If you write a playbook to install some software on your home network, you have some YAML that took longer to write than it would have taken to do the task manually and isn't likely to be useful to anybody else. And without maintenance, that playbook will eventually decay and stop working. The scarf will continue to keep you warm forever.
Even if you go by the philosophy that something has to be useful to be valuable (not something I personally believe), toy projects have their place. Plus, they’re fun.
This is the part that has killed this as an activity for me. I really enjoyed the experience of setting up playbooks and so on for my home server (deluge, jellyfin, zoneminder, etc), but in the end I didn't have the time to do much more than make the occasional config tweaks and restart it all live, and once that started happening, the scripts were no longer of value, and it was clear there was no point.
That said, I know some Nix acolytes swear by it for this kind of thing, in part because it really forces you to do things using its declarative wrappers and intentionally doesn't provide workarounds the way containers do ("just shell in and change whatever, lol").
Many other things - Nextcloud, caddy, proxmox to name a few, are long gone now because they demanded hours of attention at unpredictable times, and I just can't be jeffed.
I still love tinkering with bits of tech on the home network, but I'm extremely wary of coming to rely on any of it until it's proven itself to need minimal ongoing babysitting.
'If you use ansible to configure some stuff on your home network, you have some self-hosted stuff at the end of it. You can use it yourself or let guests log in too.
If you use needles and threads, you have some tools that took longer to go to the shop and buy and use to make something than it would have taken to go to the shop and just buy the thing. And without regular use, you'll lose the needles and the yarn will tangle and discolour. The self-hosted services will continue to run.'
But also, why do you care so much about what other people do with their time? Live and let live, my friend. Nobody is forcing you to write ansible playbooks, build your own homelab, or comment on posts you view as a waste of everybody's time.
This is debatable. Some of those manual tasks you'd simply forget about and would end up with partially reproduced environment later, which is okay if you miss out on configuration that you don't actually particularly care about. It is much more annoying when you expect everything to work but realize that your workflows are randomly blocked because you forgot to manually install and configure some piece of software when reinstalling the OS or perhaps have to set up your IDEs completely anew because the configuration directories weren't preserved anywhere and are now simply lost. One of the benefits of using something like Ansible would be avoiding situations like this, or perhaps using something like NixOS (even though there are usability concerns presently).
In the more common case of using Ansible to manage servers (perhaps a homelab) as opposed to just using it for handling personal devices, the implications of this would be far more sinister - i've seen Java applications fail to work after migrating to a new OS release because fonts weren't installed, because someone forgot to document that step as necessary. And even if instructions are given (say, either when setting up some package anew, or reading your own documentation about your setup), there's no guarantee that you'll remember to follow all of them to the letter, or maybe you'll simply glance over a failure in one of the steps. That becomes even more likely as the size of your homelab and the count of your personal devices increases.
Clearly the impact of things like that happening is far lower in a homelab setting than it would be in a professional environment, but that also means that you'll essentially be pigeonholed into using some sort of an automation solution at your workplace (hopefully) to avoid situations like that, so also using it for your personal stuff is just the next logical progression. No one likes dealing with failures that aren't immediately apparent and could have been avoided entirely. I don't know about you, but Ansible's standard modules provide really good reusability, so i've definitely borrowed samples of how to do something from my personal setup for my work projects and vice versa (not verbatim, but syntax, how to use parameters and get things done in general).
> And without maintenance, that playbook will eventually decay and stop working. The scarf will continue to keep you warm forever.
This doesn't feel entirely accurate - everything, from your software, to your scarf will eventually decay. It's only a matter of time for the most part, though you can mitigate this by using more stable OS distributions like Ubuntu LTS (until very recently, i would have also recommended CentOS) or by using better materials for your scarf. Oh, and choose the stable versions of boring software, perhaps cut out the technologies that have the most rapid changes out of your stack entirely, until the development there slows down.
For me, that currently means:
- using Debian because it's stable and boring enough for my needs (both servers and desktop/laptop with XFCE)
- using Ansible for servers, treating personal devices and disposable otherwise (no attempt to preserve configuration, too much effort)
- using automated incremental backup software for the data, just in case
- manually provisioning any VMs/VPSes that i require, but having most of the configuration be similarly automated
- using Docker containers within those VMs/VPSes with Docker Swarm liberally, to separate software runtime environments from their data output and their configuration input
- using Docker Swarm to make managing all of that simpler and partially automate it, alongside something like Portainer for making that process more user friendly
- using Caddy to never have to deal with certificates manually, even though i manage DNS manually
- not updating software i don't expose publically and don't need the newest versions of (GIMP, Blender, LibreOffice, some private containers)
- using automated security upgrades within everything else, but also using the latest stable versions of server software, never bleeding edge
A lot of it is about finding what works for your particular circumstances and seeing which parts cause the most pain and then automating those.I don't want to run my own infrastructure. But the commercial providers will scan your data, "unperson" everything they, the government, or the copyright holders don't like, and charge me a fortune for the privilege or withhold features.
But many of these things aren't actually a major effort. Its some yaml for ansible to configure a raspberry pi for security and running docker. And run a few existing docker images. Its might even be less total time spent to just stick it all in ansible and run it rather than have to run each command by hand.
