wew new #ArgoCD and #cloudflared tunnel for the #AREDN connected #RaspberryPi 5
still a lot more to do but this has been on my agenda for waaaaaay too long.
wew new #ArgoCD and #cloudflared tunnel for the #AREDN connected #RaspberryPi 5
still a lot more to do but this has been on my agenda for waaaaaay too long.
Gah, so I'm really struggling with a docker image for #nextcloud. I'm able to get it working just fine in a docker image with a #cloudflared tunnel, but for some reason, even though I was able to add an additional network for my local network, the "trusted_domains" setting just isn't working.
Here's how to setup the URL shortener @shlinkio with Docker and a Cloudflare Tunnel
https://thedxt.ca/2024/11/shlink-with-docker-and-cloudflare-tunnel/
Bruh I'm still so confused about this - can any #networking people or anyone with #PiHole/#Pi-hole experience chime in and tell if my goal is privacy, and if I were to prioritise one, it'd be better privacy against my ISP, what should I use on my Pi-hole DNS server?
- #Unbound as a recursive DNS server (my interpretation of this route is, it's the best privacy vs 3rd party DNS - but I'm assuming it's the worst privacy vs ISP?)
- Enable #DNS-Over-TLS (#DoT) using Unbound and upstream DNS provider set to something like #Cloudflare
- or Enable #DNS-Over-HTTPS (#DoH) using #Cloudflared
I initially thought you could have Pi-hole run with all three (I have a feeling this a really stupid noob networking moment right here) but I don't think so, no?
I'm not sure this is better than no manual at all.
#cloudflared #archlinux
Have lots of tasks outside of my #homelab, so there is almost nothing that happened inside.
I stopped using #Synology #NAS built-in reverse proxy for external access to #HomeAssistant. Now it is through the #Cloudflare tunnel: https://github.com/brenner-tobias/addon-cloudflared
Also, there are no non-Hue smart plugs left in my #SmartHome. It was a surprise for me that every #Philips #Hue smart plug is a light entity, not a switch.
Happy Friday, fediverse!
Despite some WiFi issues at the beginning, #Synology RT6600ax is the best home #router I ever had. It's like #Asus but with modern UI and some additional features for #HomeLab.
I finally have a separate #VLAN for my public services and potentially misconfigured Linux containers.
I also replaced #Traefik with the #cloudflare tunnel and I like it.
Oh, and I fixed my broken #AdGuardHome. Its only upstream was a DoH, but DoHs were not allowed on a router to make traffic monitoring more precise.
How's your weekend?
@poes @yonle klo mo tes #snac pake cara ane aja, ambil file docker-compose.yml
nya jalanin trus pake #cloudflared
Thinking about my (still WIP) #PiHole setup. AFAICT, the guide for #DoH with #cloudflared at https://docs.pi-hole.net/guides/dns/cloudflared/ only coveres using DoH between the PiHole and the upstream DNS provider (e.g., Cloudflare, Google, etc.). But if I want to use DoH between my browser and my PiHole, I seem to need another DoH Proxy, which makes request flow like this:
1. incoming on dns.ljrk.org:443 (traefik reverse proxy)
2. forwarded to 127.0.0.1:80 (DoH Proxy #1)
3. upstream classic DNS resolver on 127.0.0.1:53 (PiHole)
4. forwards any non-blocked requests to 127.0.0.1:5053 (DoH Proxy #2)
5. upstream DoH DNS resolver such as 1.1.1.1:443/dns-request
Of course, most PiHole setups are local and I'll probably end up opening dns.ljrk.org only through a #TailScale/#HeadScale #VPN, but my browser may still prefer to speak DoH instead of RFC1035. I'm also not sure how #DNSSEC plays into this...
Ahora con el proyecto iniciado de #selfhosting, tengo una duda para los que son expertos y saben mucho más que yo:
Aunque lo único que haría público sería un sitio web/blog, en teoría al haber un túnel con #cloudflared ya toda la infraestructura está (más o menos) expuesta al internet. ¿Será suficientemente seguro, o mejor me pongo a estudiar el uso de #NginxProxyManager como segunda capa?
#knative on #raspberrypi with #springboot native compiled for #arm64 made publicly available by connecting #cloudflared to to the #ingress
I setup #ingress to point to #Springcloudgateway which handles the routing to the other services.
@jitteringrunt @compulsivecyclist @eskibrew +1 to using #NabuCasa for #Alexa and #GoogleHome integrations. While I'm using #cloudflared for tunnels, I think it's worthwhile to pay for nabu.casa to support the devs and get the much nicer integrations.
@byron_miller I would use a Cloudflare tunnel using an addon in homeassistant called #CloudFlared very easy to setup and you can use a free domain name from #freenom at https://www.freenom.com
@HalsandRey hubo.be is always the last place I check because their website is #Cloudflared & I boycott businesses that use Cloudflare. But despiration brought me there after looking everywhere else, and Hubo did not have flared fittings. I appreciate the suggestion though.
Clarification: I didn't even look at pricing for 11 #VirtualMail services because they’re #Cloudflared.. so when I said “the 3 cheapest” I should have said “3 cheapest non-Cloudflare services”
@dachary @fedeproxy @werwolf Note that #Gitlab.com is a much bigger offender here. Gitlab is a #Cloudflared tor-hostile walled-garden, where I cannot even /view/ bug reports (unless I were to hypothetically solve their captcha)
@joerebelloharley @josias @nytpu @scifirenegade well in any case, staying off Tor means your reality is a subset of others, which means unwittingly posting links that not everyone can visit. There are some plugins you can use that will tell you if a site is #Cloudflared, so that you know when others will be blocked.