jrollans.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Site description
These are the voyag... uh, things I post about.
Admin email
jrollans@gmail.com
Admin account
@jrollans@jrollans.com

Search results for tag #selfhosting

AodeRelay boosted

[?]Daltux [ele/eles/he/them] » 🌐
@daltux@snac.daltux.net

:bah: MinIO, então, revelou-se outra empresa californiana que mantinha um modelo híbrido de licenciamento do software que desenvolvia e, na capitania do navio com uma extensa comunidade embarcada, resolveu abandoná-lo, voltando-se ao desenvolvimento de software totalmente privativo de liberdade. Pior, consta que fez isso para pular com os dois pés no inafundável supertransatlântico da dita inteligência artificial... :noAI:

Qual será a próxima? Desconfiemos de todo projeto com esse modelo híbrido "Community Edition" altamente merdificável. Tentemos focar no software livre e não nos deixemos enganar pela ladainha corporativa do chamado código aberto enquanto convém.

Felizmente, o que foi desenvolvido até então está publicado sob , algo que, por nos conceder as quatro liberdades essenciais para isso, garante à comunidade que qualquer parte interessada assuma a liderança do projeto para tirar o barco da deriva, digo, continuar seu desenvolvimento como derivado. Parece até que isso já começou. Contudo, como há outros projetos mais ativos com propósitos semelhantes, não há certeza de que seu desenvolvimento continuará.

A notícia já é antiga, de meses atrás, mas tomei ciência apenas hoje. A primeira vez que tive contato com esse programa e o utilizei foi muito recentemente, ao implantar meu servidor , de cuja documentação MinIO faz parte como armazenamento local. Agora vai ter que ficar assim, na última versão lançada, ao menos por algum tempo. Estava cogitando usar MinIO para mais funções, mas vou deixá-lo apenas para o armazenamento de objetos locais do Ente mesmo. Já devia ter usado algum outro sistema de armazenamento com API compatível com S3. Não é interessante começar algo com um componente importante já descontinuado. Lembrete a mim mesmo: mais atenção a dependências, na próxima vez! :blobCatThisIsFine:


    [?]Kai Draven 🍀🌄 » 🌐
    @mikolasan@cupoftea.social

    My philosophy of self hosting is that it supposed to be free. Despite, I already accepted the burden of paying for my domain.
    Some people turn into self hosting because of privacy concerns or branding. But I mainly suffer from the lack of customization.
    For example, with emails, I don’t really use them, but I receive spam and I want to filter it smartly

      AodeRelay boosted

      [?]Kai Draven 🍀🌄 » 🌐
      @mikolasan@cupoftea.social

      I am really upset by my attempt to self host a mail server. So it’s not about configuration complexity. That went fine with a good docker setup that I chose. But what is failing me is that port 25 is blocked by my home Internet provider and by cloud service provider.

        AodeRelay boosted

        [?]BlablaLinux » 🌐
        @blablalinux@mastodon.blablalinux.be

        🛡️ Retour d'expérience : chasse aux bots et scrapers derrière Nginx Proxy Manager

        Au programme : architecture custom-block.conf + ai-blocklist.conf, un bug silencieux qui neutralisait tout le blocage, et les patterns observés en live (bots IA, scrapers SearXNG, Tencent Cloud, scanners credentials AWS/GCP...).

        Note technique complète ici 👇
        joplin.blablalinux.be/shares/S

        [?]Owl Eyes » 🌐
        @d1@autistics.life

        @labellaragassa It's a bunch of tradeoffs. There are acceptable solutions where trust is warranted, but they're less convenient, and require more skills. How far down the rabbit hole of inconvenience are you willing to go, to satisfy more of your ideals?

          [?]Owl Eyes » 🌐
          @d1@autistics.life

          @Aethel @jwildeboer @mullvadnet @rysiek I for one use a lot, but I also have and administration skills, and run these on my own VPS'.

          PiVPN (and ) is software, is not a business per se. I subscribe to a VPN service which I provide to myself.
          Serious geek skills allow for this.

          **The point being: If people want to divorce and indemnify themselves from underlying politics of any provider, this is how at least one "middleman" is eliminated, IMHO.** If one feels like one can't trust any VPN provider, then at the end of the day, one needs to learn more skills.

          There needs to be some trust, somewhere.

