I came to say excactly that.
I came to say excactly that.
Immich itself is running on docker, so it’s the same than every other setup. For me it just makes more sense to run that on a separate VM than keeping all the docker containers in a same operating system due to backups, manageability, access control and so on, even if it costs a bit of memory to run a full operating system. Biggest consumers on the host process list are immich-api, postgres-processes and immich. Actual used memory is around 2,5GB for the whole system with ~5GB on buffers/cache.
But I often import hundreds of raw photos at a time from DSLR and/or 4K video footage from my drone and processing those takes quite a lot of memory. With less memory and slower drives the whole thing crashed when importing bigger batches to out of memory erros, but I suppose it could run just fine with even less than 4GB of memory, if the usage pattern is just to upload photos from your cellphone in a relatively slow pace.
It’s a full VM, so OS and docker creates some overhead, but before I upgraded the server it ran on far less resources and specially big imports were painfully slow. Also that’s just the number from proxmox console, so there’s likely some cache included, but stats show that the VM pulls over 10G every now and then with shorter spikes over 20GB of consumed RAM.
As I mentioned, it can run on way less, but it feels a lot more responsive when it has enough resources.
16GB of ram is a bit low for the load you’re planning. That can work, but Nextcloud and Immich are pretty hungry for memory. My immich instance right now is using 7GB of RAM and nextcloud uses a bit over 4. I have the hardware to give them pretty much all the memory they want, so those are not absolute minimum amounts, but I wouldn’t try to run either with less than 6GB allocated memory on my load (few users, about a terabyte of data on both).
With 16GB you can pretty much forget using ZFS, but that’s not a big loss. LVM works just fine and with thin provisioning you can use snapshots too just fine. Bigger SSD/NVME for drive cache would be good. And of course all-SSD setup would be nice, but that gets expensive pretty fast. Second ethernet port might be nice to have, depends on how you’re planning to build your setup. Otherwise that hardware looks pretty good, altough I’d search for something second hand. CPU is most likely a bit overkill for what you need, I have Xeon E5-2620 v3 @ 2.40GHz and it’s running on around 10% load most of the time.


You’re of course correct on that, but Mullvad the company gave (somewhat) clear news release that their company is against far right (or left or any ‘far’ direction) politics. I’m not a customer and I couldn’t care less about Mullvad, but I think it’s worthwhile to keep in mind that company isn’t the same than one of it’s founders.
Of course if that is a breaking point to you, feel free to vote with your wallet and I can very much understand the decision, but there’s very few fully reputable companies around so I can also understand if that’s not a hill to die on.


Don’t send spam, behave nicely, have proper configuration on postfix and dovecot, set up SPF and preferably DKIM, keep your domains reputation clean and so on. You’ll likely still end up on some lists, so you need to manually dig them trough and ask nicely for removal.
Self hosting email has a pretty bad reputation and many will strongly advice against it, but in reality it’s really not that bad. But email as a whole is more complex beast to manage than simple website or running Jellyfin for your family and friends. You need to understand how the mail routing side of things work (SMTP itself, authentication for it encryption included and so on) and also you need to understand how DNS works and how various entries are related to mail transport. Then you’ll likely want at least some kind of spam filtering and so on. And with email you’ll need to have proper backup scenario too so that you don’t lose the likely pretty important data. All of that is perfectly doable and it’s not as difficult as many claim it to be, but there’s a bunch of stuff you need to understand and implement all of them correctly.


There’s various permission errors on the log file, I’d start from those. Also your dovecot configs seem a bit funny to me, usually mails are not stored to user home directories with dovecot, but instead somewhere under /var, likely you’ll want /var/vmail. Logfiles are pretty good with these tools, so pay close attention to those.
And take your time to understand what the config options actually do. Too permissive configurations will get your sever to every spamlist on the world pretty quickly.


Fines are just the cost of doing business.
In theory fines in EU don’t have a ceiling. 10% fine of companys turnover with OpenAI (or any other company running on borrowed money) would be a pretty steep cost of doing business and I don’t think all (if any) of AI-hype entities could actually swallow that.
Obviously that’s just in theory, so far the fines have been a slight slap on the wrist, but mechanisms are in place to give actually meaningful fines for unethical practices. No one will go to jail tho, as EU doesn’t really have the power to jail US citizens.


That style stoves are pretty common around here on older buildings. We have one and it really helps during winter and cuts down the electricity bill, at least as long as we have enough firewood to keep that thing going.


