Tipi – A personal homeserver for everyone
github.com
github.com
I hope meienberger here hasn't plagiarized source-available project named Umbrel.
The comments in this file seems similar too:
https://github.com/getumbrel/umbrel-apps/blob/eb0f119df8ed89...
https://github.com/meienberger/runtipi-appstore/blob/c86641b...
This text is identical word for word in the Syncthing app file at the Umbrel repo.
https://github.com/getumbrel/umbrel-apps/blob/master/syncthi...
> cloud Light: no JavaScript, no ads, no tracking, no bloat
I have been an addicted reddit user since before they had user accounts. I never had any desire to block reddit ads until the last ~6-12 months or so when it would autoplay ads when I scroll. I have "no thumbnails" so it doesn't show me the ad other than a line of text or so. I have "old" reddit enabled on my account -- this works for desktop. And now I've started using the explicit "old.reddit.com" on mobile. But I would prefer mobile-optimized reddit without audio ads. I will probably give libreddit a try.
[1] https://github.com/spikecodes/libreddit
EDIT: of course, since it's privacy focused I can't login to my account and reddit is unbearable if you try and use it without your account to curate the subreddits. Whoops, scratch that idea!
teddit does actually have a subscription concept, accountless, but in general the multireddit solution would work for your libreddit example
Teddit is a free and open source alternative Reddit front-end focused on privacy.
Teddit doesn't require you to have JavaScript enabled in your browser.
The source is available on Codeberg at https://codeberg.org/teddit/teddit.
No JavaScript or ads
All requests go through the backend, client never talks to Reddit
Prevents Reddit from tracking your IP or JavaScript fingerprint
Lightweight (teddit frontpage: ~30 HTTP requests with ~270 KB of data downloaded vs. Reddit frontpage: ~190 HTTP requests with ~24 MB)I’ve been on Reddit basically daily for 15 plus years…
I only use old.reddit with RES and UBO and I never see ads…
And my Information density this way is so much more enjoyable than anything the new shitty reddit can show!
New reddit is worse than new DIGG was.
But they are trying really hard to fuck up the UX via their new UI…
Go to the hamburger menu > settings > manage your subreddits.
Another mobile option is i.reddit.com.
I've been trying Infinity from time to time which others have mentioned as the new OSS client, but it seems less textual than Slide. Sline also has great navigation that is immediately missed elsewhere.
(At least the Android version, dunno about the iOS)
I don't know if you've tried it already, but https://i.reddit.com might fit the bill.
It has JS. Optimized for mobile. No tracking from my side.
Open in congnito for NSFW subreddits. Enable pictures/NSFW mode to load all pictures in line. Close it when you are done.
There are 3rd party mobile-optimized apps btw. Support logging in and most reddit features. I use Boost for Reddit personally, but there are others like Baconreader.
Docker/containers used to not be hardened enough. Are they now?
Virtualization/VMs used to be the answer but it adds both performance and management overhead. Is there a good system here?
Or something else entirely? Like old school separate users.
You can still use VMs, and some use that as an additional layer of isolation because they're virtualizing anyways (performance overhead is really negligible).
I've been self-hosting on my home server for at least 5 years now, and I think I've only seen two or three vulnerabilities across all the services I know about, none of which were ever really exploitable.
But still, for a single or less than 3 machines and/or in a single location I don't see the point.
It’s your home environment. You want it to be easy. You want to use the tools you run not maintain them. If you want to learn k8 for professional growth, learn it separately from a home server.
Your home server can be more pet than cattle.
As far as disaster is concerned, it's not that difficult to install software that really needs minimal maintenance. But it comes down to what you want out of the software and hardware that you run.
There’s only one and it changes manually as I need features to change. I download and install things as needed, from gui, with no version control or script to manage it. It’s a pet.
Yes absolutely. I can afford a new one, and I would immediately buy a new one (well I’m already waiting for the newly released one but still). I would still be quite upset and my life would be interrupted at least a little.
I took the pet/cattle analogy to be about how manual the setup is, and how replaceable it is. I think apple has smartly blurred that line with great backup tech, but I would still consider the “lovingly” hand customized aspect of maintaining a phone solidly a pet. Some version of my current phone has been around for ~10 years through various hardware iterations, all restarted from a backup image. I would be distraught if i had to recreate it without a backup, just finding my apps, logging in, finding wallpaper, rearranging icons, setting up shortcuts, etc. Maybe that’s the ideal state for a home server - a nearly no-op backup and restart process that you still manage as you need
I've been moving workloads to an old gaming rig running NixOS with varying levels of isolation (some containers, but really just good user/group/permissions management), and it runs super well.
Of course, you could do the same with just Docker Compose and no Swarm, and I think you'd still be better off than using Swarm.
