• 1 Post
  • 43 Comments
Joined 3 years ago
cake
Cake day: July 19th, 2023

help-circle




  • I’ve never used Netbird or casaOS. I run debian and docker containers. I would recommend looking at wg-easy as a VPN. it also uses wireguard but for me it just works. you open 1 port on UDP and route it to wireguard, it’s a secure way to access your network and is quite hard to detect from the outside.

    I’ve heard good things about caddy.

    “data at rest/LUKS” is something you should consider if your personally worried about someone physically trying to get information off your computer/server. if the server is running or an attacker gets into your system remotely, it doesn’t matter. as a beginner, I would determine if the data your saving is worth the extra headache of encrypted media, especially if something goes wrong/an update breaks something or your configs/setup messes something up. if you do, keep a copy of your decryption keys on a NEW USB drive (flash drives go bad) or printed out in addition to saved on your workstation/laptop/password manager.

    Personally for new systems I recommend Proxmox hypervisor instead of running directly on the laptop. having your debian OS/casa or whatever you use virtualized gives you the ability to take snapshots in time of your OS, makes backups easier and can help when you expand later (backup and restore on the new computer running proxmox). mine is: proxmox on bare metal old office PC

    • | debian > docker w/ portainer (I plan to replace portainer w/ komono)
    • | TrueNAS > S3 bucket application (garage)

    if Casa becomes limiting as you learn and grow, I would recommend docker compose stacks w/ a web gui like komono.

    one final note, although AI can be very useful for troubleshooting and getting some code to fix a problem (albiet logic/problem solving isn’t their strength) it’s awful for retaining knowledge and learning in the same way that using a calculator or other tool before fully understanding how to do addition/multiplication manually. I would strongly recommend taking some time to learn the basics without ai if your goal is to understand how everything works. resources to start with are using and reading “man + command”, command help flags, online courses and websites: https://linuxbasecamp.com/ https://explainshell.com/ - copy paste a command with all arguments and it tells you what it does. https://training.linuxfoundation.org/training/introduction-to-linux/







  • I’m not entirely sure about the technical differences but from my understanding VPN connections are preferred. From a security perspective, ssh has some more considerations since it’s easier to detect it’s open, and you should lock down root access and other privileged accounts. but SSH seems simpler to actually get working vs a VPN solution which would probably require a reverse proxy or something to get the TV working.

    For example, compromising a ssh service gives you access to the shell immediately vs wireguard or similar that historically (from my knowledge) has had fewer critical vulnerabilities that could lead to remote code injection or access. This is also why many corporate and best practices recommend layering ssh through a private VPN like IPsec, OpenVPN, wireguard, etc.

    in practice it’s most likely fine as long as

    • you don’t use root or an account with sudo to do the ssh forwarding
    • require a ssh key for all connections (at minimum any remote/internet connections)
    • update the system regularly. you can automate security updates with unattended upgrades on debian-based systems.

  • Are you connecting from a public network or something? like a hotel wifi or other?

    The easiest solution would be to setup the pi as your router and use a VPN like wireguard (wg-easy) or tailscale.

    if it is a public network, you can double NAT. There’s dedicated boxes like the GL.inet travel routers that support wireguard/openVPN and beta for tailscale. they have some features that work well with captive portals.

    If it’s a home network, you can probably use your PI as a entry/exit node or VPN client instead of using ssh.


  • wireguard is self hosted and you do have to “expose” one UDP port. From the outside it’s difficult to detect that this “opening” exists because wireguard just listens and ignores everything unless you send the encrypted credentials. Compared to hosting a webpage or jellyfin directly this is much more secure. As long as you keep wireguard relatively up to date you don’t really have to worry much about it.

    I personally use wg-easy. It’s designed to be deployed into docker (using docker compose is by far the easiest).

    Then you can either use your IP address, or ideally a dynamic DNS provider so you’d connect to myexample.com:51820. Duckdns is free, otherwise options are available like cloudflare. If you can get jellyfin working, this should be relatively straightforward.



  • I recently had to increase my proxmox storage as well from an old 256 to 1TB. What I did was make a copy of /etc via PVE Host Backup and saved that on my NAS/external storage. Almost everything is in /etc/pve. Then I created backups of all the VMs and stored those on the same external storage. I then installed proxmox as normal and compared configs between backup and new configs then restored VMs from backup. The reason I did it this way is because 1) I had installed proxmox a while ago and new config > old config for stability after adding some necessary PVE scripts (e.g. intel chip, and 2) I’ve had weird issues before cloning drives and a fresh install was easier than risking some weird edge case troubleshooting. It also let me keep the old SSD as a backup in case something went wrong.

    Edit: Also recommend going with zfs mirrored on the new install during the setup: target disks options and zfs mirrored. ZFS offers some benefits vs the default lvm.




  • 1GB is probably enough to run one basic service without a GUI. If you want anything more than that you’re going to probably end up running out of RAM and hitting the SWAP file–grinding everything to a snail’s pace. Useful projects here might be to add smarts to something dumb around the house or making an old printer support wireless printing via cups.

    Like others have said if you want to tinker, a virtual machine via virtualbox or VMware is free for your use case.

    If you strongly prefer hardware, an old PC will probably be cheap or free.

    If you really want a pi you’ll probably have to look for something that has at minimum 4Gb (which will be easy to outgrow), recommending 8GB+. Note that raspberry pi’s run best on the official power plug as a USB-a to micro/c won’t provide enough power to be stable and will cause weird issues or crash the pi under heavier loads or when drawing power from the pins.