What are your most used self-hosted applications?
noted.lol
noted.lol
Nextcloud - for caldav and carddav calendar, contacts, and tasks
Xbrowsersync - sync bookmarks across device
Synchthing - backup data from my phone. I use Neo Backup to take a snapshot of all apps, so the phone should theoretically be restorable from scratch.
Jellyfin - Spotify replacement. The Finamp app is fantastic.
Home Assistant - automate my media center, as well as control outdoor lights and door locks, and check if any doors or windows are open or unlocked when I'm away.
OPNSense on a protectli box - amazing open source gateway software that does everything.
AdGuard Home (on OPNSense) - DNS based ad blocking
Wireguard (on OPNSense) - allows me to have an always on partial tunnel VPN on my phone and laptops that allows access to home services while remote, and also allows me to use my Ad Guard DNS.
HAProxy + LetsEncrypt (on OPNSense) - setup to provide subdomains for each of the services at home. Only a couple are public (contacts and calendar), but the rest become available when the VPN is on.
Smokeping - use it to collect data to rub into Spectrums face when they go down.
Pintry - Pinterest clone
> I've got an msi desktop gaming PC, an LG CX OLED TV, and a Yamaha RX-A2A receiver and they never played well together. The kids always had a hard time getting them all on at once and set to the right inputs and launching steam.
> So I created a Home Assistant automation that does all that, bought a Zwave button that sits on the coffee table, and now they just turn it all on with one button like it's a video game console.
I also plan to add "scenes" where I can just tap the button and the lights dim, and the media center gets put into movie mode, as well as a "music" scene for when I have parties, which would join the two zones my receiver supports an then start playing a playlist from spotify.
If you want to get creative, you could create a custom dashboard and put an old iPod touch/Android device in kiosk mode and use it as a remote touch panel control for your home theater (or anything else in HomeAssistant).
I have two Lenovo M8 tablets ($100/each) that I'm using as home control panels - super convenient and rock solid. https://imgur.com/a/f0aNTRq
If you go this route, definitely buy the Android app FullyKiosk. It will let you lock the tablet to the HomeAssistant dashboard, automatically recover if something crashes, etc. I have it set up to use the built-in camera & motion sensor to automatically turn on the display if someone walks up to it or touches the tablet, and automatically turns the screen off after a few minutes of no motion.
Example: I have some cheap Govee LED strip lights behind my TV for ambient lighting. HomeAssistant can detect when my Apple TV (or Samsung smart TV) is on and automatically turn on the lights for me. I don't have to reach around the back of the TV to try and find the little button to turn the lights on (or remember to turn them off).
I can also control both my TV and Apple TV through HomeAssistant. It's not exactly the most polished/straightforward, but you could definitely string together some automations - something like a "movie night" button that dims the lights, turns on the TV, switches to the appropriate input, and cues up a file. For me that's more hassle than it's worth.
For instance, when I turn on the PS4, HA turns on the receiver and the TV, switches to the correct inout, adjusts the lights in the room.
When I turn off the ps4, it switches off the tv and the avr, unless I switched the receiver to the music or media player input (in which case it turns the tv off or not)
It also lets me use these cheapo ikea zigbee volume buttons to adjust the sound on the receiver, pause and skip songs or video (via libreelec). And the “light switch” aqara button to turn off all lights at bedtime from my bed and keep the music running (if I double tap) or switch it off otherwise.
The above wouldn’t be possible otherwise: ikea’s volume switch only works with these ikea/Sonos lamp things otherwise.
Whenever I try to install OPNSense it fails to load once installed. Maybe there are some initial configuration steps that I am missing? Last time I tried this, about a month ago, internal DHCP addresses were not getting assigned to clients. Troubleshooted for an hour, no results. So back to PFSense I went.
Do you have a guide for installing and configuring the basics? Or something you would recommend?
I was having both bad connectivity to Spectrum as well as buffer bloat, which I think was upstream. Had to get Spectrum in three times, after which the spent several days up on the pole and in the field doing major work, and the problem resolved.
My neighbors still have problems with the cable connection.
I finally found a use case for Pinterest after creating an account years ago and their landing page refreshed and acted weird so much in Firefox that they decided it was a phishing attempt and locked my account for some arbitrary amount of time. I'd rather not even start using it if there's a viable alternative
I've searched for 5 minutes now.
For security there are these scanners:
https://github.com/flyingcircusio/vulnix
https://github.com/andir/nix-vulnerability-scanner
I also run all services in docker and my network uses VLANs behind an OPNSense firewall. I use Wireguard as a pinch point into my network to access most services. So I'm not too worried about the security aspect.
Upgrading on Nix is pretty easy - just bump your lock file and it will get the latest packages, assuming you are on the unstable channel. But unstable does break on occasion. You an also use the latest stable release of Nix and selectively choose unstable packages, which is probably the way to go. I rarely need to fix anything - it's been pretty reliable - I feel like with each patch I make to my config (which is all checked into git), the system gets more reliable and reproducible - 2 steps forward, no steps back. It only starts eating time when I want to add or upgrade some element to the system, but I always make sure to never do any action that isn't captured in Nix config and backed up, so that I don't have to come back and figure out what exactly I did or how something works again. It's been fine. Nix has a pretty steep learning curve, but considering its power, I think it's absolutely worth it.
https://github.com/MatthewCroughan/nixcfg
https://github.com/hlissner/dotfiles
https://github.com/georgewhewell/nixos-host
https://github.com/ipetkov/dotfiles
There's also the DevOS project, which is an attempt to create a base of boilerplate than anyone can use as a start to build a system:
Recommendations:
* Definitely use flakes
* Use Agenix to store secrets out in the open (encrypted with your SSH key)
* Use home-manager
* Keep config modular so you can selectively include it in various hosts and domains (e.g. desktop vs server).
Think of it as building software when you figure out how to organize your config. The bulletpoints above can all be a bit difficult to figure out so don't feel bad if you don't get them installed right away. Try to start with a machine that isn't your daily driver and blocking your workflow.
Either way, I am more inclined currently to use packages on top of a base Linux distro, so suspect I can mess around more without committing to either for now.
As for languages, it's a very marginal factor. If I have a large number of possible services in a given space, I usually gravitate towards Go, because most Go applications are closer to 12-Factor compliance and generally stability than, say, most Python applications. If I have no options or the best service in a given space is written in COBOL or something equally bad, I'll still take that. I'm quite pragmatic.
IMO, if you want to get into this, keep a few things in mind:
- Docker (Compose) will save you a lot of work
- if you want to expose stuff to the internet, you'll need to stay reasonably current with updates
- have a good system for backing up your data. Experimenting is far easier if you can back up what you've got, and start over from scratch to try a different approach. Doing this "live" is riskier.
This was a major pain. Docker is fine for local development, but unless you have a full time department dedicated to babysit it, it’s not scalable for self hosting. Observing services becomes complicated and requires a whole tool chain, ditto keeping on top of new versions, etc.
What I did instead is install proxmox on my server, and run the former server (that was running all the docker stuff) as a virtual machine within proxmox.
I was then able to gradually move everything away from docker and into VMs or LXC containers (which are basically lightweight VMs, but you can use all existing tooling and treat it like a VM). I’m using ansible roles and playbooks, I can ssh into the containers, and unattended upgrades for updating, and tarsnap or borg for backups.
It’s much saner this way ad I don’t end up running versions that are several years old because of the complexity/inertia of docker.
Thank you, this is exactly something I was looking for!
- cadvisor - simple graphs of resource consumption, insights per docker stack
- cyberchef - a LOT of handy operations packed into one small app. Encode/decode any secrets you need and don't bother about privacy
- dozzle - logs browser from all docker stacks
- gogs - git mirror
- heimdall - all apps main panel
- minio - private S3 for my side projects
- nextcloud - private google drive / dropbox
- photoprism - photo management
- pypiserver - private pypi
- registry - docker registry (with UI)
- traefik - reverse proxy of all these services
- portainer - easily manage all of the above.
The coolest thing is that I don't even need to ssh into the instance (Synology NAS) to update / add / remove something. Literally everything can be achieved via portainer.example.com in this setup.
I just recently made my setup public so here's the repo if you're interested. https://github.com/tomwojcik/homeserver-traefik-portainer
Self-hosting would at least give me the guarantee that the code I'm running is the same code I ran last week: If nothing left my browser then, it probably isn't leaving my browser today.
I don't get that guarantee with someone else's hosted version.
