Zum Inhalt der Seite gehen



OPNsense Bare Metal vs Virtualization


Looking for some advice / recommendations / considerations on running OPNsense on bare metal vs virtualized, and if virtualized how best to do so.

I currently have OPNsense running bare metal on a Protectli FW6E Vault, with the following specs:

  • Intel i7-8550U CPU @ 1.80GHz
  • 120GB mSATA (1% utilization)
  • 16GB RAM (6.5% utilization)
  • 6 Gigabit Ethernet NIC ports

The Vault running OPNsense is the primary firewall and router, any wireless devices connect through a dumb AP running OpenWRT. Connected over Ethernet I have a RPi running HomeAssistant OS (would probably also move to virtual if that's the chosen direction) as well as a TrueNAS setup.

How much of a performance hit would be expected running in some sort of container vs the current bare metal setup? Are there any other concerns with running the main firewall / router virtually vs bare metal to take into account?

Als Antwort auf CosmicRanger

I run opnsense in proxmox for a couple reasons. 1) I can snapshot the VM prior to upgrading, in case of an issue I can just rollback. 2) backups, I can backup the whole VM, which includes all the plugins, Not just the base opnsense config. 3) I don't run anything on bare metal except my laptop.


Promised myself I will support them after they go stable. They kept their promise and so did I


One of the best pieces of self-hosted software ever to exist.

Edit: This is Immich! for the folks who don't know.

Dieser Beitrag wurde bearbeitet. (3 Tage her)
Als Antwort auf sonofearth

Seriously everyone pushes Immich so hard I'm a little suspicious of it now :D
Als Antwort auf kalpol

Yeah :) Maybe give lychee a try :) it's minimalist and does one thing, but it does it well !!!
Dieser Beitrag wurde bearbeitet. (3 Tage her)


Is Twingate good for remote access to a selfhosted Nextcloud server?


I run a Nextcloud instance on my home server and want secure remote access without exposing ports. I came across Twingate, which looks like a VPN alternative.

Has anyone used it for personal setups? Is it overkill compared to something simpler like Tailscale? I’d like to know how you use it, or what else you use.

Als Antwort auf rtxn

there isn't one yet. but check in this weeks events....tested the relay feature and it's really solving a bunch of issues. tailscale.com/events-webinars


What's the best chat to self host?


I'm looking into a few different chat servers, probably just for family on my tailnet.

I like the idea that simplex allows video chat. My server is a repurposed optiplex 3060so I think it should be able to handle it. Is anyone doing this? Do you think it's worth it?

Should I be considering other options like XMPP?

Als Antwort auf gedaliyah

IMO Snikket (XMPP) is the easiest all-in-one solution with audio/video chat at the moment. Pretty good on resources too.

I currently host a Matrix Synapse server, but:

  • Matrix seems to be expanding in the corporate / institutional direction, more services are expected for regular functionality
  • Element X (upcoming client) breaks calls compatibility with old Element, now requiring Element Call. It's kind of a mess, I presume this is to support group calls, but makes it a PITA to use currently.
  • Even with small number of users, Synapse DB grows in size due to state_groups_state table, non-deletable users, and copying ALL data from other servers' rooms (this one is by design but still...)
Als Antwort auf Yaky

I have gone down the matrix rabbit hole but i choose Continuwity, which is the successor to Conduwuit after the community drama.

It's a rust server alternative to synapse, it's lightweight and works very well.

Fuck synapse, it's a colossal pain for small servers, not worth it. I also actively avoid anything related to the company behind it since I think they poison what matrix could be.

I wish I started with XMPP, but now I am selfhosted on matrix, so.



Briar - secure p2p group communications


Briar is a messaging app designed to be used by groups of people to allow for secure and censorship resistant communications.

This technically isn't self hosted in the strictest sense but I think it is still relevant.

Als Antwort auf Possibly linux

Seems pretty similar to Jami except that it lacks the iOS and desktop clients that Jami already has.


I created a NixOS Install script for Proxmox


For quite a while, I've wanted to try out hosting my services in NixOS LXCs, but it did not seem like there were any definitive one-stop-shop scripts such as the ones on Proxmox Helper Scripts. So, I waited for some clever cookie to make one, because surely this was not something just I was interested in.

