HNHacker News
TopNewBestAskShowJobs

mirdaki

259 karma · joined October 20, 2020

submissionscomments
mirdaki··on My Self-Hosting Setup
I can touch on it more. Docker and compose files are great for getting things going, contained, and keeping everything declarative

But I found the more services I used with Docker, the more time it took to update. I didn't want to just update to latest, I wanted to update to specific version, for better rollback. That meant manually checking and updating every single service, bringing each file down, and then back up. It's not entirely unmanageable, but it became enough friction I wasn't updating things consistently. And yes, I could have automated some of that, but never got around to it

NixOS, in addition to the things I mention in the post, is just a two step process to update everything (`nix flake update` and `nixos-rebuild`). That makes updating my OS and every package/service super easy. And provides built in rollback if it fails. Plus I can configure things like my firewall and other security things in NixOS with the same config I do everything else

Also, Nix packages/services provides a lot of the "containerization" benefits. It's reproducible. It doesn't have dependency problems (see this for morehttps://nixos.org/guides/how-nix-works/). And most services use separate users with distinct permissions, giving pretty good security.

It's not that Docker can't do those things. It's that Nix does those things in a way that work really well with how I think

mirdaki··on My Self-Hosting Setup
Hey, I ruled out a mail server for external, since I've heard many people have issues with other providers (Gmail, Outlook, etc) randomly blocking email. Didn't feel I could rely on it

Having an internal only mail server for notifications is an interesting idea. I've been using ntfy and Matrix to achieve something like that, but not all services support those notification methods. I'll keep that in mind!

mirdaki··on My Self-Hosting Setup
Oh that sounds really rad! Certainly could have it's use cases. I really appreciate how NixOS enables projects like this. Best of luck with it!
mirdaki··on My Self-Hosting Setup
Yes! On top of the data safety features of ZFS, the fact you can encrypt a dataset and incremental send/receive is a fantastic ability
mirdaki··on My Self-Hosting Setup
Thank you! It's all a journey, hope flame works well for you!
mirdaki··on My Self-Hosting Setup
Oh thanks for pointing it out! I've updated it so clicking on the diagram opens it up directly
mirdaki··on My Self-Hosting Setup
That is a great question I don't actually know the answer to. I need to grab something to track it
mirdaki··on My Self-Hosting Setup
I found the Tailscale client experience is quite nice and headscale had built in OIDC support (so easy auth for my users)

If I started this setup later I might have also used pangolin, which also provides a nice management interface on top of WireGuard https://github.com/fosrl/pangolin

mirdaki··on My Self-Hosting Setup
Yes it is, rock on!
mirdaki··on My Self-Hosting Setup
Thank you for the work and the kind words! I've had a great experience with LLDAP. Really appreciate it
mirdaki··on My Self-Hosting Setup
It is something I considered. Ultimately I didn't want to depend on Clouflare (or any other provider) for something as core to my setup as my remote access

But it's a totally valid option, just not one that fit with my preferences

mirdaki··on My Self-Hosting Setup
I do have to sit down and walk folks through setting up Tailscale, Nextcloud, etc on their devices. So far though, I haven't had any complaints once that is done. Nextcloud just syncs in the background and they can navigate to sites like normal. But my family is probably more tech literate than most, so that helps
mirdaki··on My Self-Hosting Setup
It's entirely because I've used it before. I just wanted something familiar to solve a problem quickly. I also think it looks nice. I'm not too worried about the security implications, since it is behind Tailscale and Authelia. I'm not committed to it, and do want to explore other options in the future
mirdaki··on My Self-Hosting Setup
I've done two kinds of testing

On my NixOS laptop I you can setup services I'm interested in trying, but just run them locally. So I don't setup things like SSL (you can, it sometimes just makes getting a new SSL cert for that same domain take some time). I just update my /etc/hosts to the local IP and can give that a go

For trying out the more complicated setup parts, like SSL, Tailscale, etc, I created a NixOS VM that I setup the same way I wanted for my "production" use case. Once I have the config file the way I wanted, it's as simple as moving it to my non test VM (baring previous mentioned SSL issues). And I only tested one part at a time, adding them together as I went

But also, one of the great things about NixOS is it's really easy to incrementally try things and rollback. Once I got the skeleton of the setup working, I've mostly done my testing on my "production" server without issue

mirdaki··on My Self-Hosting Setup
The big difference for me was NixOS provides really simple rollbacks if something goes wrong, where with Ansible and compose files, that's possible, but you have to do it yourself

But also if you're setup is working for you, I think that's great! It sounds like you have a good system in place

mirdaki··on My Self-Hosting Setup
With previous setups, I was certainly guilt of not upgrading and doing the maintenance needed. That's one reason why I like using NixOS and ZFS. Both provide really easy rollback options. So all I need to do is run an update and rebuild. If things work, no more for me to do. If things don't, I can try debugging or just revert back to the previous release till I have time to

But also I think using a cloud provider is fine if you're happy with the experience. It is a time sink to get things setup and it's not zero maintenance time. It's reasonable to weight those costs

mirdaki··on My Self-Hosting Setup
The services we use, like Nextcloud or Mealie, are designed for folks to have their own user accounts. SSO means they can use the same login across all of them without me having to manage that for them (and also avoids me having to know their passwords). It does complicated the setup, but not the operation, and that makes it more likely folks will use the services
mirdaki··on My Self-Hosting Setup
Thank you! The naming add a little bit of extra fun to it
mirdaki··on My Self-Hosting Setup
Nice! I have a friend who is starting to program his infrastructure/services from scratch. It's a neat way to learn and make things fit well for your own needs
mirdaki··on My Self-Hosting Setup
Oh yeah, I don't think the way I went about it was necessarily the most cost effective. I bought half of them on sale one year, didn't get around to setting things up, then bought the other two a year later on another sale once I finally got my server put together. I got them before I had my current plan in place. At one point I thought about having more services in a Kubernets cluster or something, but dropped that idea

