Avatar

AnApexBreadB

AnApexBread@alien.top
Joined
2 posts • 41 comments
Direct message

I just did a proxmox update and reboot last week, but before that it was months of uptime.

permalink
report
reply

Some networks block Wireguard connections.

Dollars to doughnuts they’re blocking the default Wireguard port. Change your wireguard port to something like 8080 or 8443 and you’ll almost certainly make it through

permalink
report
parent
reply

CF tunnels to access generic apps I want public.

I totally could move everything that’s on CF tunnels over to Wireguard, but I see no need to do it

How would you keep the public apps public if you require a wireguard connection to access them?

permalink
report
parent
reply

Yes.

I use all three for different purposes.

It all depends on what my requirements for self hosting some are.

permalink
report
reply

Tailscale has its use when you are behind CGNAT and don’t want to VPS a Wireguard server somewhere with a static IP, other than that, it has no use in my opinion. I’m fully aware that I get downvotes from people who praise the zero trust principals of Tailscale and all the rest, but they always forget that you can do zero trust since decades with any network equipment (VXLAN) and add Wireguard to the mix.

People just forget that all Tailscale is is a fancy GUI for managing Wireguard. That’s it.

Wireguard lacks a lot of user management features so you need a service like Tailscale to handle that, but everything zerotier does is something you can already do in wireguard, just simplified.

permalink
report
parent
reply

How do you access those services from a public network?

With Wireguard?

permalink
report
parent
reply

It’s mostly for internal stuff with a NAS. Uploading and downloading files off a NAS or streaming 4K content can all benefit from 10G

permalink
report
reply

I got 2x1000v/800w USPs for $145.

Some light strips to put in TM server rack for $9

A 24port patch panel and keystone Jacks for $35

A keyboard drawer for $50

And a rack mounted Fan for $100.

My 2024 New Years resolution is to make my server rack not look like a piece of shit.

permalink
report
reply

disabling password login and use pubkey authentication will be safe enough?

Just make sure you actually disable password login. Simply enabling key doesn’t disable password. So as long as the password is disabled then you’re fine.

permalink
report
reply

This is probably the optimist in me saying this, but I don’t think the data is actually gone.

Its probably some misconfiguration that is locking people out of their data. That may not functionally be different but technically it’s majorly different. My guess is there will be some announcement made in a few days that they fixed a permissions error and everyone’s data is back.

permalink
report
reply