The main material could be smashed/pulverized glass.
As in sand. Glass is recyclable material, it makes no sense to use that for this kind of application since sand is already everywhere. Also at least some flavours of glass can melt on temperatures used on these which I’d imagine could cause problems.
I hear aircrete is an insulation thats already prevalent in europe is this true?
At least here in Finland it is not. It could be, but it’s not really widely available right now. Maybe in the future, but that would need at least some changes on how things are built.


It’s interesting piece of technology, but it’s not ‘radical’. The company behind the storage has done their homework and they seem to be well engineered, but the “technology” itself is pretty much as old as bonfires, people have used hot rocks to heat up tents for ‘a while’.
But sand has pretty good thermal properties and size of these new iterations of old tech makes them pretty decent solution for energy storage with renewables. I’ve been following various ‘sand battery’ products for our own house, but the main problem with all of them tends to be the size required. In practise for our own house we’d need a sand battery roughly the size of 6m storage container (with heat pumps and all the other hardware) and that’d be so expensive that the investment wouldn’t pay itself back in my lifetime.


15% of GDP just from TLD is wild. But they have only ~10k people there, so makes sense that their GDP isn’t really high.
Montenegro is ‘a bit’ bigger country by GDP, so for them it’s a lot closer to rounding error.


Theoretically, yes. But .me domains are pretty cheap, ~10$/year from Joker and likely even cheaper elsewhere.
Just protecting for spoofed IP doesn’t add much in my opinion, at least compared to the effort of setting up and maintaining 802.1x. Easier way would be to set up different local networks per family and allow access to shared services via common firewall. That doesn’t require support from devices nor it doesn’t rely on security on them. Properly setting 802.1x would mean that you’ll need to manage every device on the network somehow and, assuming you don’t actually own or control the devices, that would be at least challenging.
Your thinking isn’t wrong, in that scenario network level authentication would help, but overhead of such setup is, again in my opinion, way more complex than what you can actually get in return. Of course if you want to just do it for the fun of it, go ahead. And also, if the devices are on the same network, they can sniff MAC addresses and IPs of neighboring devices, so protecting anything with just IP/MAC is a lost cause.
Radius is a part of 802.1x standard and for your threat model that does absolutely nothing. If a bad actor can access a device already in your network, then network level authentication doesn’t do anything. For example it prevents from someone randomly plugging their device in your switch and getting access that way, or it only allows verified clients to your WLAN. But once the network connectivity is already established you need a totally different tools.
Mainly that means firewall on your network and/or servers. There’s multiple ways to build that. You could get a separate firewall device to block access from the rest of the network to your devices or you can set up firewall for each of your things separately. All solutions have their own pros and cons and ‘correct’ solution depends on multiple variables.
Perhaps the easiest, and still at least decent, approach is to just run nmap (or any other port scanner) against your own subnets/IP addresses. That way you’ll at least find out if the firewall allows something trough which it shouldn’t, Also you can run tcpdump/wireshark on destination host to see if it receives packets it shouldn’t.
For client authentication, if ARP filtering is not enough, you could set up 802.1x, but that’s likely a massive overkill (and overhead) for home network. I personally don’t authenticate clients separately. Just WPA2 on wifi and firewall rules to allow/deny traffic between subnets. Sure, it’s pretty easy to bypass, but in practise you’d need to be inside the house to access some parts of the network. But my threat model is mostly about a handful of IOT things which I don’t trust with full network access, not about someone unauthorized getting access to my home network.


unless the data is off site, its not truely a backup
Two is one and one is none. No matter if it’s offsite or on top of your main server. Also 3-2-1 is an industry standard for a reason. Plus unless you test that you can actually restore your backups they don’t really exist (also known as Schrödinger Backups).


Don’t put words in my mouth. I didn’t say anything about not needing to be concerned, I was just interested on what kind of virus they cooked in the datacenter-incubator and how that might affect on a general population. “Deadly bacteria”, while not incorrect, is a bit clickbait-y, as it doesn’t just kill everyone and their dogs.
Of course there are reasons to be concerned and Meta should absolutely throw boatloads of money to clean up their mess. I was just interested about the bacteria in general, where it came, how it works and so on, nothing more and nothing less. I’m across the big pond and in here environmental regulations actually work, so I personally am not the one who should get angry about the situation, but it doesn’t mean that no one should, even if I don’t explicitly say so.


Yes, but infections are somewhat rare on healthy adults, at least based on a quick search around the net about the virus. If you have some underlying condition you’re more likely go get the infection in the first place and as your immune system is already weakened by something it’s going to be more dangerous.
Absolutely. And 1980s was about 20 years ago.