not trying to deny it, just really curious what it is about

[–] brewery 2 points 2 weeks ago (1 children)

Feels a bit like the horse has already bolted. I am very against this move and also believe everyone should delete their Facebook accounts (I did so years ago and not missed anything). However, it feels like (a) it's already happened so people are in these bubbles where the fact checks won't help and (b) it feels like it's mostly shared through WhatsApp groups where there is no content moderation.

I really want to delete WhatsApp but all my family and friends use the groups, and just don't care enough about this stuff to bother moving elsewhere. I only know one person who isn't on it and have no groups of people not using it as their main form of communication within those groups.

[–] brewery 5 points 2 weeks ago

After some research on here and reddit about 6 months so, I settled on Borgbase and its been pretty good. I also manually save occasionally to proton drive but you're right to give up on that as a solution!

The hardest part was choosing the backup method and properly setting up Borg or restic on my machine properly, especially with docker and databases. I have ended up with adding db backup images to each container with an important db, saving to a specific folder. Then that and all the files are backed up by restic to an attached external drive at well as borgbase. This happens at a specific time in the morning and found a restic action to stop all docker containers first, back them up, then spin them back up. I am find the guides that I used if it's helpful to you.

I also checked my backups a few times and found a few small problems I had to fix. I got the message from order users several times that your backups are useless unless you regularly test them.

[–] brewery 2 points 3 weeks ago (1 children)

Theres a lot of different things going on here although it sounds simple, you're actually touching many different technologies. I started a few years ago to self host and it took me a while to get my head around these and still have issues so don't worry too much!

Im not familiar with caddy but the ports look wrong. It would be looking for 80 and 443 presumably on the docker host (right hand side / "RHS Ports". You could use any ports on the left hand side ("LHS Ports").

The section "DOMAIN}:1443" might be telling caddy to be looking on port 1443 inside docker, which means the port need to be flipped around. The RHS Ports are what the service inside docker is looking to use (often these are set by the developer but they can be changed in settings, it's easier to leave these as default and only change the LHS Ports). The LHS Ports are what you choose to expose on the actual server itself. https://docs.docker.com/get-started/docker-concepts/running-containers/publishing-ports/

Theres no mention of the router settings so the problem might be there. Are you forwarding the right ports through? You would need to forward ports 80 and 443 to the LHS Ports you choose for caddy. These port forwards would also need to point to your servers internal address. (Search " port forward settings")

What do you have on port 80 as I would recommend to change that to something else and have caddy on ports 80 and 443. I would also suggest trying nginx proxy manager which is available on docker, has a nice web interface to add reverse proxy's, and can handle your SSL certificates (inc automatic renewals). This would replace caddy and would use ports 80 and 443 on your server. https://nginxproxymanager.com/

Also, just to mention, your safest option is not to expose vaultwarden to the internet unless your very sure you need to and add other protections (firewalls, fail2ban etc). If it's just you/a few people, look into using a VPN like tailscale (easiest but relies on external party) or Wireguard (fully yours to control but pretty complicated).

You would still need an SSL cert but your can do this through DuckDNS using https://github.com/maksimstojkovic/docker-letsencrypt. You could also buy a cheap domain and never have to expose anything, as they would give you a certificate to download (cloudflare or porkbun are good - https://kb.porkbun.com/article/71-how-your-free-ssl-certificates-work) and you manually upload it to caddy or nginx proxy manager. the best option is to use nginx proxy manager or certbot to handle these as the certificates expire. You can set up "DNS challenge" in your SSL certificate manager which needs details from your DNS to obtain the SSL certificates on your behalf.

If I was you, I would search for online guides and setup in this order: nginx proxy manager, SSL cert (buying your own cheap domain from cloudflare and setting up DNS challenge in nginx proxy manager), tailscale, then vaultwarden.

[–] brewery 2 points 1 month ago

First time I've seen this and wow, this really hits the reasons! Thank you

[–] brewery 8 points 1 month ago

As someone who used to cycle, walk or ride a bus across these bridges, please don't blow them up. In fact, I think all the central London bridges have bus lanes, plenty of walking space and some have cycle lanes. Theres one bridge for people only. I know im taking this too seriously but it's a very scary thought

 

In London, England, where the roads are narrow, the parking spaces are limited and we have plenty of availability of vans that can actually fit things in, we still get these a*holes with their unnecessary large pick up trucks made for a road system completely different to ours...

These spaces are wider than usual and long enough to fit them but they still have to park like w*nkers blocking the only footpath around!

