• 4 Posts
  • 51 Comments
Joined 1 year ago
cake
Cake day: March 27th, 2025

help-circle









  • Oh yeah. https://hub.docker.com/r/linuxserver/wireguard

    Basically, docker can and does create network devices. It’s as easy for it to create wg0’s as it is to create networks for your other docker containers. If you’re going to run wireguard and docker, you’re better off to let docker handle the network routing and just run one of the various containers out there to stop them from fighting. That particular container is more general. You can run it client or server. Wg-easy, I believe is server-only, or even hide it inside other containers like docker-qbittorrent-wireguard, where it just hangs out and connects to whatever .conf you give it.

    I did the whole thing in my early days selfhosting where I installed wireguard, docker, some apps, rebooted, everything breaks.

    Install a wireguard container, configure it as you would, your apps, reboot… it still works, because docker isn’t conflicting with native wg-quick. It’s either this, or untangle and make an iptables setup permanent so when you reboot, it doesn’t break again.








  • I use restic in combination with rsync.

    Two days ago, I tried to setup unbound and fucked up my Nextcloud instance on the same host.

    Restic restored /opt, /etc, /home and /var and then I used rsync to divvy them all out. For some reason, restic didn’t recognize the --delete flag so, rsync it was.

    Reboot, waited 3 minutes, reload, there’s my Nextcloud login screen. Database cleaned up using occ commands and I’m back.

    My restic repo sits on my main NAS, and a copy of it on another system. It holds all of my host’s aforementioned directories for easy setup and restore from either bad luck or dumb ideas.

    …usually dumb ideas.




  • A while back there was a situation where outsiders could get the name of the contents of your Jellyfin server, which would incriminate anyone. I believe it’s patched now, but I don’t think Jellyfin is winning any security awards. It’s a selfhosted media server. I have no frame of reference for knowing whether or not any of my information was overkill and I’m sure there are even some out there that would say I didn’t go far enough, even.