I'm building PhotoStructure, which is (yet another) photo and video organizing app. It only transcodes videos that won't render properly on popular desktop and mobile browsers (what it does and doesn't transcode is configurable, and _how_ it transcodes is also configurable--I use ffmpeg or vlc under the hood).
The biggest issue with videos is probably their common lack of metadata: they never include timezones (but sometimes include GPS, so PhotoStructure uses that to infer TZ), so I had to build a "metadata inference" engine to glean metadata from relevant "sibling" files.
I also pull in any metadata from sidecars (XMP, MIE, EXIV2, and Google Takeout JSON), so that can help flesh out more browsable aspects: PhotoStructure browsing is all hierarchical tag based, including date hierarchies, keyword hierarchies, filesystem hierarchies, and file type hierarchies.
Note that PhotoStructure is freemium commercial software: if you want to give it a spin, here's a 15% off coupon: "HN15". Details about pricing are on https://photostructure.com/about/pricing/
https://docs.photoprism.app/user-guide/organize/video/
Metadata is extracted from videos and potential sidecar files.
Transcoding can be turned off in settings:
https://docs.photoprism.app/user-guide/settings/advanced/#di...
More finetuning of ffmpeg parameters can be done using config options:
https://docs.photoprism.app/getting-started/config-options/#...
adguard/adguardhome - Blocks ads on devices that don't support ad block extensions
charlocharlie/epicgames-freegames - Bot that will automatically "purchase" free games from the epic game store. I have it setup to telegram me a link to enter the captcha.
chuckmacdev/adrfinder - Checks for Disney dining reservations and emails a link to reserve
fusengine/apaxy - Decent web file browser
linuxserver/*arr - ya'll know why :)
linuxserver/smokeping - Really useful to troubleshoot network issues
plexinc/pms-docker - I want to switch to jellyfin but I have so much data in Plex now it'll probably be a huge pain
jlesage/nginx-proxy-manager - I'm lazy and hate setting up reverse proxies
jlesage/qdirstat - Pretty useful when dealing with a server that has as much data as mine does
adolfintel/speedtest - Good for troubleshooting networks that might preferentially give speedtest.net better speeds, also good for internal network testing
linuxserver/sabnzbd - Obvious
haugene/transmission-openvpn - I don't feel comfortable downloading any torrent unless it goes through a vpn
What is “*arr”?
Netflix today is just mockery, at least in Europe.
That said, I don't pirate, mostly because I believe in law and order.
But I certainly won't report anyone else for doing it. And if I have a chance I will vote for the guys who will crush copyright in its current form.
Where do you live? Seriously, I'd love to emigrate somewhere that gives me this comfort.
Everyone believes in law and order. There are pirates who believe in law and order more than you, inevitably. It's not a justification to not pirate.
Wiki (linked from one of the githubs, has links to all apps and more info than the githubs): https://wiki.servarr.com/
Lidarr (Music): https://github.com/Lidarr/Lidarr
Radarr (Movies): https://github.com/radarr/radarr
Readarr (Books): https://github.com/readarr/readarr
Sonarr (TV): https://github.com/sonarr/sonarr
You run this at home? How’s your power bill? And why so many drives?
I've got a high density 42RU rack at home, it's a fun hobby.
My rack - despite being high density - is relatively low draw. I'm currently pulling around 500w/h and expect to only burst to about 800w/h.
As such, I'm looking at a 25-30kwh system, depending on what I can efficiantly squeeze in. I'd also like to chain together 2-3 Powerwalls or similar battery systems for a storage capacity of 2 days or so of total draw. I also have an electric car and a family, so 2 days is probably about 40kwh.
The expectation is it'll save around $300-350 a month, so it'll take a few years for ROI, but that's ok - as long as it allows me to feed my hobby!
Currently my must haves are:
* Router - pfSense - https://www.pfsense.org/
* Movies/TV/Home Videos - Plex
* Minecraft Server - AMP - https://cubecoders.com/AMPInstall
* Music - Roon - https://roonlabs.com/
* Automation - HomeAssistant - https://www.home-assistant.io/
* Unifi Controller
* Email - Zimbra - https://www.zimbra.com/downloads/
* Files - Synology
My experience:
* I can't recommend AMP enough for gamers
* Roon is £££ but if you like music it's such a unique piece of software
* Zimbra isn't what it used to be alas and I've been moving this to Microsoft 365
* HomeAssistant is fantastic and allows me to use pretty much any IoT device whether it has HomeBridge capability or not
* Synology - again expensive but after years of using Debian with my own custom setup, then OMV, then Unraid (briefly) then FreeNAS - Synology's DSM offers a level of capability and zero touch that none of the home rolled solutions match
* Plex - I really hope they never mess with this product, I find it super good although I need to check out Jellyfin
* pfSense - again, a top quality product - I'd love to use Unifi's offering but nothing I've seen (apart from OPNSense) competes feature wise
Surprising how much functionality and configurability it offers via a Web UI and it's all written by one person. They did a Q&A last year to discuss the product:
Personally I've always been happy with the McMyAdmin license I had, and ended up also getting an AMP license later.
Plex also doesn’t let me pay for one premium subscription for the server so my family can watch old family guy episodes longer than 30 seconds on a phone. They each have to buy a subscription.
I still use Plex because so much infrastructure investment to get my parents to use it but honesty I’m not sure I’d recommend it anymore.
It seems someone at Plex decided they wanted the project to finally make some serious cash and started removing functions and moved them behind a paywall (like basic analytics of if someone is currently using it or what they have watched) while shoehorning in bizarre not even B-Movies.
Settings -> <server name> -> Network -> Show Advanced -> List of IP addresses and networks that are allowed without auth
You can also toggle off some of the extra crap they are pushing:
Settings -> <your username> -> Online Media Sources
In Plex settings you need to the IP addresses of devices you will allow to connect to your server without authentication. The setting is listed as "List of IP addresses and networks that are allowed without auth". That way, if Plex or your internet is down, those devices will bypass a check for credentials and have access.
>Plex also doesn’t let me pay for one premium subscription for the server so my family can watch old family guy episodes
Set them up as managed accounts. You can have 15 users on one Plex pass subscription.
I moved to a new server, installed plex, tried to set everything up under my existing account. It was impossible to move my account to a new server, it seemed to just expect my old one to still be there.
After creating new accounts, removing the old server, etcetc. I just gave up and moved to Jellyfin. It’s been mostly equally good. Better in the sense that it stutters less on my TV (Could be TV app too). Worse in the sense that my parent cannot figure it out.
https://support.plex.tv/articles/203815766-what-is-plex-home...
I’ll set up my users as managed and pay for them, that’s really perfect. Since all users are accessing via a vps I control I can just whitelist that and my home networks CIDR and might be back in business!
Thanks for the help folks!
I'll probably end up with Roundcube or something similar.
I'm also stuck on Zimbra, but planning a move for me and my dozen users. I really like Zimbra's calendar sharing features, but Sogo seems to have a good implementation too.
Unfortunately it's the better option in that space.
Jellyfin is ok. Plex several years ago was much better.
I guess I technically self-host things like E-mail, web, dnsmasq-based spam blocking, and so on, but I don't consider them applications either, so much as they're basic out-of-the-box Linux services.
Clicking through to the article, I have never heard of any of those applications, so I guess I don't self-host anything. Such an odd question, really.
Master Foo said: "All of them and none"
Upon hearing this, the student was enlightened.
But it seems like the right response to this thread lol
- People don't trust anymore to install softwares on their computer, using them in the browser is safer
- There is no good cross-platform UI, so nearly everything is now a web app
- There is tons of good open-source softwares that you can self-host and use from anywhere instead of just one computer, also there is more expectations around sharing access to friends, coworkers, ...
Most of the softwares described in the article are for personal usage, I'm pretty sure you know a lot of the "self-hosted" apps from this list: https://elest.io/fully-managed-services
I doubt users know the difference. We got here because OS vendors don't trust users to install software on their computer. What we really need are simple, solid sandboxing APIs to empower developers to ship secure software.
> There is no good cross-platform UI, so nearly everything is now a web app
Yep. I spent the last few days surveying the cross-platform GUI landscape. It really is pretty sad. Qt and wxWidgets seem super bloated, and the Qt company appears to be actively attempting to escape from their open source obligations[0].
I think there's hope on the horizon though. Flutter is pretty dang good, and the licensing story is much better than Qt. Also, there are several toolkits for Rust and Golang that are shaping up to be awesome. I think we might have a native GUI renaissance in 5 years or so.
[0]: https://mail.kde.org/pipermail/kde-community/2020q2/006098.h...
