

If it was microsoft they would ban github and gitlab account and not give cve.


If it was microsoft they would ban github and gitlab account and not give cve.


Gitlab CEO - 16 years in Microsoft, Gitlab CTO - 13 years in Microsoft
Can we say Microsoft Gitlab ?


All I see is layoffs and creating office space to force people to go to office. Well RIP Gitlab.
ovh dedicated kimsufi servers are deadly cheap https://eco.ovhcloud.com/en/kimsufi/
hetzner server auction https://www.hetzner.com/sb/
It’s better to buy 4x 16-20TB drives and expand storage instead of buying 16 4TB drives. Also 16 3.5 inch HDD drives draw around 200W of power alone.


yeah but I don’t mind having duplicated scripts, it’s just easier to go to single script and don’t have to worry about everything else, I keep them like bin/synapse/run, bin/synapse/stop, bin/synapse/logs etc. What I haven’t figured out is better way to keep all ports in one place instead of ports.md file but on the other hand it’s not like I have thousands of containers running.


I have a git repo with some directory convention and bash scripts. Ex stop is just
#!/bin/bash
name=synapse
docker stop $name
docker rm $name
etc. depending on what actions I need to do against container I have bash script for that and if I need to perform same action against other container I just copy paste this file and change name variable. I pull this repo to my containers host and just type ./bin/synapse/stop and I stop synapse.
Hope that makes sense.


I don’t like compose files :)


If you’re proficient it’s 30minutes
Something like this for server.
generate config
docker run -it --rm \
-v <your-data-path>:/data \
-e SYNAPSE_SERVER_NAME=<your-public-address-subdomain> \
-e SYNAPSE_REPORT_STATS=no \
matrixdotorg/synapse:v1.136.0 generate
run
docker run -d \
--restart=always \
--name synapse \
-e SYNAPSE_REPORT_STATS=no \
-v <your-data-path>:/data \
-p 8008:8008 matrixdotorg/synapse:v1.136.0
register user
docker exec -ti synapse register_new_matrix_user http://localhost:8008/ -c /data/homeserver.yaml -u <username> -p <password> --exists-ok
Proxy it using ex. openresty / nginx
location / {
proxy_pass http://127.0.0.1:8008/;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-for $remote_addr;
proxy_connect_timeout 600;
proxy_read_timeout 86400;
}
For UI if you want element on your domain, download and unpack tar.gz from.
https://github.com/element-hq/element-web/releases
Point this location to your proxy server ex. openresty / nginx
location / {
root /opt/element-v1.11.109;
index index.html;
}
Modify config.json inside /opt/element-v1.11.109 to point location to <your-public-address-subdomain>
By default it’s using sqlite if you want postgres or other database then modify homeserver.yaml to use postgres


Thank you for answer. I think I do this one instead https://academictorrents.com/details/30dee5f0406da7a353aff6a8caa2d54fd01f2ca1 Looks like it’s divided by year-month.


How long it takes to download this 3TB torrent ?
You can host ollama and open-webui on container. If you want to wire search you can connect open-webui to playwright (also container) and searxng (also container) and llm will search the web for answers


this is nginx / openresty config - upstream is just definition of server / bunch of servers if you do loadbalancing - you can specify load balancing strategies and stuff. Or when want to separate server layer from proxy layer.
stream {
upstream something {
server xxx:123;
server yyy:321;
}
server {
listen 666;
proxy_pass something;
}
}
https://docs.nginx.com/nginx/admin-guide/load-balancer/tcp-udp-load-balancer/
I use openresty with autossl, it renews certificates automatically. The only problem is maintaining subdomain allowance otherwise bots will ddos letsencrypt with random domain names, after some quota they will soft ban you for a week to create certificates for new domains / subdomains.


you can reverse proxy other ports than 443 and ex. upstream ssh, the advantage of having reverse proxy over everything is to have traffic in one place so you can manage it, that’s why for example kubernetes have ingress server, example nginx / openresty upstream ssh, you can restrict traffic to limited amount of IP etc.
stream {
upstream ssh {
server 127.0.0.1:22;
}
server {
listen 2222;
ssl_preread on;
proxy_pass ssh;
}
}
Buy refurbished / used Mini PC with at least 16GB RAM and 1Gbit network card. Don’t bother with M.2, SSD is enough.
I have right now refurbished hp g4 ryzen 5 mini pc. There is 12 docker containers running there and couple applications in screen, I just add things. Don’t do ARM, as far as I remember running on ARM is compilation hell. Stick with x86.
You want it to ease your life and not to make it harder.


Country level internet and passport control before you visit another country domain is inevitable. That’s just like people want it or at least sociopaths.
The future is P2P
I hate google but they still pay good money to opensource and take responsibility by organizing google summer of code.