            AodeRelay boosted

            [?]Jools » 🌐
            @jools@friendica.de

            Da ich gestern auch auf angesprochen wurde...

            Nicht jeder hat die Möglichkeit oder das Interesse an SelfHosting. Aber wenn man es "kann" und sich ein wenig unabhängiger machen möchte - es gibt viele Möglichkeiten!

            Kleines persönliches Beispiel von mir:

            Angefangen hatte ich mit einem ausgedienten Raspberry, auf der ich Nextcloud installierte. Mittlerweile - mit mehreren Zwischenstationen - steht bei mir daheim mit allen selbstgehosteten Diensten ein ausgedienter, gebrauchter Lenovo ThinkCentre, den ich letztes Jahr geschenkt bekommen hatte. Da wir noch eine dazu passende CPU hatten, bekam der ThinkCentre ein feines Upgrade auf einen i7. 😁

            Darauf installiert ist Debian in der Minimal-Konfiguration und - weil ich es mir einfach machen wollte - Docker. Darüber habe ich u.a. installiert:

            Zusätzlich werkelt darauf auch noch eine , allerdings nicht über Docker installiert. Ein ist darauf ebenfalls installiert sowie ein zum zocken. 😎

            Das alles nutze ich mal mehr, mal weniger.

            Gerade bezüglich der Suchmaschine SearXNG war ich erst echt skeptisch. Aber ich nutze diese nun schon über ein Jahr und bin sehr, sehr zufrieden damit. Die Ergebnisse sind nicht - wie bei Google z.B. - voll mit zusammengefassten KI-Ergebnissen, die kein Mensch sehen möchte, sondern mit "echten" Ergebnissen.

            Meine Fotos landen allesamt bei Immich - eine wundervolle Software, die ich gerne nutze. Auch die OpenCloud, deren Anfänge ich miterleben durfte, hat sich sehr etabliert und ist für meine gesamten Daten absolute Nummer 1 bei mir, da sie schnell und zügig lädt und Collabora Online als integriert hat.

            Auch Bookstack finde ich super nützlich. Wenn ich Änderungen an der Konfiguration der Server vornehme, trage ich diese Änderungen mit Datum und Uhrzeit hier ein und kann später so nachsehen, was ich wann geändert habe. Ebenso habe ich mir in Bookstack Anleitungen hinterlegt, tägliche Checks, die ich auf den Servern durchführe und weitere Dinge, die ich einfach nur schnell per Copy & Paste ins Terminal einfügen kann.

            Am Lenovo ThinkCentre angeschlossen habe ich 3 2,5 Zoll HDDs.

            Thema Sicherheit: Das alles ist nur für mich in meinem lokalen Netzwerk erreichbar. Ausschließlich. Zusätzlich ist der Login abgesichert mittels (ein kleiner, physischer Hardware-Sicherheitsschlüssel).

            Trotz all dieser Maßnahmen bin ich nach wie vor noch an einige Dinge gebunden. So nutze ich z.B. Proton. Auch habe ich meine persönliche Daten an mehreren Stellen als Backup hinterlegt, auch online, nicht nur bei mir selbstgehostet daheim.

            Wer technisches Interesse und Verständnis hat, kann also auch diesen Schritt gehen und ein wenig unabhängiger werden, um von Google und Co. wegzukommen.

            Und wer noch einen Schritt weitergehen möchte, kann natürlich auch seine ganz eigenes Mastodon, Friendica o.ä. auf seinem Heimserver installieren - auch das ist gut umsetzbar. So kann man sich noch einen Schritt unabhängiger machen. Die Möglichkeiten, digital unabhängiger zu werden sind groß - man muss es nur umsetzen! 😉

            , , , ,

              [?]al » 🌐
              @alan@lighthouse.co.im

              Wrote up why lighthouse.co.im finally moved from bare metal to Docker Compose -- and why it took a toot from @adamhavelka to make me look at my own setup properly.
              The short version: the bare metal wasn't ideology, it was Certbot trauma. Caddy fixed the actual problem.
              One database migration did not survive the journey. Now documented so you don't have to rediscover it.
              haunted.lighthouse.co.im/artic

                AodeRelay boosted

                [?]Jools » 🌐
                @jools@friendica.de

                Wenn man sich größtenteils nur mit US-Alternativen, digitaler Unabhängigkeit, SelfHosting usw. auseinandersetzt und dann auf Menschen trifft, die den ganzen Sinn dahinter nicht verstehen (wollen)... das ist schon schwer.