The main reasons swarm is better than other options for clustering IMO is networking. They can be set up to share the ports on all devices and map it back to the correct container on whatever host it’s on, so you can disconnect the target IP:Port from the container.
If you want to try out <insert tech here> to learn something, then just learn it, don’t try to fit it in your normal life and eat at your existing stuff. Don’t replace your mac with a chrome book just because you’re learning webdev, and don’t replace your home server with terraform just because you’re learning it. What if you learn it but stop needing it or never use it professionally? You’ll now need to maintain that skill to maintain something at home.
If you want something more than a blank Linux box for your home server, check out HASS.io, synology, QNAP, TrueNAS, or one of the many “hold your hands” distros/tools designed to make it less work. Even Portainer/Proxmox will give you a bit of a GUI without being too opinionated. I use a blank Linux box primarily, but only because I live with other SWEs who all want to mess with the shared server, and everyone wants their own thing and we couldn’t agree on anything else. We plan to switch to TrueNAS and give everyone a VM but haven’t coordinated the switch yet…
The overhead on something like an RPi would be ridiculous, but on modern x86 hardware with an IOMMU (VT-d in Intel speak, AMD-Vi for AMD), the overhead of passing through HW is, for homelab purposes, essentially 0. A lot more expensive, but the organization and extensibility is well worth it.
I have anything that I expose directly to the internet on a separate VM from my "internal" services. If I were super paranoid, I'd expose them to separate VLANs, and then use my FW to control network traffic. The Intel 82599 can enforce different vlans on different VFs with SR-IOV.
I have a VM that runs flatcar for docker for things that are too hard to set up otherwise, but I vastly prefer NixOS for most things.
This is exactly what I did initially, but it was indeed a bit of a pain to manage. Eventually I went with something in between, by first compartmentalizing services and then putting them in separate VMs with separate VLANs:
0. Router / FW.
1. WireGuard / reverse proxy.
2. Personal, e.g. file storage, backups.
3. Hosting. My personal site is reverse proxied through Cloudflare and only their IP ranges are whitelisted.
4. Compute, i.e. stuff I want to compile / develop / run on my server. Handy if I want to run a heavy simulation overnight or need more disk space / RAM / CPU power than my M1 MB Air has available.
5. Services. This runs many small tools / services that don't need access to my RAID pool or anything like that. If this gets infected I wouldn't really care.
6. VPN. This VM can only access the internet through a VPN. Doesn't have anything installed ATM, but has been used in the past for urlwatch and torrenting.
7. Test. This is where I try out new software before actually installing it on the correct VM. Once I've concluded testing I rollback this VM to a clean install.
It takes a weekend to install Proxmox and set up the VMs / VLANs, but after that it easy to use.
and the best reason to use SR-IOV with networking is you completely avoid the awfulness that is the Linux bridging/firewalling stack
Use userns-remap. Run the docker daemon rootless if you want but don’t stress about it. Set up auth to the docker socket. Don’t bother with running the processes in the container as not uid 0, with remap it’s effort for little gain.
Now breaking containment means having a local privesc on your Linux distro or breaking the auth on the docker socket. Like that’s plenty for drive by attackers.
The WordPress Sandstorm app is slow enough at rebuilding the static side of our large site that I’ve been meaning to try forking it or building my own though. But Sandstorm itself has been great.
For standard services, I use Apparmor with the default `apparmor-profiles`, as well as fail2ban with some additional firewall rules.
[1]: https://man.archlinux.org/man/systemd.exec.5
[2]: https://wiki.archlinux.org/title/User:NetSysFire/systemd_san...
Generally your just serving a single user - you - so even potato grade gear is fine
I don’t think they ever will be. At least once a year there is a kernel bug where root in a non-root container/namespace can be elevated to root on the host
I am confused as what homeservers are. It seems this one is allowing me to run some apps. Does this mean I would otherwise not be able to use these apps if I did not have a homeserver? Also is there a difference between a homeserver and localhost?
Some of these server apps are made available to others by hosts of servers. The more people hosting servers for their friends and family, the less we all rely on the big central services.
I will let you lookup the definition of localhost. You will need to learn some networking if you decide to host your own services, and I encourage you to do so. It is fun and empowering.
It means send this from my network connection to my network connection.
This homeserver is kind of like a smartphone loaded with default apps (and kinda not like that, too).
What I mean is that this homeserver is essentially a bunch of apps and a platform for running those apps all bundled together to make setup easier.
You can setup and run all the same apps yourself if you want, but it might be a lot of melodrama for little, no, or negative advantage (or it might not).
The same applies to the homeserver itself. It might not make your life easier and might make it worse.
Which is to say it might not be for you — it isn’t for me, because it seems like a bit of bother to address things I don’t really care about.
