• 1 Post
  • 709 Comments
Joined 2 years ago
cake
Cake day: June 6th, 2024

help-circle

  • We had a close call with a tornado once. We were driving down the highway in torrential rain and strong winds when I got the tornado warning pop up on my phone. There was no one else on the highway except one semi truck. We aren’t used to tornados and weren’t sure what to do, and considered just pulling over, but decided to just get off at the next exit, but that ended up being like 5 more miles, which doesn’t sound like much, but while terrified and driving as fast as I could in heavy rain and winds, it felt like an eternity. When we did find an exit, we pulled into a gas station right by the freeway and ran inside. There were a bunch of locals there who were sheltering but seemed really nonchalant about it.

    Checking the news later, the tornado passed only a few miles from us. I know others have worse tornado stories, but this was still one of the scariest things that’s happened to me.










  • I have my Immich instance setup with an nginx proxy for security and ssl, and that’s exposed to the internet. I have a domain for my personal website, so I just put up my Immich instance at a subdomain of that. I can now make public share links I can just copy and paste into a group chat. I haven’t added any other users yet but I’d I wanted to all they’d need to do is login via email/password.

    This is an officially supported kind of setup for Immich, so I would consider it secure: https://docs.immich.app/administration/reverse-proxy/

    I don’t have all of my homelab services exposed publicly though; I VPN in for those.

    General tips for exposing a server to the internet:

    • only expose the ports you need for services you intend to be accessible. Use a firewall and/or your router’s port forwarding settings to enable only what you need, with blocking as a default.
    • update all software regularly
    • only expose programs that are built to be exposed. For example, if you make a Flask website, they will warn you several times not to expose it directly, but to proxy it through something like nginx



  • This meme was inspired by my frustration from trying to switch. I like the idea of podman, but it just doesn’t work. Tbf the bugs I encountered this time were with podman compose rather than podman itself, but still, I’d rather use the tools that work. I’ve had similar experiences when I’ve tried to switch to podman in the past.


  • Podman is unironically the better choice.

    I like the idea of podman, but it’s just not stable. This meme was inspired by my frustration of trying to switch.

    Just try to make docker comply with your firewall.

    I literally did this yesterday and it wasn’t that hard. You just add iptables:False to the docker config file.