                Spätestens wenn dann aber die wiederholte Frage auftaucht, warum man nicht bei "renommierten Anbietern" (Facebook und Co.) bleibt und sämtliche Erklärungsversuche als "Nerdkram" oder "Spinnerei" abgestempelt werden bin ich ja thematisch sowas von raus... 😂 Aber: Ich versuche niemanden, zu seinem Glück zu überreden!

                Deswegen: Aufklärung ist weiterhin wichtig, viele Menschen haben immer noch nicht verstanden, warum der heutige DiDay so wichtig ist.

                Noch wichtiger: Man muss nicht auf den nächsten DiDay warten, sondern kann jederzeit loslegen! Interessierte sollten in den für sie vertretbaren Schritten und Tempo ihren Wunsch nach Alternativen umsetzen können, man kann dabei beratend unterstützen, sollte aber niemals jemanden dazu überreden.

                , ,

                  [?]Larvitz :fedora: » 🌐
                  @Larvitz@burningboard.net

                  Had the problem on my DN42 (a distributed overlay network, that is sperated from the internet), that my FreeBSD servers couldn't update without hacky firewall tricks (NAT etc.)

                  Did now finally solve that cleanly with a single caching Nginx server that is dual-homed (internet+dn42) and that enables me to use freebsd-update AND pkg from systems that only have DN42 connectivity :-)

                  Also add that to the DN42 wiki and offer others to use it as infrastructure!

                  bsdmirror.chofstede.dn42 (IPv6-only by design)

                    [?]Larvitz :fedora: » 🌐
                    @Larvitz@burningboard.net

                    New blog post: Ansible-Native Quadlets: Deploying a Mastodon Greeter Bot with containers.podman

                    Hand-written Quadlet files are great for one host. For a small fleet, I want them in Ansible: templated config, registry login, Podman secrets, systemd handlers, SELinux labels, and repeatable deployment.

                    The example: a tiny Mastodon welcome bot running as a Podman Quadlet-managed systemd service.

                    blog.hofstede.it/ansible-nativ

                      AodeRelay boosted

                      [?]Bernd » 🌐
                      @hopfigkeit@nb-fedi.de

                      There's something about the blinkenlights when zfs is resilvering a new drive, knowing that during that time a second drive could fail without loss of data or availability.
                      #homelab #zfs #selfhosting #NetBSD

                      Alt...The front of a black server with 8 vertically mounted quick-exchange drive sleds, their LEDs blinking.

                        AodeRelay boosted

                        [?]Daltux [ele/eles/he/them] » 🌐
                        @daltux@snac.daltux.net

                        Minha instância de Ente Fotos, implantada no fim de semana passado, populada aos poucos com o que tinha em tornozeleiras eletrônicas de bolso e armazenamentos locais incluindo o que já esteve em nuvens usurpadoras, está bombando: 122GB no momento, em no próprio VPS, e crescendo. Agora que isso ficou sério (não estava conseguindo mais armazenar tudo aqui), vou ter que ir atrás de mais salvaguardas, neste fim de semana. Recomendações são bem-vindas, tanto de armazenamento remoto quanto possivelmente de montar um local. Só não hospedo literalmente tudo aqui com um VPS mais próximo só para proxy reverso porque a conexão não é suficientemente estável.


                          fedicat boosted

                          [?]FediHost » 🌐
                          @fedihost@mstdn.social

                          RE: mstdn.social/@fedihost/1168173

                          All instances have been upgraded to v4.6.2 !

                          Thank you for your patience.

                          If you notice any issues please let us know.

                            AodeRelay boosted

                            [?]🏳️‍⚧️ Christin Löhner 🏳️‍🌈 » 🌐
                            @christin@lsbt.me

                            APBoard ist zurück.

                            Das erste offizielle APBoard Release war am 13. Oktober 2000. Der letzte klassische Stand folgte am 19. April 2006. Exakt zwanzig Jahre später ist APBoard v3.0.0 der Punkt, an dem das Projekt wieder lebendig wird.

                            Das ist wichtig, weil APBoard nie nur ein Ordner mit altem PHP Code war. Es hatte Nutzerinnen und Nutzer, Installationen, Supportforen und Spuren, die bis heute existieren. Die neue Version hält am einfachen Versprechen von damals fest: eigenes Forum betreiben, Daten behalten, Code lesen, Code ändern, wenn es nötig ist.