The Windows store especially isn't, because (as far as I understand) until somewhat recently, you were locked to only publishing UWP apps to it.
Browser is maybe not so common compared to hypervisors on end users computers?
If you're looking for a C++ solution -- judging from the mention of Qt and WxWidgets -- have you tried Ultimate++ (https://www.ultimatepp.org)? To me it seems much more compact than either of the two.
If I had fewer devices, I'd definitely just run everything locally and forget about a lot of this cloud stuff. But I need access to certain things from 3 different devices with different OSes, so a hard drive full of data and Portable apps won't be enough.
(Disclaimer: I wrote it.)
No discussion as of yet, but I favorited it because I plan to try it out in the near future.
Thank you binwiderhier for doing all this hard work, your drive is impressive!
Plex
Audiobookshelf - Kind of like plex, but for audiobooks
n8n - automation tool
Heimdall - browser start page with shortcuts to all of these apps
Nginx Proxy Manager - Reverse proxy and wildcard cert hosting.
Bookstack - note taking app.
Pihole - ad blocker and local DNS.
YoutubeDL-material - archiving youtube videos.
FileRun - gdrive replacement.
iCloudPd - sync's pics and videos from iphone to local server
Gitea - git server
Code-Server - webbased IDE/VS code in browser.
Shiori - like pocket or wallaby or read-it-later bookmarking.To that end, my main server (self built around an Asrock Rack mITX motherboard with a low power Core i3 9100T which supports ECC RAM and 6 4TB IronWolf NAS drives in ZRaid2) has:
- Urbackup - backup client and server for all desktops and laptops in the house
- Seafile - much more performant than NextCloud as it's just file sync for the mobile devices
- Portainer to manage Docker
- Plex
- Wireguard for tunneling into the network
- Minecraft server for the kids
- Homeassistant
- InfluxDB for recording a heap of metrics
All of this is then backed up with Restic to JottaCloud (Norwegian cloud hosting provider)
Jellyfin. Movies/TV/Music server with a variety of clients, including a built-in web client, but also AndroidTV/Shield, Roku, Kodi, and more. It's like having a personal Netflix.
Minecraft. The old Java kind. May be leaving for something open-source soon because MS has fucked up the account transitions so badly, and also make buying new copies bizarrely painful, error-prone, and time-consuming—like, I don't know how someone who's not a computer nerd can actually manage to buy and use it, now. It's really bad.
All in Docker on a used workstation, running... IDK, Debian, I think? It hardly matters, because Docker. I don't even mess with Systemd or whatever, I just let Docker figure out what should be started when based on what I set each container to do (restart-unless-stopped, I think? It seems to start them at boot and if they crash, which is all I need).
I hosted PHPNuke and PHPBB on Apache2 out of my basement for years so they'd be contenders for some kind of lifetime total-hours-running-the-service, but that was a long time ago.
https://support.plex.tv/articles/207538527-do-i-need-a-plex-... has more detail
It does have an account system, including the ability to restrict which "libraries" an account can access, which is great if you have kids. For adults, it lets you track your viewing progress/status separately, just like having multiple Netflix profiles.
One thing to account for is that it has to transcode and/or remux videos for clients that can't handle a file's native codecs, audio or video, which can put a pretty heavy load on the server. A Raspberry Pi or weaker x86 machine won't be able to do this without frequent pauses and frame-dropping, for any but very low-resolution media. Solutions to this include: 1) ensuring that your clients can all handle a huge range of codecs, so it never has to transcode (IME audio is, these days, trickier than video, especially ensuring things like Dolby Atmos are supported), 2) getting a really powerful server, in particular with a video card that Jellyfin can use for transcoding, and 3) falling back on just downloading the file and throwing it in VLC (the web interface makes it really easy to download the raw video files in a pinch, though if you have big high-quality 4K rips they'll come down at full size, which can be inconvenient on devices with limited storage, like, say, iPads).
However, I think Plex or anything else will have similar limitations, since they all have to do something like that to accommodate players & devices with limited codec support.
Jellyfin's been very stable for me, which is part of why I'm still on it. I also find the UI in most of their clients much, much more to my liking than something like Kodi. But IDK about Plex.
[EDIT] Oh, I guess you could also batch-job transcode all the files to something very widely-supported, outside of JellyFin, though likely at some cost in quality and maybe also file size. Plus it'd probably take at least an hour or two to hack together a script to do it, for a wide range of input codecs.
Plex has definitely started to try and commercialize itself more and offer other stuff, when all I want is access to my own media. So I may look into Jellyfin more soon.
As for batch transcode jobs, I had a system that I was able to set up as essentially a black box. Drop a rip into a folder and out the other side comes a smaller one at a reasonable quality. With forced subs burned right into the actual video. Mostly based on https://github.com/donmelton/video_transcoding
This can be tricky if you're stuck behind a CGNAT, which is becoming more common. I maintain a list of solutions to this problem here:
There are 3rd party apps for jellyfin on apple tv, but it's just not as smooth of an experience as plex.
I'm hoping that jellyfin will push plex to get better, as some of the most requested features for plex have gone unanswered for years, which is quite frustrating for software that is paid.
There’s also a bare bones native Jellyfin app for tv/iOS called SwiftFin, but it’s currently only (publicly) available in TestFlight.
I went with plex years ago, because they had good app support on the various devices in my house. (Mostly roku now)
The problem with Plex is:
1. during a recent half day internet outage (during prime-time) I was unable to use plex because the app didn't have access to the internet. The network was all up and running, devices could see each other, but plex decided that even though the media was on the local network it wasn't good enough and refused to finish playing the video we were watching. (The internet went out 20 minutes in)
2. Plex the company has gone fully into adding all kinds of streaming services in order to make a buck. While you can remove these things from your menu, it is just annoying.
3. Plex doesn't always fix known issues. Over the years I've run across several issues in plex that after trying to troubleshoot find that it is a known issue Plex refuses to address. For example, I've recently had some issues with some videos dropping half or more of the frames while the audio is fine. Turns out, plex doesn't like something in the files metadata and this is the result. Plex is the only one that has the issue with the file. It plays fine locally with VLC and streams fine with other programs.
And you'll need to juggle logins to both accounts—the parent account, and the child account—and bounce between them a couple times to get it all working. There's no way normal users are managing to do it successfully.
As for the account transitions, it took me a couple tries to get mine working, and my wife's tried several times and they keep telling her on her MS account(s) that she doesn't own Minecraft and needs to buy it. I haven't looked into it, but I imagine she's missing some non-obvious step. Her experience is likely pretty common.
[EDIT] Oh, another thing I haven't looked into yet: as of a few days ago its started telling my kid they don't own it, and we need to buy it. They fucking definitely do own a copy. No idea what's up with that, and I'm dreading having to figure it out.
We haven't had any issues since then.
Seriously! Between hamfistedly pushing Edge to us Firefox users, raising Office 365 cost a double digit percentage the other year (yes, we moved to GSuite a couple of months later) and all the other stuff, how do you find motivation?
My main operation pain is ZFS. Every time I have to touch it, I'm terrified I'll destroy all my data. It's like Git. "I want to do [extremely common thing], how can I do that?" "Great, just do [list of arcane commands, zero of which obviously relate to the thing you want to do] but don't mess up the order or typo anything or your system is hosed". Yeah, super cool. Love the features, hate the UI (again, much like git)
docker adds its own daemon that creates additional attack surface that you would not have otherwise.
Previously tried rooting my LG TV which worked but too many random issues like full restart of your TV puts the root in a bad state.
I've also got a bunch of smaller services that I don't really use as often. I used to run Grocy and Firefly III quite intensively for a while, but Grocy's UI started annoying me too much and tracking finances became too annoying to do every day. I should look into updates on those or alternatives, because they served quite a useful purpose.
It's like HTTP Basic Auth but with extra steps. It's basically these rules:
OIDCCryptoPassphrase secretsecretsecret
OIDCProviderMetadataURL https://keycloak.example.com/auth/realms/realmnamehere/.well-known/openid-configuration
OIDCClientID my-web-server
OIDCClientSecret secretsecretsecret
OIDCRedirectURI https://example.com/authenticated/
OIDCRemoteUserClaim preferred_username
<Location /authenticated/>
AuthType openid-connect
Require valid-user
</Location>
<Location /sonarr/>
AuthType openid-connect
Require valid-user
</Location>
# Sonarr
ProxyPass /sonarr http://localhost:8989/sonarr
ProxyPassReverse /sonarr http://localhost:8989/sonarr
This basically ensures that if you try to visit https://example.com/sonarr you'll get redirected to Keycloak and asked to log in. It's the main reason I'm still running Apache instead of nginx because I haven't figured out an easy way to do this with nginx. I think you can do it with some custom LUA and an extension?You'd have to be careful with custom code like this, though, because it's very easy to try to get the server to send a redirect but end up sending actual content that just has its HTTP status code changed to 301. The example seems to fail with 500 instead of redirecting, that's one way to do it.
