karlthemailman

joined 2 years ago
 

I have all my services running locally on a 192.168.10.x subdomain. Many are docker containers but some (like gitlab) are proxmox vms. Everything is behind a reverse proxy so I can access services through a url like paperless.mydomaon.com. the reverse proxy automatically pulls certs as needed.

This is great for accessing stuff when I'm home.

I'm trying to set up something for remote access. I don't want to use cloudflare as I just want access for myself from my phone and laptop. So I'm leaning towards tailscale or similar.

But do I need to move all my services to use the tailscale subnet? Seems like a pain and also requires installing tailscale on everything (even on docker containers?). Or do I just install tailscale on the reverse proxy since it can reach everything else. But then I wouldn't be able to ssh into a proxmox vm remotely unless I installed tailscale on the vm?

Or is this what the tailscale subnet router is for?

archive.is usually works

Exactly. They have all the data in the world, but I'm sure they are doing what's optimal for their profit.

[–] karlthemailman@sh.itjust.works 1 points 2 years ago (1 children)

I'm not familiar with the terminology. What's the distinction between a terminal and a console?

Tmux does let you copy from a shell to your system clipboard using the keyboard, which is nice. But many terminal emulators like mobaxterm on windows let you copy as well.

[–] karlthemailman@sh.itjust.works 0 points 2 years ago (3 children)

Same here. Well worth it for $10 a year

[–] karlthemailman@sh.itjust.works 1 points 2 years ago* (last edited 2 years ago)

Thanks. Authelia looks promising, but I can find anything about tls client auth.

Edit: actually maybe caddy supports this directly? https://caddyserver.com/docs/json/apps/http/servers/tls_connection_policies/client_authentication/

Works fine for me on 0.0.38

[–] karlthemailman@sh.itjust.works 14 points 2 years ago

Exactly. Even if the standard Lemmy software does it, there's no guarantee that your instance admin hasn't altered the code or done something else to keep that data.

[–] karlthemailman@sh.itjust.works 4 points 2 years ago (3 children)

How do you have this set up? Is it possible to have a single verification process in front of several exposed services? Like as part of a reverse proxy?

[–] karlthemailman@sh.itjust.works 4 points 2 years ago (2 children)

Or mergerfs if you are not too concerned with performance

 

Spurs are acquiring Reggie Bullock and an unprotected 2030 pick swap from the Mavericks, in order to open up salary room for Dallas to acquire Grant Williams from the Celtics.

[–] karlthemailman@sh.itjust.works 3 points 2 years ago (1 children)

This is my exact setup as well. Proxmox with one beefy vm dedicated just to docker and then a few other vms for non docker workloads (eg, home assistant, pihole, jelltfin). I can probably run those in docket as well, but the to worked better as vms when I set them up

Yeah that makes sense.

This is great info thank you

view more: next ›