                            APBoard hat einmal echte Communities getragen, darunter ein Teil des Deutschen Bundestags, die Spieleschmide Ubisoft, oder auch rcpanzer.de, wo APBoard und APPortal Geschichte sogar noch heute sichtbar ist. Version 3 gibt dieser Linie wieder eine gepflegte Zukunft.

                            APBoard v3 ist der vollständige Neuaufbau ab Juni 2023. Gleiche Seele, moderner Kern. GPL-3.0, PHP 8.5, Twig, Docker – und ein Sicherheitsstandard, der sich nicht hinter kommerziellen Produkten verstecken muss.

                            Mehr Infos: apboard.de/

                              AodeRelay boosted

                              [?]Fox Ritch :fjoxicon:🇩🇪 » 🌐
                              @fox@social.hostnetwork.xyz

                              I wish i could connect 2 proxmox servers without all the bullshit of clustering

                                [?]Michael » 🌐
                                @michael@mstdn.thms.uk

                                Anyone got recommendations for a self hosted blog?

                                Currently I’ve got my posts in markdown in a git repo together with some templates, and push this to omg.lol through their API.

                                I’m after something that would replicate that ‘DX’ for me: Ideally I’d want to be able to run the whole thing in a Forgejo Action, and then only spit out static HTML/CSS.

                                I don’t want all the URLs to change either so probably need some custom routing.

                                And I don’t want anything with too steep a learning curve.

                                Any suggestions?

                                Thanks in advance.

                                  AodeRelay boosted

                                  [?]Paul Chambers🚧 » 🌐
                                  @paul@oldfriends.live

                                  Doing more self-hosting. Finally killed the hosting account I've had since 2001 that managed my email and several domains. Losing it was like losing a limb of my body. It took a bit to pull the trigger.

                                    fedicat boosted

                                    [?]FediHost » 🌐
                                    @fedihost@mstdn.social

                                    instances are being updated to v0.21.3

                                    Your instance might be unavailable for no longer than 10 minutes while the update is ongoing.

                                    Thank you!

                                      [?]Saoirse Dulip [Whatever You Like] » 🌐
                                      @SitaDulip@gamepad.club

                                      So I have a server of my own that I would like to put a blog on. Does anyone know of, or recommend, any free blogging software I can load onto my Apache server? Or where to start looking?

                                        AodeRelay boosted

                                        [?]Yehor 🇺🇦 » 🌐
                                        @yehor@mastodon.glitchy.social

                                        Meanwhile, ~24 hours left until media storage migration from object storage to a cluster. I'm starting to get nervous.

                                          [?]🏳️‍🌈 leberschnitzel 🏳️‍🌈 [He / Him] » 🌐
                                          @leberschnitzel@existiert.ch

                                          My fellow enthusiast and specialist: I currently have two small server racks with a UPS each. Next year I probably get solar on my roof and get a battery: Would that make the UPSs unnecessary, or is there an advantage of having the UPS still in my setup? They are currently Line Interactive, and my hardware doesn't have a problem with this.

                                            [?]José M. Requena Plens » 🌐
                                            @jmrplens@mstdn.jmrp.io

                                            🔧 MCP retira 3 funciones del core en su próxima revisión (RC 2026-07-28, SEP-2577): Roots, Sampling y Logging.

                                            Deprecadas, no eliminadas: siguen funcionando ≥12 meses (lifecycle SEP-2596).

                                            Migración:
                                            • Roots → params de tool / resource URIs
                                            • Sampling → API del LLM directa o MRTR
                                            • Logging → stderr / OpenTelemetry

                                            Yo los tenía implementados en mis MCP… toca planificar.

                                            ¿Tú usabas alguno? 👇

                                            Infografía técnica sobre fondo oscuro, slide 1 de 2. Cabecera: Model Context Protocol, etiqueta «SEP-2577 · FINAL». Titular: «MCP retira 3 funciones del protocolo». Se listan las tres funciones deprecadas con sus métodos: Roots (roots/list y notifications/roots/list_changed), Sampling (sampling/createMessage) y Logging (logging/setLevel y notifications/message). Un aviso en verde indica «Deprecadas, no eliminadas: siguen plenamente funcionales durante al menos 12 meses, sin cambios a nivel de protocolo». Línea temporal de tres pasos: deprecada en la próxima revisión de la spec (RC 2026-07-28); soporte de al menos 12 meses en cada versión (SEP-2596); posible retirada no antes de mediados de 2027. Fuente: modelcontextprotocol.io/seps/2577.

