• 0 Posts
  • 27 Comments
Joined 1 year ago
cake
Cake day: July 1st, 2023

help-circle








  • If they’re a beginner, what better way is there to learn? My home lab and their Windows laptop running VirtualBox are two different things. The topic of security is too deep to cover now, but if they don’t open it up to the world, there shouldn’t be much risk. Local access only should be safe enough, and they might try a dozen different services before settling on one—or none at all.

    Edit: Sysadmin is boring, I need to create. DevOps or some other automation role would be perfect IMO


  • Regarding your third point, you might find it helpful to search for beginners’ guides whenever starting a new project. One thing that people don’t seem to tell new users about is the struggles they faced when getting started themselves. Countless thousands of hours could be spent on this before someone decides to get started, while others pick it up in a much shorter timeframe. It just depends on you and what you are looking to get out of it.

    It’s much more difficult than many people realize. If you need a space to test things out, I’d recommend installing VirtualBox with a couple of VMs to host whatever services you decide on. You can take a snapshot of the VM at any point in time, so when things go bad, you can simply restore whichever snapshot you like.



  • My life got immensely easier when I figured out I did not need any features ZFS brought to the table, and I did not need any of the features K8s brought to the table, and that less is absolutely more.

    Same here. Sometimes I get carried away, but overall, a very basic setup is more than fine. Nearly all of my devices run Ubuntu/Debian, and only the work-related stuff gets over-engineered.

    It’s helpful for me to have something like a home lab where I can get hands-on experience with many different technologies. I’ve worn many hats, from developer to sysadmin, so a certain segment of my network tends to be built like Fort Knox. However, overall, 90% of my installs are minimalist with common best practices applied.





  • Media server: Jellyfin, qBittorrent, Radarr/Sonarr/Lidarr/Prowlarr, and OpenVPN/Traefik/WireGuard

    Misc: PiHole, Vaultwarden, HashiCorp Vault, and FreeIPA

    VMware ESXi for the VMs, but I’ll be switching to Proxmox soon.

    All running in Docker or Podman containers on their own VMs. I’m trying to automate the deployment and configuration of each of these services via pipelines in GitLab CI using Ansible and Terraform right now. I also have a couple of Kubernetes clusters for testing and dev stuff on this server.

    Accessed via SSH or an NGINX reverse proxy. I’m using certificates where possible, but a lot of the traffic between VMs is still unencrypted. I’ll eventually force everything local to use Traefik, but for now, only a few services are using it.

    There are a lot of projects on awesome-selfhosted and selfhosted that I’ve been meaning to get around to installing. Home Assistant and AdGuard Home are two of them.

    OpenStack has a really good Ansible hardening project for securing servers that I try to always use. I also have a Red Hat developer license, so I try to use their OS when possible because of their FIPS and other security profiles. Some services just don’t work with any of the newer RHEL versions though, and I usually fall back to CentOS Stream or Ubuntu whenever that happens.