Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil.
-
No spam.
-
Posts are to be related to self-hosting.
-
Don't duplicate the full text of your blog or readme if you're providing a link.
-
Submission headline should match the article title.
-
No trolling.
-
Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.
-
AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
view the rest of the comments
I unfortunately don't have an answer to your question since I'm not on Android 17, but I do want to ask about this part. What's the benefit of this? Does it improve speed when streaming on Jellyfin?
Not OP but I do the same for two reasons.
A) it eleimitaes my ISP traffic. It doesn't have to go out to my router, to come back in on the public IP. They can't track what never hits them.
B) I also have completely internal services. So the DNS entries are internal only. Can't map my internal network publicly.
I've also got a completely different DNS config for WAN and LAN traffic. WAN devices can only resolve PTR records for my mail server. My LAN devices have DDNS so internally they a get allocated DNS entries by hostname. Even my guest network has a different config for isolation.
They definitely all need to be kept separate.
A router shouldn't be sending that traffic outside. It should already have routes to send it right back, either regular or NAT rules.
It still has to hit the ISP router?
Depends on the IP. I have a static block, so the other IPs have to hit the public IP and come back, because the router doesn't hold those IPs, itnjust forwards the traffic.
Would you have any recommendations to resources where I can read about setting something like this up? I’ve recently picked up a managed switch and set up a computer to act as a router, and I’ve been learning how VLANs be. I don’t have things fully working on my home network yet, though, but I’m very interested!
I don't know how the others set theirs up, but I use "views" in bind 9 https://kb.isc.org/docs/aa-00851
Essentially, the DNS I run on a router-like box much like you describe uses a different database depending on whether you query from an internal IP address or a public address. For me, the advantages are that I can let devices on my local network declare their own names to DHCP and enter them in DNS without worrying about the outside world. Mu internal network doesn't crash if my ISP changes my address, Certbot happily requests certs for any site with a public address, and that cert works seamlessly on the corresponding internal address, no wildcards or DNS challenge required.
That's exactly what I'm doing.
That’s so sick! That’s definitely above my skill level at the moment, but I will save this for when I’m more knowledgeable—thank you much!
What are you running on your router? If you use opnsense, I'm pretty sure it has a GUI for DNS stuff. Been a while since I've used it.
If you use pihole for DNS, you can set it up in there too, but it's not the same process as most other systems.
I right now have an ISP router, but I’ve got an OpenWRT Pi5 and some Lenovo Tinys I can install OpnSense on when I know more things about stuff!
If you host your own internal dns server like a pihole, you can just add them in as local names.
Careful of something called split brain dns though.
For reference, I use AWS Route53 to host my dns domain publicly and internally I use pihole and Traefik. Traefik deals with getting certificates for my internal resources.
Thank you! I currently do run a PiHole, which I’ve been running for like six years? I really need to get that updated as well hahaha. I’ll look into doing it they way!
I'll admit I dont have one.
I've been meaning to write one myself on how I use things. As how I've gotten it to work has really been from a decade of doing this professionally. And I have opnions.
I'll for sure post links to this community when I have them.
Do your apps complain about SSL certs?
Nope. SSL certs are pinned to the hostname, not the IP address. I can change the IP address in DNS and it will still work.
Ahh, OK I see. I don't know why I didn't realize that before.
Traefik serves DNS challenge certificates
Routing between two interfaces on the same NIC takes nanoseconds. You wouldn't notice a performance difference.
When I first set it up, I didn't have a static IP address, so it would not be great when it changed. I also want my server to remain reachable locally if my internet goes down. I had different firewall/ACL rules for wifi too. For example, some of my internal websites only prompt for a login if you're outside the network.
IPv6 has been awesome here. I have my server and clients on different /64 subnets in the same /48 block. The nearby devices on Android assumes only the same /64 is local.