And there are actually some really nice benefits to running something like pi-hole on your home network and forcing all DNS through it. You can get ad and malware blocking on devices that don't typically let you easily. And you can just set it up in one place rather than on every single device.
None of this tooling is "heavy duty" by any means. If you just apply a little thought, you'll see how this saves time and effort.
For you, sure. For many others, it's just about doing something you like doing just because you like doing it. DJ'ing is my hobby, has been for 15+ years. I regularly spin sets a couple of times a week for at least 2, often up to 4 hours at one time, just for myself. I love doing it and feel so content and happy inside when I'm done. I feel even better during it, when everything clicks and I hit a really nice groove.
I have no need to share it with the world, have other people listen to it, or use my hobby to get gigs and make money with it. My sets are ephemeral, my own happy place, and always will be. I'm sure this is the case for many other people and their own hobbies.
Why can't people just enjoy doing a hobby simply because they like doing it? Why does there often need to be pressure from somewhere to do something more with a hobby?
Tapping your foot can't be considered a hobby right? It produces nothing tangible and involves no creativity.
The same can be said about a lot of other hobbies, regardless of what kind of process it might or might not be. Just doing it and being in it - reading and getting lost in a book, watching a movie and getting lost in it, going on a hike and getting lost in the woods (metaphorically, not actually lost, lol), writing code and getting lost in it, etc..
Ansible playbooks can be the same way! The point of hobbies for many people is just because they like to do it, nothing more, nothing less. There may also be other reasons, such as the creativity for me, but there are also times when I'm not feeling super creative and my set will just be an un-mixed playlist of music that I just want to get lost in in that moment... if that makes sense.
Some people might just like losing themselves in an Ansible playbook, or think they're fun for fun's sake or whatever reason. :)
Also, there is no requirement that a hobby has to produce something tangible or be creative. Watching television, drinking, people watching, and meditating could all be considered hobbies. Anything you do somewhat regularly to relax or for enjoyment, that isn't your job, is a hobby.
It doesn’t have to be creative nor worthwhile. Just something that you enjoy. Perhaps yours is trolling nerd forums about other peoples choice of hobbies? :P
Let me introduce you to the world of tap-dancing my friend.
Like the experience and newfound knowledge that Ben gained from this endeavor?
How dare someone experience pleasure! Especially from a hobby.
/s
This toxic "grind until you die" mindset needs to end.
Hobbies *do not* need to produce something to "show for it". The thing you are "producing" is happiness for yourself.
How I re-OVER-ENGINEERED my home network for privacy and security
This is what us "tech people" do.My Ansible playbooks are barely a step up from shell scripts, my Docker images are basically always whatever each project supplies themselves (and don't run on top of Kubernetes), and my infrastructure consists of a grand total of one Raspberry Pi and an 8-port switch.
These things don't have to be overcomplicated if one doesn't want to overcomplicate them. Docker and Ansible lead to real time savings, both because they document the exact software setup and because they make replicating it very easy when switching servers (as inevitably happens in a hodge-podge home lab).
[0] https://tvtropes.org/pmwiki/pmwiki.php/Main/ArsonMurderAndJa...
Every once and awhile a good clean 'toss the whole thing out and start over' is in order. For me it is typically an ubnutu upgrade has done something odd. Then I spend a few hours digging on it and fixing it. But it would be easier/quicker to just scratch the whole thing and rebuild it, or at least toss it in a VM beforehand so I know what will go sideways. A bit of ansible would let me do that quickly. The other 4 I can just leave them alone. Starting at a known state (broken or fixed) is always handy. Basically it may save me several afternoons of work. Where I would rather be programming instead of digging out some weird error some upgraded bit of software started throwing because some leftover config file is getting in the way.
It astonishes me how people can enjoy this kind of tedious work as a hobby.
It's just mental exercise.
But it looks like a lot (all?) of the work here was just to get pi-hole functioning well - and that now needs him to deploy pi-hole, cloudflared, caddy plus all the surrounding tools of Docker, Docker Compose, Ansible etc.
You're spot on that if he'd have applied some thought outside of simply 'fixing pihole' he might have seen there are more modern and elegant solutions to configure network-wide adblocking.
e.g. AdGuard Home is an opensource single-binary precompiled for most architectures and OSes. Self-updating with an HTTPS multi-user GUI; supports DoH, DoT, dnscrypt out-of-the-box. Has a single yml config file to backup/sync; supports adblock lists based on regex as well as hosts file format.
Downloading and running that one little binary gives him the endgame he wants a lot more elegantly.
It's like those "there's no place like 127.0.0.1" shirts, which work despite the fact that we don't pronounce the localhost address as "home". It's a way of saying "hey, look, I'm just like you!" without being overt about it.
Microsoft is a clever company, and they recognize that they have to do a lot to offset their corporate stink that they brought to the GitHub and npm brands.
Also kubernetes is easy when using the right spin up tool, like portainer or rancher. It's also the only way to run docker images across multiple machine today. For a while I ran swarm but that's dead, then I just used docker compose but started running into compatibility issues. With kube you also get to leverage all the existing helm charts., which saves a lot of time.
It's still a bit overkill but a lot of fun, and I learned networking and infra things doing it on a homelab. I also use it to try new things.
There are also political reasons to do so. I suspect the internet will get less free and it's nice having your own private space.