• 0 Posts
  • 31 Comments
Joined 2 years ago
cake
Cake day: September 21st, 2024

help-circle






  • self hosted gitlab. each server has a repo with all the docker configs and application configs. also have any scripts for the server itself on there as well, things like required libs, network configs, etc.

    I also have a repo dedicated for let’s encrypt SSL that retrieves new certs every month. then on each server is an install script scheduled that pulls the certs down, installs them, and restarts any services automatically.

    should anything go wrong, I have a siem monitor that will alert me that a service failed to start etc.

    currently running four servers like this with varying degrees of complexity.



  • I wish it would because there’s no way to stop someone from creating an alt to promote their own projects and claim “they didn’t know it was AI” when they knew full well it was.

    It’s kind of funny how much people have to lie just to use a stupid tool. either you’re proud of using it and will stand by your decision to use it, or you don’t use it at all and don’t need to worry about backlash.

    IMO I think it would benefit both this community and those who want to use AI if there was a completely different community to post AI developed projects on.

    they win because nobody will shit on their posts, and we win because nobody has to read slop.


  • all the problems you expressed with docker aren’t real problems.

    I think you may not like it because you don’t know how to use it.

    don’t like how often a maintainer updates their images? build your own.

    don’t like having multiple bridge interfaces on your host? configure and manage networks within docker and assign them to your containers.

    don’t like having dozens of containers with random names? use docker compose. bonus, you can set up networking with it even easier.



  • something that can push at least 2-3 4K streams.

    12th gen i5 with 16GB DDR4. Maybe 32GB if I can swing it.

    unless you’re transcoding each stream that should work, at least for Plex.

    Currently running 10th gen i5 with 32gb of DDR and can run one 4k transcode, five 1080 streams, and four live TV streams. though, the transcode is laggy but if you pause and let it buffer it should work.

    keep in mind I’m also running headless transmission, a VPN, tor, and like 8 other services on the same server.

    if all you’re streaming is 4k, you will hit a point of diminishing returns on network throughput. I’d recommend getting a switch with SFPs and connect your server up to a 2.5gbe or even a 10gbe (though overkill but the sky is the limit). as long as all your stream boxes are connected through that switch on their regular 1gbe they should be fine.

    personally I run a opnsense router/firewall and have everything passed through an unlocked Brocade ICX6610-48P-E. you can find them on eBay. FYI, these are commercial units and are VERY LOUD. basement or attic installation is a must if you don’t have a network closet. bonus, the ICX6610 allows you to turn on/off POE per port and even set the voltage. this means you can power everything from cameras, stream boxes, wireless APs, to even some POE lights. it’s also a managed switch, which means you can split your ports up on VLANs and other really neat things.



  • a VLAN is assigned to a specific port on the same subnet.

    now I have to know which port is for that VLAN specifically.

    now I have to segment my network to ensure I know which IPs are on that VLAN.

    now I have to statically assign IPs.

    now I need to replace my router and rebuild everything.

    or I setup a separate network on a different subnet with firewall rules to ensure nothing can talk to anything outside of the private network and let dhcp do assignments.

    hmmmm…which one is easier to maintain… I wonder…

    VLANs literally exist because it would be too costly to run dedicated networking hardware in enterprise solutions. from a networking perspective in a selfhosting or small business environment VLANs are overkill and high maintenance.


  • A. Do you absolutely NEED the VLAN for your NVR? Why not just isolate the devices on the network with a bogus DNS record or FW rule blocking via MAC or IP?

    DNS doesn’t stop direct IP comms. I have seen a few devices that talked direct IP to bypass DNS blocks. as you said, a firewall rule is a far better solution.

    However, I don’t trust my Chinese cameras enough to not rootkit their way across my network, so it has to be quarantined. a VLAN is one way to successfully do that.

    personally I dislike the high maintenance costs of VLANs. That’s why I opted to run a completely different network for all my IOT devices including cameras. the DVR is on that network and proxied through a dual homed server that straddles the two networks. firewall rules in place that only allow specific ports through on specific devices to specific devices.