                                            Alt...Infografía técnica sobre fondo oscuro, slide 1 de 2. Cabecera: Model Context Protocol, etiqueta «SEP-2577 · FINAL». Titular: «MCP retira 3 funciones del protocolo». Se listan las tres funciones deprecadas con sus métodos: Roots (roots/list y notifications/roots/list_changed), Sampling (sampling/createMessage) y Logging (logging/setLevel y notifications/message). Un aviso en verde indica «Deprecadas, no eliminadas: siguen plenamente funcionales durante al menos 12 meses, sin cambios a nivel de protocolo». Línea temporal de tres pasos: deprecada en la próxima revisión de la spec (RC 2026-07-28); soporte de al menos 12 meses en cada versión (SEP-2596); posible retirada no antes de mediados de 2027. Fuente: modelcontextprotocol.io/seps/2577.

                                            Infografía técnica sobre fondo oscuro, slide 2 de 2: cómo migrar. Titular: «Las alternativas fuera del protocolo». Tres bloques, uno por función deprecada. Roots (roots/list): por baja adopción y semántica vaga; migrar a parámetros de tool, resource URIs o configuración y variables de entorno. Sampling (sampling/createMessage): por ser compleja y la función más sensible en seguridad (prompt injection, exfiltración); migrar a llamar la API del LLM directamente desde el servidor, o usar Multi Round-Trip Requests (SEP-2322). Logging (logging/setLevel): porque ya existe infraestructura más madura; migrar a stderr en transportes stdio, u OpenTelemetry. Aviso final en azul: «Menos superficie de ataque: un core más mínimo y auditable, apoyado en estándares ya consolidados». Fuente: modelcontextprotocol.io/seps/2577.

                                            Alt...Infografía técnica sobre fondo oscuro, slide 2 de 2: cómo migrar. Titular: «Las alternativas fuera del protocolo». Tres bloques, uno por función deprecada. Roots (roots/list): por baja adopción y semántica vaga; migrar a parámetros de tool, resource URIs o configuración y variables de entorno. Sampling (sampling/createMessage): por ser compleja y la función más sensible en seguridad (prompt injection, exfiltración); migrar a llamar la API del LLM directamente desde el servidor, o usar Multi Round-Trip Requests (SEP-2322). Logging (logging/setLevel): porque ya existe infraestructura más madura; migrar a stderr en transportes stdio, u OpenTelemetry. Aviso final en azul: «Menos superficie de ataque: un core más mínimo y auditable, apoyado en estándares ya consolidados». Fuente: modelcontextprotocol.io/seps/2577.

                                              [?]Dima » 🌐
                                              @dima@dol.social

                                              Second incident with my OVH VPS in the Zürich local zone today.

                                              The first incident was a network problem - dol.social/@dima/1167812608375

                                              This time their super resilient storage failed.

                                              The first image is from the KVM console. It shows many I/O errors on the disk device sda1.
                                              The EXT4 file system aborted the journal and remounted as read only.

                                              The second image is from the OVH panel.
                                              It says Remote storage Resilient is included (haha).

                                              The third image is my monitoring graph.
                                              It shows 4 hours of downtime on June 19 (due to the network issues).

                                              The fourth image shows another downtime today. It lasted 2 hours.

                                              Super resilient storage does not look very reliable right now.

                                              Has anyone else seen problems with OVH storage or local zones? That's insane. 7h downtime per week.

                                              Terminal screenshot with Linux kernel logs. Multiple I/O error messages for device sda1. EXT4 file system shows journal errors. The system remounted the file system in read only mode.

                                              Alt...Terminal screenshot with Linux kernel logs. Multiple I/O error messages for device sda1. EXT4 file system shows journal errors. The system remounted the file system in read only mode.

                                              OVH VPS settings screenshot. Storage type is Remote storage Resilient. It is marked as included.

                                              Alt...OVH VPS settings screenshot. Storage type is Remote storage Resilient. It is marked as included.

