Watch out to not accidentally make a typo and change a vowel. Otherwise pacman will be upset and sabotage your install.
Elvith Ma'for
Former Reddfugee, found a new home on feddit.de. Server errors made me switch to discuss.tchncs.de. Now finally @ home on feddit.org.
Likes music, tech, programming, board games and video games. Oh… and coffee, lots of coffee!
I � Unicode!
- 1 Post
- 342 Comments
No, that’s just another hypothetical app that you’re using a reverse proxy for. I just included it to show how you can also set settings for a single subdomain/reverse proxy entry that isn’t used globally on all domains that get served. I used a hypothetical REST API that needs a CORS Header that other apps don’t need (or maybe serve themselves).
admin offdisables Caddy’s admin interface (which shouldn’t be public and if you’re using config files this usually isn’t needed. So just a bit of gardening)serverssets some general server options.and then I just inserted several blocks that each define a reverse proxy to a different app / backend to show that you can just dump them all in a single Caddyfile. And the last example to show that you can set specific settings only for a specific subdomain instead of globally. As I set headers mostly used by REST APIs, I just called that
api.example.cominstead ofapp3.example.com.
If you like, I can send you an example of the Caddyfiles, that I’m using (I used the import directive to split every service into its own Caddyfiles, you could just copy and paste everything in the same file). It will take a few hours until I get home, though.
But basically you can just put every subdomain and it’s target in a separate block and the add some things globally (e.g. passing the original IP, switching off the admin API of Caddy,…)
Something like this should work:
admin off servers { client_ip_headers X-Forwarded-For X-Real-IP } app.example.com { reverse_proxy 127.0.0.1:8080 } app2.example.com { reverse_proxy 127.0.0.1:8081 } api.example.com { reverse_proxy 127.0.0.1:8082 header { Access-Control-Allow-Methods "GET, OPTIONS" Access-Control-Allow-Origin "*" } }
Go ahead and give them your Social Security number, and see what happens.
“Socially I’m rated 3/10, but for security I’m an 8/10. Now that I’m replying to this, I think my security score just dropped a bit, though.”
Yes, but at least they do admit it. It’s way worse if you post “help, XY isn’t working, how can I solve this?” and someone posts an AI answer without disclosing it. It cloud be right, but more often than not you’re now exchanging comments with someone who will just feed your output into an LLM and basically paste its answers back. Worse if they just summarize it so that you don’t easily see this happening (e.g. summarize the output and just copy&paste the necessary commands/config entries,…)
And that’s a waste of time. I could ask $LLM directly for that.
Elvith Ma'for@feddit.orgto
Technology@lemmy.world•Microsoft Teams can record office presence from DecemberEnglish
402·15 days agoI mean… Is it really spying? Your company can detect which AP or Switch you’re connected to (or if you’re using a VPN from home), so they do have that data anyways.
WTF?
I mean, my work PC is managed by the company and thus a Windows device, but why disable that feature? Yes, it somewhat makes sense if you see it like “we don’t want other OS to have all features to make costumers less likely to switch” BUT Teams on Mac has some unique features that haven’t been ported to windows and are still exclusively available on Mac, so…?!
Elvith Ma'for@feddit.orgto
Selfhosted@lemmy.world•Internal domain and reverse proxyEnglish
1·16 days agoYeah, that’s exactly why I didn’t use my own CA. There’s a plethora of devices that you now need to import the CA to and then you need to hope, that every application uses the system cert store and doesn’t roll its own (IIRC e.g. Firefox uses its own cert store and doesn’t use the system cert store. Same for every java based application,…)
It’s fiddly with Caddy, as you need a specific plugin to get it to work with anything else than the default challenge. That means using a custom build via caddy - and with docker, you’re SOL. BUT you can just use certbot and point caddy to the cert file in your file system.
Elvith Ma'for@feddit.orgto
Selfhosted@lemmy.world•Internal domain and reverse proxyEnglish
14·17 days agoI have this setup. I bought a domain (say homeserver.tld) from a registrar that allows zone edits with an API. Then I use certbot with a plugin that supports my registrar to get real Let’s Encrypt certificates. Usually Let’s encrypt connects to your server to ensure that it responds to the domain you’re requesting a certificate for, but this challenge can also be done by editing the DNS record of your domain to prove ownership. That is called DNS-01 challenge and is useful of your domain is not publicly reachable. Google for certbot DNS-01 your registrar to find some documentation.
