Thanks for the link to go-sendxmpp. It’s nice to have an xmpp-native way to send notifications
- 2 Posts
- 19 Comments
I think they encourage that increased frequency by offering shortlived certs to begin with…
Although do note that normal certificates will reduce its lifetime to 45 days over the next few years
You can use
caddy reload -c /path/to/Caddyfileto reload the config midway through
For TLS I am looking into using CertBot and it appears there’s a module (https://github.com/desec-io/certbot-dns-desec) I can use that works for https://desec.io/ to handle my certs.
You can consider using lego-acme as well. It’s not too different, just that it comes prepackaged with a bunch of DNS providers including desec, so you don’t need to install an additional module.
Since Caddy is handling my certs automatically, how often would I want to renew my certs?
By default, certs are valid for 90 days so you’d wanna renew a bit earlier than that. There’s also the option to use 45-day certs or 6-day certs, depending on the profile chosen.
Would I be required to run the same command periodically to renew my cert?
Yes, but it’s better if you automate them, like Caddy did, and both Certbot and lego can do this well. I run lego via a cronjob which checks for the certs’ expiry, and renew it when it passes a certain deadline.
I am looking to hear any suggestions or experiences about different reverse proxies that are preferably free of AI
Not sure I can recommend anything from that list because I’m not familiar with them, but I’ve heard haproxy to be very performant.
You can consider selfhosting maubot + RSS plugin if you wanna keep using Matrix
stratself@lemdro.idto
Selfhosted@lemmy.world•SOLVED Issues with https certs locallyEnglish
4·1 month agoCaddy does certs by responding to ACME challenges on port 80 and 443. You need to forward those ports from the public internet back to Caddy, have you done that?
Edit: it seems like you’re doing DNS challenges. Did you compile Caddy yourself with the right plugins? Have you tested the API token work? Any Caddy logs?
stratself@lemdro.idto
Selfhosted@lemmy.world•Replacing Cloudflare Tunnel with a Selfhosted Towonel TunnelEnglish
7·1 month agoIt bundles WireGuard transport layer and a SNI reverse proxy natively, along with optional authentication. Good enough for beginners or people who need quick deployments.
stratself@lemdro.idto
Selfhosted@lemmy.world•QubesOS workstation + homeserver, and DANE for TLS without 3rd party companyEnglish
9·1 month agoHi, the sourcehut seems to be pretty interesting. If I understand it correctly, this DANE-without-root provides a TOFU model as an alternative to the normal case of verifying up all the parts of the domain levels, right? If feasible, maybe that could be nice to extend with other methods for OOB verification and key rollover
stratself@lemdro.idto
Selfhosted@lemmy.world•I measured the idle RAM of 19 self-hosted apps on identical hardware so you can size a VPS without guessingEnglish
10·2 months agoMost of the software are old versions, Forgejo 7 is like years ago now. Why are you running benchmarks on these versions and not the latest ones?
I do this albeit with Tailscale. Netbird/Tailscale would act as a node of your VPN and you can configure reverse proxy routes (via
tailscale serveor Netbird’s equivalent) from the VPS edge to the homelab. You can even do SNI passthrough and have TLS terminated at your home, if you want, though this can be a bit slowerAlternatively you can even expose stuff via their servers. Tailscale Inc calls this service Funnels, and Netbird should have similar offerings. It’s kinda like Tunnels but you gotta use their domains, so a VPS acts greater as a dedicated entrypoint.
Lastly yes you’d be exposing the service to the general public internet, so some basic security is needed. Netbird has a Crowdsec module integration, might wanna look at that one and set up rules/detections. Consider putting extra auth in front of Jellyfin, use Authelia or something with an auth screen. And only expose the stuff you need, not your internal dashboard or whatever admin UI.
yeah, it’s consuming. I believe a big part of this is due to Matrix’s HTTP sync-polling being more expensive than simply maintaining a TCP stream (which is what XMPP does)
In fact, since XMPP syncs in the background so well, I use Conversations as a UnifiedPush backend for Matrix. You can find another article here as well
stratself@lemdro.idto
Selfhosted@lemmy.world•[AIP] I am selfhosting Active Matrix Rooms which is helping users find activity in the matrix networkEnglish
4·3 months agoSince this is a selfhosting sub can you actually explain how you’re hosting it?