Organizing music is always a pain. But I use MusicBrainz picard on a desktop or laptop over an sshfs mount to my server. It works quite nicely.
I use Calibre-Web, but the whole Calibre system is just plain awful. It's straight out of the 1990s in terms of UI and work flow. I'd like to replace it one day, but I haven't found anything better.
I also self-host an instance of Cyberchef[1] which is an incredibly cool web app that does a variety of data conversions and other things. No real point to hosting it I guess, but nice if you're working with private data.
https://github.com/jdoss/ppngx
I will most likely move this to a Hashicorp Nomad job on my home server once I find the time.
Can concur, it’s very convenient and satisfying to have hundreds of documents over the years archived, OCRed, and fully searchable. Reduced clutter drastically and I’ve never lost a paper again.
my.domain {
reverse_proxy 10.0.0.2
}
is all you need to get
https://my.domain
running with automatic Let's Encrypt.It doesn't do SSO with SAML, OIDC, etc. like more heavyweight solutions. It's basically just a database of users (not even LDAP, it's all internal) who you grant access to proxied apps. Internally it just uses nginx's forward auth proxy support to do all this, it's not using anything complex or fancy. You'll have to configure proxied apps to read the logged in user from a header that nginx sets on redirect (most apps can do this, but not all).
edit: Spin up a docker container of it to kick the tires, it's very easy to get going and see what it can do: https://nginxproxymanager.com/guide/#quick-setup
I already have it running, I just had no idea it could do that. Guess I know what I'll do on the weekend :)
$ caddy reverse-proxy --from my.domain --to 10.0.0.2Hope that helps!
What I have right now:
- integration with Tuya lights/electrical outlets
- integration with AirThings air quality sensor
- integration with EcoBee thermostat/presence sensors
- integration with an LG Oven (status only as far as I can tell)
- integration with Garmin ecosystem
- integration with presence detection via the iPhone app
- integration with the sound system/spotify
So far my favourite feature is the ability to tap an NFC tag by my bed and execute the "bed time" workflow:
- ensure the lights are off
- dim the lights in the hallway, for kids
- reduce the speed of the bathroom fans
- sunset the lights in the bedroom for 10 minutes, so that when they finally turn off it's bed time.
> Out of the box, AppDaemon has support for the following automation products:
> Home Assistant home automation software. > MQTT event broker.
So I created a Home Assistant automation that does all that, bought a Zwave button that sits on the coffee table, and now they just turn it all on with one button like it's a video game console.
The only issue with the Ikea shades is that they can't be cut - so they'll only work for you if your window is the size of shades they carry. None of the Ikea sizes worked for me, I ended up taking the measurements and just ordering custom cut shades from a company called Select Blinds. A little more expensive than Ikea, but the quality does seem a bit better.
- Nextcloud (files, contacts, agendas, picture sharing),
- Invidious
- WordPress I guess for the few websites I maintain.
- PeerTube (to host videos for my choir)
- Trivabble [1], a network Scrabble game I started, which is used quite a bit, so I guess it counts, but not by me (because I don't enjoy playing Scrabble).
I probably forget something but those are the most used.
[1] https://trivabble.org/demo/ | https://gitlab.com/raphj/trivabble
I lost the ability to use Windows software that interfaced with devices over USB when I got my M1 MBP - or so I thought - until I learned that you can share USB devices over the network to a VM running on ESXi.
So now I have my windows ham radio programming software (uses a USB-Serial interface), my Toyota diagnostic software (uses a specialized USB-OBD2 cable) running on a VM. I can VPN into my home network and attach the devices connected to my M1 Mac to the Windows VM from anywhere.
I do the same thing now with qemu/kvm server. I just fire up virt-manager, open the VM I want to use and pick redirect USB device from the menu. Then I can select a local USB device and send it through. I haven't used it for much besides flash drives though. It requires a couple tweaks to the VM settings and I think it needs spice tools but that's expected, VMware needed VMware tools for this as well.
- Swag - Nginx reverse proxy for my other services. Similar to other reverse proxies people have mentioned, but it plays nice with other linuxserver containers I run so it's what I've stuck with. Has decent letsencrypt integration.
- Authelia - Integrated with Swag to handle single sign-on for most of my services
- Mylar3 - Helps keep track of comic series and, if you choose, can be used to search and download them as well
- Komga - For organizing/reading comics. I use Klutter as a companion app for reading comics from my Android devices
- readarr - Newer member of the *arr family. Still a bit clunky compared to its siblings, but it's a relatively useful way to organize ebooks and audiobooks. It doesn't do well with mixed book types, though, so I run one instance for ebooks and one for audiobooks.
- Ombi - For managing media requests
1. HRConvert2 - File Conversion Server. https://github.com/zelon88/HRConvert2
2. HRCloud2 - Self hosted Cloud Platform & App Launcher. https://github.com/zelon88/HRCloud2
It has a 1080Ti GPU so I'm just mining Ethereum on it (T-Rex miner) which pays for the electricity and actually makes 2-3 extra coffees a month :)
Of course, mining uses only the GPU (and a little bit of RAM) which leaves the CPU completely free to run a bunch of other services. I'm running an Ark Xbox server and Jellyfin on bare metal, with everything else in Docker (on a Windows 11 base install): AdGuard, OpenVpn client + socks5 proxy, Portainer, Watchtower, Speedtest, Grafana, Prometheus, Awair and Ecobee exporters, CloudFlare DDNS plus a couple of other this-and-thats :)
It's been a pain in the ass to even view what emails came and went with what volume, it will let you run event hooks as well and can integrate with rspamd as well and view each email's score as well.
Interface is very clean too.
- Vaultwarden. I see this in a shockingly small amount of lists. Selfhosted password manager. It’s been absolutely amazing and works with the Bitwarden apps.
- Proxmox. Specifically LXC. For courses/sideprojects/whatever, I just spin up a clean Alpine/Arch LXC and use it for remote development through CLion/IDEA/PHPStorm or VSC. It’s been great and saves me from installing a bunch of stuff and weird dependency management on my laptop. Which is also an M1 Air, so doing it on a linux server is much nicer.
- Nginx Proxy Manager. Quick and easy reverse proxies to all my containers/services. Both local and internet facing.
Tracks (GTD style ToDo webapp, wrote an Android app for it)
HappyAPI: I use it to maintain a chat accessible villager trade inventory for our Minecraft server (HappyAPI allows players to associate an IP with there Minecraft name on that server, so you can send "/h RedNifre Mending" and get a response with all villagers that sell Mending)
Local Video/Music: mythtv with fanless minipc for front end.
email: (sendmail/spamassassin/dovecot with Thunderbird front end)
sharing/collaboration: Nextcloud
Chat: Matrix/Synapse with Element web for the past year or so, Openfire (XMPP) for at least a decade.
Ad block: pi-hole
DNS: local recursive resolver (BIND)
spell/usage check: langtool (minimal usage, but interesting)
torrents: deluge/deluge web
proxy (forward): squid (mostly to cache fedora updates)
Podcasts: podgrab (just installed this based on an HN story a few weeks ago. I like it!)
Firewall: Netfilter/IPTables on fanless minipc
I was also running a Diaspora pod for a while, but got rid of it. I may go back to it at some point.
Streaming: Currently I use a Roku stick for this, but have been playing around with kodi and jellyfin. I hate kodi. jellyfin is pretty cool, but can't handle large music collections (jellyfin server crashes when trying to load my 20,000+ music tracks).
I won't use them for video, since both seem to think that I should organize my video files (10,000+) according to their strictures (TV vs. Movies, etc.) rather than allowing me to maintain the organization I've used for decades (genre). What's more, using their clients, I'd likely need to transcode many videos, whereas my mythtv front end (via ffmpeg) handles just about any format I throw at it.
Now that I think about it, I self-host everything and eschew any "cloud" (read: someone else's servers) services, as my data is mine and how/when I use it is my business, not anyone else's.
I just wish that more developers would focus on ease of installation[0] instead of docker containers or rafts of non-standard dependencies, which would allow less technical folks to self host this stuff -- incentivizing a broader ecosystem for FOSS and self-hosted stuff.
[0] https://news.ycombinator.com/item?id=30783477
Edit: Fixed list formatting.
