kumi

joined 2 weeks ago
[–] kumi@feddit.online 2 points 16 hours ago* (last edited 15 hours ago) (1 children)

One way to go about the network security aspect:

Make a separate LAN(optionally: VLAN) for your internals of hosted services. Separate from the one you use to access internet and use with your main computer. At start this LAN will probably only have two machines (three if you bring the NAS into the picture separately from JF)

  • The server running Jellyfin. Not connected to your main network or internet.

  • A "bastion host" which has at least two network interfaces: One connected outwards and one inwards. This is not a router (no IP forwarding) and should be separate from your main router. This is the bridge. Here you can run (optional) VPN gateway, SSH server. And also an HTTP reverse proxy to expose Jellyfin to outside world. If you have things on the inside that need to reach out (like package updates) you can have an HTTP forward proxy for that.

When it's just two machines you can connect them directly with LAN cable, when you have more you add a cheap network switch.

If you don't have enough hardware to split machines up like this you can do similar things with VMs on one box but that's a lot of extra complexity for beginners and you probably have enough of new things to familiarize yourself with as it is. Separating physically instead of virtually is a lot simpler to understand and also more secure.

I recommend firewalld for system firewall.

[–] kumi@feddit.online 1 points 1 day ago* (last edited 1 day ago) (4 children)

I do not ask you to read?

So that's the mistake I made and the important part. Thanks for clarifying.

I still feel misled that it's labelled as somehing it isn't ("my reasoning").

[–] kumi@feddit.online 5 points 1 day ago* (last edited 1 day ago) (6 children)

It is indeed with the help of llm. But reasoning is still solid and very curated.

It isn't your reasoning and promoting it as such when asking us to read doesn't feel honest at all.

[–] kumi@feddit.online 1 points 2 days ago* (last edited 2 days ago)

Try answering the questions I asked for yourself and see if anything comes up!

[–] kumi@feddit.online 10 points 2 days ago* (last edited 2 days ago) (10 children)

Linux MATE desktop is pretty established and I think has a similar audience. Pretty confusing name choice... "want to install mate on linux? Try linuxmate (no relation)"

BTW are those actually your reasonings on the blog as you say? It reads very LLMy.

[–] kumi@feddit.online 4 points 2 days ago (2 children)

What makes you suspect the Nginx config instead of Lemmy? Do you have any failing requests (timeout or statuscode >= 400) in nginx log? What are the failing endpoints?

[–] kumi@feddit.online -1 points 2 days ago* (last edited 2 days ago)

Both can be true.

I think such character assessment and calling names is unnecessary and off-topic here though. Better engage with substance than judging by vibes and doing ad-hominem.

[–] kumi@feddit.online 41 points 3 days ago* (last edited 3 days ago) (4 children)

I guess they now have large enough number of users that it would be wise to shift some focus to supply-chain security from growth-hacking.

This is growing pains.

[–] kumi@feddit.online 44 points 3 days ago* (last edited 3 days ago) (1 children)

Cool! Keeping up with platform changes is a challenge for projects like this. I think to be successful beyond initial popularity you need an active community that can do this together. It's draining for just one person - especially once you get big enough that they might actively break things just to mess with your integration. Following maintenance of alternative YouTube clients as well as searx-ng is illustrative.

Not to discourage but be prepared. Best of luck!

https://cadence.moe/blog/2022-09-01-discontinuing-bibliogram

[–] kumi@feddit.online 3 points 4 days ago

Just to rule it out (wouldn't be the case on default debian):

Is SELinux enabled? sudo getenforce (if command missing or false, it's not your problem here)

You are not running with podman as compose backend? sudo systemctl status podman shouldn't show an active service unless you use it.

 

How to test and safely keep using your janky RAM without compromising stability using memtest86+ and the memmap kernel param.

view more: next ›