Hi, ntfy/another unified push backend is the third party. As in: it doesn’t just go between you and your server
Android notifications are notoriously difficult to get right. May I ask how is Nextcloud Talk currently implementing notifications? Is it through ntfy, a background service, or Google’s Firebase? Have you allowed background usage for both the push app and the chat app?
I use Matrix with Continuwuity and Element X, and it’s doable most of the time except for small bugs. If you disable federation, the resource usage should be minimal too. But it also requires a third party for push service which can be unreliable.
On the XMPP side, there is also Snikket which you could look into. It offers both a server (running modified Prosody) and a mobile client (modified Conversations). XMPP can run as an efficient background service on Android, so it’ll receive in-band notifications.
Regardless of options, one of the main problem I’m aware of is that Android variants tend to overkill various background app, leading to missed notifications. I think it’s better to debug on that aspect as well
stratself@lemdro.idto
Selfhosted@lemmy.world•NutriTrace v1.0.0-rc.54 released: Health Connect sync fix, local LLM proxy support, backup fidelity pass [AIP]English
2·3 months agoHow on earth do you have 54 release candidates, each of them adding significant feature, and not bumping your versions? Wouldn’t it be nicer to just put them on the main branch and cut a semver release every now and then? At least that’ll save on the frequency of posts here
stratself@lemdro.idto
Selfhosted@lemmy.world•what's the simple way to map services to subdomains instead of specifying the port number?English
3·3 months agoWhen you say “on each device” you mean this configuration would refer to the services running on that device right? Not that every client device needs to have this set up?
The device that runs multiple services will set that up, yes. Not the client.
All my web services use apache or lighttd. Do I use caddy just for this or do I have to figure out how to move each of them to use this web server?
Apache and lighttpd can both do the same thing that Caddy does (multiplex many services via subdomain names on port 80). Caddy is just simpler and hence recommended.
You can move all services to use Caddy, takes some learning but overall better. Alternatively, if you already set up apache/lighttpd for each of your services, you can put Caddy in front and do something like
http://service1.devicename.lan/ { tls off reverse_proxy localhost:<port-that-apache-listens-on> }Also does it work for non-web services, like ssh or samba? (Which wasn’t in my original question, I only thought of it now.)
No. Also, those should be running on their dedicated ports anyways
stratself@lemdro.idto
Selfhosted@lemmy.world•what's the simple way to map services to subdomains instead of specifying the port number?English
15·3 months agoUse Caddy on each device, with tls turned off. Basically
http://service1.devicename.lan/ { tls off reverse_proxy localhost:8000 } http://service2.devicename.lan/ { tls off reverse_proxy localhost:8096 }
If you can run WireGuard on all your devices, you may wanna set up a multihop node that forward outbound traffic to the VPN tunnel via that hub


Hi, I’ve been running something similar with Tailscale. Instead of traefik, you can use any other TCP proxy like nginx or caddy-l4, or even use
tailscale serveon the edge VPS as well. Do note that all of your listed services except Zola will make outbound requests, so it could be better to also exit node through the VPS (like the article did), as to avoid exposing your residential IP.As for the linked personas, you may wanna use one domain instead of two. Matrix homeservers can be resource-heavy for example, so maybe consider
@persona1:example.comand@persona2:example.comon a single server instead of having two resource hubs that does essentially the same thing. The same applies to GotoSocial and Lemmy. By the way, I recommend Continuwuity for the Matrix server :)Static sites don’t actively take up resources, so they can be on separate domains. But again you may wanna save some money, so maybe consider using
persona1/persona2.example.comsubdomains, or even pubnix-styleexample.com/~persona(1|2)paths!As for the Docker management frontend, I have no idea which one’s the best right now 😅 but do make use of Tailscale SSH feature to troubleshoot other parts of your machines as well. And as for updates, I just subscribe to RSS feeds to keep the important software updated. Highly recommend you do that too to check out changelogs yourself.