Wiki.js Nginx Proxy Manager.
Mastodon: @SeeJayEmm@noc.social
Wiki.js Nginx Proxy Manager.
Enough people have already commented on the “proxy at the vps solution”. Another option is to configure routing and nat on the VPS and have it route over the wg tunnel.
Requires you to have postup/predown scripts that modify your routing tables on the wg endpoint.
I made the plunge about a year ago. Spectrum assigns me a prefix but routing was spotty at best. In the end after all the troubleshooting pointed to the problem being the ISP I gave up and stuck with what works, IPv4.
DDOS protection is going to depend on the VPS. But for most services you could spin up a pretty lean Debian vm running a proxy like nginx proxy manager and run that over the tunnel. Something like opnsense seems like overkill.
I gave it the old college try about 6 months ago. Found out how to send the req for a subnet to my ISP. Configured my opnsense. When it worked, it worked. But it would randomly stop routing regularly. After a lot of troubleshooting determined it was the isp and have up.
Maybe I’ll try again in another 6 months.
Pretty good breakdown of the current science on the topic. Thanks.
This is how I learn and half the reason my home lab exists. I need projects to get/stay motivated.
I feel this post so hard. I’m always about 5 seconds from going Office Space on my printer.
I’m fond of Beekeeper Studio and a sqlite DB.
However, if my VPS is compromised, wouldn’t the attacker still be able to access my local network?
That depends on your setup. I terminate my wireguard tunnels on my opnsense router, where I have explicit fw rules for what the vps hosts can talk to.
I’m using CheckMk for pretty much all of that. Personally I found zabbix to have too much overhead.
No but less power hungry than a full desktop. It’s a good trade-off between power and performance.
If you want the small footprint and power costs are a concern, look for a second hand mini computer. Dell, Lenovo, Intel nuc.
Something like this as an example.
You know b2 has multi region replication now, right?
Then you didn’t understand how the system uses swap.
https://www.wireguard.com/protocol/
Looks like wireguard encrypts traffic to me.
I just wanted to say I loved your analogy.
Thanks I may give it a try if I’m feeling daring.
Media should exist in its own with a tuned record size of 1mb
Should the vm storage block size also be set to 1MB or just the ZFS record size?
That’s the business ed not the community. There’s no limit in aware of in the community ed