• 0 Posts
  • 23 Comments
Joined 2 years ago
cake
Cake day: January 22nd, 2025

help-circle

  • I’ve had good success spinning up an authentik instance, and having my reverse proxy hit it first before it routes to the actual app. Puts another security layer in front in case sonarr itself has an issue, for ex.

    Caddy snippet

    
    handle {$host} {
    		route {
    			# always forward outpost path to actual outpost
    			reverse_proxy /outpost.goauthentik.io/* authentik-server-1:9000
    
    			# forward authentication to outpost
    			forward_auth authentik-server-1:9000 {
    				uri /outpost.goauthentik.io/auth/caddy
    
    				# capitalization of the headers is important, otherwise they will be empty
    				copy_headers X-Authentik-Username X-Authentik-Groups X-Authentik-Entitlements X-Authentik-Email X-Authentik-Name X-Authentik-Uid X-Authentik-Jwt X-Authentik-Meta-Jwks X-Authentik-Meta-Outpost X-Authentik-Meta-Provider X-Authentik-Meta-App X-Authentik-Meta-Version
    			}
    			
    			reverse_proxy {this_host_or_ip}:{this_port}
    		}
    }
    
    

    Not gonna solve all your problems. Works for 70% of apps. Nice to slap on when you can.



  • Star ratings and smart playlists! Oh my! I love this stuff. Im currently using plex, which allows for half stars since im a masochist

    I dont know that I need the full ten options, but 5 wasn’t quite enough for me. If there was like 7 star system id do that, hah.

    • 0.5 - I would delete if other people weren’t listening to the library. Never play again
    • 1 - on my shitlist. Unless something changes, will probably go to 0.5 stars the next time I hear it.
    • 1.5 to 2 - Not opposed, but forgettable or slightly not my style
    • 2.5 - average content. Not memorable but fine
    • 3 - solid content, still not memorable
    • 3.5 - the good stuff. I’ll put it on a solo car ride and generally not skip
    • 4 - Amazing songs. If I was to put a Playlist on for other people and not worry about it
    • 4.5 - Favorite songs. Maybe a fault or two but will still stay with me for a lifetime
    • 5 - Id play these for anyone without hesitation and then look at them and say “was that not perfection?!”

    For smart playlists:

    • playlists by star rating
      • alts for excluding facemelting stuff to play in public
    • Car ride - 3.5 stars and up + havent heard in a month
    • “Frontier” playlist. Only play things i havent heard in a year that aren’t 0.5 stars

    I generally listen to my frontier Playlist and try to rate as I go. Other playlists for when im listening but busy and just want the good stuff.

    I havent found a good way to tag on the go, unfortunately. Maybe someday



  • Posted in a similar thread

    My baseline is a public VPS with Pangolin/Crowdsec installed. I have authentik as a login system. Pangolin let’s me put authentik in front of any service so they have to log into it before it gets to the service in question whatsoever. This is different than the app itself just using Authentik as the OIDC provider. Helps give a bit of peace of mind with the services which themselves might not be security focused. Also, these pangolin routes are able to block anything outside my country by rules, so that trims a good portion of attacks as well.

    Some things don’t like that authentik layer in front though. Audiobookshelf’s phone app for example cant handle it. For that, I route those domains through cloudflare tunnels. Their tunnels do a good job blocking lots of attacks, so not having authentik in front is more acceptable.

    But then there’s jellyfin that doesnt want to be on cloudflare tunnels and doesnt want authentik in front. For that, I just have it on my pangolin side with only crowdsec helping. Not ideal, but best I can do without making my grandma install a VPN on a raspberry pi in so her TV can connect or some shit.

    And lastly, I have some private services like forgejo that don’t like authentik in front and only I myself care about. I tailscale to those rather than exposing sometimes.



  • Looks like a cool idea! I could see the mappings getting out of hand real quick if you actually braindumped everything in there. I think it needs some more collapsing functionality so i can close sections when im not focused on them.

    True, everything is everywhere and this aims to put everything in one place… but that can be equally detrimental to ALWAYS have everything in one place. I guess you have some “control” in how far you put things from each other, but probably needs more tooling besides that for organization and especially “archiving”.



  • It’s set up on the same box as my caddy install. I believe it’s getting passed the real IP because that’s what gets banned, and what I type in to unban it.

    It just sees normal operations as http probing. Like if some other service goes down, my GetHomepage will then 404 and that’s seen as probing. It bans surprisingly quick. Even after just one or two events (normal for someone just visiting the homepage) it’ll just kick em right out

    I’ve been having to inspect every alert and hand write whitelist parsers to whitelist 404s or whatever it may be for that app. Slowly accumulating a workable collection… but seems like I’m missing something as no one else seems to complain about this in threads like these

    Another example is my brother got banned for normal audiobookshelf usage. He just thought the server was buggy. It was just blocking him without us really noticing or thinking much of it at the time. Not great


  • I’ve been using crowdsec … but I’ve yet to see anyone banned but myself so far. Is everyone else having to write tons of whitelist parsers? I could whitelist my IP but I feel like that’s sidestepping the issue and doesn’t address friends/family also getting banned, coffeeshops, etc.

    Feels like I’m missing something as so far it’s been quite a pain to configure








  • Noggog@programming.devtoSelfhosted@lemmy.worldReplacing Spotify
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    1 year ago

    Definitely a cool project! Can crack it open to get some API insights. The goals don’t quite line up for me, as I eventually want to actually get the tracks into my Plex setup. Additionally, I’m after a more “assisted curation” where I actively consider new artists and thumbs 👍👎 to let them through, rather than trying to make a radio type feature that passively plays new stuff.


  • It’s on my “short” Todo list to write an app that looks at your current library (Plex, for me) and finds related artists through other apis (like Spotify) and exposes a UI to show what things to check out. Maybe some tracking of what you’ve accepted as interesting and still missing so you can grab off Bandcamp or wherever else you get your music. But at least it would help track/expose WHAT bands to seek out