Great question!
Yes, with podgrab[0] you can add RSS urls or OPML files or use the "search" feature which, using your search term, will query the podcasts in either Apple podcasts or podcastindex.com.
As an aside, the software developer seems to have a preference for Docker. I do not. As such, I downloaded the sources (Go) and installed on an existing VM. I even packaged up the binary with the rest of the package and it runs just fine, using very little (~150MB) RAM and only 33MB disk space, not including the podcasts, of course.
I encourage you to check it out. It works nicely so far (a couple weeks).
If you don't care for windows, airsonic is also pretty good; it supports both dlna and subsonic protocols. The only reason I use fb2k more often is that airsonic doesn't support multiple genres (I frequently shuffle a genre instead of using playlists). It's pretty heavy with memory compared to fb2k, though.
While you can't cast _to_ Roku using a dlna controller, Roku media player will allow you to browse and play content from a dlna server. There's also multiple channels available that provide other methods to stream music to Roku.
Truth be told, mythtv works okay for my usual use case: shuffle all my music tracks (~22,000). But it has crappy playlist support.
I've been testing out a variety of music servers and am currently playing around with Navidrome[0], which seems to have better playlist support. And it's FOSS that runs on Linux.
BTW, Navidrome supports the Subsonic API and, as such, supports airsonic/subsonic clients.
I'm not so interested in using my phone to "cast" anything and I have plenty of storage and can fit the bulk of my music collection on the phone itself. I play that music with VLC[1] on the device -- no streaming.
>While you can't cast _to_ Roku using a dlna controller, Roku media player will allow you to browse and play content from a dlna server. There's also multiple channels available that provide other methods to stream music to Roku.
I tried that with jellyfin and mythtv (both are dlna servers too), but Roku Media Player can't handle anywhere near that many songs. It just hangs until I quit the app. And jellyfin can't handle such large playlists either -- it crashes the jellyfin server when I try to play a lot of songs.
I'm not in a huge rush to move the music off mythtv, but I do want to host my own streaming platform (I wish I didn't hate Kodi so much, Emby and Plex want to spy on me, and jellyfin's UI and Kodi-like strictures on folder structure (separating TV from Movies, rather than just dealing with the Genre --> Title --> Seasons[TV] --> Episodes[TV] structure I've been using for decades. As such, those are really non-starters for me.
Mythtv's plugin ecosystem is weak and streaming plugins are pretty much non-existent.
Eventually, I'll find (Navidrome?) a new music server and a media manager with decent streaming plugins. Then I'll add another fanless PC to plug into my receiver and run with it.
Until then, while what I have isn't awesome, between Mythtv, Roku and TiVo, most of my home media needs are met. I don't care about watching videos on my phone or "casting" them. And if I did, can access my video library and stream via Nextcloud.
Thanks for the suggestions. While they don't currently fit my use cases, I appreciate the information and discussion!
Of course I also like messing with that kind of thing and being in control but those are not the main reason.
edit oh and I’m 100% through someone else hosting and messing with my calendar and contacts, which Nextcloud does fine for me.
I've got Resilio Sync running on both my NASes to get photos and videos backed up and importable. It's like SyncThing, but also has an iOS app.
I've used both nginx proxy manager and Caddy as an authenticating reverse proxy. Caddy's simplicity in setup, speed in use, and docs are wonderful.
I've also used cloudflared to proxy my home server: it's a bit more involved to set up auth, but it's (currently) free.
And, of course, I run PhotoStructure: I'm the author.
PhotoStructure is a web-based digital asset manager, but I've focused on really robust de-duplication, library portability (so I can plug my library drive or mount the same NAS directory on macOS, Windows, or Linux, and everything "just works"), as well as support for very large libraries with sub-100ms page load latencies on cheap hardware (because slow browsing is maddening). I have many users with libraries that track 1mm+ asset files, but it's also relevant for smaller libraries, given how simple it is to set up (one-click install, answer 4 questions, and you're done with setup).
PhotoStructure is freemium commercial software, as it's currently paying for me to work on it full time. A bunch of my user base harks from Hacker News: if you want to give the paid plan a spin, use coupon code "HN15" for 15% off (forever!). Details about plans and pricing are on https://photostructure.com/about/pricing/ (and visit us on Discord and the PhotoStructure Forum: I'm lucky to have really friendly and helpful users!)
- AdGuard for DNS blocking.
- HomeAssistant for all of my smart home stuff.
- Confluence for my wiki (back when you could get a $10 license, and yes I know it's overkill/unnecessary pain).
- Postgres (for Confluence)
- Nginx for reverse proxy.
I also have a Synology NAS (DS1618+) with a bunch of 10TB drives. The stock Synology apps are pretty decent and the entire package is polished compared to using something like FreeNAS. I use the built-in Photos app to manage my photo collection, ActiveBackup handles backups across all my PCs, and the Synology Drive software replaces Dropbox for me (complete with the ability to share a file via a password protected link). I run a dockerized version of SabNZBd/Sonarr/Radarr as well right on the NAS. Synology's CloudSync utility copies my most important files to a Backblaze B2 bucket.
I have the NAS connected via a 10 gig NIC for the NAS and a cheap Mikrotik 10 gig switch (with a gigabit uplink to the rest of my network). Combined with a QNAP Thunderbolt to SFP adapter for my MacBook, it's more than fast enough to use like local storage, including running VMs.
searx. Self-hosted meta-search engine.
Navidrome. Music streaming solution (paired with DSub).
Wallabag. Self-hosted Pocket. Scrapes and offlines content.
Paperless. Document management system. Paired with Genius Scan on my phone. Particularly handy at tax time.
Huginn. Self-hosted IFTTT-like solution.
Gotify. Mobile push notification infrastructure that is integrated with a ton of other stuff here.
deluged/deluge-web - Bittorrent client.
pi-hole. Nothing much to say here.
I also use syncthing all over the place (e.g. transferring scanned documents from my phone to Paperless), but I don't think of that as a self-hosted service per se.
It hosts all of my data plus my personal diary. I update it at least once a day. My photos, backups and geolocation are automatically uploaded to it.
https://github.com/nicbou/timeline
My home server gets a lot of use too. It's mostly my own code, plus Transmission.
https://github.com/nicbou/homeserver
I also have a few lines of code that take my browser's search queries and routes them according to keywords. Browsers do this natively now, but old habits die hard. Every search query goes through it.
Gitea: because gitlab is too heavy for a cheap cloud server, and projects like microsoft/github's copilot project sort of ticks me off, frankly.
Also I dislike sites that require JavaScript to display text and images.
icloudpd. Pulls photos from iCloud onto the Pi and Syncthing takes care of it from there.
Prometheus/Grafana. Monitor indoor air quality with nice dashboards. I have other ideas I'd like to dashboard, but never get around to doing it.
Pi-hole.
For me, reliability and data backups/recovery play an important role in setting up systems like this. I find that if I think about setting up a self-host solution, my mind goes to, "But what if it fails and you lose all your effort in a theft, fire, flood, or just hardware/data failure?"
And that side of my brain would be right: what if that happened?
So I guess I'd ask the author: how do you handle this niggling feeling in your brain, if you get it like I do.
First of all, I have a little bit of fault tolerance with using ZFS and ZRaid 2 with 6 disks - so I'm good until 2 disks have failed.
But more than that, everything is backed up offsite using Restic and the JottaCloud RClone backend - the data I don't want to lose is around 4TB (backups from all computers in the house, and SeaFile sync of all mobile devices) so whilst the initial upload wasn't super fast (although not too bad as I've got a 70Mbps upload speed) periodic sync each day is super quick.
Some things you can just copy the files on a regular schedule (with tarsnapper or borgmatic), others you also have to stop the DB and take a dump of it before restarting it. And everything I can set up again with a collection of custom ansible playbooks and roles.
But yes I wouldn’t self host without a reliable backup strategy and auto updates (with unattended-upgrades).
I know nothing about docker. I have a handful of VMs(Jitsi, pfsense,VPN). Want to be able to set up useful self-hosted services at home without killing my family downtime.
My current plan: yunohost https://yunohost.org/ and a RPi4 to see the possibilities. Then if I see a rock solid requirement maybe go for something more specific. (NixOS config seems interesting...)
Seem fair?
I have not tried yunohost, but the interface looks nice.
docker is not required, but docker + docker compose, on an RPi4, with auto-restart of failed containers has been very solid for me.
Simply using Docker and Docker-compose on RPi linux may indeed be what I am after to start with. A commandline + YAML file is totally fine! Thanks!