Some of the VMs/LXC now get certificates for a specific subdomain (“some-app.homeserver.tld”), other just get a wildcard certificate (“*.homeserver.tld”) - e.g. my docker host.
Elvith Ma'for@feddit.orgto
Lemmy Shitpost@lemmy.world•If you want to be classy and impress people
3·17 days agoWouldeth youeth liketh toeth seeth myeth dicketh?
Elvith Ma'for@feddit.orgto
Technology@lemmy.world•The AWS Outage Bricked People’s $2,700 SmartbedsEnglish
3·20 days agoWasn’t it also some kind of DNS problem on top?
Elvith Ma'for@feddit.orgto
Technology@lemmy.world•AWS crash causes $2,000 Smart Beds to overheat and get stuck uprightEnglish
1·20 days agoJust use the terms as every layman does:
- Dumb X <- offline/manual/no app (or none that works if you’re not in your home network/no cloud
- Smart X <- requires a increasingöy more costly monthly subscription, spies on you and shits itself on the thought of losing internet access. Usually yields worse results than Dumb X
In this case, she just wanted to make sure that everything is off and without current before the vacation and since I told her to not trip that one breaker, she unplugged some seemingly unrelated cables and just unplugged the wrong one
My wife: accidentially unplugs homeservers (with PiHole running)
Also my wife: the internet is down?!
For effective shitposting, right?
Yes, but many modern mainboards do feature two UEFI copies and can switch to the backup on the fly - and most let you restore a bricked UEFI from a USB drive. Not sure if this can help here or even work on this situation, but it might be worth a try.
PC / General:
- Nextcloud with Collabora Office CODE Server for Filesync and Online editing. I also setup STUN and TURN for Nextcloud Talk, which I use to groupcall friends for virtual board game nights. And I use Deck as a Kanban-Board.
- Bitwarden/Vaultwarden - I do not need to say more, I think.
- Firefox + uBlock Origin. This combo also works on mobile, so… Good Bye ads!
- Thunderbird. Also available on Android. Though Thunderbird Mobile is the same as K9 Mail, but reskinned IIRC.
- PiHole (at least in my home network). Same as above, but also (somewhat) blocks ads in proprietary apps/devices. Even works on the ad supported tier of streaming services to at least reduce ads.
- SearXNG - Meta search engine, that you can self host. There are public instances, but if you want full control over the available feature set/ available search engines, etc. just host it yourself.
- I host a private instance of an unofficial open source web app of the board game Terraforming Mars, as one person in our game group has incompatible hardware for the official implementation. One of the options for the mentioned virtual board game nights.
- Jellyfin. My BluRay Player died. I had most of my library ripped anyways, so… I finally got around to set it up.
On Android:
- DAVx5 and ICSx5 to Sync contacts and calendar with my Nextcloud.
- Etar Calendar. It’s a simple calendar. Just a simple “no bullshit” app. I like it.
- Firefox/uBlock Origin/K9 Mail
- Signal/Threema/SchildiChat(Matrix) - secure messengers
- OSMAnd/Street complete/Organic Maps - all three are Open Street Map apps. OSMAnd is the killer-app that does everything. Organic Map for a more streamlined experience. Street complete, to quickly contribute to OSM by doing “quests” (= answer questions) in your surroundings to fill in incomplete data. (Street names, types of streets, house numbers, opening times, is X still here?,…)
- Shattered Pixel Dungeon. Roguelike Dungeon Crawler, high quality. Looks easy, but hard to master.
- Lichess - Chess app/plattform.
- Öffi - Germany centered, but also somewhat usable in other places. Open Source public transit app, with many integrations of local and national networks. The developer has had some problems with Google and their app review process (IIRC regarding donation instructions?), so better to get it from FDroid, where updates are not blocked by some company policy…






370 to go