But it might be perfect for other people anyway.
Essentially, it's a single-click installer and management interface for a bunch of apps that you might want on your home server. Tipi isn't a "homeserver" itself, but it's goal is to let you turn any old computer (even if it's somebody's Windows desktop while they're not heavily using it) into a home server without needing server OS administration or related expertise.
Admittedly, a better title is "Tipi - a personal homeserver manager for everyone." But the idea behind the current title seems to be that it enables everyone—regardless of hardware and expertise—to run a homeserver.
A server provides software services. Your router could be considered a server: it helps your wifi devices get online and manages the Internet connection.
Tipi is an example of a pre-configured router, but as a server for certain apps: by using it, you don't have to set it up yourself. It comes with software that you can use, already available, installed, and configured. But it is a server too--and running in your home, it is a "homeserver."
You could likely use those same apps without Tipi, with varying amounts of time spent configuring something similar.
> Also is there a difference between a homeserver and localhost?
Yes, it would be different. If Tipi is running on a separate machine (the server), its localhost may load some kind of web control panel. However, when you visit localhost on your personal machine, if a web server is not running, the browser may just load an error page.
See this nearby comment for some advantages of running your own server(s) at home: https://news.ycombinator.com/item?id=32794629
In your home you are protected (this is why Hillary's email server was self-hosted, to get the same rights against unreasonable search and seizure you get with US Mail), on the cloud the third-party doctrine rules and they can just give out your private data at any time.
(some providers have now said they won't give it out for requests about people seeking abortion, but that could end up in there when they search it based on a request about something else, and I don't know if any put the restriction on sharing abortion stuff with law enforcement in their actual legal agreements)
Basically, it allows you to run the apps that you were already running natively on your own computer, but now in a browser on your own computer :)
Otherwise, pretty similar, it's Docker plus fancy glue. :)
For an example, compare https://github.com/meienberger/runtipi/blob/master/scripts/a... with https://github.com/getumbrel/umbrel/blob/master/scripts/app.
You know we weren't in the dark ages before Docker, right?
"I have to download F-Droid, compile it, and then install your app? Nah brah."
Now: making minimal edits to a provided compose file for initial configuration, run command to spin up everything application needs, and you're done.
Then: install application package onto system (best: from developer package source/better: from old version in operating system repo/worst: by compiling from source after locating all dependencies and running make install), setting up any necessary databases or storage by hand, editing configuration files that are hopefully in /etc if the developer thinks the FHS is something to be honored, setting up init scripts/unit files so the application starts up in the environment it wants and when you want, and finally running the command which starts the application (which is probably distro specific).
And that's not even getting into updates. I'll take pulling the latest version of the container and restarting over app specific update instructions any day of the week. Life is too short for putting up with that kind of minutia.
Really liked the concept, not the execution so much as it turns out.
Thinking of taking a look at CapRover next, which is docker based. This Tipi thing might be worth a go too, though maybe when it's a bit more mature.
I deploy it in an unprivileged LXC container [2] and went through several upgrades already. It really worked great for me.
[1] https://benou.fr/www/ben/14-years-of-self-hosting.html [2] https://github.com/bganne/yunohost
That is SCREAMING for iPhone 1.0 style icons. There was just an HN post on how crappy modern icons are, I think it was the "there is no personality in 2020". This would be Exhibit A.
But true, if you can work past those things, it might be better than tipi.
Otherwise it looks interesting, I like the UI and the demo instance shows the UX well.
Then the tool could be used readily on the many docker appliances (Synology, Qnap, etc.).
The initial setup but then it's just OS updates, rarely a major version configuration adjustment, nothing wild.
Postfix Dovecot Postgres ezpz I also use milter rspamd opendkim
UI is vimbadmin, but I'm working on writing a drop in replacement for it in Go. I'll release it open source once it's ready, likely also a setup script for the whole deal.
And with this you can be pretty sure no one eavesdrops. And then install Delta Chat to have a messenger-like workflow.
I use it for my personal mail along with some clients.
It was quite easy to setup by following this guide: https://workaround.org/ispmail/buster/.
There's also an ansible playbook by the author to automate all of that for you.
Other solid solutions include Mail-in-a-box and Mailcow. DuckDuckGo them to learn more.
A lot of people say that you shouldn't waste your precious time hosting email. Then, these same people won't hesitate to spend countless hours browsing Pornhub or Netflix and playing video games.
Forget about these losers and roll your own email for fun. The last thing you want is to be on your deathbed regretting not having had your own personal mail server.
::proceeds to require It guy level setup::
This looks good but still doesn't look proper home media server enabled.
The screenshot shows what I presume is actually the logo, which is a tipi.
Emojipedia article for "Tent": https://emojipedia.org/tent/