Docker Compose has worked great for me so far. I'm not sure about Nix.
And in the end it isn't a formfactor standardised and stackable solution.
You've sold me on this one. Thank you!
I went the docker route for home and I don’t recommend it. It’s too high maintenance to keep up to date, it’s over engineered for the home. I’ve since switched to proxmox and vms/lxc.
I was hoping to keep things simple. To start with. Docker+compose on a linux image seems like only "one" system to learn and there seems to be a whole library of prebuilt docker images for most services I could want to run.
Not sure how well the "image library" translates to proxmox.
Also not sure how the Trust(images from online source) Vs Capability (roll my own secure image) balance works out.
Well, nothing says I have to keep proxmox forever so I will try it out and go from there. Thank you for your time!
Folks shouldn't have to understand DNS, TLS, HTTP, IP addresses, ports, NAT, CGNAT, port forwarding, etc in order to run a server application on their own hardware.
I think we can build usable abstractions around most of it, while being secure by default.
[0]: please consider open source Jellyfin instead
once you bookmark "devicename:4567" or reference it in some other app, you won't have to change it again.
and of course having outside access to your devices when you are away is a nice plus as well
Notice how most of the software listed is free and open source - if the end user can't be arsed to learn a few things, why would the developers go out of their way to accommodate them?
They're just not the intended market.
Pi-Hole - DNS caching and adblocking for networked devices that I can't run a normal adblocker on. I also set it up to block Facebook where possible.
Minecraft (Java) - Because gotta have fun, right?
I found an alternative which is still a very young project but I've replaced Portainer.
It's a question of do you want a pull-based architecture (prometheus) or a push-based one (influxdb). Grafana is just a frontend that supports either, although influx also has its own frontend.
Let's look at the manual on variables, found at this URL: https://grafana.com/docs/grafana/latest/variables/.
Variables are shown at the top of the screen. You would assume that adding a new variable would involve a UI element placed in proximity to the existing variables. However, that's not the case at all. None of the sections in the manual would even tell you where you need to go to do that. The answer: you need to go to the dashboard settings dialog and open the Variables tab.
What about editing the name of an item? Well, that functionality could be anywhere. If it's a variable name, you go back to the "Settings" tab. If it's a query name, you can change it inline. For a panel, you do it from the sidebar. Hurray for consistency.
The UI looks great, but the learning curve is terrible due to inconsistency.
Then to feed it metrics use Telegraf.
Monica really needs some sort of smart insertion system - just a free-form field that can parse a full sentence and handle the logistics.
For example, "Mary and I spoke on the phone last week and said she was going to Italy for a vacation and offered to show me photos" - Monica should be able to parse the conversation, the event and a follow-up somehow.
I guess I use a VPN, and a browser that talks to my Roku, but I tend to think the automation is the thing.
Weird question.
I get a hell of a lot of utility out of ansible scripts to deploy LXCs/VM though. Faster than spinning up something in cloud. Zero cost and locally accesible.
Gitlab CI has also proven to be a neat thing for various digital glue and deployments
- Dispatch: IRC client
- Grafana: to create graphs for all sort of stuff
- Gogs: for private git repos
- minio: a selfhosted s3 compatible
- Apache: to host some files I want to share and a few api endpoint as a dirty lambda alternative
- Radicale: for caldav cardav with agendav for webclient
- Webmail-lite: for mails
* You get features like issues, project wiki, etc
* You can still collaborate/handle PRs easily with other people
I selfhost for the above and just to have a handy backup in case github is down.
- lighttpd webserver
- ZeroBin [1] pastebin
- Gogs [2] git hosting
- qr code generator [3] (some lines of bash)
- static ios OTA test deployments [4]
- Minecraft Server Spigot 1.16.5
- dokuwiki
[0] https://demo.mro.name/shaarligo
[1] https://github.com/elrido/ZeroBin
[2] https://gogs.io
Plex - Basically all TV's use this now on rokus in my house. With a few other roku Apps like Netflix or PBS. But Plex is 99% used
AtomicToolkit - arrr
Pi-hole - i guess..Most arent aware its inline though.
NGINX+LetsEncrypt box - reverse proxy for internet request and give them https (for things like plex). But again, transparent.
More recently Ive setup HomeAssistant to mostly consolidate the number of APPs. Ie: 1 app now controls both my central and window AC's.
Less "self hosted" but i did buy into an Opnsense AMD epyc SOC appliance. Dang thing is pretty awesome and a pretty big upgrade to the supermicro/Intel Celeron J1900 router opnsense router i was using.
* Miniflux as an RSS reader
* Home Assistant for home automation stuff with various door/window/movement sensors, Hue management, workflows like bedtime and welcome home
* AdGuard for DNS adblocking
* An OpenVPN VPN for me to get into my home network, and another to a VPS in another country that my network gets routed over when connecting to geoblocked content ( ip sets are awesome)
* Not really self-hosted per se ( just local) and as a replacement for what some here self-host, Obsidian for note taking and wiki.
For many, this is better than simply spinning up a localhost Ethereum network as offered by Ganache, because those lack any data to manipulate.
Most popular apps are: WordPress, Filerun, Nextcloud, Uptime Kuma, Umami and PhotoPrism.
This would be for anyone lacking time or sysadmin skill to run this as hobby. I'm also working on a sponsorship or revenue sharing schema to get some financing back to FOSS authors. Since you're already paying for something there is less friction than actively donating to each project.
* Blue Iris - for video surveillance
* Home Assistant
* Jellyfin
My main backend things are:
* Node-RED - for more complicated home automation than can be reasonably built in Home Assistant
* deCONZ - for my Zigbee lights and sensors
* PostgreSQL
* StrongSwan and Wireguard VPNs - I'm still evaluating Wireguard. I like the simplicity, but there are some things that I can do with StrongSwan that I can't do with WireGuard (specifically, split-DNS).
* Pi-hole
* Kubernetes - I'm just playing with this at the moment, but I'm running Pi-hole in it as it's not a critical service.
* Nginx - reverse proxy and TLS termination.
* TrueNAS Core on a QNAP NAS
I'm sure there's some I missed.
I also use it for publishing file upload status messages, and recently, the carbon-zero fuel power generation percentage for my neighbourhood.
Is it easy to display the last message received on a collection of topics? It would make it easy to watch a custom summary of a large system.
I did a writeup at https://petergarner.net/notes.php?thisnote=20190811-Lightwei... which should give you some ideas. As regards clients I'd recommend the cross-platform MQTT Explorer https://mqtt-explorer.com/ and for iOS, I've settled on EasyMQTT which also provides some graphing options. I don't use Android but most of the clients are good (and free). Hope this helps!
- Node-red - Node-based GUI to supplement Home Assistant
- Mosquitto MQTT server
- Invidious - Alternate YouTube frontend
- Libreddit - Alternate Reddit frontend
- Jellyfin - TV/Movie/Music streaming server
- Gitea - Private git repositories
- Nginx Proxy Manager - What it says on the tin
- PiHole - Ad blocking
- MakeMKV - GUI frontend to MakeMKV running in Docker on my headless server
- Various Discord bots
- Nginx + PHP for my personal sites
- Wireguard for remote access
- Samba for file management
All of this running on a local Arch Linux server with ZFS for RAID. I also have hosted some game servers in the past (Minecraft and Terraria mostly) but don't at the moment.
I actually don't redirect my Reddit requests, since once in a blue moon I will want to comment on something, which libreddit doesn't support. However Invidious does have the option to let you follow certain channels, and since I don't comment on YouTube videos, it covers all of my use cases, so I redirect all Youtube traffic to it.
I use synapse as the server and Element as the client. I had tried out a bunch of other clients a few months ago, but found Element to be the most mature.
My experience has been pretty great overall. There were a few early issues (relating largely to a slightly weird network setup) but otherwise it works very well once setup.
Recently when I was trying to setup Mastodon, I realized how much more mature the setup process for synapse was. The setup needed for networking is better documented and they have a tool for testing if federation is working (and if not, attempting to provide an explanation why). This made it relatively easy to set things up correctly for my network compared to Mastodon, where I finally just gave up and setup a digitalocean droplet instead.
Functionality wise, everything works pretty well, E2EE requires a bit of preplanning to maintain across devices (ie. Keeping a backup of the keys or having the key store setup) but that's reasonable. The spaces feature needs a bit of UI polish but otherwise provides a similar hierarchical channel grouping system as Discord and Slack.
