OPNsense Bare Metal vs Virtualization
Looking for some advice / recommendations / considerations on running OPNsense on bare metal vs virtualized, and if virtualized how best to do so.
I currently have OPNsense running bare metal on a Protectli FW6E Vault, with the following specs:
- Intel i7-8550U CPU @ 1.80GHz
- 120GB mSATA (1% utilization)
- 16GB RAM (6.5% utilization)
- 6 Gigabit Ethernet NIC ports
The Vault running OPNsense is the primary firewall and router, any wireless devices connect through a dumb AP running OpenWRT. Connected over Ethernet I have a RPi running HomeAssistant OS (would probably also move to virtual if that's the chosen direction) as well as a TrueNAS setup.
How much of a performance hit would be expected running in some sort of container vs the current bare metal setup? Are there any other concerns with running the main firewall / router virtually vs bare metal to take into account?
Promised myself I will support them after they go stable. They kept their promise and so did I
One of the best pieces of self-hosted software ever to exist.
Edit: This is Immich! for the folks who don't know.
LycheeOrg — Self-hosted photo-management done right.
Lychee is a free photo-management tool, which runs on your server or web-space. Upload, manage and share photos like from a native application. Lychee comes with everything you need and all your photos are stored securely.Lychee
Is Twingate good for remote access to a selfhosted Nextcloud server?
I run a Nextcloud instance on my home server and want secure remote access without exposing ports. I came across Twingate, which looks like a VPN alternative.
Has anyone used it for personal setups? Is it overkill compared to something simpler like Tailscale? I’d like to know how you use it, or what else you use.
Events & Webinars | Tailscale
Find recordings of Tailscale experts, webinars and events. Learn how our VPN securely connects users, services and devices regardless of environments and locations.tailscale.com
What's the best chat to self host?
I'm looking into a few different chat servers, probably just for family on my tailnet.
I like the idea that simplex allows video chat. My server is a repurposed optiplex 3060so I think it should be able to handle it. Is anyone doing this? Do you think it's worth it?
Should I be considering other options like XMPP?
IMO Snikket (XMPP) is the easiest all-in-one solution with audio/video chat at the moment. Pretty good on resources too.
I currently host a Matrix Synapse server, but:
- Matrix seems to be expanding in the corporate / institutional direction, more services are expected for regular functionality
- Element X (upcoming client) breaks calls compatibility with old Element, now requiring Element Call. It's kind of a mess, I presume this is to support group calls, but makes it a PITA to use currently.
- Even with small number of users, Synapse DB grows in size due to state_groups_state table, non-deletable users, and copying ALL data from other servers' rooms (this one is by design but still...)
I have gone down the matrix rabbit hole but i choose Continuwity, which is the successor to Conduwuit after the community drama.
It's a rust server alternative to synapse, it's lightweight and works very well.
Fuck synapse, it's a colossal pain for small servers, not worth it. I also actively avoid anything related to the company behind it since I think they poison what matrix could be.
I wish I started with XMPP, but now I am selfhosted on matrix, so.
Briar - secure p2p group communications
Briar is a messaging app designed to be used by groups of people to allow for secure and censorship resistant communications.
This technically isn't self hosted in the strictest sense but I think it is still relevant.
I created a NixOS Install script for Proxmox
For quite a while, I've wanted to try out hosting my services in NixOS LXCs, but it did not seem like there were any definitive one-stop-shop scripts such as the ones on Proxmox Helper Scripts. So, I waited for some clever cookie to make one, because surely this was not something just I was interested in.
But the cookie never appeared, and after a while of waiting, I decided that maybe I should try it myself! A few nights of chicken scratch bash later, and I've got a decent little script to boot up and configure a NixOS 24.11 LXC, with a configuration.nix file!
Important disclaimer though, this script is still pretty early in development. While it does boot and set up an LXC, there is very little error handling, and don't get me started on the UX. I just thought I'd share, and maybe get some suggestions from others.
GitHub - CatRass/nixos-lxc: Bash script to create a NixOS 24.11 LXC in Proxmox VE
Bash script to create a NixOS 24.11 LXC in Proxmox VE - CatRass/nixos-lxcGitHub
In your Proxmox console, enter the following command:
bash -c "$(curl -fsSL raw.githubusercontent.com/....)
Do not do this. Never run scripts like this directly without inspecting them first. Do not tell people to run your exciting new script like this. Provide a link to the script and encourage users to inspect it first then run it.
GitHub · Build and ship software on a single, collaborative platform
Join the world's most widely adopted, AI-powered developer platform where millions of developers, businesses, and the largest open source community build software that advances humanity.GitHub
XPipe - A connection hub for all your servers: Status update for the v16 release
GitHub - xpipe-io/xpipe: Access your entire server infrastructure from your local desktop
Access your entire server infrastructure from your local desktop - xpipe-io/xpipeGitHub
Plex has paywalled my server!
I tried testing a movie from my home server in plex through firefox and repeatedly got this message, even after reloading.
I knew that they had paywalled the apps on mobile and streaming from outside the network but now they have also blocked watching your own movies through your own hardware.
I do get the point that making software should be able to sustain people but I dont see the move of plex as a fair thing to do. Yes, they have made great software but taking your home server hostage feels like the wrong move.
Even a pop up that says "we need you to donate please" would have been fine. make it pop up before every movie, play donation ads before any movie but straight up disabling the app is kinda cruel.
Anyway, i have switched to jellyfin and it is insanely good. please give it a try. you can run it alongside plex with not issues (at least i had none) and compare the two.
In any case, good luck. Let me know if you need help.
jellyfin-vps-setup
This project contains docker compose files on how to make Jellyfin accessible to the internet through a VPSCodeberg.org
Is there any good decentralized cloud storage for personal backups as a self-hoster?
Thoughts on the recent Swiss law that might require ProtonVPN to start blocking certain domains?
Seems that the Swiss legislature may pass a law requiring ProtonVPN to start banning certain domains from being access by French users (mostly illegal sports streaming sites)
For those using ProtonVPN, is the writing on the wall?
Does anyone have thoughts on the IPv6 privacy extensions? They theoretically could help a lot with privacy
The idea is that your device has tons of temporary IP addresses that can be used for various tasks like surfing the web.
All of your temporary privacy addresses will be coming out of the same subnet, so it's clear they all belong to the same people.
Ultimately the privacy extensions are just bringing IPv6's privacy back in line with IPv4, because without the privacy extensions every single device has a separate IPv6 address based on its MAC address whereas in IPv4 most consumer networks have every device sharing a single IP.
Is there a FOSS selfhosteable alternative to iLovePDF?
iLovePDF | Online PDF tools for PDF lovers
iLovePDF is an online service to work with PDF files completely free and easy to use. Merge PDF, split PDF, compress PDF, office to PDF, PDF to JPG and more!iLovePDF - Online tools for PDF
What webapps do you selfhost that aren't media/game servers?
I've been testing MatterMost for a few days.
It's closer to Slack than Discord but has most of the same features.
immobile7801
Als Antwort auf CosmicRanger • • •