I mean, I have a 5 door hatchback and know that my car overhangs the back wheels, as does any primary school kid drawing a car...

[–] brewery 6 points 1 month ago

Does it include cleaners? Most offices seem to hire external companies so don't hire cleaners themselves, or any of the "menial" jobs required to have a functioning office. Might hide much worse jobs

[–] brewery 3 points 1 month ago* (last edited 1 month ago)

Im using a free Mailgun account for all my self hosted services. Happy with it so far.

Proton only has SMTP on it's business accounts, and you have to apply for one with a good reason (ie not for spam)

9
Upgrading to 3G broadband (self.selfhosted)
submitted 1 month ago by brewery to c/selfhosted
 

I've really landed on my feet here.

Background

Our road recently got upgraded to full fibre so I switched my ADSL supplier from 300MB to 1G (is it still ADSL?!?). I also have cable broadband at 600MB so last year bought an omada router with dual wan, then bought two EAPs and been quite happy with the speeds. My equipment includes a desktop PC as home server, and a mini PC with pihole and home assistant.

Cable broadband (virgin media) just came up to renewal so they offered me 1G at same price (£35 a month) to compete with the new speeds on my street.

The new 1G ADSL provider had incorrect info on their website so ended up on CGNAT instead of Dynamic IP. It said they have dynamic IP for 1G and 3G lines, so part of the reason I went for 1G was this, which I made clear to them. They took a while to try and fix it and were pretty poor so just for offered a 3G upgrade for £39pm and 6 months free !!!

They're coming on Monday to replace the modem \router for a 3G one. I can keep the old router (brand new 1G wifi 6 router) as a mesh.

Advice needed

Please help me figure out what I need to change to make the most of it?! I purposefully didn't go beyond 1G as was not expecting this much speed for many, many years!

If anybody knows good resources on upgrading speeds past 1G please let me know.

For my home network, do I just sell everything I have and start again? Do I just use their modem and WiFi?

Do I need to check all my wires and potentially upgrade them? How do you check the speeds if they don't have them printed?

On my home server, do I need to upgrade the network card to get the most out of it? Will it be fine if the connection to the pihole DNS is still 1G if it's only requesting addresses?

I am sorry for anyone on lower speeds seeing this with envy. I do appreciate how lucky I am.

TLDR: broadband provider messed up so got ridiculously cheap upgrade to 3G ADSL and also upgraded to 1G Cable (dual wan 4G). How do I make the most of this given my equipment is all 1G?!?

 

After self hosting several services for a few users, with SSO, backups, hardware issues etc, I really appreciate how good the IT was in my old company. Everything was connected, smooth, slick and you could tell it was secure. I had very few issues and when I did, they were quickly solved. Doing this all at scale for thousands of employees spread across the world, it is a wonderful sight to see.

Now at my current company, it's at the opposite end of the scale where I almost believe that I could do a better job by myself! They've trying to do everything you would expect but somehow doing it wrong. They are so heavy on security I have a Citrix environment that takes me 3 logins to get to, fails constantly and means I can't work without internet (like on a long train journey for work purposes recently), and on the other hand they've only just turned off admin rights for users so we could've installed anything we wanted!!! All our attachments (incoming and outgoing) are saved to a secure website (like OneDrive) and replaced with a link. It doesn't save the file names on the email so it's really tricky to find old emails if it's a document you're looking for. I could go on but just venting at this point as it's so frustrating!!!

Thank you to the good IT people out there. Your roles are so important but not appreciated enough!

 

I had a child and both of our parents were in another country so wanted to keep them updated with photos and videos but refused to use social media. I have been using Back Then which, to be fair, has worked pretty well. I pay a subscription and can give access to anybody I want through their email. They then have to download an app and sign in to see. It updates them if there's new photos and shows them in a nice chronological order by age. There are other features (likes and comments) but tbh, no-one really uses them and I don't care about that. For me, it's just the privacy and access control I'm after

Now I have built my home server and got to the point where it's reliable (enough), plus I'm happy with my security/SSO setup, does anybody recommend a self hosted photo sharing tool?

 

My son is 4 and is now randomly saying I love you to me and my wife, and at other times giving us proper tight hugs. We are so buzzing about it. Ever since he was born we have been doing that to him as neither of us got it growing up so wanted to show him all the time that he is loved, and it really feels like all that effort and work is really paying off as he is such an emotional and lovely boy.

Just wanted to share as a super proud dad...

view more: next ›