chiisana

joined 1 year ago
[–] chiisana 1 points 1 year ago

Yep! Basicall, they sit between you and your visitors as a reverse proxy. When you domain is accessed through their infrastructure (you set this up via DNS), they’ll sign SSL for you domains so you don’t need to worry about it. Using the origin certificate secures communication from your server to theirs, so there’s no point in the chain being left in the open. They’ll even do DDOS protection and some basic web application firewall for free as well.

Additionally, since they’re globally distributed, your website could have static content cached closer to your visitor, thereby giving a faster experience.

They’ve also added lots of great stuff to help with locking down remote access to your internal infrastructure. For example if I want to SSH into my homelab, I don’t have to expose my SSH globally, and when I try to access it, I get a browser pop up asking me to login to my SSO, and then grants access.

I really enjoy and recommend trying their free offering.

[–] chiisana 3 points 1 year ago* (last edited 1 year ago) (3 children)

Everyone has an opinion, and at the end of the day, whatever works best for you is what you should stick with.

I like Traefik because you can mount /var/run/docker.sock:/var/run/docker.sock:ro to Traefik, then it can read labels from containers, and automatically wire up new instances based on labels on them. I'm sure there's equivalent in other reverse proxy solutions, but as I said, it works for me and I like it.

I give that container my Cloudflare origin certificate, everything gets encrypted in transit to Cloudflare, and then Cloudflare handles all the SSL management for me, as well as provide extra layer of DDOS protection.

[–] chiisana 19 points 1 year ago (1 children)

Lemmy is very “open” right now; some might say by design, other might say flawed. OP is maybe coming from a good place and actually wants to help, but instead of doing it tactfully, OP is becoming the exact thing they’re advocating against — a spammer posting garbage.

[–] chiisana 52 points 1 year ago (4 children)

This right here.

Op, if you’re not ready to moderate, don’t spin up your own server or do your own private instance. If you’re going to moderate, do it properly and don’t spew bad ideas while hiding behind a dumb “alert” throwaway.

[–] chiisana 1 points 1 year ago

testy mctest message

[–] chiisana 2 points 1 year ago* (last edited 1 year ago)

Yeah, I'm getting mixed results as well. Federation seems to be super finicky right now. A lot of finger pointing going on and some posts I've seen suggests it is Cloudflare being the culprit. As much as I'd like to shed Cloudflare to get federation working, I just don't see that being something that's viable long term. It is very easy to DDOS someone, and I do not want to expose my instance IP publicly.

Looking at the commit logs, the difference between 0.17.3 and 0.17.4 seems to be just some database optimizations, so I think the problem we're seeing is still something else.

Also, the lemmy.ml instance is acting up across the board, even from the lemmy.world instance, or other major instances, the subscribe doesn't seem to return properly... so I wouldn't necessarily use them as the benchmark.

[–] chiisana 2 points 1 year ago (1 children)

I did some quick google'ing when I saw it... otel is probably opentelemetry, but the Lemmy developers didn't include that in the released docker-compose. Perhaps it is something they're using internally. I haven't notice any telemetry related issues, yet, so I'm just keeping my fingers crossed for now...

[–] chiisana 1 points 1 year ago

Make that the two of us! I'm still very much still trying to figure things out, too!

The two links I've shared, in theory, should present the same content, and interaction on either (depending where you have your account) should be reflected on the other fairly quickly. Since your account currently is on Lemmy World, you'd want to use this link to interact with it on Lemmy World. Again, in theory, once you interact with it, be it upvoting, adding a comment, or whatever, it should propagate to my instance and be reflected there... but that's not what I'm seeing right now.

Hopefully someone can point out where I am going wrong, and help me correct the error, so we'd all be able to interact with the various instances as expected :)

[–] chiisana 1 points 1 year ago (2 children)

I have shared them in a separate post; though, it would appear that there are still some federation issues as the post appears to be some what de-sync on my own instance and lemmy.world. I'm also for some strange reason unable to see your reply on my own instance, hence why I'm replying with my lemmy world account instead... If you do make some more progress, please do share it with the community at large so more of us can have the setup we'd like!

[–] chiisana 1 points 1 year ago (1 children)

Do you have federation enabled? I think the checkbox in /admin isn't checked by default.

[–] chiisana 5 points 1 year ago (2 children)

Unfortunately, it would appear that there's not without very significant problems... I'm commenting to your comment via my lemmy.world account because I'm not seeing your comment on my instance.

If you do get it working, and find ways to resolve issues I'm having, please do share back so I can get my instance fixed as well! Thanks!

[–] chiisana 1 points 1 year ago

I’m seeing only partial federation on my instance. I see some posts but the comments are sporadic and I’m not sure why. I am also behind cloudflare. If you find more details, please do share so we can get up and running!

 

Seems like an easy missed opportunity. In the settings pane, there is a link to this community. Tapping it opens an in app safari view… if we’re already in the mlem app, why shouldn’t the link open the community as if it were a feed?

view more: next ›