                                              Monitoring chart showing response time in milliseconds for June 2026. Several lines for different locations. Big red bars indicate downtime on June 19 with a 4 hour outage. A tooltip shows average response time of 857 ms and high values for some cities.

                                              Alt...Monitoring chart showing response time in milliseconds for June 2026. Several lines for different locations. Big red bars indicate downtime on June 19 with a 4 hour outage. A tooltip shows average response time of 857 ms and high values for some cities.

                                              Monitoring chart screenshot focused on June 23 2026. It shows a red downtime marker for 2 hours. A tooltip details the incident with average response time of 855 ms. Latencies listed for Miami 951 ms. Sydney 1.26 s. Helsinki 544 ms. Roubaix 581 ms. Frankfurt 823 ms. Los Angeles 980 ms.

                                              Alt...Monitoring chart screenshot focused on June 23 2026. It shows a red downtime marker for 2 hours. A tooltip details the incident with average response time of 855 ms. Latencies listed for Miami 951 ms. Sydney 1.26 s. Helsinki 544 ms. Roubaix 581 ms. Frankfurt 823 ms. Los Angeles 980 ms.

                                                AodeRelay boosted

                                                [?]Rad Web Hosting » 🌐
                                                @radwebhosting@mastodon.social

                                                How to Install on Easily In this tutorial we are going to show you in detail how to install Gitlab on AlmaLinux VPS.
                                                What is GitLab?
                                                GitLab is open-source written in Ruby, Go and JavaScript operated by GitLab Inc. GitLab offers a wide range of features such as CI/CD (Continuous Integration, Continuous Delivery) which makes the work of ...
                                                Continued 👉 blog.radwebhosting.com/how-to-

                                                  [?]The Unknown Universe » 🌐
                                                  @unknownuniverse@unkn.uk

                                                  Starmer is out, but the surveillance contracts aren't going anywhere.

                                                  Politicians love the theatre of a resignation, but the "Online Safety Act" is still a rigged market. It’s a vicious circle: private firms help write the laws, then "win" the contracts to fix the problems they invented.

                                                  https://the.unknown-universe.co.uk/privacy-security/vicious-circle/

                                                  #Privacy #UKPolitics #DigitalID #CyberLinkUK #SelfHosting #FOSS #OnlineSafetyAct

                                                    AodeRelay boosted

                                                    [?]rootwerkstatt » 🌐
                                                    @rootwerkstatt@mastodon.social

                                                    Neuer Artikel: Sunshine und Moonlight – Spiele vom PC auf den Fernseher streamen – rootwerkstatt.de/sunshine-moon

                                                      [?]Netzblockierer » 🌐
                                                      @Netzblockierer@tech.lgbt

                                                      @mysk don't believe for a second WhatsApp ever had E2EE at all.

                                                      • Same for Signal, Telegram, Threema, Matrix, etc…

                                                      If you can't

                                                      • self-host it's servers,reproduceably build servers & clients
                                                        • dev. your own servers and clients w/ feature parity.
                                                      • as well as use it without self-doxxing aka. needing a Phone Number,

                                                      it's insecure!

                                                      Because Phone Numbers are intrinsically insecure, as they can always be linked to a device [Number->SIM->ICCID->IMEI) / client (SIP uses UDP = no Tor!) and thus trivially connected by circumstances to a person!

                                                      So go with PGP/MIME ( @delta & @thunderbird and/or XMPP+OMEMO ( @gajim and/or @monocles ) over @torproject!

                                                        [?]The Hat Fox » 🌐
                                                        @thehatfox@mastodonapp.uk

                                                        Do any folks know of a good solution for note taking that includes pen/drawing support?

                                                        I’m considering options to move away from Apple Notes, but pen support for drawing diagrams etc is essential for me. Apple Notes does this well with the iPad version, but I’d like to find something more cross platform.

                                                          AodeRelay boosted

                                                          [?]DeltaLima 🐧 » 🌐
                                                          @DeltaLima@social.la10cy.net

                                                          Check_MK 2.5.0 is a nice update. Feels waaay more snappier and the "facelift" looks nice :)

                                                            [?]asmw [he/him|they/them] » 🌐
                                                            @asmw@infosec.exchange

                                                            I just sent my first mail from my new Yunohost VPS, and it did not get flagged as spam! :)

                                                            Now to try some apps.