I can't really think of any other particular criticisms I have of it except that to administrate a server we still seem to have to lean on a third party application, synapse-admin (or hand write curl requests), it would be nice for it to just be incorporated into the client or into the server. I haven't had to use it much due to not having many users, but I imagine it's pretty relevant for servers with more users.
I've tried running Synapse (and was partially successful) a little while ago but didn't try to federate as I never took the basic hosting of it anywhere.
I will try again when I have my new home infra set up.
PiHole, it's the first thing I add to every network I set up. Can't live without it.
The *arr -stack (son-, rad-, baz- etc)
Plex for media at home and on the go (Plex Pass). Maybe I'll look up Jellyfin at some point, but for now Plex is superior.
Home Assistant + zigbee2mqtt + NodeRED + n8n for home automation and other tasks.
Mosquitto + Redis for communication and database use for my own projects.
Tailscale node for accessing my home network as a bastion host.
i have a sync folder called 'drop' that gets added to every device, mainly just so i can quickly drop a file in and take it out on another device.
each OS i use has its own sync folder, linux, android, windows etc.
i have a 'config' folder with a huge alphabetical list of every program i use on any OS. that gets added to most devices
i have separate sync folders for programming stuff, art, music making stuff, books/audiobooks, note taking stuff, openstreetmap. i usually use some ignore patterns on those when syncing to my phone or tablet to reduce the size of the folders
each phone that i take photos on has a send-only sync folder which is synced to my home server, so i don't need to worry if delete a photo by accident or whatever
i still haven't figure out my music folder yet. im currently just syncing the full folder between every device which is not great due to the size. im thinking it might be possible with a quick script that would get a list of tracks from whatever .m3u playlists i choose and then use the inverted ignore pattern so it will only sync those songs and ignore everything else.
These are all on my small NixOS VPS (or individual devices for SyncThing) - I've been meaning to setup an old laptop as a server at home for home automation and media.
While they're cheap, should I really self-host on shared CPUs because that's all I can afford right now.
My basic system would be Pi-Hole, Miniflux, Linkding. Maybe Bitwarden.
What would be a good way to get started? Any suggestions are welcome.
It's what I did. It costs me less in electricity than a VPS but it's way more powerful.
The only thing I eventually bought was an UPS, because for some reason I regularly have micro power cuts at home.
I have it connected to a small UPS due to the occasional random brown-out in my neighborhood. The server only runs on the UPS for about 15 minutes, but during the rare substantial power outage, that's enough for me to power it down gently.
I also have a little desktop Lenovo PC I found cheap (used) at microcenter that I use as my primary zwave hub with a custom MQTT/JS based home automation script. This replaced a Raspberry Pi, which I loved, but after losing the storage a couple times, I no longer rely upon as a primary server
Bonus, those MicroServers are supported by ESXi, IIRC
It is a (fairly small) desktop tower, so it takes up quite a bit more space than a couple of Pis, though, again, it also encloses some internal hard drives, which is nice. I'm not sure about power use but I'd just gut-instinct guess it's equivalent to four or five Raspberries Pi, even if you take out the power to run the hard drives, so it is (probably) worse on that front.
Rent a Linux server, deploy the Tailscale client, run apps on it.
> should I really self-host on shared CPUs
That shouldn't generally be a problem unless you're a very high value target (or really unlucky), but if you're that worried, rent a bare metal server.
Pi-Hole and bitwarden are simple enough applications that you can host both of them on a pi. Plus there are plenty of guides available online to guide you thru the process if you do get stuck.
I got started with self-hosting pi-hole on a raspberry pi myself.
And it's nearly impossible to get any of them. I've been trying to buy another 4 with 8 GB for over a year now, but am not willing to go beyond 80 € for just the board.
Also, there is a LOT of resource congestion for the arm systems. Be prepared to try every day to fire up new instances for a couple of weeks until you can find free capacity.
You can get them on eBay for <$100, they will typically have a fair amount of RAM and a quad-core AMD CPU (enough to outperform a raspberry pi pretty easily), and they will typically be on the order of <20W of power usage, meaning that even running 4-5 of them with k8s/Docker-Swarm won't murder your power bill.
Just an example: https://www.ebay.com/itm/154783701325?hash=item2409d3d94d:g:...
You can pretty easily install Ubuntu or something on there and treat it like a normal computer.
You would be better off with a like-new Dell Wyse 5070 off ebay for ~100 (and occasionally less if you're patient). Supports up to 32GB ram and an M.2 SATA slot.
You'll have much better IO, stability, and capacity compared to RPI4 for not much more cost. Power envelope of the system is pretty similar, the 5070 idles around 5W and loaded down it goes up to ~15W and is fanless which is in the neighborhood of the pi.
I host a VM for my router I host a VM of open media vault I host an arch box for my development.
Any notes or projects I have are edited in vim and committed to GitHub. Any networking stuff that isn't supported by openwrt isn't bothered with and I spend my free time mostly reading books. Actuall paper books and occasionally taking actual paper notes.
Xen-Orchestra, OPNsense, nginx, wireguard: This is the foundation and plumbing to run all my other applications.
Nextcloud: I'd be very unhappy if this broke. It syncs my files, calendars, contacts and also has the rss feeds I'm subscribed to.
Jellyfin: movies, shows and music
Kavita: a more recent (and still wip) addition, books and manga reading
WikiJS: my current wiki. I'm moving to grav for a full CMS though
Here are mine:
- Nextcloud - files, calendar, todo, contacts syncing
- Tiny Tiny RSS - RSS reader
- Wallabag - read it later, also a database of interesting things I've read so I can recall later
- Photoprism - photo organizing/tagging
- CheckMK - monitoring
- The Lounge - IRC client that connects to my ZNC bouncer
- Plex - media streaming
- Airsonic - music streaming (since Plex sucks at that)
- Gitea - git repos/issues
- Code-Server - VSC instance hosted in the browser
1) Requires PlexPass (iirc), 2) Makes you pick a library rather than searching/playing from all. Switching libraries is extremely quick and simple though.
To give an answer more in line with what the post author appears to want, I've been playing around with Pleroma lately, so it's my most-used self-hosted application until I find something newer and shinier to distract me.
It removes the unnecessary thinking that I do not want to waste time on. (e.g. is the washer flooding the basement? Light off if I am not around, close and lock garage at night, etc.)
Navidrome - nice lightweight self-hosted music server
Miniflux - my RSS reader
PiVPN - An easy to use wireguard manager that I use every day. (Technically I interact with only wireguard, not the manager PiVPN every day)
Emby. Network media streaming.
qBittorrent with the web server enabled. Downloading Linux ISOs.
Airsonic. Music library streaming, though I find myself using Emby for this more often.
All running on Ubuntu 20.04 on an Intel NUC with 16GB RAM.
Garage: s3 for backups and Docker images
Loft: for managing a small cluster and providing oauth
Rob’s Magic VPN: custom software for managing a VPN and switching to/from the VPN with some routing magic.
Longhorn by Rancher: for providing volumes on the cluster.
Harbor: personal Docker registry using Garage as a backend.
I've used keepass for close to a decade, and synched via dropbox originally but utlimately switched to nextcloud for the synching...but, curious how and why you are sharing via *Caldav*? Care to share the "how" and the "why"?
HomeAssistant w/ AdGuard Home and various other things on it.
Used to also do PFSense, but ended up just using Ubiquiti now. Miss a few things, but its one less place to manage things.
I have an actual app too that's also a note taking app (use it everyday) basic React/Electron thing with Express backend
my goal is centralizing my own info
It's perfect for my needs, I need to work out setting up separate databases for separate note purposes (keeping personal and work separate). I find tiddlywiki / noteself's structure perfect for the various streams required for the management of projects.
Anyone have a simple, straightforward and secure process for remote access to a home server?
However to get it actually simple, Tailscale. It’s truely ludicrous. I had it running inside 10 mins, but only because I wasted 5 minutes trying to work out what to do next, when it was already running.
- Wiki.js
- HomeAssistant
- lychee - pohotos
- nginx-proxy-manager - proxy/letsencrypt
- jellyfin - movies
- audiobookshelf - audiobooks
- nextcloud - news/talk
- ghost - few blogs
- httpd - many private and commercial web pages
- domistyle/tor-browser - easy access to TOR
- exatorrent - downloading linuxes ;)
- m4yur/mindmaps - mindmap
- portainer - administrating all those dockers
Configuration I tend to store in a git repository that I back up.
For the VMs/whatever, I just document the setup and, in the case of a disaster, would just rebuild. It'd be a gigantic PITA, but the data and configuration are the important bits. The rest is just labour.
