

I deployed Technitium with docker, but generally this got me heading in the right direction with the initial setup. It’s more of an overview and quickstart than an in depth guide though.


I deployed Technitium with docker, but generally this got me heading in the right direction with the initial setup. It’s more of an overview and quickstart than an in depth guide though.


I was doing basically this with a different sync tool, but I had a couple issues with it:
I’ve been a very happy Pihole user for years and years and Pihole 6 is the best yet, but once you’re dealing with multiple pihole instances, Nebula Sync and Unbound, then Technitium is actually simpler to manage since it does all that natively.


DNSWeaver has support for caddy labels too! Specifically for use with caddy-docker-proxy. So yeah, really good fit for your architecture.


Oh do I have a treat for you, check out DNSWeaver.
It’s designed to do exactly that, to automate creation of DNS records for container services. I use it with Traefik. It reads from the same labels that Traefik already uses to proxy services but if you already use another reverse proxy and don’t want to switch it supports dnsweaver-specific labels as well which are easy to add to your current deploys.
I used it both with pihole and technitium and actually used it to make the migration easier. Great tool.


Switching SSH to a non-standard port can cut down on log noise but it doesn’t really help with security. It’s trivial to identify ssh running on any port and attackers typically do full port scans anyway.
I’d put that effort towards allowlisting only trusted public ips or setting up wireguard/tailscale for ssh access instead.


I migrated from pihole to technitium a few weeks ago and it was so smooth.
Native support for clustering is huge. I didn’t even realize how complex managing the pihole had gotten trying to get it to sync to multiple instances.
I avoided tailscale for so long because I was already using wireguard and I didn’t know you could self-host with headscale. But once I started using it with headscale the mesh design really is a big improvement to usability. I don’t miss having to carefully manage my config files and ip route rules.
I need to get setup with app connectors and then I think it’ll finally be a high enough wife-usability factor for me to remove some things I still have exposed over the internet.
DERP is the service that actually relays packets between tailscale connected devices when they are crossing a NAT (leaving one private network and going across the internet to another private network).
If you host headscale (the self-hosted community version of the tailscale control plane) and use it with tailscale, by default it will still use the public Tailscale DERP servers. Your traffic is still encrypted and not visible to them, but it does still rely on part of their centralized architecture even though you are hosting the control plane yourself.
That being said, you can just use the embedded DERP that ships with headscale, although there are some other considerations when doing that because it will need to be publicly on the internet, probably with a proper domain name and publicly trusted certificate.
Headscale includes an embedded DERP server but you need to enable it. Their example yaml has it disabled by default, which I assume is because it needs to be publicly available on the internet, requires HTTPS, and thus a certificate and other network/security considerations.
You can self host the control plane for Tailscale using a community project called Headscale. I use that along with Headplane which gives you a nice admin web UI.
Then you just use the tailscale client on devices like normal but you authenticate new clients with your endpoint instead of the centralized one.


This exactly. I’d use rsync to sync a directory to a location to then be backed up by kopia, but I wouldn’t use rsync exclusively for backups.
Definitely do not do tapes.
I’d also recommend Backblaze. Their S3 compatible storage is pretty affordable. I backup to a Kopia repo and then replicate to Backblaze nightly.
Tapes require so much more work to keep up to date and mght not even be cheaper over time.


I use GarHAge which uses open hardware and software and was pretty easy and cheap too. https://github.com/marthoc/GarHAge


Everyone on the fediverse is Nicole and you can’t prove otherwise.


This is my exact concern.
If I pay for the lifetime pass now, what’s to stop them from restricting even more features behind new types of subscriptions and paywalls. “We’re adding back the ‘Watch Together’ feature but it requires a Platinum Plex subscription and will not be a part of Plex Lifetime Pass users.”
Seems kind of inevitable honestly.


If you mean that you are using Proton VPN on your Raspberry Pi to mask your downloading traffic, then no that same VPN will not help you access services like Jellyfin on your home network while you are remote.
Instead you’ll want to use something like Tailscale (or Wireguard). You run it as a service on your home network and it then becomes your own VPN that you (or others) can use to connect to your home network when you are remote.
You could run Wireguard on the same RaspberryPi that you use for downloading but I would recommend against it assuming that you’re running Proton VPN right on the host itself (and not inside a container).
I’m assuming your phone has to be rooted for this right? Or is docker running without root? I didn’t realize anything like this was possible. This is interesting.
I don’t know the details but I’ve had to ban her account several times (from a number of different source instances) for sending everyone the exact same unsolicited private message.
I never bothered to figure out of if it’s actually malicious or just some nonce trying to drive up engagement. Either way it’s a weird quirk of Lemmy right now that she’ll eventually DM you…
This is basically how I do it too.
I used to be more creative but then I got in the habit of running more servers and swapping hardware more frequently so it got harder to remember what hardware I was actually connecting to. Now they get hardware based names and everything else is named by service-based Ansible roles.
I like and use Cloudflare but it’s worth mentioning you must use their dns for domains you purchase from them.