Also agree, RAID isn't a replacement for a backup. I have all my important data on my desktop and laptop with plans for a dedicated backup server in the future. RAID does give you more breathing room if things go wrong, and I decided that was worth it

mirdaki··on My Self-Hosting Setup
This article (https://xeiaso.net/blog/paranoid-nixos-2021-07-18/) walks through a lot of the steps I've done on all my NixOS systems

As for Nextcloud vs a restic server, Nextcloud is heavier, but I do benefit from it's extra features (like Calendar and Contact management) as well as use a couple of apps (Memories for photos is quite nice). Plus it's much more family friendly, which was a core requirement for my setup

mirdaki··on My Self-Hosting Setup
I've found a lot of docs (Proxmox and TrueNAS are both guilty of this) assume you have existing domain or tool knowledge. I'd recommend checking out some videos from selfhosting YouTubers. They often explain more about what's actually happening than just what buttons to select

Also, I found TrueNAS's interface a little more understandable. If Proxmox isn't jiving with you, you could give that a try

mirdaki··on My Self-Hosting Setup
I think that's a fair point. Kinda like with Arch, you do have to know what you want to setup NixOS right now

I really like what's happening in the ublue space were folks are tweaking and optimizing distros for specific use cases (like bazzite for gaming) and then sharing them

NixOS does support that to an extent, but it certainly doesn't have the same community movement behind it like those

mirdaki··on My Ultimate Self-Hosting Setup
Lol, yeah. It was a journey to get to it, and a slightly shorter journey to feel comfortable with it, but it has won me over
mirdaki··on My Self-Hosting Setup
Everyone will have different goals and preferences. For instance, my dad just wanted a way to backup and remotely access some files, so we got him a Synology NAS. It's great for it's target users and if you're one of them, awesome!

I just don't like the lock-in that you get Synology. Plus I do enjoy tinkering with these things, so I wanted to put together something that balances usability, complexity while minimizing that lock-in

mirdaki··on My Ultimate Self-Hosting Setup
Agree. If low cost and maximum value is you're goal, grab a used one of these or similar speed laptop (and you sort of get battery back up in that case)

Really, any machine from the last decade will be enough, so if you or someone you know have something lying around, go use that

The two main points to keep in mind are power draw (older things are usually going to be worse here) and storage expandability options (you may not need much storage for your use case though). Worse case you can plug in a USB external drive, but bare in mind that USB connection might be a little flaky

mirdaki··on My Self-Hosting Setup
I think planning for what happens once you aren't there to manage the setup (whether it be a vacation, hospital stay, or death) is important. It's not something I built specifically to make easy and I should think more on it

The most important thing is to be able to get important data off of it and have access to credentials that facilitate that. You could setup something like Nextcloud to always sync important data onto other people's devices, so make part of that easier

But I think another important aspect is making folks invested in the services. I don't expect my partner to care about or use most of them, but she does know as much as I do about using and automating Home Assistant (the little we've done). Things like that should keep working because of how core they can become to living our lives. It being a separate "appliance" and not a VM will also help manage that

But also that's a lot of hope and guessing. I think sitting down with whoever might be left with it and putting together a detailed plan is critical to any of that being successful

mirdaki··on My Self-Hosting Setup
No I haven't heard of it before. I do like the idea though, especially for side projects. Thanks for sharing, I'll look more at it!
mirdaki··on My Self-Hosting Setup
I certainly didn't take to Nix the first few times I looked at it. The language itself is unusual and the error messages leave much to be desired. And the split around Flakes just complicates things further (though I do recommend using them, once you set it up, it's simple and the added reproducibility gives nice peace of mind)

But once I fully understood how it's features really make it easy for you to recover from mistakes and how useful the package options available from nixpkgs are, I decided it was time to sink in and figure it out. Looking at other folks nix config on GitHub (especially for specific services you're wanting to use) is incredibly helpful (mine is also linked in the post)

I certainly don't consider myself to be a nix expert, but the nice thing is you can do most things by using other examples and modifying them till you feel good about it. Then overtime you just get more familiar with and just grow your skill

Oh man, having a 25U rack sounds really fun. I have a moderate size cabinet I keep my server, desktop, a UPS, 10Gig switch, and my little fanless Home Assistant box. What's yours look like?

I should add it to the article, but one of my anti-requirements was anything in the realm of high availability. It's neat tech to play with, but I can deal with downtime for most things if the trade off is everything being much simpler. I've played a little bit with Kubernetes at work, but that is a whole ecosystem I've yet to tackle

mirdaki··on My Self-Hosting Setup
Appreciate that! Simple login and access was certainly the hardest requirement to hit, but it can be the difference between people using something and not

And I agree with the feeling that open source is everywhere, up until a regular user picks up something. I think part of the paradox you mention is that every project is trying to work on their own thing, which is great, but also means there isn't a single entity pushing it all in one direction

But that doesn't mean we can't get to nice user experiences. Just in the self-hosting space, things have gotten way more usable in the last 5 years, both from a setup and usage perspective

Page 1 of 2Next →