But the cookie never appeared, and after a while of waiting, I decided that maybe I should try it myself! A few nights of chicken scratch bash later, and I've got a decent little script to boot up and configure a NixOS 24.11 LXC, with a configuration.nix file!

Important disclaimer though, this script is still pretty early in development. While it does boot and set up an LXC, there is very little error handling, and don't get me started on the UX. I just thought I'd share, and maybe get some suggestions from others.

Als Antwort auf catrass

In your Proxmox console, enter the following command:
bash -c "$(curl -fsSL raw.githubusercontent.com/....)


Do not do this. Never run scripts like this directly without inspecting them first. Do not tell people to run your exciting new script like this. Provide a link to the script and encourage users to inspect it first then run it.



XPipe - A connection hub for all your servers: Status update for the v16 release


Dieser Beitrag wurde bearbeitet. (4 Monate her)


Plex has paywalled my server!


I tried testing a movie from my home server in plex through firefox and repeatedly got this message, even after reloading.

I knew that they had paywalled the apps on mobile and streaming from outside the network but now they have also blocked watching your own movies through your own hardware.

I do get the point that making software should be able to sustain people but I dont see the move of plex as a fair thing to do. Yes, they have made great software but taking your home server hostage feels like the wrong move.

Even a pop up that says "we need you to donate please" would have been fine. make it pop up before every movie, play donation ads before any movie but straight up disabling the app is kinda cruel.

Anyway, i have switched to jellyfin and it is insanely good. please give it a try. you can run it alongside plex with not issues (at least i had none) and compare the two.

In any case, good luck. Let me know if you need help.

Als Antwort auf Vanilla_PuddinFudge

Thats not what I meant. I of course have wireguard set up for administration and my own streaming needs. But friends of mine who were able to use plex by just making an account but now they cant because of course there is no relay server etc. I'll have to think of a way to make it available to them (easily!) without putting my network at risk.
Als Antwort auf haui

This is how I do it: codeberg.org/skjalli/jellyfin-…


Is there any good decentralized cloud storage for personal backups as a self-hoster?


I’m thinking of using Storj because I’d like a trustless solution. Are there any other good alternatives in the decentralized or Web3 space?
Unbekannter Ursprungsbeitrag

lemmy - Link zum Originalbeitrag
SayCyberOnceMore
Got a link for that? Searching for "garage backup storage" doesn't really get me anywhere...


Thoughts on the recent Swiss law that might require ProtonVPN to start blocking certain domains?


Seems that the Swiss legislature may pass a law requiring ProtonVPN to start banning certain domains from being access by French users (mostly illegal sports streaming sites)

For those using ProtonVPN, is the writing on the wall?

Als Antwort auf CapitalNumbers

Does anyone have thoughts on the IPv6 privacy extensions? They theoretically could help a lot with privacy

The idea is that your device has tons of temporary IP addresses that can be used for various tasks like surfing the web.

Dieser Beitrag wurde bearbeitet. (5 Monate her)
Als Antwort auf Possibly linux

All of your temporary privacy addresses will be coming out of the same subnet, so it's clear they all belong to the same people.

Ultimately the privacy extensions are just bringing IPv6's privacy back in line with IPv4, because without the privacy extensions every single device has a separate IPv6 address based on its MAC address whereas in IPv4 most consumer networks have every device sharing a single IP.



Is there a FOSS selfhosteable alternative to iLovePDF?


For those who don't know what iLovePDF is, it basically allows you to convert a literal equal copy of PDF into docx or a format more suited towards editing on LibreOffice/OpenOffice and some other things related to PDF, rarely losing some visual formatting when it does its usually related to the font but its not so often
Als Antwort auf Maicon

StirlingPDF converts from PDF to many thing including RTF, Word, and XML.


What webapps do you selfhost that aren't media/game servers?


Since selfhosted clouds seem to be the most common thing ppl host, i'm wondering what else ppl here are selfhosting. Is anyone making use of something like excalidraw in the workplace? Curious about what apps that would be useful to always access over the web that aren't mediaservers.
Als Antwort auf ChuckTheMonkey

I hear about people wanting alternatives to discord though I never got into using it too much personally, but does anyone know about whether or not Revolt chat is a good open-source self-hostable solution?
Als Antwort auf Donn

I've been testing MatterMost for a few days.

It's closer to Slack than Discord but has most of the same features.