That said, this is why I don't self-host truly critical infrastructure like email or messaging. Everything I run are things I could live without for a while if I had to.
- NextCloud - Dropbox alternative
- UXWizz - Website analytics
- Percona Monitoring and Management - Database/server monitoring- Caddy, very easy reverse proxy
- Authelia, single-sign on for all my services (I prefer that to VPN)
- PiHole, for blocking ads
- Nextcloud, private Dropbox
- Gitea, private Git
- InfluxDB + Chronograf, for monitoring my home
- Jellyfin, media server
- Sabnzbd, NZB client
- Deluge, Torrent client
- IPSec VPN
I like it much better.
I don't have much to show, I'm running Home Assistant, Ubiquiti Unifi-controller, Pi-Hole, that's it so far.
1. MediaWiki (internal wiki)
2. Bugzilla (issue tracker, used internally and externally)
3. SugarCRM CE (internal CRM)
Syncthing - File syncing across my network.
FreeNAS - Storage across the network.
Plex - Media streaming.
Work: Jitsi, Nextcloud, Mattermost, Gitea
Network: ZeroTier (which is our own dogfood)
(this is not a criticism, btw)
- Proxmox to run all mentioned services
- Software router to bind them all together (OpenWRT in a container)
- Database services (Postgresql, Mysql, Redis) used for many of the mentioned services
- Backup services (rsnapshot, custom backup scripts)
- mail services (Exim, Dovecot, Spamassassin, greylistd, dovecot-managesieve)
- web-related things (first Apache, then lighttpd, then nginx) running:
- "Cloud" (first Owncloud, then Nextcloud) with functional equivalents of e.g. Google Docs (Nextcloud Office), Google Reader (Nextcloud News), Google Meet (Nextcloud Talk, Jitsi Meet), Gmail (Rainloop app in Nextcloud, Roundcube), Google Maps (OSM app in Nextcloud), Calendar etc.
- Wiki (first Twiki, then Mediawiki, now Bookstack)
- Media (mpd, Airsonic, Jellyfin, Peertube, Pixelfed)
- version control (first CVS, then Subversion, then Gogs, then Gitea)
- Search (Searx and Recoll)
- big-tech proxies (Invidious, Nitter, libreddit, Spodcast, searx (see Search))
- Video surveillance (Zoneminder)
- Remote application/desktop service (X2go, NoVNC, now experimenting with Kasm)
- P2P services (Transmission, IPFS, MLDonkey (when needed))
- "Chat" services (first Prosody, then ejabberd, then back to Prosody)
- Timelimit service + app on my daughter's phone to keep her screen time in check, I can remotely give her more time when required
- a "stable" and "development" build server (Debian running in containers)
- ...and a lot more
Basic services are divided over a few containers - base, mail, auth. Most services run on a single container - serve. Some get their own container because they are only started irregularly (bookcook, the bookkeeping service) or they should be separated from the rest - p2p, session (remote application/desktop services). I tend to shun docker, preferring to tailor services to my own needs. Currently the only services using docker are Kasm Workspaces [1] and some linuxserver.io instances which I'm experimenting with.
[1] ...with the database (postgresql) and cache (redis) services being redirected to the 'base' container which runs all database services
Plex - media panacea
Transmission
Valheim - currently disabled, waiting for more content
I was creating "htmlz" archives from calibre and then extracting them to a directory my nginx server could see but this is way cleaner/better.
- Retropi
- Openwrt router with dns ad blocking
- Radarr
- Sonarr
- matrix
- nextcloud
everything a family needs.
At home:
- Miniflux - rss, much nicer than ttrss, less complicated
- FoundryVTT - Tabletop RPG system to play remote games with some friends around the country - Seafile - mostly use it for an imgur/filesharing solution, but can also double as a dropbox alternative. I dont like nextcloud.
- Portiner - manage my docker stuff easily
- Caddy - simple reverse proxy
- Syncthing - Mostly for sycnthing my local code worksapces, and MMO configs/settings between my computers at home.
- HomeAssistant - handle mostly Zigbee stuff, and some motion sensor lights over the baby changing table at night. Rigged a ESP32 board with ESPHome and it connected it to a string of faerie lights. Turns on when you walk in with the baby in the middle of the night without blinding you. And some other odds and ends. Still use Google Home and Google Nest devices for most things.
- Authentik - Oauth2, OIDC, SAML provider for my domain.
Third party:
- ImprovMX - This hosts my email domain/smtp, which allows me to do mx forwarding for my emails to any provider. I still use Gmail under the hood, but lets me skip out on the Google workplace nonsense (used to have a grandfathered free account, then paid for a while), while still keeping my email nimble. I can switch to any email provider in mins with no downtime if caught fast enough.
- Tailscale - I like the wireguard based solution to have a VPN mesh between my computers. All servers and computers I own have this installed. Makes it easy to keep certain things on a private IP but easy to access remotely.
- Cloudflare - anything publicly exposed runs through cloudflare dns. I also moved a lot of my domains there.
I used to run a k8s cluster with Traefik as an ingress and all sorts of fancy things, but as a DevOps engineer for work, it was annoying to maintain yet another thing I do at work. Also I tried doing a multi-machine k8s with Longhorn and it died miserably. Switched back to Docker containers, Portainer, and a simple Caddy with a caddy config.
I also run everything currently on 2 Raspberry Pi 4 8gb (want to go up to 4 of them). Most are running on 1, but the Caddy and other non-docker stuff run on the other. I also run the HomeAssistant on a dedicated RPi 3 with a Zigbee adapter plugged in.
Going to look into some of these things people posted here that I havent seen on Awesome Self-Hosted or /r/selfhosted
The thing I havent found something for is Raindrop.io, shiori is close, but not quite as good as Raindrop is for my needs.
My home server:
- Nextcloud It is my family's main cloud platform, with a 4TB nas HDD. I run it with PHP opcahe enabled and nginx caching to speed it up. And since its local, the upload/download speed is unmatched.
- Nginx proxy manager(NPM) and Portainer For NPM its easy and simple to maintain, and the WebUI makes it easy for someone else to change settings Its mostly the same reason with Portainer, but I prefer to not use it, its very handy capped, quite often in stupid ways like not being able to disable the admin account when enabling sso, just to push you towards the paid version
- Pihole
- qbittorrent
- uptime kuma Easy and simple way to monitor websites I manage. I wish they showed incident history in the status page.
- IPfire Firewall Its easy, simple and gets out of the way, I mainly use it to block outside dns and as a doh resolver. There is also file caching using squid proxy, but its a headache to make devices actually use it.
I don't use its dns directly, devices connect to Pihole which filters queries then forwardes it to ipfire. Pihole is more advanced and has many community integrations.
All of it is running of Proxmox, ipfire as a VM, and all others are running inside a debian LXC with docker, nextcloud is on a separate LXC so I can ZFS snapshot it independently of others.
I also have a personal vps.
I host a matrix server(Synapse) on it, and its been a good experience, its not light, IMO it needs at least 2VCpus with 4gb of ram(on hetzner). I'm still a bit hesitant about installing bridges on it, since bridges decrypt messages, I may install it on the home server but its upload speed is limited to 25mpbs.
I also host headscale[1] Its a reversed engineered open source tailscale server implementation. It supports most of tailscale features. It mostly good enough, I also use the same server as an exit node, so its a full vpn.
I want to use a mesh vpn so I can have a single ip which will have full performance in my home while it still works when I'm out, because I have a separate pihole on the vpn server which has more opinionated ad lists for me and still have DNS filtering on the go. Yes I can just use the homes pihole, but the rest of the family doesn't use my vpn, so the dns override would breaks their connection.
And since tailscale/headscale support an exit node, I don't have to lose my normal VPN.
I'm not sure if I'm going to stick with it long term though, the tailscale app needs to be rebuilt to support a custom server(there is a PR adding support on their repo)[2] And it consumes a lot of bettery, it accounts for more than 30% of my phones battery usage, while the wireguard app doesn't even showup in the top 10 apps.
And the nextcloud app sometimes takes for ever to connect to their server, I'm using another pihole as the dns server for the network and I had setup my domain overrides correctly for both ipv6 and ipv4. The browser loads nextcloud web just fine while the app is still loading
If only there was to setup a standard wireguard server that cab be used wtih the official app with mesh networking.
* Syncthing
Google Colab clone
Jitsi
Plex and Jellyfin (yes, both)
Calibre-web
Vaultwarden
TrueNAS
PiHole
Paperless-ngx
Edit to add: Syncthing
unifi controller
home assistant
mythtv
mailcow
ntp/chrony with a gps antenna