                                                              🗳

                                                              [?]weed stallman » 🌐
                                                              @incentive@mastodon.circlewithadot.net

                                                              [?]ay » 🌐
                                                              @ay@polymaths.social

                                                              Building a immich only box thinking of going debian and btrfs any other ideas or tips?

                                                              It's a 8th gen nuc


                                                              Tia

                                                              #selfhosting #immich #server #debian

                                                                AodeRelay boosted

                                                                [?]Matt :nixos: :wayland: » 🌐
                                                                @thelinuxcast@fosstodon.org

                                                                [?]I Value the Goose [He/Him] » 🌐
                                                                @paco@infosec.exchange

                                                                I built my pool controller on so that I could control it with . Worked great. I was so proud. It had been the least reliable bit of in the house. (Because it was the bit that I had the majority role building 😜)

                                                                Then a combination power strike/UPS failure took out my running . That NEVER happens. So instead of being super convenient, I spend my weekend trying to rebuild the NAS.

                                                                I lost one of the pair of NVMe boot drives and at least one of my SAS spinning rust drives is not working. “zpool import -F -n hope” runs for about 30 seconds and then I get a kernel panic and reboot. I am not a happy camper.

                                                                  AodeRelay boosted

                                                                  [?]Larvitz :fedora: » 🌐
                                                                  @Larvitz@burningboard.net

                                                                  New post: Monitoring our FreeBSD Mastodon instance.

                                                                  burningboard.net runs as a stack of Bastille jails on FreeBSD, so I watch it from a separate box with Prometheus, Grafana and Loki. The interesting part is the FreeBSD-shaped gaps: no native ZFS metrics, nothing for the Mastodon API or our S3 media bucket. A small textfile collector fills all of it.

                                                                  This is how I keep an eye on the very instance I'm writing this on:

                                                                  blog.hofstede.it/monitoring-a-

                                                                    [?]I Value the Goose [He/Him] » 🌐
                                                                    @paco@infosec.exchange

                                                                    One of my (adult) sons is very technical. Chip off the old block. I'm troubleshooting a problem with my NAS, and he's helping. We identify one of the 2 boot NVME drives as a culprit. When it's in the system, it doesn't boot. Cool.

                                                                    So he says:

                                                                    "I'm going to mark this one with a sharpie until we're sure it's bad."

                                                                    "Ok"

                                                                    "Oh, this stupid sharpie doesn't work, I'm gonna go get one that works."

                                                                    "Good. And throw the broken one out."

                                                                    Son proceeds to throw the NVME drive in the trash.

                                                                    I figured it out when I asked "hey, where's that NVME drive you marked with a sharpie?"

                                                                      AodeRelay boosted

                                                                      [?]Rolle Laukkarinen » 🌐
                                                                      @rolle@mementomori.social

                                                                      What many people misunderstand about hosting your own content (like this social media instance) is thinking we somehow NEED a big audience or Big Tech involvement.

                                                                      I'm perfectly fine if the world faded away and it was just the thousand of us here. It's like the early days of the web when we had small forums, nobody missed Reddit back then. Federation is a big plus, not a requirement.

                                                                      It's the same with websites or IRC for me. I know people use Discord, but I still stick to IRC even if there are only about a hundred of us left. I know people use AI now and website visitors are dropping, but who cares? I still keep doing it for those who like to read.

                                                                      I don't need the whole world involved for this to feel worthwhile. It's mine, I own it, and I host it for as long as I breathe. After that, it won't matter to me anymore, but I hope other admins keep things running the way I did.

                                                                        [?]Geoff » 🌐
                                                                        @sternecker@infosec.exchange

                                                                        Velvet Ant's "Operation Highland" doesn't exploit a CVE for persistence, they replaced trusted binaries: trojanized pam_unix.so + backdoored ssh/sshd/scp that take a hardcoded password and log creds. No patch fixes a swapped binary; the defense is file integrity.
                                                                        On Debian:
                                                                        dpkg -V libpam-modules openssh-server openssh-client

                                                                        No output = your auth stack matches the package DB.
                                                                        Then confirm /etc/ld.so.preload is empty.

                                                                        Installing debsums enhances the file integrity checking!!

                                                                        Scripted it to check files they swap + flag any unowned .so in the PAM dir.

                                                                        github.com/sternecker/midil/bl

                                                                        My personal GIT Repo is not public.. that is on my ToDo list.