She/Her - Was bullied off reddit by mean moderators, but it’s a corporation anyway - 🏳️‍⚧️omni, heart - Pro kindness|gressiveness, Anti cruelty|bullshit.

  • 1 Post
  • 7 Comments
Joined 7 months ago
cake
Cake day: February 23rd, 2025

help-circle

  • For inspiration, here’s my list of services:

    Name ID No. Primary Use
    heart (Node) ProxMox
    guard (CT) 202 AdGuard Home
    management (CT) 203 NginX Proxy Manager
    smarthome (VM) 804 Home Assistant
    HEIMDALLR (CT) 205 Samba/Nextcloud
    authentication (VM) 806 BitWarden
    mail (VM) 807 Mailcow
    notes (CT) 208 CouchDB
    messaging (CT) 209 Prosody
    media (CT) 211 Emby
    music (CT) 212 Navidrome
    books (CT) 213 AudioBookShelf
    security (CT) 214 AgentDVR
    realms (CT) 216 Minecraft Server
    blog (CT) 217 Ghost
    ourtube (CT) 218 ytdl-sub YouTube Archive
    cloud (CT) 219 NextCloud
    remote (CT) 221 Rustdesk Server

    Here is the overhead for everything. CPU is an i3 6100 and RAM is 2133MHz:

    Quick note about my setup, some things threw a permissions hissy fit when in separate containers, so Media actually has Emby, Sonarr, Radarr, Prowlarr and two instances of qBittorrent. A few of my containers do have supplementary programs.


  • An LXC is isolated, system-wise, by default (unprivileged) and has very low resource requirements.

    • Storage also expands when needed, i.e. you can say it can have 40GB but it’ll only use as much as needed and nothing bad will happen if your allocated storage is higher than your actual storage… Until the total usage approaches 100%. So there’s some flexibility. With a VM the storage is definite.
    • Usually a Debian 12 container image takes up ~1.5GB.
    • LXCs are perfectly good for most use cases. VMs, for me, only come in when necessary, when the desired program has more needs like root privileges, in which case a VM is much safer than giving an LXC access to the Proxmox system. Or when the program is a full OS, in the case of Home Assistant.

    Separating each service ensures that if something breaks, there are zero collateral casualties.




  • Hi, Cloudflare DNS needs to point to the external IP address, aka 201.172.48.922 (check using any ‘what’s my IP’ site on any device connected to the same router). 192.168.x is internal and only used by the router. Changing this, and port forwarding 80 and 443 to the NPM host, will allow everything to work remotely.

    That said, in a comment you said you’re only aiming for local access. The only requirement for this is setting your Plex client to the internal IP of the server, 192.168.x. Only when setting up external access do you need a cert, domain and DNS records.

    Finally, if you can set your router’s DNS servers, set one to the NPM server. That may allow local devices to find the internal IP by querying the FQDN (domain). Or use your Pi-Hole to add DNS rewrites.


  • Where I come from roads are for motor vehicles and anything below 15mph shares the path/sidewalk. The national law started fucking with that and I’ve argued with my partner, who wants to follow the rules, against me, who thinks the rules are stupid and dangerous.

    I went cycling with her recently, once, and while following her rules and the law, had three pricks. One in a car committed a blind hump overtake well above the speed limit to get past us - only incredibly dangerous - and two white van men were impatient also, one of which, at a traffic light, revved engine scaring my partner and pissing me off. I am a defiant person so I fight a threat. In this case I only took more time speeding up and flipped him off, because you know, I left my weapons at home. Bro nearly busted his engine to intimidate us, only to turn left and not even be slowed down by us.

    Now she’s scared to cycle because it’s too dangerous on the road - duh - and she’s also experienced pedestrian pricks too. It’s not an apocalyptic or feudal era but you have to prepare to be assaulted before going out all the same.